The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Schneider Electric Software Update (SESU) V2.4.0 and prior
- Summary
- A CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability exists which could cause execution of malicious code on the victim´s machine. In order to exploit this vulnerability, an attacker requires privileged access on the engineering workstation to modify a Windows registry key which would divert all traffic updates to go through a server in the attacker’s possession. A man-in-the-middle attack is then used to complete the exploit.
- Remediation
- This vulnerability is fixed in version 2.5.0 and is available for download below: https://www.seupdate.schneiderelectric.com/download/SystemConsistency/SoftwareUpdate/SESU_250/SESU_2.5.0_setup_sfx. exe If you have already installed SESU, it will show that a new critical update is available for installation. To install the security update, download and execute the setup file.
