Vulnerability Database

309,961

Total vulnerabilities in the database

CVE-2023-25555

A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow a user that knows the credentials to execute unprivileged shell commands on the appliance over SSH.

Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)

  • Published: Apr 18, 2023
  • Updated: Nov 16, 2025
  • CVE: CVE-2023-25555
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 5.6
  • AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

CWEs:

OWASP TOP 10: