ZeroHour

CVE-2016-2278

CVSS 3.0
7.2 high
EPSS
13%p96
Published
()
Modified
Description

Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows remote authenticated administrators to execute arbitrary OS commands by defeating an msh (aka Minimal Shell) protection mechanism.

Vendors
schneider-electric
Products
struxureware building operations automation server as firmware, struxureware building operations automation server as-p firmware
Weakness
CWE-284
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.