QID 590541
Date Published: 2021-09-22
QID 590541: Schneider Electric EcoStruxure IT Gateway uncontrolled search path element Vulnerability (ICSA2012601)
AFFECTED PRODUCTS
Schneider Electric reports the vulnerability affects the following EcoStruxure IT Gateway versions:
Versions 1.5.x, 1.6.x, 1.7.x
CISA will update this document as more mitigations are identified by affected vendors.
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
Successful exploitation of this vulnerability could allow an unauthenticated attacker to execute arbitrary code on a targeted system.
Solution
Customers are advised to refer to CERT MITIGATIONS section ICSA2012601 for affected packages and patching details.
Vendor References
- ICSA2012601 -
www.us-cert.gov/ics/advisories/ICSA2012601
CVEs related to QID 590541
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA2012601 |
|