Code Injection Vulnerability in DCE by Schneider Electric
CVE-2023-37198
6.8MEDIUM
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 12 July 2023
What is CVE-2023-37198?
A vulnerability exists in Schneider Electric's DCE that allows an admin user to upload or manipulate install packages, leading to a risk of remote code execution. The flaw is categorized as a code injection issue, which could be exploited by an attacker to execute arbitrary code within the application. This vulnerability places a significant risk on systems utilizing vulnerable versions of the product, highlighting the need for immediate mitigation and patching.
Affected Version(s)
StruxureWare Data Center Expert v7.9.3 and earlier