High severity8.8NVD Advisory· Published Jul 12, 2023· Updated Jun 17, 2026
CVE-2023-37196
CVE-2023-37196
Description
A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to access unauthorized content, change, or delete content, or perform unauthorized actions when tampering with the alert settings of endpoints on DCE.
Affected products
3cpe:2.3:a:schneider-electric:struxureware_data_center_expert:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:schneider-electric:struxureware_data_center_expert:*:*:*:*:*:*:*:*range: <=7.9.3
- (no CPE)range: v7.9.3 and earlier
Patches
Vulnerability mechanics
References
1- download.schneider-electric.com/filesnvdVendor Advisory
News mentions
0No linked articles in our index yet.