The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric SCADAPack x70 Remote Connect V3.6.3.574 and prior
- Summary
- A CWE-284 Improper Access Control vulnerability exists which allows an attacker to place executables in a specific folder and run code whenever RemoteConnect is executed by the user.
- Remediation
- For SCADAPack x70 Remote Connect and SCADAPack x70 Security Administrator these vulnerabilities are fixed in SCADAPack x70 RemoteConnect V3.7.3.904 and SCADAPack x70 Security Administrator V1.6.2 respectively and are available for download in the link below, as part of the RemoteConnect V2.4.2 package: https://shop.exchange.se.com/en-US/apps/58663 There is no need to reboot.
