OS Command Injection Vulnerability in StruxureWare Data Center Expert by Schneider Electric
CVE-2021-22795
9.1CRITICAL
What is CVE-2021-22795?
A vulnerability exists in StruxureWare Data Center Expert that allows for OS command injection, enabling attackers to execute arbitrary commands remotely. This issue arises from inadequate sanitization of input, posing significant risks to the integrity and confidentiality of the managed systems. It is crucial for users of versions V7.8.1 and earlier to assess their exposure and apply necessary patches to mitigate potential threats.
Affected Version(s)
StruxureWare Data Center Expert < unspecified