The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric SCADAPack Workbench versions 6.6.8a and prior
- Summary
- A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could result in information disclosure when opening a malicious solution file provided by an attacker with SCADAPack Workbench. This could be exploited to pass data from local files to a remote system controlled by an attacker.
- Remediation
- Version 6.6.10 of SCADAPack Workbench includes a fix for this vulnerability and is available for download here: https://shop.exchange.se.com/en-US/apps/62860/scadapack-workbench-and-utilities Please follow the instructions on the download page for installation.
