CVE-2013-0655

The client in Schneider Electric Software Update (SESU) Utility 1.0.x and 1.1.x does not ensure that updates have a valid origin, which allows man-in-the-middle attackers to spoof updates, and consequently execute arbitrary code, by modifying the data stream on TCP port 80.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:schneider-electric:software_update_utility:1.0:*:*:*:*:*:*:*
cpe:2.3:a:schneider-electric:software_update_utility:1.0.13:*:*:*:*:*:*:*
cpe:2.3:a:schneider-electric:software_update_utility:1.1:*:*:*:*:*:*:*

Information

Published : 2013-01-21 08:55

Updated : 2013-01-21 21:00


NVD link : CVE-2013-0655

Mitre link : CVE-2013-0655


JSON object : View

CWE
CWE-20

Improper Input Validation

Advertisement

dedicated server usa

Products Affected

schneider-electric

  • software_update_utility