The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric IGSS using the service: IGSSupdate version 14 and prior
- Summary
- A CWE-22: Improper Limitation of a Pathname to a Restricted Directory exists which could allow a remote unauthenticated attacker to read arbitrary files from the IGSS server PC on an unrestricted or shared network when the IGSS Update Service is enabled.
- Remediation
- These vulnerabilities are fixed in IGSS14 version 14.0.0.20009 and the update is available for download below: http://igss.schneider-electric.com/igss/igssupdates/v140/IGSSUPDATE.zip For IGSS version 13 and prior we recommend updating to IGSS version 14.
