The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Accutech Manager Version 2.08.01 and prior
- Summary
- CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause a crash of the Accutech Manager when receiving a specially crafted request over port 2536/TCP.
- Remediation
- Version 2.10.0 of Accutech Manager includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/download/document/Accutech_Manager/ Instructions are provided with the software installation package on how to verify software revision.
