QID 590560
Date Published: 2021-11-03
QID 590560: Schneider Electric StruxureOn Gateway Remote Code Execution (RCE) Vulnerability (ICSA-18-046-04)
AFFECTED PRODUCTS
StruxureOnGateway all versions prior to 1.2
QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys
Successful exploitation of this vulnerability could allow a remote attacker to upload a malicious file to any directory on the device, which could lead to remote code execution.
Solution
Customers are advised to refer to CERT MITIGATIONS section ICSA-18-046-04 for affected packages and patching details.
Vendor References
- ICSA-18-046-04 -
www.us-cert.gov/ics/advisories/ICSA-18-046-04
CVEs related to QID 590560
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-18-046-04 |
|