IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Security notifications

CRITICAL
CVSS 10.0
Date 2026-07-28T15:18:04+00:00
Source schneider-electric
Published by Schneider Electric

// Description

![Image 1](https://cdn.builder.io/api/v1/pixel?apiKey=87a13b564d504489a60e78515594f31e) Choose a video ![Image 2](https://www.se.com/ww/en/assets/v2/564/media/363042/560/990909516-IC-1920x1080.jpg) # Cybersecurity support portal We address cybersecurity vulnerabilities via responsible vulnerability management to better ensure the safety and security of our installed solutions and customers. * [Security Notifications](https://www.se.com/ww/en/work/support/cybersecurity/security-notificatio

// Vulnerabilities (786)

CVE ID CVSS Score Severity Description
CVE-2023-28004 0.0 unknown
No description available.
CVE-2026-2404 0.0 unknown
CVE-2026-2404. CWE-116 Improper Encoding or Escaping of Output vulnerability exists that could cause log injection and forged log when an attacker alters the POST /j_security check request payload.
CVE-2026-9650 0.0 unknown
No description available.
CVE-2026-9716 0.0 unknown
CVE-2026-9716. CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuration functionality unavailable when malformed requests are received over exposed network interfaces.
CVE-2026-6865 0.0 unknown
CVE-2026-6865. CWE-22: Improper Limitation of a Pathname to a Restricted Directory (“Path Traversal”) vulnerability that could cause unauthorized access to sensitive files when user-supplied input is improperly handled during server-side file path processing.
CVE-2026-4832 0.0 unknown
CVE-2026-4832. CWE-798 Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to sensitive device information when an unauthenticated attacker is able to interrogate the SNMP port.
CVE-2026-8045 0.0 unknown
CVE-2026-8045. CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert user account submits crafted XML payloads to SOAP service endpoints
CVE-2025-13901 0.0 unknown
CVE-2025-13901. CWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of Service on Machine Expert protocol when an unauthenticated attacker sends malicious payload to occupy active communication channels.
CVE-2026-6866 0.0 unknown
CVE-2026-6866. CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in rare circumstances, enabling unauthorized authentication using known credentials
CVE-2026-9651 0.0 unknown
No description available.
CVE-2026-14354 0.0 unknown
No description available.
CVE-2025-13902 0.0 unknown
CVE-2025-13902. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause condition where authenticated attackers can have a victim’s browser run arbitrary JavaScript when the victim hovers over a maliciously crafted element on a web server containing the injected payload.
CVE-2026-2405 0.0 unknown
CVE-2026-2405. CWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting zip file creation and denial of service when a Web Admin user floods the system with POST /helpabout requests.
CVE-2026-2399 0.0 unknown
CVE-2026-2399. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause critical files overwritten with text data when a Web Admin user alters the POST /REST/upssleep request payload.
CVE-2025-11739 0.0 unknown
CVE-2025-11739. A deserialization of untrusted data vulnerability exists that could cause arbitrary code execution with administrative privileges when a locally authenticated attacker sends a crafted data stream, triggering unsafe deserialization.
CVE-2026-2401 0.0 unknown
CVE-2026-2401. CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information to be exposed when a Web Admin user executes a malicious file provided by an attacker.
CVE-2026-2403 0.0 unknown
CVE-2026-2403. CWE-1284 Improper Validation of Specified Quantity in Input vulnerability exists that could cause Event and Data Log truncation impacting log integrity when a Web Admin user alters the POST /logsettings request payload.
CVE-2026-9717 0.0 unknown
CVE-2026-9717. CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution of commands with elevated privileges, impacting system integrity, confidentiality, and availability when a privileged authenticated user interacts with a vulnerable network-exposed service.
CVE-2026-2400 0.0 unknown
CVE-2026-2400. CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists that could cause application user credentials to reset when a Web Admin user alters the POST /setPCBEDesc request payload.
CVE-2026-9718 0.0 unknown
CVE-2026-9718. CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-service condition, impacting system availability when a specially crafted request is sent to a vulnerable network-exposed service.
