ZeroHour

CVE-2023-37199

CVSS 3.1
7.2 high
EPSS
<1%p56
Published
()
Modified
Description

A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE tampers with backups which are then manually restored.

Vendors
schneider-electric
Products
struxureware data center expert
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.