The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Accutech Manager <= 2.7
- Summary
- A CWE-120: Buffer Copy without Checking Size of Input (Classic Buffer Overflow) vulnerability exists that could cause user privilege escalation if a local user sends specific string input to a local function call.
- Remediation
- Version 2.8 of Accutech Manager includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/download/document/Accutech_Manager/ Instructions are provided with the software installation package on how to verify software revision.
