CVE-2016-2278
high · 7.2Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows remote authenticated administrators to execute arbitrary OS commands by defeating an msh (aka Minimal Shell) protection mechanism.
7.2
CVSS
13.4%
EPSS (exploit prob.)
96th
EPSS percentile
2016-03-02
Published
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-284
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| schneider-electric | struxureware_building_operations_automation_server_as | <= 1.7 |
| schneider-electric | struxureware_building_operations_automation_server_as_firmware | <= 1.7 |
| schneider-electric | struxureware_building_operations_automation_server_as-p | all versions |
| schneider-electric | struxureware_building_operations_automation_server_as-p_firmware | 1.7 |
Check a specific version with /api/v1/cve/match.
References
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2016-025-01
- https://ics-cert.us-cert.gov/advisories/ICSA-16-061-01
- https://www.exploit-db.com/exploits/39522/
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2016-025-01
- https://ics-cert.us-cert.gov/advisories/ICSA-16-061-01
- https://www.exploit-db.com/exploits/39522/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2016-2278