The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric IGSS Definition (Def.exe) versions 14.0.0.20247 and prior
- Summary
- CWE-787 Out-of-bounds Write vulnerability exists that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.
- Remediation
- Version 14.0.0.20248 of the IGSS Definition module: Def.exe includes a fix for this vulnerability and is available for download through IGSS Master > Update IGSS Software or here: https://igss.schneider-electric.com/igss/igssupdates/v140/IGSSUPDATE.ZIP Customers should use appropriate patching methodologies when applying these patches to their systems. We strongly recommend the use of back-ups and evaluating the impact of these patches in a Test and Development environment or on an offline infrastructure. Contact Schneider Electric’s Customer Care Center https://www.se.com/us/en/work/support/ if you need assistance removing a patch.
