Lucene search

K
cveSchneiderCVE-2023-25551
HistoryApr 18, 2023 - 9:15 p.m.

CVE-2023-25551

2023-04-1821:15:08
CWE-79
schneider
web.nvd.nist.gov
14
cve-2023-25551
cwe-79
cross-site scripting
struxureware data center expert
nvd
dce file upload endpoint

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

22.7%

A CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site
Scripting’) vulnerability exists on a DCE file upload endpoint when tampering with parameters
over HTTP.

Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)

Affected configurations

Nvd
Node
schneider-electricstruxureware_data_center_expertRange7.9.2
VendorProductVersionCPE
schneider-electricstruxureware_data_center_expert*cpe:2.3:a:schneider-electric:struxureware_data_center_expert:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "StruxureWare Data Center Expert",
    "vendor": "Schneider Electric",
    "versions": [
      {
        "lessThanOrEqual": "V7.9.2",
        "status": "affected",
        "version": "All",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

22.7%

Related for CVE-2023-25551