QID 590511

Date Published: 2021-08-26

QID 590511: Schneider Electric Accutech Manager Heap Overflow Vulnerability (ICSA-13-043-01)

The following Schneider Electric versions are affected:
Accutech Manager 2.00.1 and older.

QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys

This buffer overflow will cause the Accutech Manager application to crash and could be exploited to allow an attacker to execute arbitrary code with administrator privilege. Because this vulnerability can be exploited remotely, there is a potential for an attacker to gain control of the host computer.

  • CVSS V2 rated as Critical - 10 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-13-043-01 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590511

    Software Advisories
    Advisory ID Software Component Link
    ICSA-13-043-01 URL Logo www.us-cert.gov/ics/advisories/ICSA-13-043-01