Schneider-electric
Schneider-electric Struxureware Data Center Expert: vulnerabilidades y CVE
Schneider-electric Struxureware Data Center Expert tiene 49 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE49
Últimos 12 meses1
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-8045 | Alta (7.1) | 0.39% | — | 9 jun 2026 | CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert user account submits… |
| CVE-2023-37199 | Alta (7.2) | 0.86% | — | 12 jul 2023 | A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE tampers with backups which are then manually restored. |
| CVE-2023-37198 | Alta (7.2) | 0.86% | — | 12 jul 2023 | A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE uploads or tampers with install packages. |
| CVE-2023-37197 | Alta (8.8) | 0.60% | — | 12 jul 2023 | A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to access unauthorized content,… |
| CVE-2023-37196 | Alta (8.8) | 0.60% | — | 12 jul 2023 | A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to access unauthorized content,… |
| CVE-2023-25555 | Alta (8.1) | 0.82% | — | 18 abr 2023 | A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow a user that knows the credentials to execute unprivileged shell commands on the… |
| CVE-2023-25554 | Alta (7.8) | 0.59% | — | 18 abr 2023 | A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that allows a local privilege escalation on the appliance when a maliciously crafted Operating… |
| CVE-2023-25553 | Media (6.1) | 0.39% | — | 18 abr 2023 | A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists on a DCE endpoint through the logging capabilities of the webserver. Affected products: StruxureWare… |
| CVE-2023-25552 | Alta (8.1) | 0.50% | — | 18 abr 2023 | A CWE-862: Missing Authorization vulnerability exists that could allow viewing of unauthorized content, changes or deleting of content, or performing unauthorized functions when tampering the Device File Transfer… |
| CVE-2023-25551 | Media (6.1) | 0.40% | — | 18 abr 2023 | A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists on a DCE file upload endpoint when tampering with parameters over HTTP. Affected products: StruxureWare… |
| CVE-2023-25550 | Crítica (9.8) | 1.2% | — | 18 abr 2023 | A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows remote code execution via the “hostname” parameter when maliciously crafted hostname syntax is entered. Affected… |
| CVE-2023-25549 | Crítica (9.8) | 1.2% | — | 18 abr 2023 | A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows for remote code execution when using a parameter of the DCE network settings endpoint. Affected products: StruxureWare… |
| CVE-2023-25548 | Media (6.5) | 0.55% | — | 18 abr 2023 | A CWE-863: Incorrect Authorization vulnerability exists that could allow access to device credentials on specific DCE endpoints not being properly secured when a hacker is using a low privileged user. Affected products:… |
| CVE-2023-25547 | Alta (8.8) | 0.94% | — | 18 abr 2023 | A CWE-863: Incorrect Authorization vulnerability exists that could allow remote code execution on upload and install packages when a hacker is using a low privileged user account. Affected products: StruxureWare Data… |
| CVE-2021-22795 | Crítica (9.8) | 3.1% | — | 13 abr 2022 | A CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when performed over the network. Affected Product:… |
| CVE-2021-22794 | Crítica (9.8) | 2.2% | — | 13 abr 2022 | A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution. Affected Product: StruxureWare Data Center Expert (V7.8.1 and prior) |
| CVE-2018-7807 | Alta (8.8) | 1.3% | — | 30 nov 2018 | Data Center Expert, versions 7.5.0 and earlier, allows for the upload of a zip file from its user interface to the server. A carefully crafted, malicious file could be mistakenly uploaded by an authenticated user via… |
| CVE-2018-3693 | Media (5.6) | 8.6% | — | 10 jul 2018 | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a speculative buffer overflow and… |
| CVE-2018-1126 | Crítica (9.8) | 1.9% | — | 23 may 2018 | procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related to CVE-2018-1124. |
| CVE-2018-1124 | Alta (7.8) | 1.9% | — | 23 may 2018 | procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privilege escalation for a local attacker who can create entries in procfs… |
| CVE-2018-3639 | Media (5.5) | 61% | — | 22 may 2018 | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an… |
| CVE-2018-2815 | Media (5.3) | 5.1% | — | 19 abr 2018 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161;… |
| CVE-2018-2814 | Alta (8.3) | 4.0% | — | 19 abr 2018 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161. Difficult to… |
| CVE-2018-2811 | Alta (7.7) | 0.49% | — | 19 abr 2018 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Install). Supported versions that are affected are Java SE: 8u162 and 10. Difficult to exploit vulnerability allows unauthenticated attacker with… |
| CVE-2018-2800 | Media (4.2) | 5.2% | — | 19 abr 2018 | Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u181, 7u171 and 8u162; JRockit: R28.3.17. Difficult to exploit vulnerability… |
| CVE-2018-2799 | Media (5.3) | 15% | — | 19 abr 2018 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Java SE: 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit:… |
| CVE-2018-2798 | Media (5.3) | 7.4% | — | 19 abr 2018 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit:… |
| CVE-2018-2797 | Media (5.3) | 7.4% | — | 19 abr 2018 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JMX). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit:… |
| CVE-2018-2796 | Media (5.3) | 6.5% | — | 19 abr 2018 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Concurrency). Supported versions that are affected are Java SE: 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit:… |
| CVE-2018-2795 | Media (5.3) | 7.4% | — | 19 abr 2018 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161;… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Schneider-electric
Interactive Graphical Scada System · 43Modicon M580 Firmware · 41Modicon M340 Firmware · 39Modicon M340 Bmxp342020 Firmware · 32Modicon M340 Bmxp3420302 Firmware · 28Modicon M340 Bmxp341000 Firmware · 27Ecostruxure Control Expert · 26Modicon M340 Bmxp342000 Firmware · 25Modicon Quantum Firmware · 25Modicon M340 Bmxp3420102 Firmware · 25Easergy T300 Firmware · 24U.motion Builder · 24