HIGH🇬🇧 English

CVE-2023-27975

CVSS 7.1v3.1pub. 2024-02-14upd. 2024-12-11

CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized access to the project file in EcoStruxure Control Expert when a local user tampers with the memory of the engineering workstation.

oryginał EN
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
  • Schneider Electric Ecostruxure Control Expert

    APP
    Schneider-Electric
    < 16.0
  • Schneider Electric Ecostruxure Process Expert

    APP
    Schneider-Electric
    < 2023
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2022-37300CRITICAL9.8PL ✓ten sam produkt

Słaby mechanizm odzyskiwania hasła w produktach Schneider Electric — dostęp przez Modbus

CVE-2022-26507CRITICAL9.8PL ✓ten sam produkt

Heap-based buffer overflow w AT&T Xmill — możliwe zdalne wykonanie kodu

CVE-2021-22779CRITICAL9.1PL ✓ten sam produkt

Authentication Bypass w produktach Schneider Electric via Modbus Spoofing

CVE-2020-28212CRITICAL9.8PL ✓ten sam produkt

Brak limitu prób uwierzytelnienia w PLC Simulator EcoStruxure Control Expert

CVE-2020-7475CRITICAL9.8PL ✓ten sam produkt

Injection (reflective DLL) w produktach Schneider Electric — przesyłanie złośliwego kodu do sterownika