Password Storage Vulnerability in Data Center Expert by Schneider Electric
CVE-2022-32519

8HIGH

Key Information:

Vendor
CVE Published:
30 January 2023

Summary

A vulnerability exists in Schneider Electric’s Data Center Expert, where passwords are stored in a recoverable format. This can lead to unauthorized access to a DCE instance if exploited by a malicious third-party over a network connection. It is crucial for users of affected versions to update to version V7.9.0 or later to mitigate this risk and enhance the security posture of their data center management.

Affected Version(s)

Data Center Expert All

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.