CVE Published: 11/10/2024 |
CVE Updated: 15/10/2024 |
CVE Year: 2024 Source: schneider |
Vendor: Schneider Electric |
Product: Data Center Expert Status : PUBLISHED
CVE-2024-8531 Description
CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could
compromise the Data Center Expert software when an upgrade bundle is manipulated to
include arbitrary bash scripts that are executed as root.
Metrics
CVSS Version: 3.1 |
Base Score: 7.2 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H