A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by sending a specifically crafted packet to the application.
2023-10-04T19:15:10.777
2024-11-21T08:41:40.707
Modified
CVSSv3.1: 9.8 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | schneider-electric | ecostruxure_power_monitoring_expert | * | Yes |
| Application | schneider-electric | ecostruxure_power_operation_with_advanced_reports | * | Yes |
| Application | schneider-electric | ecostruxure_power_scada_operation_with_advanced_reports | * | Yes |