Remote-access Guide

webctrl remote access

by Arch Hegmann DVM Published 2 years ago Updated 2 years ago
image

What is Automated Logic WebCTRL?

The WebCTRL building automation system is a powerful web-based platform that provides facility managers with software tools to keep occupants comfortable, manage energy conservation measures, identify key operational problems, and analyze the results.

Is Automated Logic owned by carrier?

Automated Logic is a part of Carrier Global Corporation (NYSE: CARR), the leading global provider of healthy, safe, sustainable and intelligent building and cold chain solutions.

Who owns Automated Logic?

Carrier GlobalUnited Technolog... CorporationAutomated Logic Corporation/Parent organizations

What is ALC HVAC?

About Automated Logic Corporation (ALC) Automated Logic Corporation (ALC) provides innovative building automation and control systems.

When did Carrier buy Automated Logic?

2004Automated Logic Corporation was acquired by the Carrier Corporation (parent: United Technologies Corporation.) in 2004. As a founding member of the BACnet Manufacturers Association, Automated Logic was one of the first to offer products using the industry's standard protocol – BACnet.

How do I turn off Automated Logic thermostat?

Newer Automated Logic wall sensor Press the on/off button one to three times for 30, 60 or 90 minutes of override. 2. Press the down arrow button to lower setpoint.

Who owns Carrier HVAC?

United Technologies CorporationCarrier Corporation was acquired by United Technologies Corporation (UTC) in July 1979. Prior to the acquisition by UTC, Carrier Corporation was known as the Carrier Air Conditioning Company. International Comfort Products (ICP), headquartered in Lewisburg, Tennessee, was acquired by Carrier in 1999.

What is LSAT and VSAT?

VSAT: Vapor Saturation Temperature (from P-T chart) LSAT: Liquid Saturation Temperature (from P-T chart)

What is VCD in HVAC?

COSMOS Square, Rectangular and round Volume Control Dampers (VCD) are the specific types of dampers designed for purpose of controlling air flow and pressure in HVAC systems. For square and rectangular VCD's, standard damper construction comes with opposed blade arrangement with external linkage.

What is HVAC abbreviation?

HVACHeating, ventilation, and air conditioning / Short nameHeating, ventilation and air-conditioning (HVAC) equipment with the ENERGY STAR® label meets or exceeds federal guidelines for energy-efficient performance.

What does PRV stand for in HVAC?

Pressure Reducing ValvePRV – Pressure Reducing Valve. PSI – Pounds per Square Inch.

What You'll Need to Set Up The Web Client

Before getting started, keep the following things in mind: 1. Make sure your Remote Desktop deployment has an RD Gateway, an RD Connection Broker,...

How to Publish The Remote Desktop Web Client

To install the web client for the first time, follow these steps: 1. On the RD Connection Broker server, obtain the certificate used for Remote Des...

How to Update The Remote Desktop Web Client

When a new version of the Remote Desktop web client is available, follow these steps to update the deployment with the new client: 1. Open an eleva...

How to Uninstall The Remote Desktop Web Client

To remove all traces of the web client, follow these steps: 1. On the RD Web Access server, open an elevated PowerShell prompt. 2. Unpublish the Te...

How to update the Remote Desktop web client

When a new version of the Remote Desktop web client is available, follow these steps to update the deployment with the new client:

How to install the Remote Desktop web client without an internet connection

Follow these steps to deploy the web client to an RD Web Access server that doesn't have an internet connection.

Connecting to RD Broker without RD Gateway in Windows Server 2019

This section describes how to enable a web client connection to an RD Broker without an RD Gateway in Windows Server 2019.

How to pre-configure settings for Remote Desktop web client users

This section will tell you how to use PowerShell to configure settings for your Remote Desktop web client deployment. These PowerShell cmdlets control a user's ability to change settings based on your organization's security concerns or intended workflow. The following settings are all located in the Settings side panel of the web client.

