The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Andover Continuum All Versions
- Summary
- Continuum XSS Vulnerability – The web.Client has a Cross Site Scripting (XSS) vulnerability that may expose the user to various possible attacks. A CWE-79:Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists which could enable a successful “Cross-site Scripting” (XSS attack) when using the products’ web server.
- Remediation
- Andover Continuum is a classic Schneider Electric product line. New projects are utilizing our more modern, secure and feature rich platform, EcoStruxure Building Operation. For customers with active Continuum installations, Schneider Electric continues to provide resources in a support function where we continue to support the platform per our BMS support policy as these sites work towards transition and modernization to EcoStruxure Building Operation. Given the clear path to EcoStruxure Building Operation and available alternatives to these specific issues, we will not provide a patch for this issue. To reduce risk until modernization to EcoStruxure Building, it is strongly recommended that customers use the methods below: • It is strongly recommended that the Continuum system be installed on an isolated network segment. • Compensating controls could include, but not limited to, incorporating firewalls with access control lists, deep packet inspection and packet filtering.
