CVE-2023-1049
14.06.2023, 08:15
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause execution of malicious code when an unsuspicious user loads a project file from the local filesystem into the HMI.
Vendor | Product | Version |
---|---|---|
schneider-electric | ecostruxure_operator_terminal_expert | 𝑥 < 3.3 |
schneider-electric | ecostruxure_operator_terminal_expert | 3.3 |
schneider-electric | ecostruxure_operator_terminal_expert | 3.3:sp1 |
schneider-electric | pro-face_blue | 𝑥 < 3.3 |
schneider-electric | pro-face_blue | 3.3 |
schneider-electric | pro-face_blue | 3.3:sp1 |
𝑥
= Vulnerable software versions