Fiche vulnérabilité
CVE-2023-37199 : faille élevée schneider-electric struxureware data… (CVSS 7.2)
Description
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE tampers with backups which are then manually restored.
En bref
- Sévérité
- Élevée (CVSS 7.2)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 12 juil. 2023
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- schneider-electric struxureware data center expert