The vendor explicitly identifies these products as affected by this CVE.
- EcoStruxure Panel Server PAS800 Versions 002.005.000 and prior
- EcoStruxure Panel Server PAS800V2 Versions 002.005.000 and prior
- EcoStruxure Panel Server PAS600 Versions 002.005.000 and prior
- EcoStruxure Panel Server PAS600V2 Versions 002.005.000 and prior
- EcoStruxure Panel Server PAS400 Versions 002.005.000 and prior
- Summary
- CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in rare circumstances, enabling unauthorized authentication using known credentials
- Remediation
- Version 002.006.000 of EcoStruxure Panel Server includes a fix for this vulnerability and is available for download here: • https://www.se.com/ww/en/download/document/PAS800_Fir mware_Package/ • Reboot needed: Yes
