The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric SESU Versions prior to v3.0.12
- Schneider Electric SESU Versions prior to v3.0.12 installed on Schneider Electric BESS ANSI
- Schneider Electric SESU Versions prior to v3.0.12 installed on Schneider Electric Easergy MiCOM P30
- Schneider Electric SESU Versions prior to v3.0.12 installed on Schneider Electric Easergy MiCOM P40
- Schneider Electric SESU Versions prior to v3.0.12 installed on Schneider Electric Easergy Studio
- Schneider Electric SESU Versions prior to v3.0.12 installed on Schneider Electric EcoStruxure™ Automation Expert
- Schneider Electric SESU Versions prior to v3.0.12 installed on Schneider Electric Harmony XB5S Soft
- Schneider Electric SESU Versions prior to v3.0.12 installed on Schneider Electric eXLhoist Configuration Software
- Schneider Electric SESU Versions prior to v3.0.12 installed on Schneider Electric EcoStruxure™ Automation Device Maintenance
- Schneider Electric SESU Versions prior to v3.0.12 installed on Schneider Electric EcoStruxure™ Machine Expert
- Schneider Electric SESU Versions prior to v3.0.12 installed on Schneider Electric EcoStruxure™ Machine Expert Basic
- Schneider Electric SESU Versions prior to v3.0.12 installed on Schneider Electric EcoStruxure™ Automation Expert Motion
- Summary
- CWE-59: Improper Link Resolution Before File Access ('Link Following') vulnerability exists that could cause arbitrary data to be written to protected locations, potentially leading to escalation of privilege, arbitrary file corruption, exposure of application and system information or persistent denial of service when a low-privileged attacker tampers with the installation folder.
- Remediation
- Version 3.0.12 of SESU includes a fix for this vulnerability and is available for download here: https://www.seupdate.schneiderelectric.com/download/SystemConsistency/Soft wareUpdate/SESU_latest_version/SESU_latest _setup_sfx.exe Follow the installation instructions. If a predecessor version of SESU is already installed, then the update to V3.0.12 will be done automatically as a critical update in the background depending on the “automatic” update configuration.
