A CWE-94: Code Injection vulnerability exists in ProClima (all versions prior to version 8.0.0) which could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system in all versions of ProClima prior to version 8.0.0.
Una CWE-94: existe una vulnerabilidad de inyección de código en ProClima (todas las versiones anteriores a la versión 8.0.0) que podría permitir que un atacante remoto no autenticado ejecute código arbitrario en el sistema objetivo en todas las versiones de ProClima anteriores a la versión 8.0.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
AV:N/AC:L/Au:N/C:C/I:C/A:C
| Access Vector | NETWORK |
|---|---|
| Access Complexity | LOW |
| Authentication | NONE |
| Confidentiality Impact | COMPLETE |
| Integrity Impact | COMPLETE |
| Availability Impact | COMPLETE |
| Source | Type | Description |
|---|---|---|
| [email protected] | Secondary |
en
CWE-94
|
| [email protected] | Primary |
en
CWE-94
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| schneider-electric | proclima | * | <built-in method update of dict object at 0x7e60a88ac640> | Application |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:schneider-electric:proclima:*:*:*:*:*:*:*:* |