A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that
allows for remote code execution when using a parameter of the DCE network settings
endpoint.
Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-29501 | A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows for remote code execution when using a parameter of the DCE network settings endpoint. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior) |
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: schneider
Published:
Updated: 2025-03-03T19:14:28.433Z
Reserved: 2023-02-07T17:00:03.778Z
Link: CVE-2023-25549
Updated: 2024-08-02T11:25:19.200Z
Status : Modified
Published: 2023-04-18T21:15:08.523
Modified: 2024-11-21T07:49:42.627
Link: CVE-2023-25549
No data.
OpenCVE Enrichment
No data.
EUVD