Vulnerabilities > Schneider Electric > Struxureware Data Center Expert > 7.8.1

DATE CVE VULNERABILITY TITLE RISK
2023-04-18 CVE-2023-25553 Unspecified vulnerability in Schneider-Electric Struxureware Data Center Expert
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists on a DCE endpoint through the logging capabilities of the webserver.
network
low complexity
schneider-electric
6.1
2023-04-18 CVE-2023-25554 Unspecified vulnerability in Schneider-Electric Struxureware Data Center Expert
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that allows a local privilege escalation on the appliance when a maliciously crafted Operating System command is entered on the device. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
local
low complexity
schneider-electric
7.8
2023-04-18 CVE-2023-25555 Unspecified vulnerability in Schneider-Electric Struxureware Data Center Expert
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow a user that knows the credentials to execute unprivileged shell commands on the appliance over SSH.
network
high complexity
schneider-electric
8.1
2022-04-13 CVE-2021-22794 Unspecified vulnerability in Schneider-Electric Struxureware Data Center Expert
A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution.
network
low complexity
schneider-electric
critical
9.8
2022-04-13 CVE-2021-22795 Unspecified vulnerability in Schneider-Electric Struxureware Data Center Expert
A CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when performed over the network.
network
low complexity
schneider-electric
critical
9.8