CVE-2016-2278
Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows remote authenticated administrators to execute arbitrary OS commands by defeating an msh (aka Minimal Shell) protection mechanism.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.4%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows remote authenticated administrators to execute arbitrary OS commands by defeating an msh (aka Minimal Shell) protection mechanism.
- CVSS 3.0
- 7.2 HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 13.43% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- schneider-electric/struxureware building operations automation server as firmware · schneider-electric/struxureware building operations automation server as-p firmware
- Source
- ics-cert@hq.dhs.gov
References
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2016-025-01Vendor Advisory
- https://ics-cert.us-cert.gov/advisories/ICSA-16-061-01Third Party Advisory, US Government Resource
- https://www.exploit-db.com/exploits/39522/Third Party Advisory, VDB Entry
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2016-025-01Vendor Advisory
- https://ics-cert.us-cert.gov/advisories/ICSA-16-061-01Third Party Advisory, US Government Resource
- https://www.exploit-db.com/exploits/39522/Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.