EcoStruxure Power SCADA Anywhere Security Notification
This document details a vulnerability (CVE-2022-1467) in Schneider Electric's EcoStruxure Power SCADA Anywhere software, where an authenticated user can escape the application context into the operating system via the Windows Language Bar, potentially executing arbitrary OS commands. It provides affected versions (2022, 2021, 2020 R2, 2020, 9.0, 8.x) and recommends mitigations such as disabling the Language Bar, using minimal-privilege accounts, and applying Group Policy restrictions.
Failed to load PDF
Download insteadYou might also like
APC Smart-UPS SCL400/SCL500 Lithium-Ion Battery Pack Safety Data Sheet
12 pages
EcoStruxure Reference Design 110 for AI Factory Data Centers
8 pages
Energy Efficiency for Hospitals White Paper
12 pages
SecurityExpert TouchSense LCD Keypad Manual
4 pages
Smart-UPS RT Deployment Best Practices Application Note
5 pages
SDC 30-4 Series Electric Strike Manual
1 pages
Theta II Optimiser ES4 Optimum Start Controller Data Sheet
4 pages
STP100 and STP101 Immersion Pipe Temperature Sensor Datasheet
4 pages
Dell PowerEdge Blade Server NCPI Deployment Application Note
10 pages
Uni-Telway Driver Vulnerability Security Notification
4 pages