Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows remote authenticated administrators to execute arbitrary OS commands by defeating an msh (aka Minimal Shell) protection mechanism.
2016-03-02T11:59:02.600
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 7.2 (HIGH)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Hardware | schneider-electric | struxureware_building_operations_automation_server_as | ≤ 1.7 | No |
| Operating System | schneider-electric | struxureware_building_operations_automation_server_as_firmware | ≤ 1.7 | Yes |
| Hardware | schneider-electric | struxureware_building_operations_automation_server_as-p | - | No |
| Operating System | schneider-electric | struxureware_building_operations_automation_server_as-p_firmware | 1.7 | Yes |