CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert user account submits crafted XML payloads to SOAP service endpoints.
References
Configurations
History
20 Jul 2026, 20:10
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
23 Jun 2026, 15:04
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
| References | () https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-160-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-160-01.pdf - Vendor Advisory | |
| First Time |
Schneider-electric struxureware Data Center Expert
Schneider-electric |
|
| CPE | cpe:2.3:a:schneider-electric:struxureware_data_center_expert:*:*:*:*:*:*:*:* |
09 Jun 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-09 16:16
Updated : 2026-07-20 20:10
NVD link : CVE-2026-8045
Mitre link : CVE-2026-8045
CVE.ORG link : CVE-2026-8045
JSON object : View
Products Affected
schneider-electric
- struxureware_data_center_expert
CWE
CWE-611
Improper Restriction of XML External Entity Reference
