The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric SoMove V2.8.1 and prior
- Summary
- A CWE-276: Incorrect Default Permission vulnerability exists which could cause elevation of privilege and provide full access control to local system users to SoMove component and services when a SoMove installer script is launched.
- Remediation
- This vulnerability is fixed in SoMove V2.8.2 and is available for download below: https://www.se.com/ww/en/download/document/SoMove_FDT/
