Impact
The vulnerability is an improper neutralization of argument delimiters in a command, classified as CWE‑88. It allows an attacker who has a privileged account to inject arbitrary arguments into backup configuration parameters. If the attacker supplies malicious arguments, the underlying system may execute those arguments as commands, resulting in full remote code execution. This could compromise confidentiality, integrity, and availability of the data center infrastructure, potentially affecting all users and services that rely on it.
Affected Systems
Schneider Electric’s EcoStruxure™ IT Data Center Expert platform is affected. The advisory does not specify individual firmware or software build numbers, but all deployments of this product line are considered vulnerable until a vendor correction is applied.
Risk and Exploitability
The CVSS base score of 8.6 categorises the issue as high severity. EPSS data is not available, so the likelihood of exploitation cannot be quantified, but the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. The attack strongly relies on the attacker having privileged access to the configuration interface and the ability to supply custom backup configuration parameters. Thus, the primary threat vector is privileged local/remote configuration manipulation, and the consequence of a successful exploit is remote code execution.
OpenCVE Enrichment