The vendor explicitly identifies these products as affected by this CVE.
- EcoStruxure™ Power Operation (EPO) 2022 CU6 and prior
- EcoStruxure™ Power Operation (EPO) 2024 CU1 and prior
- Summary
- Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy's HTTP/2 codec may leak a header map and bookkeeping structures upon receiving `RST_STREAM` immediately followed by the `GOAWAY` frames from an upstream server. In nghttp2, cleanup of pending requests due to receipt of the `GOAWAY` frame skips de-allocation of the bookkeeping structure and pending compressed header. The error return [code path] is taken if connection is already marked for not sending more requests due to `GOAWAY` frame. The clean-up code is right after the return statement, causing memory leak. Denial of service through memory exhaustion. This vulnerability was patched in versions(s) 1.26.3, 1.25.8, 1.24.9, 1.23.11.
- Remediation
- The CVE's listed above affect the PostgresSQL pgadmin tool. If you have installed this tool, not required by EcoStruxure™ Power Operation 2024, we recommend you uninstall it from your EPO server and client machines.We strongly recommend customers take the following actions:• If waveform analysis and ETAP simulation features are not used, uninstall PostgreSQLOR• For those customers using waveform analysis and ETAP simulation features, we recommend all deployments of EPO only accept connections from localhost in PostgresSQL. Contact customer care for information on how to modify PostgreSQL. Further, we recommend you manually uninstall PostgreSQL 14.10 and update to PostgreSQL 14.17 or higher. EcoStruxure™ Power Operation 2024 CU2 includes an updated version of PostgreSQL and is available for download here: https://community.se.com/t5/EcoStruxure-Power-Operation/v2024-Release-amp-Updates-Install-Procedure/m-p/478928/thread-id/6997#M6997
