The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Zelio Soft 2 Versions prior to 5.4.2.2
- Summary
- CWE-20: Improper Input Validation vulnerability exists that could cause a crash of the Zelio Soft 2 application when a specially crafted project file is loaded by an application user.
- Remediation
- Version 5.4.2.2 of Zelio Soft 2 includes a fix for these vulnerabilities and can be updated through the Schneider Electric Software Update (SESU) application and is also available for download here: https://www.se.com/ww/en/product-range/542-zelio-soft/#software-and-firmware
