The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric GP-Pro EX WinGP for iPC v4.09.450 and prior
- Schneider Electric GP-Pro EX WinGP for PC/AT v4.09.450 and prior
- Summary
- A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause memory corruption when an authenticated user opens a tampered log file from GP-Pro EX.
- Remediation
- Version 4.09.500 of GP-Pro EX WinGP includes a fix for this vulnerability and is available for download here: https://www.proface.com/en/download/search?fileTypeId=updates&serieIds=screen_creation%2Fgpproex
