Rewterz
Pakistani Users Targeted in Military-Themed Email Scam Campaign – Active IOCs
June 24, 2024
Rewterz
CVE-2024-33001 – SAP NetWeaver and ABAP Platform Vulnerability
June 24, 2024

ICS: Schneider Electric SpaceLogic AS-P and AS-B Automation Servers Vulnerability

Severity

Medium

Analysis Summary

CVE-2024-5557

Schneider Electric SpaceLogic AS-P and AS-B Automation Servers could allow a remote authenticated attacker to obtain sensitive information, caused by the insertion of sensitive information into log file. By gaining access to the log file, an attacker could exploit this vulnerability to obtain SNMP credentials information, and use this information to launch further attacks against the affected system.

Impact

  • Information Disclosure

Indicators of Compromise

CVE

  • CVE-2024-5557

Affected Vendors

Schneider Electric

Affected Products

  • Schneider Electric SpaceLogic AS-P 5.0.3
  • Schneider Electric SpaceLogic AS-B 5.0.3

Remediation

Refer to Schneider Electric Security Advisory for patch, upgrade or suggested workaround information.

Schneider Electric Security Advisory