The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric EcoStruxure™ Operator Terminal Expert Runtime installed on Windows PC using legacy BIOS 3.1 Service Pack 1A and prior
- Schneider Electric EcoStruxure™ Operator Terminal Expert Runtime installed on Harmony iPC(HMIG3U) using legacy BIOS 3.1 Service Pack 1A and prior
- Schneider Electric Pro-face BLUE Runtime installed on Windows PC using legacy BIOS 3.1 Service Pack 1A and prior
- Schneider Electric Pro-face BLUE Runtime installed on Pro-face iPC (SP-5B10) using legacy BIOS 3.1 Service Pack 1A and prior
- Schneider Electric WinGP installed on Windows PC using legacy BIOS V4.09.120 and prior
- Schneider Electric WinGP installed on Pro-face PS4000 & PS5000 series and SP-5B40, SP5B41 using legacy BIOS V4.09.120 and prior
- Summary
- CWE-269 Improper Privilege Management vulnerability exists that could cause privilege escalation on the workstation when interacting directly with a driver installed by the runtime software of EcoStruxure™ Operator Terminal Expert or Pro-face BLUE or WinGP.
- Remediation
- • V3.1 Service Pack 1B of the EcoStruxure™ Operator Terminal Expert includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/productrange-download/62621-ecostruxure%E2%84%A2-operator-terminal-expert/#/softwarefirmware-tab o This fix is also available through Schneider Electric Software Update (SESU). Customers should use appropriate patching methodologies when applying these patches to their systems. We strongly recommend the use of back-ups and evaluating the impact of these patches in a Test and Development environment or on an offline infrastructure. Contact Schneider Electric's Customer Care Center https://www.se.com/ww/en/work/services/field-services/industrial-automation/industrial-cybersecurity/industrial-cybersecurity.jsp or Pro-face's Customer Care Center https://www.proface.com/en/contact if you need assistance removing a patch.
