QID 591226
Date Published: 2022-12-09
QID 591226: Schneider Electric Building Operation Automation Server OS COMMAND INJECTION Vulnerability (ICSA-16-061-01, SEVD-2016-025-01)
AFFECTED PRODUCTS
Schneider Electric reports that the vulnerability affects the following products from the StruxureWare Building Operations line:
Automation Server, V1.7.0 and prior.
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
A malicious authenticated user could exploit this vulnerability to circumvent the Linux operating system's user access controls.
Solution
Customers are advised to refer to CERT MITIGATIONS section ICSA-16-061-01 for affected packages and patching details.
Vendor References
- ICSA-16-061-01 -
www.cisa.gov/uscert/ics/advisories/ICSA-16-061-01
CVEs related to QID 591226
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-16-061-01 |
|