Command Injection Vulnerability in CX-Supervisor by Schneider Electric
CVE-2018-19013

5MEDIUM

Key Information:

Vendor

Ics-cert

Vendor
CVE Published:
22 January 2019

What is CVE-2018-19013?

A vulnerability exists in CX-Supervisor that allows an attacker to inject commands through a specially crafted project file. This can potentially enable unauthorized deletion of files or alteration of file contents, affecting project integrity and operational security. Users are advised to upgrade to the latest version to mitigate this risk.

Affected Version(s)

CX-Supervisor Versions 3.42 and prior

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.