The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric EcoStruxure™ Power Automation System User Interface (EPAS-UI) Secured Versions from version 2.1 up to and including version 2.9
- Summary
- CWE-287: Improper Authentication vulnerability exists that could cause an Authentication Bypass when an unauthorized user without permission rights has physical access to the EPAS-UI computer and is able to reboot the workstation and interrupt the normal boot process.
- Remediation
- Version 2.10 of EcoStruxure™ Power Automation System User Interface (EPAS-UI) includes a fix for this vulnerability and is available by contacting Schneider Electric’s Customer Care Center https://www.se.com/us/en/work/support/contacts.jsp.
