The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric StruxureWare Data Center Expert version 7.9.2 and prior
- Summary
- A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow a user that knows the credentials to execute unprivileged shell commands on the appliance over SSH.
- Remediation
- Version 7.9.3 of StruxureWare Data Center Expert includes fixes for these vulnerabilities and is available on request from Schneider Electric’s Customer Care Center.
