The vendor explicitly identifies these products as affected by this CVE.
- Uni-Telway driver All versions
- Uni-Telway driver installed on EcoStruxure™ Control Expert All versions
- Uni-Telway driver installed on EcoStruxure™ Process Expert All versions
- Uni-Telway driver installed on EcoStruxure™ Process Expert for AVEVA System Platform All versions
- Uni-Telway driver installed on OPC Factory Server All versions
- Summary
- CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of engineering workstation when specific driver interface is invoked locally by an authenticated user with crafted input.
- Remediation
- For customers requiring the use of Uni-Telway driver, Schneider Electric recommends using following mitigations to reduce the risk of exploit:• McAfee Application and Change Control software for application control. Refer to the Cybersecurity Application Note available https://www.se.com/ww/en/download/document/EIO0000004778/ • Follow workstation, network and site-hardening guidelines in the Schneider Electric [Recommended Cybersecurity Best Practices](https://www.se.com/ww/en/download/document/7EN52-0390/) document. For customers not requiring the use of Uni-Telway driver, Schneider Electric recommends uninstalling the driver. Version 16.2 of EcoStruxureTM Control Expert, version 2025 of EcoStruxureTM Process Expert, version 2025 of EcoStruxureTM Process Expert for AVEVA System Platform, and version 3.63SP3 of OPC Factory Server do not include Uni-Telway driver by default anymore. This vulnerability is only affecting customers who have installed Uni-Telway driver.
