VYPR

SEVD-2023-283-01

by Schneider Electric

CVEs (2)

  • CVE-2023-5391CriOct 4, 2023
    risk 0.64cvss 9.8epss 0.01

    A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by sending a specifically crafted packet to the application.

  • CVE-2023-5402CriOct 4, 2023
    risk 0.64cvss 9.8epss 0.01

    A CWE-269: Improper Privilege Management vulnerability exists that could cause a remote code execution when the transfer command is used over the network.