Remote Code Execution Vulnerability in StruxureWare by Schneider Electric
CVE-2023-25549
7.2HIGH
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 18 April 2023
What is CVE-2023-25549?
A vulnerability exists in StruxureWare Data Center Expert that enables attackers to execute arbitrary code remotely through improper control of the DCE network settings parameter. This flaw, categorized as CWE-94: Improper Control of Generation of Code ('Code Injection'), poses significant security risks, allowing unauthorized users to take control of the affected system. Effective measures should be implemented to mitigate these risks and secure your infrastructure.
Affected Version(s)
StruxureWare Data Center Expert All