The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric SpaceLogic C-Bus Home Controller (5200WHC2) <=V1.31.460
- Summary
- A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote root exploit when the command is compromised.
- Remediation
- Customers need to use V4.14.0 of PICED installer to install the updates that remediate this vulnerability, available here: https://www.se.com/ww/en/product-range/2216-spacelogic-cbus-home-automation-system/?parent-subcategory-id=88010&filter=business-5-residential-and-small-business#software-and-firmware A reboot is needed.
