EcoStruxure Power SCADA Anywhere Security Notification
This document details a vulnerability (CVE-2022-1467) in Schneider Electric's EcoStruxure Power SCADA Anywhere software, where an authenticated user can escape the application context into the operating system via the Windows Language Bar, potentially executing arbitrary OS commands. It provides affected versions (2022, 2021, 2020 R2, 2020, 9.0, 8.x) and recommends mitigations such as disabling the Language Bar, using minimal-privilege accounts, and applying Group Policy restrictions.
Failed to load PDF
Download insteadYou might also like
Modular PDU Installation with Neutral Conductor Protection Application Note
3 pages
ComPacT NSX and NSXm Molded-Case Circuit Breakers Catalog
54 pages
SmartStruxure Technician Tool Mobile App for Android Manual
3 pages
DEGB Electronic Light Transmitter Installation Guide
2 pages
EcoFit Life Extension Advanced for UPS Batteries Service Description
2 pages
Clipsal ARGUS 753CF2 Ceiling Movement Detector Datasheet
1 pages
51M-B and 51F Surface Sockets Datasheet
1 pages
TAC Universal Series MicroRegulator MR55 Specifications
6 pages
iCLASS 13.56 MHz Contactless Smart Card Technical Reference
2 pages
iCLASS Contactless Smart Adhesive Tag Datasheet
2 pages