The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric StruxureWare Data Center Expert version V7.9.3 and prior
- Summary
- A CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to access unauthorized content, change, or delete content, or perform unauthorized actions when tampering with the alert settings of endpoints on DCE.
- Remediation
- Version 8.0 of EcoStruxure™ IT Data Center Expert (Formerly StruxureWare Data Center Expert) includes fixes for these vulnerabilities and is available on request from Schneider Electric’s Customer Care Center.