CVE-2024-3596 0.0 unknown
CVE-2024-3596. RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify responses Access-Reject or Access-Accept using a chosen-prefix collision attack against MD5 Response Authenticator signature.
CVE-2026-2402 0.0 unknown
CVE-2026-2402. CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to gain access to the user account by performing an arbitrary number of authentication attempts with different credentials on a sequence of requests to multiple endpoints.
CVE-2026-1286 0.0 unknown
CVE-2026-1286. A deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote code execution on workstation when an admin authenticated user opens a malicious project file.
CVE-2026-4827 0.0 unknown
CVE-2026-4827. CWE-331 Insufficient Entropy vulnerability exists that could lead to unauthorized access when an attacker on the network can exploit weaknesses in session‑management protections.
CVE-2025-13957 0.0 unknown
CVE-2025-13957. A hard-coded credentials vulnerability exists that could lead to information disclosure and remote code execution when SOCKS Proxy is enabled, and administrator credentials and PostgreSQL database credentials are known. SOCKS Proxy is disabled by default.
CVE-2026-12927 0.0 unknown
No description available.
CVE-2026-6332 0.0 unknown
No description available.
CVE-2026-2273 0.0 unknown
CVE-2026-2273. CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untrusted commands on the engineering workstation which could result in a limited compromise of the workstation and a potential loss of Confidentiality, Integrity and Availability of the subsequent system when an authenticated user opens a malicious project file.
CVE-2019-8963 0.0 unknown
No description available.
CVE-2022-47393 0.0 unknown
CVE-2022-47393. An authenticated, remote attacker may use a Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple versions of multiple CODESYS products to force a denial-of-service situation.
CVE-2024-8531 0.0 unknown
CVE-2024-8531. CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could compromise the Data Center Expert software when an upgrade bundle is manipulated to include arbitrary bash scripts that are executed as root.
CVE-2022-2329 0.0 unknown
No description available.
CVE-2021-22816 0.0 unknown
No description available.
CVE-2022-41666 0.0 unknown
No description available.
CVE-2020-7572 6.7 medium
CVE-2020-7572. An improper restriction of XML external entity reference vulnerability could allow an authenticated remote user to inject arbitrary XML code and obtain disclosure of confidential data, cause a denial-of-service condition, or execute server-side request forgery due to improper configuration of the XML parser.CVE-2020-7572 has been assigned to this vulnerability. A CVSS v3 base score of 6.7 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:H).
CVE-2018-7809 0.0 unknown
No description available.
CVE-2025-5742 0.0 unknown
CVE-2025-5742. CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists when an authenticated user modifies configuration parameters on the web server
CVE-2022-32528 0.0 unknown
No description available.
CVE-2020-7551 7.8 high
An improper restriction of operations within the bounds of a memory buffer vulnerability could cause remote code execution when a malicious CGF (Configuration Group File) is imported to IGSS Definition.CVE-2020-7551 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2023-37198 0.0 unknown
No description available.
CVE-2020-7539 0.0 unknown
No description available.
CVE-2025-54926 0.0 unknown
CVE-2025-54926. CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution when an authenticated attacker with admin privileges uploads a malicious file over HTTP which then gets executed.
CVE-2020-11900 0.0 unknown
Possible double free in IPv4 tunneling component when handling a packet sent by a network attacker. This vulnerability may result in use after free.
CVE-2021-22785 0.0 unknown
No description available.
CVE-2021-21866 0.0 unknown
CVE-2021-21866. A unsafe deserialization vulnerability exists in the ObjectManager.plugin ProfileInformation.ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.
CVE-2022-24311 9.8 critical
A vulnerability exists that could cause modification of an existing file by inserting data at the beginning of the file or creating a new file in the context of the data server. This could potentially lead to remote code execution when an attacker sends a specially crafted message.CVE-2022-24311 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2025-13844 0.0 unknown
CVE-2025-13844. A double-free vulnerability may lead to heap memory corruption when an end user imports a malicious SSD project file shared by an attacker into Rapsody.
