The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric NetBotz 4 - 355 version 4.7.0 and prior
- Schneider Electric NetBotz 4 - 450 version 4.7.0 and prior
- Schneider Electric NetBotz 4 - 455 version 4.7.0 and prior
- Schneider Electric NetBotz 4 - 550 version 4.7.0 and prior
- Schneider Electric NetBotz 4 - 570 version 4.7.0 and prior
- Summary
- A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause the user to be tricked into performing unintended actions when external address frames are not properly restricted.
- Remediation
- Version 4.7.2of NetBotz 4 -355/450/455/550/570includes a fix for these vulnerabilities and is available for download. Upon upgrade the system will automatically reboot. Verify the upgrade was successful by ensuring it is running version 4.7.2.
