Lucene search

K
cveSchneiderCVE-2023-25554
HistoryApr 18, 2023 - 9:15 p.m.

CVE-2023-25554

2023-04-1821:15:08
CWE-78
schneider
web.nvd.nist.gov
22
2
cwe-78
os command injection
local privilege escalation
struxureware data center expert
vulnerability
cve-2023-25554

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.8

Confidence

High

EPSS

0

Percentile

15.5%

A CWE-78: Improper Neutralization of Special Elements used in an OS Command (‘OS
Command Injection’) vulnerability exists that allows a local privilege escalation on the appliance
when a maliciously crafted Operating System command is entered on the device.

Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)

Affected configurations

Nvd
Node
schneider-electricstruxureware_data_center_expertRange7.9.2
VendorProductVersionCPE
schneider-electricstruxureware_data_center_expert*cpe:2.3:a:schneider-electric:struxureware_data_center_expert:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "StruxureWare Data Center Expert",
    "vendor": "Schneider Electric",
    "versions": [
      {
        "lessThanOrEqual": "V7.9.2",
        "status": "affected",
        "version": "All",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.8

Confidence

High

EPSS

0

Percentile

15.5%

Related for CVE-2023-25554