High severity7.2NVD Advisory· Published Mar 2, 2016· Updated Jun 17, 2026
CVE-2016-2278
CVE-2016-2278
Description
Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows remote authenticated administrators to execute arbitrary OS commands by defeating an msh (aka Minimal Shell) protection mechanism.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:o:schneider-electric:struxureware_building_operations_automation_server_as_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:schneider-electric:struxureware_building_operations_automation_server_as_firmware:*:*:*:*:*:*:*:*range: <=1.7
- (no CPE)range: <=1.7
- cpe:2.3:o:schneider-electric:struxureware_building_operations_automation_server_as-p_firmware:1.7:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- download.schneider-electric.com/filesnvdVendor Advisory
- ics-cert.us-cert.gov/advisories/ICSA-16-061-01nvdThird Party AdvisoryUS Government Resource
- www.exploit-db.com/exploits/39522/nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.