The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric EcoStruxure Power Build: Rapsody Software <V2.1.13
- Summary
- A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could allow a stack-based buffer overflow to occur which could result in remote code execution when a malicious SSD file is uploaded and improperly parsed.
- Remediation
- These vulnerabilities have been fixed in V2.1.13. Links to the fix versions in supported languages can be found below: https://www.se.com/us/en/faqs/FA379051/
