The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric ProSoft Configurator v1.002 and prior
- Summary
- A CWE-427: Uncontrolled Search Path Element vulnerability exists which could cause the execution of untrusted code when using double click to open a project file which may trigger execution of a malicious DLL.
- Remediation
- This vulnerability is fixed in ProSoft Configurator v1.003 and is available for download below: https://www.se.com/ww/en/download/document/PMEPXM0100_PCM/ or access the latest version in the “Software and Firmware” section using the link below: https://www.se.com/ww/en/product/PMEPXM0100/modicon-m580-profibus-dp-master-module/
