CVE-2024-43690 - Schneider Electric Command Centre Untrusted Control Sphere Remote Code Execution (RCE)

1 month ago 25
ARTICLE AD BOX
CVE ID : CVE-2024-43690
Published : Sept. 11, 2024, 5:15 a.m. | 24 minutes ago
Description : Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allow an attacker to perform Remote Code Execution (RCE). This issue affects: Command Centre Server and Command Centre Workstations 9.10 prior to vEL9.10.1530 (MR2), 9.00 prior to vEL9.00.2168 (MR4), 8.90 prior to vEL8.90.2155 (MR5), 8.80 prior to vEL8.80.1938 (MR6), all versions of 8.70 and prior.
Severity: 8.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Read Entire Article