A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause execution of malicious code when an unsuspicious user loads a project file from the local filesystem into the HMI.
2023-06-14T08:15:08.773
2024-11-21T07:38:21.647
Modified
CVSSv3.1: 7.8 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | schneider-electric | ecostruxure_operator_terminal_expert | < 3.3 | Yes |
| Application | schneider-electric | ecostruxure_operator_terminal_expert | 3.3 | Yes |
| Application | schneider-electric | ecostruxure_operator_terminal_expert | 3.3 | Yes |
| Application | schneider-electric | pro-face_blue | < 3.3 | Yes |
| Application | schneider-electric | pro-face_blue | 3.3 | Yes |
| Application | schneider-electric | pro-face_blue | 3.3 | Yes |