The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Wiser Smart version 4.5 and prior
- Schneider Electric Wiser Smart versions 4.5 and prior
- Summary
- A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could allow unauthorized access when an attacker uses cross-domain attacks.
- Remediation
- Wiser Smart [EER21000 and EER21001] products have reached its end of life and is no longer supported. Customers should immediately apply the following mitigations to reduce the risk of exploit: • These controller products should not have a publicly or Internet accessible IP address. • Do NOT use port forwarding to access these products from the public Internet. • These products should be on their own network segment. If your router supports a VLAN, it is preferable to locate the controller there. • Use the strongest Wi-Fi encryption available. • Never re-use passwords. • Use HTTPS in local network. • Only visit trusted websites.
