EcoStruxure Power SCADA Anywhere Security Notification
This document details a vulnerability (CVE-2022-1467) in Schneider Electric's EcoStruxure Power SCADA Anywhere software, where an authenticated user can escape the application context into the operating system via the Windows Language Bar, potentially executing arbitrary OS commands. It provides affected versions (2022, 2021, 2020 R2, 2020, 9.0, 8.x) and recommends mitigations such as disabling the Language Bar, using minimal-privilege accounts, and applying Group Policy restrictions.
Failed to load PDF
Download insteadYou might also like
NetworkAIR FM Dedicated Dehumidification Application Note
3 pages
Andover Continuum BACnet Family of Controllers Overview
14 pages
TAC 2321 Heating and Domestic Hot Water Controller Technical Data
8 pages
Modicon M221 Logic Controller TM221CE16R
18 pages
PK49SP Standard Gray Spray Enamel Safety Data Sheet
7 pages
SEVD-2019-225-04: SoMachine HVAC and SoMove FDT Vulnerability Security Notification
4 pages
SecurityExpert Mullion Reader Datasheet
6 pages
Acti9 IC2000 Twilight Switch Customer Case
2 pages
Satchwell AR Mk 7 Rotary Actuator Installation Instructions
4 pages
AP7701 Automatic Transfer Switch Datasheet
2 pages