Filtered by vendor Schneider-electric
Subscriptions
Filtered by product Data Center Expert
Subscriptions
Total
6 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2024-8530 | 1 Schneider-electric | 1 Data Center Expert | 2024-10-17 | 5.9 Medium |
CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause exposure of private data when an already generated “logcaptures” archive is accessed directly by HTTPS. | ||||
CVE-2024-8531 | 1 Schneider-electric | 1 Data Center Expert | 2024-10-15 | 7.2 High |
CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could compromise the Data Center Expert software when an upgrade bundle is manipulated to include arbitrary bash scripts that are executed as root. | ||||
CVE-2022-32521 | 1 Schneider-electric | 1 Data Center Expert | 2024-08-03 | 7.1 High |
A CWE 502: Deserialization of Untrusted Data vulnerability exists that could allow code to be remotely executed on the server when unsafely deserialized data is posted to the web server. Affected Products: Data Center Expert (Versions prior to V7.9.0) | ||||
CVE-2022-32520 | 1 Schneider-electric | 1 Data Center Expert | 2024-08-03 | 8 High |
A CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in unwanted access to a DCE instance when performed over a network by a malicious third-party. This CVE is unique from CVE-2022-32518. Affected Products: Data Center Expert (Versions prior to V7.9.0) | ||||
CVE-2022-32519 | 1 Schneider-electric | 1 Data Center Expert | 2024-08-03 | 8 High |
A CWE-257: Storing Passwords in a Recoverable Format vulnerability exists that could result in unwanted access to a DCE instance when performed over a network by a malicious third-party. Affected Products: Data Center Expert (Versions prior to V7.9.0) | ||||
CVE-2022-32518 | 1 Schneider-electric | 1 Data Center Expert | 2024-08-03 | 8 High |
A CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in unwanted access to a DCE instance when performed over a network by a malicious third-party. This CVE is unique from CVE-2022-32520. Affected Products: Data Center Expert (Versions prior to V7.9.0) |
Page 1 of 1.