The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric NetBotz 4 - 355 version 4.7.0 and prior
- Schneider Electric NetBotz 4 - 450 version 4.7.0 and prior
- Schneider Electric NetBotz 4 - 455 version 4.7.0 and prior
- Schneider Electric NetBotz 4 - 550 version 4.7.0 and prior
- Schneider Electric NetBotz 4 - 570 version 4.7.0 and prior
- Summary
- A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause account takeover when a brute force attack is performed on the account
- Remediation
- Version 4.7.2of NetBotz 4 -355/450/455/550/570includes a fix for these vulnerabilities and is available for download. Upon upgrade the system will automatically reboot. Verify the upgrade was successful by ensuring it is running version 4.7.2.
