QID 590880
Date Published: 2022-11-17
QID 590880: Schneider Electric Wonderware System Platform Arbitrary Code Execution Vulnerability (ICSA-15-169-02)
A search path vulnerability was found in Schneider Electrics Wonderware InTouch.
Affected Versions: Wonderware System Platform 2014 R2 and prior versions.
QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys
Successful exploitation of this vulnerability would require the victim to install and execute malicious code that could result in arbitrary code execution.
Solution
Customers are advised to refer to CERT MITIGATIONS section ICSA-15-169-02 for affected packages and patching details.
Vendor References
- ICSA-15-169-02 -
www.us-cert.gov/ics/advisories/ICSA-15-169-02
CVEs related to QID 590880
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-15-169-02 |
|