Troubleshooting

If a user reports any of the following issues when opening the web client for the first time, the following sections will tell you what to do to fix them.

Get help with the web client

If you've encountered an issue that can't be solved by the information in this article, you can report it on Tech Community. You can also request or vote for new features at our suggestion box.

AFFECTED PRODUCTS

The following versions of WebCTRL, i-Vu, SiteScan Web, building automation platforms, are affected:

IMPACT

Successful exploitation of these vulnerabilities could allow an authenticated user to elevate his or her privileges to execute arbitrary code on the system.

MITIGATION

ALC provides support for WebCTRL, i-Vu, SiteScan Web versions 6.0 and greater. Those users using prior versions, including 5.5 and 5.2, must upgrade to supported versions in order to install these mitigation patches.

UNQUOTED SEARCH PATH OR ELEMENT CWE-428

An unquoted search path vulnerability may allow a non-privileged local attacker to change files in the installation directory and execute arbitrary code with elevated privileges.

IMPROPER LIMITATION OF A PATHNAME TO A RESTRICTED DIRECTORY ('PATH TRAVERSAL') CWE-22

An authenticated attacker may be able to overwrite files that are used to execute code. This vulnerability does not affect version 6.5 of the software.

UNRESTRICTED UPLOAD OF FILE WITH DANGEROUS TYPE CWE-434

An authenticated attacker may be able to upload a malicious file allowing the execution of arbitrary code.

Contact Information

CISA continuously strives to improve its products and services. You can help by choosing one of the links below to provide feedback about this product.

What is fragmentation in WebCTRL?

In a new WebCTRL system, the records in a database are contiguous. As records are added, deleted, and modified, the records become scattered in the database. This condition is called fragmentation, and it can slow down system performance and increase the size of the database.

Can you run autopilot on a web server?

You can run the autopilot on the WebCTRL server or on one or more client computers. Each computer can display a different set of pages. Trend graphs (see page 57) Trend graph lines will show breaks only when time synchronizations occur or when trending is enabled or disabled.

Does WebCTRL support digital signature?

NOTE If you need a digitally signed PDF to comply with 21 CFR Part 11, open the PDF in a program that supports digital signing such as Acrobat, then sign the PDF. WebCTRL does not support digital signing because 21 CFR Part 11 requires that the signature be added manually, not through an automated process.

image

Affected Products

  • The following versions of WebCTRL, i-Vu, SiteScan Web, building automation platforms, are affected: 1. ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior, 2. ALC WebCTRL, SiteScan Web 6.1 and prior, 3. ALC WebCTRL, i-Vu 6.0 and prior, 4. ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior, and 5. ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior.
See more on cisa.gov

Impact

  • Successful exploitation of these vulnerabilities could allow an authenticated user to elevate his or her privileges to execute arbitrary code on the system.
See more on cisa.gov

Mitigation

  • ALC provides support for WebCTRL, i-Vu, SiteScan Web versions 6.0 and greater. Those users using prior versions, including 5.5 and 5.2, must upgrade to supported versions in order to install these mitigation patches. ALC applications should always be installed and maintained in accordance with the guidelines found here: http://www.automatedlogic.co...
See more on cisa.gov

Vulnerability Overview

  • An unquoted search path vulnerability may allow a non-privileged local attacker to change files in the installation directory and execute arbitrary code with elevated privileges. CVE-2017-9644 has been assigned to this vulnerability. A CVSS v3 base score of 4.2 has been assigned; the CVSS vector string is (AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L). An authenticated attacker may be able to …
See more on cisa.gov

Background

  • Critical Infrastructure Sector:Commercial Facilities Countries/Areas Deployed:Worldwide Company Headquarters Location:Kennesaw, Georgia
See more on cisa.gov

A B C D E F G H I J K L M N O P Q R S T U V W X Y Z 1 2 3 4 5 6 7 8 9