The vendor explicitly identifies these products as affected by this CVE.
- Firmware Versions 11.06.31 and prior installed on EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller
- Firmware Versions 11.06.37 and prior installed on Saitel DP Remote Terminal Unit & Controller
- Summary
- CWE-732 Incorrect Permission Assignment for Critical Resource vulnerability that could cause unauthorized disclosure of password hashes and potential account compromise when an attacker with privileged local access reads improperly protected system files.
- Remediation
- Version 11.06.32 of EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller includes a fix for these vulnerabilities and is available:• Contact Schneider Electric’s Customer Care Center to download this firmware.• Reboot needed: Yes.
