The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric EcoStruxure Power Commission version prior to 2.25
- Summary
- A CWE-285: Improper Authorization vulnerability exists that could cause unauthorized access to certain software functions when an attacker gets access to localhost interface of the EcoStruxure Power Commission application.
- Remediation
- Version 2.26 of EcoStruxure Power Commission includes a fix for these vulnerabilities and is available for download here: https://www.se.com/ww/en/product-range/62980-ecostruxure-power-commission/#software-and-firmware
