The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric StruxureWare Data Center Expert version 7.9.2 and prior
- Summary
- A CWE-862: Missing Authorization vulnerability exists that could allow viewing of unauthorized content, changes or deleting of content, or performing unauthorized functions when tampering the Device File Transfer settings on DCE endpoints.
- Remediation
- Version 7.9.3 of StruxureWare Data Center Expert includes fixes for these vulnerabilities and is available on request from Schneider Electric’s Customer Care Center.
