📦 Struxureware Data Center Expert

by Schneider Electric

🔍 What is Struxureware Data Center Expert?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-22794

CRITICAL CVSS 9.1 Apr 13, 2022

This path traversal vulnerability in StruxureWare Data Center Expert allows attackers to access files outside the intended directory, potentially leading to remote code execution. It affects Data Cent...

CVE-2023-37196

HIGH CVSS 8.8 Jul 12, 2023

This SQL injection vulnerability in Schneider Electric's DCE (Data Center Expert) allows authenticated attackers to manipulate endpoint alert settings to access unauthorized data, modify or delete con...

CVE-2023-25547

HIGH CVSS 8.8 Apr 18, 2023

This vulnerability allows low-privileged users to upload and install packages, potentially leading to remote code execution on affected StruxureWare Data Center Expert systems. Attackers with basic us...

CVE-2023-25549

HIGH CVSS 7.2 Apr 18, 2023

This vulnerability allows remote code execution through code injection in the DCE network settings endpoint of StruxureWare Data Center Expert. Attackers can execute arbitrary code on affected systems...

CVE-2023-25552

HIGH CVSS 8.1 Apr 18, 2023

This vulnerability in StruxureWare Data Center Expert allows attackers to bypass authorization controls and perform unauthorized actions like viewing, modifying, or deleting content by tampering with ...

CVE-2023-25554

HIGH CVSS 7.8 Apr 18, 2023

This CVE describes a local OS command injection vulnerability in StruxureWare Data Center Expert that allows authenticated local users to execute arbitrary commands with elevated privileges. It affect...