The vendor explicitly identifies these products as affected by this CVE.
- Firmware Versions 11.06.31 and prior installed on EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller
- Firmware Versions 11.06.36 and prior installed on Saitel DP Remote Terminal Unit & Controller
- Summary
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory (“Path Traversal”) vulnerability that could cause unauthorized access to sensitive files when user-supplied input is improperly handled during server-side file path processing.
- Remediation
- Version 11.06.32 of EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller includes a fix for this vulnerability and is available for download here: • Contact Schneider Electric’s Customer Care Center to download this firmware. • Reboot needed: Yes
