CVE Published: 12/07/2023 |
CVE Updated: 07/11/2024 |
CVE Year: 2023 Source: schneider |
Vendor: Schneider Electric |
Product: StruxureWare Data Center Expert Status : PUBLISHED
CVE-2023-37199 Description
A CWE-94: Improper Control of Generation of Code (\'Code Injection\') vulnerability exists that
could cause remote code execution when an admin user on DCE tampers with backups which
are then manually restored.
Metrics
CVSS Version: 3.1 |
Base Score: 6.8 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H