CVE-2019-1225 0.0 unknown
No description available.
CVE-2021-22809 4.4 medium
This vulnerability may cause arbitrary code execution when a malicious *.gd1 configuration file is loaded into the GUIcon tool.CVE-2021-22809 has been assigned to this vulnerability. A CVSS v3 base score of 4.4 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L).
CVE-2021-22711 7.8 high
This vulnerability could result in arbitrary read or write conditions due to missing validation of input data when a malicious CGF file is imported into an IGSS Definition.CVE-2021-22711 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2020-0601 0.0 unknown
No description available.
CVE-2025-50121 0.0 unknown
CVE-2025-50121. CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause unauthenticated remote code execution when a malicious folder is created over the web interface HTTP when enabled. HTTP is disabled by default.
CVE-2022-22727 0.0 unknown
No description available.
CVE-2021-21829 0.0 unknown
A heap-based buffer overflow vulnerability exists in the XML Decompression EnumerationUncompressor::UncompressItem functionality of AT&T Labs ' Xmill 0.7. A specially crafted XMI file can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.CVE-2021-21829 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2019-0708 0.0 unknown
The affected product is vulnerable to a remote code execution vulnerability that exists in Remote Desktop Services (formerly known as Terminal Services) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would need to send a specially crafted request to the target system 's Remote Desktop Service via RDP.CVE-2019-0708 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2024-8938 0.0 unknown
CVE-2024-8938. CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause potential arbitrary code execution after a successful Man-In -The Middle attack followed by sending crafted Modbus command in order to tamper with a function call used to evaluate memory size.
CVE-2021-22760 7.8 high
Exploitation of this vulnerability could result in loss of data or remote code execution due to missing checks of user-supplied input data when a malicious CGF file is imported to IGSS Definition.CVE-2021-22760 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2020-7503 0.0 unknown
No description available.
CVE-2023-37558 0.0 unknown
CVE-2023-37558. After successful authentication as a user in multiple CODESYS products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of-service condition.
CVE-2021-22727 0.0 unknown
No description available.
CVE-2024-2602 0.0 unknown
CVE-2024-2602. CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could result in remote code execution when an authenticated user executes a saved project file that has been tampered by a malicious actor.
CVE-2022-22811 0.0 unknown
No description available.
CVE-2020-7571 6.1 medium
CVE-2020-7571. Multiple improper neutralizations of an input during webpage generation vulnerabilities could allow a remote attacker to inject arbitrary web script or HTML due to incorrect sanitization of user supplied data and achieve a reflected cross-site scripting attack against other WebReport users.CVE-2020-7571 has been assigned to this vulnerability. A CVSS v3 base score of 6.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
CVE-2023-25553 0.0 unknown
No description available.
CVE-2024-12142 0.0 unknown
CVE-2024-12142. CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information disclosure of restricted web page, modification of web page and denial of service when specific web pages are modified and restricted functions are invoked.
CVE-2024-37039 0.0 unknown
CVE-2024-37039. CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request.
CVE-2025-2002 0.0 unknown
CVE-2025-2002. CWE-532: Insertion of Sensitive Information into Log Files vulnerability exists that could cause the disclosure of FTP server credentials when the FTP server is deployed, and the device is placed in debug mode by an administrative user and the debug files are exported from the device.
CVE-2021-22736 0.0 unknown
No description available.
CVE-2020-7486 7.5 high
A vulnerability could cause TCMs installed in Tricon system Versions 10.0.0 through 10.4.x to reset when under high network load. This reset could result in a denial of service behavior with the SIS.CVE-2020-7486 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
CVE-2024-6351 0.0 unknown
CVE-2024-6351. A CWE-120: A buffer overflow vulnerability exists that could cause a denial of service when a malicious device joins the network.
CVE-2020-28213 0.0 unknown
No description available.
