The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric EcoStruxureTM Foxboro DCS Control Core Services versions prior to Patch HF98577958
- Summary
- CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an unpredictable index to an IOCTL call in the Foxboro.sys driver
- Remediation
- Patch HF98577958 of EcoStruxureTM Foxboro DCS Control Core Services includes a fix for these vulnerabilities. Please contact your local Service Representative or Schneider Electric Process Automation Global Customer Support Center for information on how to download and install this fix. Reboot is needed
