CVE-2023-37196: Schneider Electric Struxureware Data Center Expert
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to access unauthorized content, change, or delete content, or perform unauthorized actions when tampering with the alert settings of endpoints on DCE.
Affected products
- Schneider Electric Struxureware Data Center Expert: up to and including 7.9.3
Published 2023-07-12. Last modified 2026-06-17.