The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Programmable Automation Controller (PacDrive) M All versions
- Summary
- A crafted request may cause a stack-based buffer overflow in the affected CODESYS products, resulting in a denial-of-service condition or being utilized for remote code execution.
- Remediation
- The Programmable Automation Controller (PacDrive) M product has been replaced with the newer PacDrive 3 product. Customers should consider migrating to the PacDrive 3 and following the steps below to resolve these issues: 1. Migrate to PacDrive 3 controllers: https://www.se.com/ww/en/product-range/7590-pacdrive-3/?subNodeId=12367561635en_WW. Please contact your local Schneider Electric technical support for more information. 2. Download and install latest EcoStruxure Machine Expert software available here: https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-%28somachine%29/ to program PacDrive 3 controllers. 3. Upgrade to the latest firmware versions of PacDrive 3 controllers through Schneider Electric Software Update (SESU) Note: a reboot of the controller will be required.
