The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Enerlin'X IFE interface Version 004.009.000 and prior
- Schneider Electric Enerlin'X eIFE v004.009.000 and prior
- Summary
- CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the network services running on the product when malicious IEC61850-MMS packets are sent to the device. The core functionality of the breaker remains intact during the attack.
- Remediation
- Version 004.010.000 of Enerlin'X IFE and eIFE includes a fix for this vulnerability. Download the latest version of the EcoStruxure Power Commission tool available here: https://www.se.com/ww/en/product-range/62980-ecostruxure-powercommission/#overview to install the latest firmware version of the Enerlin'X IFE and eIFE.
