The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Conext™ Advisor 2 Cloud 2.02 and below
- Schneider Electric Conext™ Advisor 2 Gateway 1.28.45 and below
- Schneider Electric Conext™ Control V2 Gateway 2.6 and below
- Summary
- A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.
- Remediation
- Version Windows 10 of the Microsoft Windows includes a fix for this vulnerability and is available for download here: • https://www.microsoft.com/en-in/software-download/windows10 • Reboot is required