CVE-2018-7844 0.0 unknown
CVE-2018-7844. An information exposure vulnerability exists, which could cause the disclosure of SNMP information when reading memory blocks from the controller over Modbus.
CVE-2025-7746 0.0 unknown
CVE-2025-7746. CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause an unvalidated data injected by a malicious user potentially leading to modify or read data in a victim’s browser.
CVE-2024-5680 0.0 unknown
CVE-2024-5680. CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denialof- service when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
CVE-2021-30061 0.0 unknown
No description available.
CVE-2023-29410 0.0 unknown
No description available.
CVE-2021-22773 0.0 unknown
No description available.
CVE-2021-22789 0.0 unknown
No description available.
CVE-2020-7540 0.0 unknown
No description available.
CVE-2022-24324 0.0 unknown
No description available.
CVE-2024-10085 0.0 unknown
CVE-2024-10085. CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause denial of service of EcoStruxure OPCUA Server Expert when a large number of OPC UA requests are sent to the server.
CVE-2021-21864 0.0 unknown
CVE-2021-21864. A unsafe deserialization vulnerability exists in the ComponentModel ComponentManager.StartupCultureSettings functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.
CVE-2022-22804 0.0 unknown
No description available.
CVE-2022-47392 0.0 unknown
CVE-2022-47392. An authenticated, remote attacker may use a improper input validation vulnerability in the CmpApp/CmpAppBP/CmpAppForce Components of multiple CODESYS products in multiple versions to read from an invalid address which can lead to a denial-of-service condition.
CVE-2025-13905 0.0 unknown
CVE-2025-13905. CWE-276 : Incorrect Default Permissions vulnerability exists that could cause privilege escalation through the reverse shell when one or more executable service binaries are modified in the installation folder by a local user with normal privilege upon service restart.
CVE-2021-22810 6.8 medium
A vulnerability could cause arbitrary script execution when a privileged account clicks on a malicious URL specifically crafted for the NMC pointing to a delete policy file.CVE-2021-22810 has been assigned to this vulnerability. A CVSS v3 base score of 6.8 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N).
CVE-2022-47391 0.0 unknown
CVE-2022-47391. In multiple CODESYS products in multiple versions an unauthorized, remote attacker may use a improper input validation vulnerability to read from invalid addresses leading to a denial of service.
CVE-2020-28214 3.3 low
A use of a one-way hash with a predictable salt vulnerability exists that could allow the attacker to pre-compute the hash value using a dictionary attack, effectively disabling the protection that an unpredictable salt would provide.CVE-2020-28214 has been assigned to this vulnerability. A CVSS v3 base score of 3.3 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
CVE-2021-21865 0.0 unknown
CVE-2021-21865. A unsafe deserialization vulnerability exists in the PackageManagement.plugin ExtensionMethods.Clone() functionality of CODESYS GmbH CODESYS Development System 3.5.16. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.
CVE-2021-22709 7.8 high
This vulnerability could result in loss of data or remote code execution when a malicious CGF (configuration group file) file is imported into an IGSS Definition.CVE-2021-22709 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2023-44487 0.0 unknown
CVE-2023-44487. The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2023-27981 0.0 unknown
A vulnerability in Schneider Electric Custom Reports could cause remote code execution if an unsuspecting user opens a malicious report. CVE-2023-27981 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2020-25180 5.3 medium
ISaGRAF Runtime includes the functionality of setting a password that is required to execute privileged commands. The password value passed to ISaGRAF Runtime is the result of encryption performed with a fixed key value using the Tiny Encryption Algorithm (TEA) on an entered or saved password. A remote, unauthenticated attacker could pass their own encrypted password to the ISaGRAF 5 Runtime, which may result in information disclosure on the device.CVE-2020-25180 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N).
CVE-2022-43376 0.0 unknown
No description available.
CVE-2021-21826 0.0 unknown
A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7. Within `DecodeTreeBlock,` which is called during the decompression of an XMI file, a UINT32 is loaded from the file and used as trusted input as the length of a buffer.CVE-2021-21826 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2024-2229 0.0 unknown
All versions of Schneider Electric EcoStruxure Power Design - Ecodial NL, INT, and FR deserializes untrusted data which could allow an attacker to perform code execution when a malicious project file is loaded into the application by a valid user.
