The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric SpaceLogic AS-P V5.0.3 and prior
- Schneider Electric SpaceLogic AS-B V5.0.3 and prior
- Summary
- CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists that could cause escalation of privileges when an attacker abuses a limited admin account.
- Remediation
- Version 6.0.1 or greater of SpaceLogic AS-P and AS-B includes a fix for this vulnerability and is available for download here: https://ecoxpert.se.com/en/softwarecenter/ building-automation/ebo-system/building-operation- 2024-version-6.0 Hotfix patches are also available for versions 5.0.3 and 4.0.5 here: https://community.se.com/t5/EBO-Hotfix-List/bgp/ sbo-hotfix-list Step1: Locate the version you need to patch on the Exchange Community using the links above. Step 2: Follow the instructions in the readme file.
