The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Saitel DR RTU Versions 11.06.29 and prior
- Schneider Electric Saitel DP RTU Versions 11.06.33 and prior
- Summary
- CWE-78: Improper Neutralization of Special Elements used in an OS Command vulnerability exists that could cause the execution of any shell command when executing a netstat command using BLMon Console in an SSH session.
- Remediation
- HUe Firmware version 11.06.30 of Saitel DR includes a fix for this vulnerability and is available for download here: • https://www.se.com/ww/en/product-country-selector/?pageType=product-range&sourceId=62685 A reboot is needed to complete the firmware upgrade.
