17% (35) 873 views 4 pages

EcoStruxure Power SCADA Anywhere Security Notification

AI-enhanced description

This document details a vulnerability (CVE-2022-1467) in Schneider Electric's EcoStruxure Power SCADA Anywhere software, where an authenticated user can escape the application context into the operating system via the Windows Language Bar, potentially executing arbitrary OS commands. It provides affected versions (2022, 2021, 2020 R2, 2020, 9.0, 8.x) and recommends mitigations such as disabling the Language Bar, using minimal-privilege accounts, and applying Group Policy restrictions.

Uploaded by Manon-463
Download
/ 4
Loading document…