7.2
CVSSv3

CVE-2016-2278

Published: 02/03/2016 Updated: 30/10/2018
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 905
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and previous versions and AS-P 1.7 and previous versions allows remote authenticated administrators to execute arbitrary OS commands by defeating an msh (aka Minimal Shell) protection mechanism.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

schneider-electric struxureware building operations automation server as firmware

schneider-electric struxureware building operations automation server as-p firmware 1.7

Exploits

*# Exploit Title: [*Schneider Electric SBO / AS Multiple Vulnerabilities] # Discovered by: Karn Ganeshen # Vendor Homepage: [wwwschneider-electriccom*] * *# Versions Reported: [* Automation Server Series (AS, AS-P), v17 and prior *] * # CVE-ID: [CVE-2016-2278] About Schneider Electric’s corporate headquarters is located in Paris, France, and ...