The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Acti9 Smartlink SI D all versions prior to 002.004.002
- Schneider Electric Acti9 Smartlink SI B all versions prior to 002.004.002
- Schneider Electric Acti9 PowerTag Link / Link HD all versions prior to 001.008.007
- Schneider Electric Acti9 Smartlink EL B all versions prior to 1.2.1
- Schneider Electric Wiser Link all versions prior to 1.5.0
- Schneider Electric Wiser Energy all versions prior to 1.5.0
- Summary
- CWE-330 - Use of Insufficiently Random Values vulnerability exists that could allow unauthorized users to login.
- Remediation
- Customers with impacted Smartlink SI B/D and PowerTag Link products should update to the latest firmware using EcoStruxure Power Comission installer v.7.0 available here: https://www.se.com/ww/en/product-range-download/64482-acti9-powertag-link/?selected-nodeid=12492093362#/software-firmware-tab
