The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Harmony Timer Relay All versions
- Schneider Electric Harmony Control Relay All versions
- Summary
- CWE-287: Improper Authentication vulnerability exists that could cause unauthorized tampering of device configuration over NFC communication.
- Remediation
- Customers should immediately apply the following mitigations to reduce the risk of exploit: Attack is possible only with physical proximity to the relay. Schneider Electric strongly recommend installing the Harmony Control Relays in locked cabinet for added security. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications. jsp
