Zero-DayОригинал на английском
Schneider Electric NetBotz 5 750/755
Русский перевод готовится и скоро появится на сайте. Пока доступен оригинал на английском.
View CSAF Summary Schneider Electric is aware of multiple vulnerabilities in its NetBotz 5 – 750/755 products.The NetBotz 5 – 750/755 products are security and environmental monitors providing temperature, humidity, leak, smoke, vibration, door contact, and video monitoring capab
CISA Alerts··3 мин чтения
View CSAF Summary Schneider Electric is aware of multiple vulnerabilities in its NetBotz 5 – 750/755 products.The NetBotz 5 – 750/755 products are security and environmental monitors providing temperature, humidity, leak, smoke, vibration, door contact, and video monitoring capabilities. Failure to apply the remediation provided below may risk arbitrary or remote code execution over the local network, which could result in device manipulation and unauthorized data access. The following versions of Schneider Electric NetBotz 5 750/755 are affected: NetBotz 5 750 vers:intdot/<=5.5.2 (CVE-2026-13336, CVE-2026-13337) NetBotz 5 755 vers:intdot/<=5.5.2 (CVE-2026-13336, CVE-2026-13337) CVSS Vendor Equipment Vulnerabilities v3 6.4 Schneider Electric Schneider Electric NetBotz 5 750/755 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), SQL Injection: Hibernate Background Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: France Vulnerabilities Expand All + CVE-2026-13336 CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause execution of Linux Operating system commands when a system back up is restored that has been maliciously modified. View CVE Details Affected Products Schneider Electric NetBotz 5 750/755 Vendor: Schneider Electric Product Version: NetBotz 5 750 versions 5.5.2 and prior, NetBotz 5 755 Versions 5.5.2 and prior Product Status: fixed, known_affected Remediations Vendor fix Version 5.6.0 of NetBotz 5 750/755 includes a fix for these vulnerabilities and is available for download here: https://www.se.com/ww/en/product-range/61830-netbotz/#software-and-firmware Reboot needed: Upon install, the offer will automatically restart. A customer can validate a successful install by logging into the GUI and selecting the ‘About NetBotz’ option. This will indicate the installed version. For more information see the associated Schneider Electric security advisory Multiple Vulnerabilities on NetBotz 5 750/755 Products - SEVD-2026-223-02 CSAF Version, Multiple Vulnerabilities on NetBotz 5 750/755 Products - SEVD-2026-223-02 PDF Version. Relevant CWE: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.4 MEDIUM CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H CVE-2026-13337 CWE-564:SQL Injection: Hibernate vulnerability exists that could allow the injection of a malicious HQL query in the NetBotz database when a malicious user is logged into the NetBotz via the web-service interface or web-ui. View CVE Details Affected Products Schneider Electric NetBotz 5 750/755 Vendor: Schneider Electric Product Version: NetBotz 5 750 versions 5.5.2 and prior, NetBotz 5 755 Versions 5.5.2 and prior Product Status: fixed, known_affected Remediations Vendor fix Version 5.6.0 of NetBotz 5 750/755 includes a fix for these vulnerabilities and is available for download here: https://www.se.com/ww/en/product-range/61830-netbotz/#software-and-firmware Reboot needed: Upon install, the offer will automatically restart. A customer can validate a successful install by logging into the GUI and selecting the ‘About NetBotz’ option. This will indicate the installed version. For more information see the associated Schneider Electric security advisory Multiple Vulnerabilities on NetBotz 5 750/755 Products - SEVD-2026-223-02 CSAF Version, Multiple Vulnerabilities on NetBotz 5 750/755 Products - SEVD-2026-223-02 PDF Version. Relevant CWE: CWE-564 SQL Injection: Hibernate Metrics CVSS Version Base Score Base Severity Vector String 3.1 4.6 MEDIUM CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N Acknowledgments Schneider Electric CPCERT reported these vulnerabilities to CISA. General Security Recommendations Schneider Electric stro