CVE-2023-1049
published 2023-06-14CVE-2023-1049: A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause execution of malicious code when an unsuspicious user…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.60%
44.6th percentile
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that
could cause execution of malicious code when an unsuspicious user loads a project file from the
local filesystem into the HMI.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| pimcore | demo | >= 0 < 10.3.0 | 10.3.0 |
| schneider-electric | ecostruxure_operator_terminal_expert | < 3.3 | 3.3 |
| schneider-electric | ecostruxure_operator_terminal_expert | — | — |
| schneider-electric | pro-face_blue | < 3.3 | 3.3 |
| schneider-electric | pro-face_blue | — | — |
| schneider_electric | ecostruxure_operator_terminal_expert | — | — |
| schneider_electric | pro-face_blue | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Pimcore Demo Allows GraphQL Introspection
ghsa·2023-09-27
CVE-2023-5192 [MEDIUM] CWE-1049 Pimcore Demo Allows GraphQL Introspection
Pimcore Demo Allows GraphQL Introspection
Introspection is enabled on `demo.pimcore.fun`. The demo site has graphql as a feature for users, but allows users to run instropection queries, which presents a potential schema information disclosure vulnerability.
GHSA
GHSA-63c6-hm8j-v6m9: A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that
could cause execution of malicious code when an unsuspic
ghsa_unreviewed·2023-06-14
CVE-2023-1049 [HIGH] CWE-94 GHSA-63c6-hm8j-v6m9: A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that
could cause execution of malicious code when an unsuspic
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that
could cause execution of malicious code when an unsuspicious user loads a project file from the
local filesystem into the HMI.
CISA ICS
Schneider Electric EcoStruxure Operator Terminal Expert
cisa_ics·2023-06-29·CVSS 7.8
[HIGH] Schneider Electric EcoStruxure Operator Terminal Expert
ICS Advisory
##
Schneider Electric EcoStruxure Operator Terminal Expert
Release DateJune 29, 2023
Alert CodeICSA-23-180-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low attack complexity/public exploits are available
- Vendor: Schneider Electric
- Equipment: EcoStruxure Operator Terminal Expert VXDZ
- Vulnerability: Improper Control of Generation of Code ('Code Injection')
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code and gain access to sensitive information on the machine.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of Schneider Electric EcoStruxure Operator Terminal Expert, a human machine interface (HMI) application, are affected:
- EcoStruxur
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-06-14
Published