CVE-2023-1049

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
14/06/2023
Last modified:
22/06/2023

Description

<br /> A CWE-94: Improper Control of Generation of Code (&amp;#39;Code Injection&amp;#39;) vulnerability exists that<br /> could cause execution of malicious code when an unsuspicious user loads a project file from the<br /> local filesystem into the HMI.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:schneider-electric:ecostruxure_operator_terminal_expert:*:*:*:*:*:*:*:* 3.3 (excluding)
cpe:2.3:a:schneider-electric:ecostruxure_operator_terminal_expert:3.3:-:*:*:*:*:*:*
cpe:2.3:a:schneider-electric:ecostruxure_operator_terminal_expert:3.3:sp1:*:*:*:*:*:*
cpe:2.3:a:schneider-electric:pro-face_blue:*:*:*:*:*:*:*:* 3.3 (excluding)
cpe:2.3:a:schneider-electric:pro-face_blue:3.3:-:*:*:*:*:*:*
cpe:2.3:a:schneider-electric:pro-face_blue:3.3:sp1:*:*:*:*:*:*