The vendor explicitly identifies these products as affected by this CVE.
- EcoStruxure™ Power Operation (EPO) 2022 CU6 and prior
- EcoStruxure™ Power Operation (EPO) 2024 CU1 and prior
- Summary
- Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- Remediation
- The CVE's listed above affect the PostgresSQL pgadmin tool. If you have installed this tool, not required by EcoStruxure™ Power Operation 2024, we recommend you uninstall it from your EPO server and client machines.We strongly recommend customers take the following actions:• If waveform analysis and ETAP simulation features are not used, uninstall PostgreSQLOR• For those customers using waveform analysis and ETAP simulation features, we recommend all deployments of EPO only accept connections from localhost in PostgresSQL. Contact customer care for information on how to modify PostgreSQL. Further, we recommend you manually uninstall PostgreSQL 14.10 and update to PostgreSQL 14.17 or higher. EcoStruxure™ Power Operation 2024 CU2 includes an updated version of PostgreSQL and is available for download here: https://community.se.com/t5/EcoStruxure-Power-Operation/v2024-Release-amp-Updates-Install-Procedure/m-p/478928/thread-id/6997#M6997
