The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric C-Bus Toolkit <1.15.9
- Schneider Electric C-Gate Server <2.11.7
- Summary
- A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could allow a remote code execution when restoring a project.
- Remediation
- Version 1.15.10 of the C-Bus Toolkit product, which contains the C-Gate Server, includes a fix for these vulnerabilities and is available for download here:
