The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric EcoStruxureTM Foxboro DCS Core Control Services version 9.8 and prior
- Schneider Electric EcoStruxureTM Foxboro DCS Core Control Services version from v9.5 to v9.8
- Summary
- CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, or kernel memory leak when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
- Remediation
- Patch HF97872598 available for v9.5 to v9.8 of EcoStruxureTM Foxboro DCS Core Control Services includes a fix for these vulnerabilities. Please contact your local Service Representative or Schneider Electric Process Automation Global Customer Support Center for information on how to download and install this fix:
