The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric SCADAPack x70 Security Administrator V1.2.0 and prior
- Summary
- A CWE-502 Deserialization of Untrusted Data vulnerability exists which could allow arbitrary code execution when an attacker builds a custom .SDB file containing a malicious serialized buffer.
- Remediation
- For SCADAPack x70 Remote Connect and SCADAPack x70 Security Administrator these vulnerabilities are fixed in SCADAPack x70 RemoteConnect V3.7.3.904 and SCADAPack x70 Security Administrator V1.6.2 respectively and are available for download in the link below, as part of the RemoteConnect V2.4.2 package: https://shop.exchange.se.com/en-US/apps/58663 There is no need to reboot.
