Schneider Electric NetBotz 5 750/755
Summary
Schneider Electric has announced multiple vulnerabilities in its NetBotz 5 750/755 security and environmental monitoring products. These vulnerabilities, including OS Command Injection and SQL Injection, could allow for arbitrary or remote code execution over a local network, leading to device manipulation and unauthorized data access. Affected versions are 5.5.2 and prior, with a fix available in version 5.6.0.
IFF Assessment
The discovery of vulnerabilities that could lead to remote code execution and unauthorized data access poses a direct threat to defenders.
Severity
The CVSS score of 6.4 reflects a medium severity rating, primarily due to the potential for OS Command Injection and SQL Injection. While the article states it could lead to arbitrary code execution, the score indicates limitations such as requiring local network access.
Defender Context
Defenders should prioritize patching or updating Schneider Electric NetBotz 5 750/755 devices to version 5.6.0 to mitigate the identified OS Command Injection and SQL Injection vulnerabilities. These vulnerabilities could allow attackers to gain control of environmental monitoring systems within critical infrastructure, leading to data breaches or operational disruptions.