CVE-2023-27975

CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized access to the project file in EcoStruxure Control Expert when a local user tampers with the memory of the engineering workstation.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:schneider-electric:ecostruxure_control_expert:*:*:*:*:*:*:*:*
cpe:2.3:a:schneider-electric:ecostruxure_process_expert:*:*:*:*:*:*:*:*

History

11 Dec 2024, 19:33

Type Values Removed Values Added
First Time Schneider-electric ecostruxure Control Expert
Schneider-electric
Schneider-electric ecostruxure Process Expert
References () https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-044-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-044-01.pdf - () https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-044-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-044-01.pdf - Vendor Advisory
CPE cpe:2.3:a:schneider-electric:ecostruxure_process_expert:*:*:*:*:*:*:*:*
cpe:2.3:a:schneider-electric:ecostruxure_control_expert:*:*:*:*:*:*:*:*

21 Nov 2024, 07:53

Type Values Removed Values Added
Summary
  • (es) CWE-522: Existe una vulnerabilidad de credenciales insuficientemente protegidas que podría provocar un acceso no autorizado al archivo del proyecto en EcoStruxure Control Expert cuando un usuario local manipula la memoria de la estación de trabajo de ingeniería.
References () https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-044-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-044-01.pdf - () https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-044-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-044-01.pdf -

14 Feb 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-14 17:15

Updated : 2024-12-11 19:33


NVD link : CVE-2023-27975

Mitre link : CVE-2023-27975

CVE.ORG link : CVE-2023-27975


JSON object : View

Products Affected

schneider-electric

  • ecostruxure_process_expert
  • ecostruxure_control_expert
CWE
CWE-522

Insufficiently Protected Credentials