The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Easergy P5 <=V01.401.102
- Summary
- A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution or the crash of HTTPs stack which is used for the device Web HMI.
- Remediation
- V01.402.101 of the Easergy P5 firmware includes a fix for these vulnerabilities and is available on request from Schneider Electric’s Customer Care Center.
