Description
CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution and compromise of system integrity when authenticated users send crafted data to a network-exposed service that performs unsafe deserialization.
Problem types
CWE-502 Deserialization of Untrusted Data
Product status
Version 2022
Version 2023
Version 2024
Version 2024 R2
Version 2022 w/ Advanced Reporting Module
Version 2024 w/ Advanced Reporting Module
References
download.schneider-electric.com/...Name=SEVD-2025-224-02.pdf