Unauthorized Access to Project File via Hard-coded Credentials
CVE-2023-6409
7.7HIGH
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 14 February 2024
Summary
A vulnerability exists in EcoStruxure Control Expert that involves the use of hard-coded credentials, leading to potential unauthorized access to projects secured by application passwords. This flaw allows attackers who exploit it to gain access to sensitive project files, compromising the overall security of the application and the integrity of the affected projects. It is crucial for users to evaluate their security measures and implement necessary updates to mitigate potential risks associated with this vulnerability.
Affected Version(s)
EcoStruxure Control Expert Versions prior to v16.0
EcoStruxure Process Expert Versions prior to v2023
References
CVSS V3.1
Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved