Code Injection Flaw in Schneider Electric HMI Software
CVE-2023-1049
7.8HIGH
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 14 June 2023
What is CVE-2023-1049?
A code injection vulnerability exists within Schneider Electric's HMI software that can allow an adversary to execute unauthorized commands. This vulnerability is triggered when an unsuspecting user loads a project file from their local filesystem, potentially opening the door to malicious code execution. Proper precautions and security measures should be implemented to mitigate the risks associated with this vulnerability.
Affected Version(s)
EcoStruxure™ Operator Terminal Expert 3.3 SP1 and prior
Pro-face BLUE 3.3 SP1 and prior