High severity7.2NVD Advisory· Published Mar 2, 2016· Updated May 6, 2026
CVE-2016-2278
CVE-2016-2278
Description
Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows remote authenticated administrators to execute arbitrary OS commands by defeating an msh (aka Minimal Shell) protection mechanism.
Affected products
2- cpe:2.3:o:schneider-electric:struxureware_building_operations_automation_server_as_firmware:*:*:*:*:*:*:*:*Range: <=1.7
- cpe:2.3:o:schneider-electric:struxureware_building_operations_automation_server_as-p_firmware:1.7:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- download.schneider-electric.com/filesnvdVendor Advisory
- ics-cert.us-cert.gov/advisories/ICSA-16-061-01nvdThird Party AdvisoryUS Government Resource
- www.exploit-db.com/exploits/39522/nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.