Home
HIGH: 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NDefault status
unaffected
Version 2022
affected
Version 2023
affected
Version 2023 R2
affected
Version 2024
affected
Version 2024 R2
affected
Default status
unaffected
Version 2022
affected
Version 2024
affected
Description
CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a locally authenticated attacker sends a crafted data stream, triggering unsafe deserialization.
Problem types
CWE-502 Deserialization of untrusted data
Product status
Version 2022
Version 2023
Version 2023 R2
Version 2024
Version 2024 R2
Version 2022
Version 2024
References
download.schneider-electric.com/...Name=SEVD-2026-069-06.pdf