The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric EcoStruxure™ Cybersecurity Admin Expert (CAE) <=2.2
- Summary
- A CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause legitimate users to be locked out of devices or facilitate backdoor account creation by spoofing a device on the local network.
- Remediation
- Version 2.4 of the EcoStruxure™ Cybersecurity Admin Expert product includes fixes for these vulnerabilities and is available for download here: https://www.se.com/ww/en/product-range/63515-ecostruxure-cybersecurity-admin-expert/#software-and-firmware Install the new CAE version 2.4 (over any previous version) and the fixes will be available.
