**VERSION NOT SUPPORTED WHEN ASSIGNED** A legacy support account in the TriStation software version v4.9.0 and earlier could cause improper access to the TriStation host machine. This was addressed in TriStation version v4.9.1 and v4.10.1 released on May 30, 2013.1
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HMicrosoft Windows 7
OSMicrosoftall versionsMicrosoft Windows Nt
OSMicrosoftall versionsMicrosoft Windows Xp
OSMicrosoftall versionsSchneider Electric Tristation 1131
APPSchneider-Electric4.10.04.12.01.0.0 – 4.9.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2020-0646CRITICAL9.8⚠ KEVPL ✓same product
RCE w Microsoft .NET Framework — nieprawidłowa walidacja danych wejściowych
CVE-2019-0708CRITICAL9.8⚠ KEVPL ✓same product
BlueKeep — krytyczny RCE w Remote Desktop Services (RDP)
CVE-2017-8543CRITICAL9.8⚠ KEVPL ✓same product
RCE w Windows Search — przejęcie kontroli nad systemem
CVE-2015-1635CRITICAL9.8⚠ KEVPL ✓same product
RCE w HTTP.sys — zdalne wykonanie kodu w Windows przez spreparowane żądania HTTP
CVE-2014-1776CRITICAL9.8⚠ KEVPL ✓same product
Use-after-free w Microsoft Internet Explorer 6–11 umożliwia RCE