CVE-2023-7032

A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker logged in with a user level account to gain higher privileges by providing a harmful serialized object.
Configurations

Configuration 1 (hide)

cpe:2.3:a:schneider-electric:easergy_studio:*:*:*:*:*:*:*:*

History

16 Jan 2024, 19:43

Type Values Removed Values Added
CPE cpe:2.3:a:schneider-electric:easergy_studio:*:*:*:*:*:*:*:*
References () https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-009-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-009-02.pdf - () https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-009-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-009-02.pdf - Vendor Advisory
First Time Schneider-electric easergy Studio
Schneider-electric
Summary
  • (es) Existe una vulnerabilidad CWE-502: deserialización de datos no confiables que podría permitir que un atacante que haya iniciado sesión con una cuenta de nivel de usuario obtenga mayores privilegios al proporcionar un objeto serializado dañino.

09 Jan 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-09 20:15

Updated : 2024-01-16 19:43


NVD link : CVE-2023-7032

Mitre link : CVE-2023-7032

CVE.ORG link : CVE-2023-7032


JSON object : View

Products Affected

schneider-electric

  • easergy_studio
CWE
CWE-502

Deserialization of Untrusted Data