CVE-2021-21811 0.0 unknown
A memory corruption vulnerability exists in the XML-parsing CreateLabelOrAttrib functionality of AT&T Labs ' Xmill 0.7. The product subtracts one value from another such that the result is less than the minimum allowable integer value, which produces a value not equal to the correct result. CVE-2021-21811 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2023-2570 0.0 unknown
No description available.
CVE-2025-50125 0.0 unknown
CVE-2025-50125. CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthenticated remote code execution when the server is accessed via the network with knowledge of hidden URLs and manipulation of host request header.
CVE-2020-7505 0.0 unknown
No description available.
CVE-2021-22724 0.0 unknown
No description available.
CVE-2022-32516 0.0 unknown
No description available.
CVE-2021-22717 8.8 high
The affected product is vulnerable to Path Traversal, which could allow remote code execution when processing config files.CVE-2021-22717 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
CVE-2020-28211 0.0 unknown
No description available.
CVE-2021-22710 7.8 high
This vulnerability could result in loss of data or remote code execution when a malicious CGF file is imported into an IGSS Definition.CVE-2021-22710 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2022-41668 0.0 unknown
No description available.
CVE-2022-47378 0.0 unknown
CVE-2022-47378. Multiple CODESYS products in multiple versions are prone to a improper input validation vulnerability. An authenticated remote attacker may craft specific requests that use the vulnerability leading to a denial-of-service condition.
CVE-2020-11905 0.0 unknown
Possible out-of-bounds read in DHCPv6 component when handling a packet sent by an unauthorized network attacker. This vulnerability may allow exposure of sensitive information.
CVE-2022-42971 0.0 unknown
Schneider Electric APC Easy UPS Online versions 2.5-GA and prior deploy the improperly secured UpLoadAction.execute method. An unauthenticated user could use this method to upload a maliciously crafted JSF file to the images directory, which is located in the application web root directory, to enable unauthenticated remote code execution.CVE-2022-42971 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2022-32515 0.0 unknown
No description available.
CVE-2024-0865 0.0 unknown
No description available.
CVE-2024-2747 0.0 unknown
No description available.
CVE-2025-1060 0.0 unknown
CVE-2025-1060. CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists that could result in the exposure of data when network traffic is being sniffed by an attacker.
CVE-2020-7485 5.5 medium
A vulnerability related to a legacy support account in TriStation 1131 versions 1.0 through 4.9.0 and 4.10.0 could allow inappropriate access to the TriStation 1131 project file.CVE-2020-7485 has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N).
CVE-2018-7812 0.0 unknown
No description available.
CVE-2022-37302 0.0 unknown
No description available.
CVE-2021-21825 0.0 unknown
A heap-based buffer overflow vulnerability exists in the XML Decompression. PlainTextUncompressor::UncompressItem functionality of AT&T Labs ' Xmill 0.7. A specially crafted XMI file could lead to remote code execution. An attacker could provide a malicious file to trigger this vulnerability.CVE-2021-21825 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2021-22706 0.0 unknown
No description available.
CVE-2023-2161 0.0 unknown
No description available.
CVE-2020-7544 7.4 high
An improper privilege management vulnerability exists that could cause privilege escalation on the workstation when interacting directly with a driver installed by the runtime software of EcoStruxure Operator Terminal Expert.CVE-2020-7544 has been assigned to this vulnerability. A CVSS v3 base score of 7.4 has been calculated; the CVSS vector string is (AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2024-2052 0.0 unknown
No description available.
CVE-2022-34765 0.0 unknown
No description available.
CVE-2022-32520 0.0 unknown
No description available.
CVE-2024-8530 0.0 unknown
CVE-2024-8530. CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause exposure of private data when an already generated “logcaptures” archive is accessed directly by HTTPS.
