threat
engine
.sh
Back
·
··:··
Home
/
Product
/
schneider electric struxureware data center expert
Product
schneider electric struxureware data center expert
48 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2023-37199
<= 7.9.3
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution wh
6.8
MEDIUM
CVE-2023-37198
<= 7.9.3
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution wh
6.8
MEDIUM
CVE-2023-37197
<= 7.9.3
A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists
8.8
HIGH
CVE-2023-37196
<= 7.9.3
A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists
8.8
HIGH
CVE-2023-25555
<= 7.9.2
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that cou
5.6
MEDIUM
CVE-2023-25554
<= 7.9.2
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that all
7.8
HIGH
CVE-2023-25553
<= 7.9.2
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists on a DCE endpo
6.1
MEDIUM
CVE-2023-25552
<= 7.9.2
A CWE-862: Missing Authorization vulnerability exists that could allow viewing of unauthorized content, changes or deleting of con
8.1
HIGH
CVE-2023-25551
<= 7.9.2
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists on a DCE file
6.1
MEDIUM
CVE-2023-25550
<= 7.9.2
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows remote code execution via the
7.2
HIGH
CVE-2023-25549
<= 7.9.2
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows for remote code execution whe
7.2
HIGH
CVE-2023-25548
<= 7.9.2
A CWE-863: Incorrect Authorization vulnerability exists that could allow access to device credentials on specific DCE endpoints no
8.8
HIGH
CVE-2023-25547
<= 7.9.2
A CWE-863: Incorrect Authorization vulnerability exists that could allow remote code execution on upload and install packages when
8.8
HIGH
CVE-2021-22795
<= 7.8.1
A CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that coul
9.1
CRITICAL
CVE-2021-22794
<= 7.8.1
A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remo
9.1
CRITICAL
CVE-2018-7807
<= 7.5.0
Data Center Expert, versions 7.5.0 and earlier, allows for the upload of a zip file from its user interface to the server. A caref
8.8
HIGH
CVE-2018-3693
all versions
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of informatio
5.6
MEDIUM
CVE-2018-1126
< 7.6.0
procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow
4.8
MEDIUM
CVE-2018-1124
< 7.6.0
procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function.
7.8
HIGH
CVE-2018-3639
< 7.6.0
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all
5.5
MEDIUM
CVE-2018-2815
< 7.6.0
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versi
5.3
MEDIUM
CVE-2018-2814
< 7.6.0
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are af
8.3
HIGH
CVE-2018-2811
< 7.6.0
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Install). Supported versions that are affected are Java SE
7.7
HIGH
CVE-2018-2800
all versions
Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Ja
4.2
MEDIUM
CVE-2018-2799
< 7.6.0
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JAXP). Supported versions that
5.3
MEDIUM
CVE-2018-2798
< 7.6.0
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: AWT). Supported versions that a
5.3
MEDIUM
CVE-2018-2797
< 7.6.0
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JMX). Supported versions that a
5.3
MEDIUM
CVE-2018-2796
< 7.6.0
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Concurrency). Supported version
5.3
MEDIUM
CVE-2018-2795
< 7.6.0
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions t
5.3
MEDIUM
CVE-2018-2794
< 7.6.0
Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected a
7.7
HIGH
CVE-2018-2790
< 7.6.0
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are a
3.1
LOW
CVE-2018-2678
< 7.6.0
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that
4.3
MEDIUM
CVE-2018-2677
< 7.6.0
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: AWT). Supported versions that are affect
4.3
MEDIUM
CVE-2018-2663
< 7.6.0
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions
4.3
MEDIUM
CVE-2018-2657
< 7.6.0
Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affec
5.3
MEDIUM
CVE-2018-2641
< 7.6.0
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: AWT). Supported versions that are affect
6.1
MEDIUM
CVE-2018-2637
< 7.6.0
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JMX). Supported versions that a
7.4
HIGH
CVE-2018-2634
< 7.6.0
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JGSS). Supported versions that are affec
6.8
MEDIUM
CVE-2018-2633
< 7.6.0
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that
8.3
HIGH
CVE-2018-2629
< 7.6.0
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JGSS). Supported versions that
5.3
MEDIUM
CVE-2018-2618
< 7.6.0
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that a
5.9
MEDIUM
CVE-2018-2603
< 7.6.0
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions
5.3
MEDIUM
CVE-2018-2602
< 7.6.0
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: I18n). Supported versions that are affec
4.5
MEDIUM
CVE-2018-2599
< 7.6.0
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that
4.8
MEDIUM
CVE-2018-2588
< 7.6.0
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: LDAP). Supported versions that
4.3
MEDIUM
CVE-2018-2582
< 7.6.0
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are af
6.5
MEDIUM
CVE-2018-2579
< 7.6.0
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions
3.7
LOW
CVE-2017-8371
<= 7.3.1
Schneider Electric StruxureWare Data Center Expert before 7.4.0 uses cleartext RAM storage for passwords, which might allow remote
6.8
MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin