The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric SCADAPack x70 Remote Connect V3.6.3.574 and prior
- Summary
- A CWE-22 Improper Limitation of a Pathname to a Restricted Directory (‘Path Transversal’) vulnerability exists which allows an attacker to place content in any unprotected folder on the target system using a crafted .RCZ file.
- Remediation
- For SCADAPack x70 Remote Connect and SCADAPack x70 Security Administrator these vulnerabilities are fixed in SCADAPack x70 RemoteConnect V3.7.3.904 and SCADAPack x70 Security Administrator V1.6.2 respectively and are available for download in the link below, as part of the RemoteConnect V2.4.2 package: https://shop.exchange.se.com/en-US/apps/58663 There is no need to reboot.
