CVE-2024-8531

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Oct 11, 2024
Updated: Oct 15, 2024
CWE ID 347

Summary

CVE-2024-8531 is a newly identified vulnerability classified as CWE-347: Improper Verification of Cryptographic Signature. This issue puts Data Center Expert software at risk, allowing an attacker to compromise the system by manipulating upgrade bundles. The bundles can contain arbitrary bash scripts that are executed with root privileges upon installation, exposing the data center to potential security breaches. This vulnerability underscores the importance of proper validation and verification of cryptographic signatures to safeguard against unauthorized code execution.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Data Center Expert

Affected Vendors

  • Schneider Electric