The vendor explicitly identifies these products as affected by this CVE.
- Eurotherm by Schneider Electric GUIcon (Build 683.003) 2.0 and prior
- Summary
- A CWE-125:Out-of-Bounds Read vulnerability exists that could cause unintended data disclosure when a malicious *.gd1 configuration file is loaded into the GUIcon tool.
- Remediation
- The GUIcon software tool was discontinued on 24 June 2020 and is no longer supported. Customers should immediately apply the following mitigation to reduce the risk of exploit: The only known method for an attacker to exploit the vulnerabilities is to create a malicious GUIcon *.gd1 configuration file and then trick a user into opening it with the GUIcon software, resulting in possible remote code execution. Therefore, the specific mitigation for these vulnerabilities is to ensure that any GUIcon *.gd1 file being loaded into the tool is from a trusted source.
