The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Trio™ Q Licensed Data Radio version prior to 2.7.2
- Summary
- CWE-1188: Incorrect Initialization of Resource vulnerability exists that could lead to loss of confidentiality when a malicious user, having physical access, sets the radio in factory default mode where the product does not correctly initialize all data.
- Remediation
- Version v2.7.2 of the TRIO™ Q Data Radio firmware includes fixes for the identified vulnerabilities and is available for download here: https://www.se.com/ww/en/product-range/61419-trio-licensed-radios/#software-andfirmware Instructions should be followed from Section 10 Part J – Firmware Updating and Maintenance in the Trio Q Series Data Radio User Manual This section provides information on how to download, install, and verify the new firmware version.
