The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric InsightHome/InsightFacility/Conext™ Gateway (Discontinued in 2019) version 1.16 Build 004 and prior
- Summary
- A CWE-20: Improper Input Validation vulnerability exists that could allow an authenticated attacker to gain the same privilege as the application on the server when a malicious payload is provided over HTTP for the server to execute.
- Remediation
- Version 1.17 Build 079 of Conext™ Gateway, InsightHome and InsightFacility includes a fix for this vulnerability and is available for download here: https://solar.se.com/us/en/product/insighthome-and-insightfacility-edge-devices/#downloads The installation procedure requires a reboot of the product to complete the update. After successful upgrade, the Insight Local and Insight Cloud Web UI will show latest firmware.
