The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric EcoStruxure™ Operation Terminal Expert <=3.3 SP1
- Schneider Electric Pro-face BLUE <=3.3 SP1
- Summary
- A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause execution of malicious code when an unsuspicious user loads a project file from the local filesystem into the HMI.
- Remediation
- EcoStruxureTM Operation Terminal Expert v3.4 includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/62621-ecostruxureoperator-terminal-expert/#software-and-firmware
