The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric PowerLogic P5 version v01.500.104 and prior
- Summary
- CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists that could cause denial of service, device reboot, or an attacker gaining full control of the relay when a specially crafted reset token is entered into the front panel of the device.
- Remediation
- PowerLogic P5 Wave 4.2.3 P5L30 firmware includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center to download this firmware.
