The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Trio Q-Series Ethernet Data Radio All Versions
- Schneider Electric Trio E-Series Ethernet Data Radio All Versions
- Schneider Electric Trio J-Series Ethernet Data Radio All Versions
- Summary
- A CWE-494: Download of Code Without Integrity Check vulnerability exists that could allow a privileged user to install an untrusted firmware.
- Remediation
- Trio Data Radios should be installed in a secure location to prevent physical access by unauthorized personnel, and appropriate password protections put in place to prevent remote access by unauthorized personnel. Firmware loaded in Trio Data Radios should be confirmed using the hash published with the release notes and following the instructions in Section 10 Part J – Firmware Updating and Maintenance in the Trio Q Data Radio User Manual, available here: https://download.schneiderelectric.com/files?p_Doc_Ref=Trio+Q+Data+Radio+U ser+Manual&p_enDocType=User+guide&p_File_Nam e=Trio+Q+Data+Radio+User+Manual.pdf This section provides information on how to download, install, and verify the new firmware
