The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Data Center Expert Versions 8.1.1.3 and prior
- Summary
- CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause exposure of private data when an already generated “logcaptures” archive is accessed directly by HTTPS.
- Remediation
- Version 8.2 of EcoStruxure™ IT Data Center Expert includes fixes for these vulnerabilities and is available upon request from Schneider Electric’s Customer Care Center.
