---
cve: "CVE-2024-8531"
severity: "HIGH"
cvss: 7.2
epss: "46%"
vendor: "Schneider Electric"
kev: false
exploited: false
published: "2024-10-11 14:15:06"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-08T16:01:48+02:00"
---

# CVE-2024-8531

> 7.2 HIGH

## Beschreibung

CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could
compromise the Data Center Expert software when an upgrade bundle is manipulated to
include arbitrary bash scripts that are executed as root.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Hoch | good |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Schwachstellen-Klasse

- **CWE-347** — Improper Verification of Cryptographic Signature
  The product does not verify, or incorrectly verifies, the cryptographic signature for data.

## Angriffsmuster (CAPEC)

- [CAPEC-463 — Padding Oracle Crypto Attack](https://capec.mitre.org/data/definitions/463.html) _(Severity: High)_
- [CAPEC-475 — Signature Spoofing by Improper Validation](https://capec.mitre.org/data/definitions/475.html) _(Severity: High)_

## Referenzen

- <https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-282-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-282-01.pdf>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-8531) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
