The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric HMISCU Controller All versions prior to v6.3.1
- Schneider Electric Modicon Controller M241 All versions prior to v5.2.11.18
- Schneider Electric Modicon Controller M251 All Versions prior to v5.2.11.18
- Schneider Electric Modicon Controller M262 All versions prior to v5.2.8.12
- Schneider Electric Modicon Controller M258 All Versions
- Schneider Electric Modicon Controller LMC058 All Versions
- Schneider Electric PacDrive 3 Controllers: LMC Eco/Pro/Pro2 All versions prior to v1.76.14.1
- Schneider Electric SoftSPS embedded in EcoStruxure™ Machine Expert All Versions prior to Machine Expert v2.2
- Schneider Electric Vijeo Designer embedded in EcoStruxure™ Machine Expert All versions prior to v6.3.1
- Schneider Electric Harmony (Formerly Magelis) HMIGK/HMIGTO/HMIGTU/HMIGTUX/HMISTU series All Versions prior to V6.3 HF3
- Schneider Electric Easy Harmony HMIET6/HMIFT6 Magelis HMIGXU all versions prior to v2.0 HF2
- Schneider Electric Magelis XBT series All Versions
- Summary
- After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-ofservice condition.
- Remediation
- Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.
