Description
CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation and arbitrary code execution when a privileged engineer user with console access modifies a configuration file used by a root-level daemon to execute custom scripts.
Problem types
CWE-269 Improper Privilege Management
Product status
Versions 11.06.29 and prior
Versions 11.06.34 and prior
References
download.schneider-electric.com/...Name=SEVD-2025-224-01.pdf