QID 591242
Date Published: 2022-12-16
QID 591242: Schneider Electric SpaceLogic C-Bus Home Controller OS Command Injection Vulnerability (SEVD-2022-193-02)
AFFECTED PRODUCTS
SpaceLogic C-Bus Home Controller (5200WHC2), formerly known as C-Bus Wiser Homer Controller MK2: V1.31.460 and prior.
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of Schneider Electric SpaceLogic C-Bus Home Controller using passive scanning
Successful exploitation of these vulnerability may risk an OS command injection vulnerability, which could result in a remote root exploit.
Solution
Customers are advised to refer to MOXA MITIGATIONS section SEVD-2022-193-02 for affected packages and patching details.
Vendor References
- SEVD-2022-193-02 -
www.se.com/id/en/download/document/SEVD-2022-193-02/
CVEs related to QID 591242
Software Advisories
| Advisory ID | Software | Component | Link |
|---|