Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2023-25554

A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that allows a local privilege escalation on the appliance when a maliciously crafted Operating System command is entered on the device.

Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)

  • Published: Apr 18, 2023
  • Updated: Apr 28, 2023
  • CVE: CVE-2023-25554
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 7.8
  • AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CWEs:

OWASP TOP 10: