The vendor explicitly identifies these products as affected by this CVE.
- PowerLogic™ P7 version 0.2.003.001.000 and prior
- Summary
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution of commands with elevated privileges, impacting system integrity, confidentiality, and availability when a privileged authenticated user interacts with a vulnerable network-exposed service.
- Remediation
- Version V02.004.001 of PowerLogicTM P7 includes a fix for this vulnerability and is available for download here: • Contact Schneider Electric’s Customer Care Center to download this firmware. • Reboot needed: Yes
