The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Vijeo Designer Versions prior to V6.3 SP1
- Schneider Electric Vijeo Designer optional component of Schneider Electric EcoStruxure™ Machine Expert Versions prior to v2.3
- Summary
- CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and availability of the workstation when non-admin authenticated user tries to perform privilege escalation by tampering with the binaries
- Remediation
- Vijeo Designer version 6.3.2.16 delivered with EcoStruxure™ Machine Expert v2.3 includes a fix for this vulnerability. EcoStruxure™ Machine Expert v2.3 is available via the Schneider Electric Software Installer: https://www.se.com/ww/en/download/document/ESEMACS10_INSTALLER On the engineering workstation, install v2.3 of EcoStruxure™ Machine Expert.
