Schneider-electric

Data Center Expert

6 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Published 11.10.2024 14:15:06
  • Last modified 15.10.2024 12:58:51

CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could compromise the Data Center Expert software when an upgrade bundle is manipulated to include arbitrary bash scripts that are executed as root.

  • EPSS 0.11%
  • Published 11.10.2024 14:15:05
  • Last modified 15.10.2024 12:58:51

CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause exposure of private data when an already generated “logcaptures” archive is accessed directly by HTTPS.

  • EPSS 0.16%
  • Published 30.01.2023 23:15:10
  • Last modified 21.11.2024 07:06:32

A CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in unwanted access to a DCE instance when performed over a network by a malicious third-party. This CVE is unique from CVE-2022-32520. Affected Products: Data Cent...

  • EPSS 0.19%
  • Published 30.01.2023 23:15:10
  • Last modified 21.11.2024 07:06:32

A CWE-257: Storing Passwords in a Recoverable Format vulnerability exists that could result in unwanted access to a DCE instance when performed over a network by a malicious third-party. Affected Products: Data Center Expert (Versions prior to V7.9.0...

  • EPSS 0.16%
  • Published 30.01.2023 23:15:10
  • Last modified 21.11.2024 07:06:32

A CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in unwanted access to a DCE instance when performed over a network by a malicious third-party. This CVE is unique from CVE-2022-32518. Affected Products: Data Cent...

  • EPSS 0.66%
  • Published 30.01.2023 23:15:10
  • Last modified 21.11.2024 07:06:32

A CWE 502: Deserialization of Untrusted Data vulnerability exists that could allow code to be remotely executed on the server when unsafely deserialized data is posted to the web server. Affected Products: Data Center Expert (Versions prior to V7.9.0...