The vendor explicitly identifies these products as affected by this CVE.
- SICK SOPAS Engineering Tool <2021.4 (4.8.0)
- Summary
- SDD files might contain an executable file that will be listed as the Emulators inside SOPAS ET. When a user starts the emulator, the executable is run without further checks. Attackers could wrap any executable file into an SDD and provide this to a SOPAS ET user. When installing the SDD the user may not be aware about the executable inside of the SDD.
- Remediation
- Update to at least version 4.8.0
