CVE-2024-8531
CVE-2024-8531
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.2EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
11 Oct 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could
compromise the Data Center Expert software when an upgrade bundle is manipulated to
include arbitrary bash scripts that are executed as root.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
Schneider Electric · Data Center ExpertWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →