CVE-2023-6032: Schneider Electric Galaxy Vl Firmware
Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause a file system enumeration and file download when an attacker navigates to the Network Management Card via HTTPS.
Affected products
- Schneider Electric Galaxy Vl Firmware: version 12.21 only
- Schneider Electric Galaxy Vs Firmware: version 6.82 only
Published 2023-11-15. Last modified 2026-06-17.