The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric StruxureWare Data Center Expert version V7.9.3 and prior
- Summary
- A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE tampers with backups which are then manually restored.
- Remediation
- Version 8.0 of EcoStruxure™ IT Data Center Expert (Formerly StruxureWare Data Center Expert) includes fixes for these vulnerabilities and is available on request from Schneider Electric’s Customer Care Center.
