A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS
Command Injection') vulnerability exists that could allow a user that knows the credentials to
execute unprivileged shell commands on the appliance over SSH.
Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-29507 | A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow a user that knows the credentials to execute unprivileged shell commands on the appliance over SSH. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior) |
Wed, 05 Feb 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: schneider
Published:
Updated: 2025-02-05T21:39:36.172Z
Reserved: 2023-02-07T17:00:03.780Z
Link: CVE-2023-25555
Updated: 2024-08-02T11:25:19.309Z
Status : Modified
Published: 2023-04-18T21:15:08.910
Modified: 2024-11-21T07:49:43.303
Link: CVE-2023-25555
No data.
OpenCVE Enrichment
No data.
EUVD