SpaceLogic AS-P and AS-B Automation Servers Security Notification
This document details multiple vulnerabilities in Schneider Electric's SpaceLogic AS-P and AS-B automation servers, including a TOCTOU race condition (CVE-2024-5558) that could lead to privilege escalation and an information exposure flaw (CVE-2024-5557) that risks leaking SNMP credentials. It provides remediation steps, including upgrading to version 6.0.1 or applying hotfix patches, along with general cybersecurity best practices for building management systems.
Failed to load PDF
Download insteadYou might also like
BAS 2800+ Voice Response System Manual
2 pages
DIGHL/DUGHL Humidity Transmitter Technical Data and Installation Guide
2 pages
SpaceLogic MP120 Thermoelectric Valve Actuator Specification Sheet
2 pages
BX500MI Back-UPS BX Estimated Runtime Table
1 pages
APC AP7802J Metered Rack PDU Specifications
2 pages
BAS UNIFACT Interface Specification and Installation Guide
4 pages
SpaceLogic RP-V Advanced VAV Controller Manual
16 pages
APC AP7911A Switched Rack PDU Specifications
2 pages
MicroNet MN 500 Controller Data Sheet
4 pages
SpaceLogic M400 Actuator Specification Sheet
6 pages