CVE-2016-2278: Schneider Electric Struxureware Building Operations Automation Server As-P Firmware

High severity, CVSS 7.2. EPSS: 13.4% chance of exploitation in the next 30 days.

Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows remote authenticated administrators to execute arbitrary OS commands by defeating an msh (aka Minimal Shell) protection mechanism.

Affected products

  • Schneider Electric Struxureware Building Operations Automation Server As-P Firmware: version 1.7 only
  • Schneider Electric Struxureware Building Operations Automation Server As Firmware: up to and including 1.7

Published 2016-03-02. Last modified 2026-06-17.