The vendor explicitly identifies these products as affected by this CVE.
- SIMATIC CP 1543-1 (incl. SIPLUS variants)
- SIMATIC CP 1545-1
- Summary
- In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.
- Remediation
- Update to V3.0 or later version
