Impact
A Server‑Side Request Forgery (SSRF) flaw has been identified that allows an attacker who holds a privileged account to send crafted, unvalidated parameters to a server endpoint. This can lead to the server executing unauthorized commands and exfiltrating sensitive data from the host. The weakness is defined by CWE‑918 and poses a direct threat to confidentiality, integrity, and availability of the affected system.
Affected Systems
The vulnerability affects Schneider Electric EcoStruxure IT Data Center Expert, previously known as StruxureWare Data Center Expert. No specific version numbers are disclosed in the CVE record.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity, and while an EPSS score is not provided, the absence of a KEV listing suggests no evidence of exploitation in the wild. The likely attack vector requires the attacker to possess privileged credentials, after which they can deliver malicious input to the vulnerable endpoint. Given the potential for remote code execution and data disclosure, the risk level is considered high.
OpenCVE Enrichment