27% (79) 1.4k views 4 pages

SpaceLogic AS-P and AS-B Automation Servers Security Notification

AI-enhanced description

This document details multiple vulnerabilities in Schneider Electric's SpaceLogic AS-P and AS-B automation servers, including a TOCTOU race condition (CVE-2024-5558) that could lead to privilege escalation and an information exposure flaw (CVE-2024-5557) that risks leaking SNMP credentials. It provides remediation steps, including upgrading to version 6.0.1 or applying hotfix patches, along with general cybersecurity best practices for building management systems.

Uploaded by MANON76
Download
/ 4
Loading document…