The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric SoMachine HVAC version prior to 2.1.0
- Schneider Electric EcoStruxureTM Machine Expert – HVAC version prior to 1.4.0
- Summary
- A CWE-787: Out-of-bounds Write vulnerability exists that could cause sensitive information leakage when accessing a malicious web page from the commissioning software.
- Remediation
- Version 1.5.0 of EcostruxureTM Machine Expert - HVAC includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/download/document/SoMachine+HVAC+-+Programming+Software+for+Modicon+M171-M172+Logic+Controllers/ No reboot is required. It is recommended that customers using SoMachine - HVAC upgrade to EcostruxureTM Machine Expert – HVAC.
