MiCOM S1 Studio Vulnerability Disclosure
This document discloses a vulnerability in Schneider Electric's MiCOM S1 Studio software (up to version 3.5.2), where the installer grants read/write access to executables, allowing local users to manipulate configuration files and Windows services, potentially leading to privilege escalation or misoperation of protective relays. Mitigations include using best IT practices, User Access Control (UAC), and upgrading to version 5.0.0, which resolves the issue with digital signatures, read-only privileges, and compiler security settings.
Failed to load PDF
Download insteadYou might also like
Acti9 iCT+ Zero Voltage Crossing Contactors for LED Retrofits Case Study
2 pages
Erie VT/VS PopTop Series Two-Position Spring Return Zone Valve Specification and Installation Guide
4 pages
V231 Two-Way Plug Valve Specification Sheet
4 pages
Okken Intelligent Switchboard Brochure
2 pages
AP8830 Metered Rack PDU Specifications
4 pages
AP8653 Switched Rack PDU Specifications
18 pages
Andover Continuum bCX1 Series BACnet Router and Controller/Router Manual
6 pages
SecurityExpert TouchSense LCD Keypad Manual
4 pages
H721HC-S6 Current Transducer Installation Guide
3 pages
EcoStruxure Reference Design 47 Modular Data Center for AI Clusters
10 pages