The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric ConneXium Network Manager All versions
- Summary
- CWE-20: Improper Input Validation vulnerability exists that could cause a loss of Confidentiality, Integrity and Availability of engineering workstation when a malicious project file is loaded by a user from the local system.
- Remediation
- Please note that the ConneXium Network Manager product has reached the end of its life and is no longer supported. Customers should immediately apply the following mitigations to reduce the risk of exploit: • Only open project files received from a trusted source. • Compute a hash of the project files and regularly check the consistency of this hash to verify the integrity before usage. • Encrypt project file when stored and restrict the access to only trusted users. • When exchanging files over the network, use secure communication protocols. • Follow workstation, network and site-hardening guidelines in the Recommended Cybersecurity Best Practices available for download here: https://www.se.com/ww/en/download/document/7EN52-0390/
