CVE-2024-8531
CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could compromise the Data Center Expert software when an upgrade bundle is manipulated to include arbitrary bash scripts that are executed as root.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.2
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.46%
- Percentil entre todas las CVEs puntuadas: 38
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1195Supply Chain Compromiseinitial access85 % - Impacto principal
T1059.004Unix Shellexecution80 % - Impacto secundario
T1068Exploitation for Privilege Escalationprivilege escalation75 %
Manipulación de bundle de actualización sin verificación criptográfica (CWE-347) permite inyectar scripts bash ejecutados como root, explotando la cadena de suministro (T1195) con ejecución de comando en shell de Unix (T1059.004) y escalada de privilegios (T1068).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-347
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-8531",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-8531",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-10-15T14:45:48.034295Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cybersecurity@se.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.2,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.2
}
]
},
"affected": [
{
"source": "cybersecurity@se.com",
"affectedData": [
{
"vendor": "Schneider Electric",
"product": "Data Center Expert",
"versions": [
{
"status": "affected",
"version": "Versions 8.1.1.3 and prior"
}
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:schneider-electric:data_center_expert:*:*:*:*:*:*:*:*"
],
"vendor": "schneider-electric",
"product": "data_center_expert",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "8.1.1.3"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-10-11T14:15:06.173",
"references": [
{
"url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-282-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-282-01.pdf",
"source": "cybersecurity@se.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "cybersecurity@se.com",
"description": [
{
"lang": "en",
"value": "CWE-347"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could\ncompromise the Data Center Expert software when an upgrade bundle is manipulated to\ninclude arbitrary bash scripts that are executed as root."
},
{
"lang": "es",
"value": "CWE-347: Existe una vulnerabilidad de verificación incorrecta de la firma criptográfica que podría comprometer el software Data Center Expert cuando se manipula un paquete de actualización para incluir scripts bash arbitrarios que se ejecutan como root."
}
],
"lastModified": "2026-06-17T08:22:48.310",
"sourceIdentifier": "cybersecurity@se.com"
}