The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric HMISCU Controller All versions prior to v6.3.1
- Schneider Electric Modicon Controller M241 All versions prior to v5.2.11.18
- Schneider Electric Modicon Controller M251 All Versions prior to v5.2.11.18
- Schneider Electric Modicon Controller M262 All versions prior to v5.2.8.12
- Schneider Electric Modicon Controller M258 All Versions
- Schneider Electric Modicon Controller LMC058 All Versions
- Schneider Electric PacDrive 3 Controllers: LMC Eco/Pro/Pro2 All versions prior to v1.76.14.1
- Schneider Electric SoftSPS embedded in EcoStruxure™ Machine Expert All Versions prior to Machine Expert v2.2
- Schneider Electric Vijeo Designer embedded in EcoStruxure™ Machine Expert All versions prior to v6.3.1
- Schneider Electric Harmony (Formerly Magelis) HMIGK/HMIGTO/HMIGTU/HMIGTUX/HMISTU series All Versions prior to V6.3 HF3
- Schneider Electric Easy Harmony HMIET6/HMIFT6 Magelis HMIGXU all versions prior to v2.0 HF2
- Schneider Electric Magelis XBT series All Versions
- Summary
- The Notification Center of the CODESYS Development System receives messages without ensuring that the message was not modified during transmission. This finally enables MITMs code execution when the user clicks the Learn More button.
- Remediation
- Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.
