A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by sending a specifically crafted packet to the application.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ecostruxure_power_monitoring_expert | Schneider-electric | * | * |
Ecostruxure_power_operation_with_advanced_reports | Schneider-electric | * | * |
Ecostruxure_power_scada_operation_with_advanced_reports | Schneider-electric | * | * |