Vulnerabilities > Schneider Electric > Struxureware Data Center Expert > 7.3.1

DATE CVE VULNERABILITY TITLE RISK
2023-04-18 CVE-2023-25553 Cross-site Scripting vulnerability in Schneider-Electric Struxureware Data Center Expert
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists on a DCE endpoint through the logging capabilities of the webserver.
network
low complexity
schneider-electric CWE-79
6.1
2023-04-18 CVE-2023-25554 OS Command Injection vulnerability in Schneider-Electric Struxureware Data Center Expert
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that allows a local privilege escalation on the appliance when a maliciously crafted Operating System command is entered on the device. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
local
low complexity
schneider-electric CWE-78
7.8
2023-04-18 CVE-2023-25555 OS Command Injection vulnerability in Schneider-Electric Struxureware Data Center Expert
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow a user that knows the credentials to execute unprivileged shell commands on the appliance over SSH.
network
high complexity
schneider-electric CWE-78
8.1
2022-04-13 CVE-2021-22794 Path Traversal vulnerability in Schneider-Electric Struxureware Data Center Expert
A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution.
network
low complexity
schneider-electric CWE-22
7.5
2022-04-13 CVE-2021-22795 OS Command Injection vulnerability in Schneider-Electric Struxureware Data Center Expert
A CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when performed over the network.
network
low complexity
schneider-electric CWE-78
7.5
2018-11-30 CVE-2018-7807 Path Traversal vulnerability in Schneider-Electric Struxureware Data Center Expert
Data Center Expert, versions 7.5.0 and earlier, allows for the upload of a zip file from its user interface to the server.
network
low complexity
schneider-electric CWE-22
6.5
2018-05-23 CVE-2018-1126 Integer Overflow or Wraparound vulnerability in multiple products
procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues.
7.5
2018-05-23 CVE-2018-1124 Integer Overflow or Wraparound vulnerability in multiple products
procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function.
4.6
2018-05-22 CVE-2018-3639 Information Exposure Through Discrepancy vulnerability in multiple products
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.
2.1
2018-04-19 CVE-2018-2815 Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). 5.3