CVEs (49)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Schneider Electric 1Struxureware Data Center Expert Jul 20, 2026 Jun 9, 2026 7.1 HIGH· v4 6.5 MEDIUM· v3 N/A· v2 CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert user account submits craf...Show more |
1Schneider Electric 1Struxureware Data Center Expert Jun 17, 2026 Jul 12, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that
could cause remote code execution when an admin user on DCE tampers with backups which
are then manually restored.
|
1Schneider Electric 1Struxureware Data Center Expert Jun 17, 2026 Jul 12, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that
could cause remote code execution when an admin user on DCE uploads or tampers with install
packages.
|
1Schneider Electric 1Struxureware Data Center Expert Jun 17, 2026 Jul 12, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to access unauthorized content, ch...Show more |
1Schneider Electric 1Struxureware Data Center Expert Jun 17, 2026 Jul 12, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to access unauthorized content, chan...Show more |
1Schneider Electric 1Struxureware Data Center Expert Jun 17, 2026 Apr 18, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow a user that knows the credentials to execute unprivileged shell co...Show more |
1Schneider Electric 1Struxureware Data Center Expert Jun 17, 2026 Apr 18, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that allows a local privilege escalation on the appliance when a maliciously crafted Operatin...Show more |
1Schneider Electric 1Struxureware Data Center Expert Jun 17, 2026 Apr 18, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists on a DCE endpoint through the logging capabilities of the webserver. Aff...Show more |
1Schneider Electric 1Struxureware Data Center Expert Jun 17, 2026 Apr 18, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 A CWE-862: Missing Authorization vulnerability exists that could allow viewing of unauthorized content, changes or deleting of content, or performing unauthorized functions when tampering the Device File Transfer sett...Show more |
1Schneider Electric 1Struxureware Data Center Expert Jun 17, 2026 Apr 18, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists on a DCE file upload endpoint when tampering with parameters over HTTP. Affec...Show more |
1Schneider Electric 1Struxureware Data Center Expert Jun 17, 2026 Apr 18, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows remote code execution via the “hostname” parameter when maliciously crafted hostname syntax is entered....Show more |
1Schneider Electric 1Struxureware Data Center Expert Jun 17, 2026 Apr 18, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows for remote code execution when using a parameter of the DCE network settings endpoint. Affected prod...Show more |
1Schneider Electric 1Struxureware Data Center Expert Jun 17, 2026 Apr 18, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A CWE-863: Incorrect Authorization vulnerability exists that could allow access to device credentials on specific DCE endpoints not being properly secured when a hacker is using a low privileged user. Affected produc...Show more |
1Schneider Electric 1Struxureware Data Center Expert Jun 17, 2026 Apr 18, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A CWE-863: Incorrect Authorization vulnerability exists that could allow remote code execution on upload and install packages when a hacker is using a low privileged user account. Affected products: StruxureWare Data Ce...Show more |
1Schneider Electric 1Struxureware Data Center Expert Jun 17, 2026 Apr 13, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when performed over the network. Affected Product: StruxureW...Show more |
1Schneider Electric 1Struxureware Data Center Expert Jun 17, 2026 Apr 13, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution. Affected Product: StruxureWare Data Center Expert (V7.8.1 and prior) |
1Schneider Electric 1Struxureware Data Center Expert Jun 17, 2026 Nov 30, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Data Center Expert, versions 7.5.0 and earlier, allows for the upload of a zip file from its user interface to the server. A carefully crafted, malicious file could be mistakenly uploaded by an authenticated user via thi...Show more |
7Arm FujitsuIntel+4 more225Atom C Atom EAtom X3+222 moreNov 21, 2024 Jul 10, 2018 N/A· v4 5.6 MEDIUM· v3 4.7 MEDIUM· v2 Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a speculative buffer overflow and side-channel...Show more |
5Canonical DebianProcps Ng Project+2 more10Debian Linux Enterprise LinuxEnterprise Linux Desktop+7 moreNov 21, 2024 May 23, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related to CVE-2018-1124. |
6Canonical DebianOpensuse+3 more9Debian Linux Enterprise LinuxEnterprise Linux Desktop+6 moreNov 21, 2024 May 23, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privilege escalation for a local attacker who can create entries in procfs b...Show more |