The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric EcoStruxure™ Operator Terminal Expert <3.3
- Schneider Electric Pro-face BLUE <3.3
- Summary
- A CWE-704: Incorrect Project Conversion vulnerability exists that allows adversaries with local user privileges to load a project file from an adversary-controlled network share which could result in execution of malicious code.
- Remediation
- EcoStruxure™ Operator Terminal Expert V3.3 Service Pack 1 includes a fix for these vulnerabilities and is available for download here: https://www.se.com/ww/en/product-range/62621-ecostruxure-operator-terminal-expert/#software-and-firmware This fix is also available through Schneider Electric Software Update (SESU).
