The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric StruxureWare Data Center Expert 7.8.1 and prior.
- Summary
- A CWE-78:Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when performed over the network.
- Remediation
- Schneider Electric has established a remediation plan for future versions of StruxureWare Data Center Expert that will include a fix for these vulnerabilities. We will update this document when the remediation is available. Until then, customers should immediately follow security hardening guidelines found in https://dcimsupport.ecostruxureit.com/hc/en-us/articles/360039289633-Data-Center-Expert-Security-Handbook to reduce the risk of exploit.
