A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by sending a specifically crafted packet to the application.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Ecostruxure_power_monitoring_expert | Schneider-electric | * | * |
| Ecostruxure_power_operation_with_advanced_reports | Schneider-electric | * | * |
| Ecostruxure_power_scada_operation_with_advanced_reports | Schneider-electric | * | * |