The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric EcoStruxure™ Control Expert version 15.1 HF001 and prior
- Summary
- A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a crash of the Control Expert software when an incorrect project file is opened.
- Remediation
- V15.2 of EcoStruxure™ Control Expert includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/download/document/EcoStruxureControlExpert_V15.2/
