Code Injection Vulnerability in StruxureWare Data Center Expert by Schneider Electric
CVE-2023-25550
7.2HIGH
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 18 April 2023
What is CVE-2023-25550?
A code injection vulnerability exists in StruxureWare Data Center Expert that enables remote code execution through the manipulation of the 'hostname' parameter. Attackers can exploit this vulnerability by submitting specially crafted inputs, leading to unauthorized execution of arbitrary code within the affected system.
Affected Version(s)
StruxureWare Data Center Expert All