High severity8.1NVD Advisory· Published Apr 18, 2023· Updated Jun 17, 2026
CVE-2023-25552
CVE-2023-25552
Description
A CWE-862: Missing Authorization vulnerability exists that could allow viewing of unauthorized content, changes or deleting of content, or performing unauthorized functions when tampering the Device File Transfer settings on DCE endpoints.
Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
Affected products
3cpe:2.3:a:schneider-electric:struxureware_data_center_expert:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:schneider-electric:struxureware_data_center_expert:*:*:*:*:*:*:*:*range: <=7.9.2
- (no CPE)range: <=7.9.2
- (no CPE)range: All
Patches
Vulnerability mechanics
References
1- download.schneider-electric.com/filesnvdVendor Advisory
News mentions
0No linked articles in our index yet.