The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric C-Bus Toolkit v1.15.8 and prior
- Summary
- A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow an attacker to use a crafted webpage to obtain remote access to the system.
- Remediation
- Version 1.15.9 of the C-Bus Toolkit product includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/2216-spacelogic-c-bus-home-automation-system/?parent-subcategory-id=88010&filter=business-5-residential-and-small-business#software-and-firmware Note: A reboot will be needed after the update.
