The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric ConneXium Network Manager v2.0.01
- Summary
- CWE-552: Files or Directories Accessible to External Parties vulnerability over https exists that could leak information and potential privilege escalation following man in the middle attack.
- Remediation
- Please note that the ConneXium Network Manager product has reached the end of its life and is no longer supported. Customers should immediately apply the following mitigations to reduce the risk of exploit: • Disable the webserver (disabled by default) • Follow workstation, network and site-hardening guidelines in the Recommended Cybersecurity Best Practices available for download here: https://www.se.com/ww/en/download/document/7EN52-0390/
