EcoStruxure IT Data Center Expert Security Notification
This document details multiple critical and high-severity vulnerabilities in EcoStruxure™ IT Data Center Expert versions 8.3 and prior, including OS command injection, insufficient entropy, code injection, SSRF, privilege escalation, and XML external entity injection. Schneider Electric recommends upgrading to version 9.0 to remediate these flaws, which could lead to unauthenticated remote code execution, information disclosure, and system compromise.
Failed to load PDF
Download insteadYou might also like
EcoStruxure System Advisor – Process Control Product Specification
10 pages
PowerLogic T500 Substation Controller Safety Guide
18 pages
Modicon M580 and Quantum Communication Modules VxWorks Vulnerability Security Notification
5 pages
TAC Vista OPC Client Manual
2 pages
TeSys Motor Starter Data Bulletin for North America
26 pages
Geo SCADA Expert 2021 Release Notes – September 2023 Update
71 pages
Andover Continuum i2865 and i2866 VAV Box Controllers with Built-in Damper Actuator
6 pages
100MPIR Modular PIR Sensor Product Data Sheet
2 pages
Easergy Studio Security Notification (CVE-2024-2747)
4 pages
SpaceLogic RTD-DI-16 I/O Module Manual
7 pages