The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric EcoStruxure IT Gateway versions 1.20.x and prior
- Summary
- CWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege escalation when logged in as a non-administrative user
- Remediation
- Version 1.21 of EcoStruxure IT Gateway includes a fix for these vulnerabilities and is available for download here: • If you have enabled auto updates in EcoStruxure IT, then the update will be automatically applied. • If you would like to manually update, follow the instructions here to upgrade the gateway software to the latest version: https://community.se.com/t5/Gateway-software-installationand/Updating-EcoStruxure-IT-Gateway-to-the-latestversion/ta-p/447049. For further information, see System Requirements The upgrade process will perform a full remediation. After performing an upgrade to version 1.21.x or later, there are no additional steps necessary. Verify the version of EcoStruxure IT Gateway software is v1.21 or later.
