The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Vijeo Designer Basic V1.1 HotFix 16 and prior
- Schneider Electric Vijeo Designer V6.2 SP9 and prior
- Summary
- A CWE-798: Use of Hard-coded Credentials vulnerability exists which could cause unauthorized read and write when downloading and uploading project or firmware into Vijeo Designer Basic and Vijeo Designer.
- Remediation
- This vulnerability is fixed in version Vijeo Designer Basic V1.1 HotFix 17. Please contact your Schneider Electric Customer Support to obtain the HotFix. This vulnerability is fixed in version Vijeo Designer V6.2 SP10 released in July 2020. • For customers using Vijeo Designer version V6.1 or earlier, please contact your Schneider Electric Customer Support to obtain the Vijeo Designer V6.2 SP10. • For customers using a version of Vijeo Designer V6.2 or greater, Vijeo Designer V6.2 SP10 will be automatically available in Schneider Electric Software Update (SESU) software.
