The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric EcoStruxure™ Panel Server Version v2.0 and prior
- Summary
- CWE-532: Insertion of Sensitive Information into Log Files vulnerability exists that could cause the disclosure of FTP server credentials when the FTP server is deployed, and the device is placed in debug mode by an administrative user and the debug files are exported from the device.
- Remediation
- Version V2.1 or later of EcoStruxure™ Panel Server includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/40739468-ecostruxure-panel-server/?parent-subcategory-id=4160#software-and-firmware Customers should download EcoStruxure™ Power Commission Software version 2.33.0 or later, and version V2.1 or later of EcoStruxure™ Panel Server firmware to complete the upgrade process.
