Researchers at Tenable have discovered a critical remote code execution vulnerability affecting Schneider Electric InduSoft Web Studio and InTouch Machine Edition products. The vulnerability can be remotely exploited without authentication and targets the IWS Runtime Data Server service, by default on TCP port 1234. Security patches were made available on April 6 for both products, the vulnerability is triggered through command 50, and is caused by the incorrect usage of a string conversion function. The flaw affects the products, which are widely adopted in almost any industry, from energy to building automation.”]
Source: https://securityaffairs.co/wordpress/72051/hacking/schneider-electric-buffer-overflow.html