The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric EcoStruxure Power Design - NL All versions
- Schneider Electric EcoStruxure Power Design - INT All versions
- Schneider Electric EcoStruxure Power Design - FR All versions
- Summary
- CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution when a malicious project file is loaded into the application by a valid user
- Remediation
- Schneider Electric is establishing a remediation plan for all future versions of EcoStruxure Power Design - Ecodial that will include a fix for this vulnerability. We will update this document when the remediation is available. Until then, customers should immediately apply the following mitigations to reduce the risk of exploit: • Compute hash of the project files and regularly check the consistency of this hash to verify the integrity before usage. • Store the hash information in a separate location from where the project file is stored. • When sharing or receiving project files with another user, the hash information should be provided over a separate, out of band channel. • When exchanging files over the network, use secure communication protocols. • Only open project files received from a trusted source. • Harden the workstation running the application. • Delete the accounts of people who no longer need access to the application and the computer running the application following the principle of least privilege. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp
