The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Enerlin'X IFE interface (LV434001) All Versions
- Schneider Electric Enerlin'X eIFE (LV851001) All Versions
- Summary
- CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the product when malicious ICMPV6 packets are sent to the device.
- Remediation
- Customers should immediately apply the following mitigations to reduce the risk of exploit: * Use devices only in a protected environment to minimize network exposure and ensure that they are not accessible from public internet or untrusted networks. * Setup network segmentation and implement a firewall to block all unauthorized access to ports supported by the product and listed in the user guide: https://www.se.com/ww/en/download/document/DOCA0084EN/ Configure the Access Control List following the recommendations of the Cybersecurity Guide: https://www.se.com/ww/en/download/document/DOCA0122EN/ and the user guide: https://www.se.com/ww/en/download/document/DOCA0084EN/ To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric's security notification service here: https://www.se.com/en/work/support/cybersecurity/security-notifications.jsp
