The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Harmony (Formerly Magelis) HMIST6, HMISTM6, HMIG3U, HMIG3X, HMISTO7 series with EcoStruxureTM Operator Terminal Expert runtime All versions
- Schneider Electric PFXST6000, PFXSTM6000, PFXSP5000, PFXGP4100 series with Pro-face BLUE runtime All versions
- Summary
- CWE-1104: Use of Unmaintained Third-Party Components exists that could cause complete control of the device when an authenticated user installs malicious code into HMI product.
- Remediation
- Customers should immediately apply the following mitigations to reduce the risk of exploit: • Use HMI only in a protected environment to minimize network exposure and ensure that they are not accessible from public internet or untrusted networks. • Setup network segmentation and implement a firewall to block all unauthorized access. • Restrict usage of unverifiable portable media • Restricting the application access to limit the transfer of Firmware to HMIScanning of software/files for rootkits before usage and verifying the digital signature. • When exchanging files over the network, use secure communication protocols.