CVE-2022-45789 0.0 unknown
An authentication bypass by capture-replay vulnerability exists that could execute unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session.
CVE-2023-5985 0.0 unknown
No description available.
CVE-2024-5558 0.0 unknown
No description available.
CVE-2020-7534 0.0 unknown
No description available.
CVE-2023-5986 0.0 unknown
No description available.
CVE-2025-0327 0.0 unknown
CVE-2025-0327. CWE-269: Improper Privilege Management vulnerability exists for two services (of which one managing audit trail data and the other acting as server managing client request) that could cause a loss of Confidentiality, Integrity and Availability of engineering workstation when an attacker with standard privilege modifies the executable path of the windows services. To be exploited, services need to be restarted.
CVE-2021-1675 0.0 unknown
No description available.
CVE-2022-22723 8.8 high
A buffer copy without checking size of input vulnerability exists in Easergy P5 devices that could lead to a buffer overflow, causing program crashes and arbitrary code execution when specially crafted packets are sent to the device over the network. Protection functions and tripping functions via GOOSE can be impacted. CVE-2022-22723 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2019-12265 0.0 unknown
The IGMPv3 reception handler does not expect packets to be spread across multiple IP-fragments.CVE-2019-12265 has been assigned to this vulnerability. A CVSS v3 base score of 5.4 has been calculated; the CVSS vector string is (AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L).
CVE-2018-7773 0.0 unknown
No description available.
CVE-2019-12264 0.0 unknown
This vulnerability requires that at least one IPv4 multicast address has been assigned to the target in an incorrect way (e.g., using the API intended for assigning unicast addresses). An attacker may use CVE-2019-12264 to incorrectly assign a multicast IP-address.. An attacker on the same LAN as the target system may use this vulnerability to cause a NULL pointer dereference, which most likely will crash the tNet0 task. An attacker on the same LAN as the target system may use this vulnerability to cause a NULL pointer dereference, which most likely will crash the tNet0 task.. CVE-2019-12259 has been assigned to this vulnerability. A CVSS v3 base score of 6.3 has been calculated; the CVSS vector string is (AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H).An attacker may use CVE-2019-12264 to incorrectly assign a multicast IP-address.
CVE-2023-27978 0.0 unknown
A vulnerability in Schneider Electric Dashboard module could cause an interpretation of malicious payload data if a malicious file is opened by an unsuspecting user. This could lead to remote code execution. CVE-2023-27978 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2019-6806 0.0 unknown
CVE-2019-6806. An information exposure vulnerability exists which could cause the disclosure of SNMP information when reading variables in the controller using Modbus.
CVE-2026-1226 0.0 unknown
CVE-2026-1226. An improper control of generation of code vulnerability exists that could result in the execution of untrusted or unintended code within the application. This occurs when maliciously crafted design content is processed through a TGML graphics file.
CVE-2020-11904 0.0 unknown
Possible integer overflow or wraparound in memory allocation component when handling a packet sent by an unauthorized network attacker may result in out-of-bounds write.
CVE-2025-8453 0.0 unknown
CVE-2025-8453. CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation and arbitrary code execution when a privileged engineer user with console access modifies a configuration file used by a root-level daemon to execute custom scripts.
CVE-2020-7487 0.0 unknown
No description available.
CVE-2019-6828 0.0 unknown
CVE-2019-6828. An uncaught exception vulnerability exists, which could cause a possible denial of service when reading specific coils and registers in the controller over Modbus.
CVE-2023-27980 0.0 unknown
A vulnerability in Schneider Electric Data Server TCP interface could allow the creation of a malicious report file in the IGSS project report directory, and this could lead to remote code execution when an unsuspecting user opens the malicious report. CVE-2023-27980 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2024-10497 0.0 unknown
An authorization bypass through user-controlled key vulnerability exists that could allow an authorized attacker to modify values outside those defined by their privileges (Elevation of Privileges) when the attacker sends modified HTTPS requests to the device.
CVE-2022-30237 0.0 unknown
No description available.
CVE-2021-22726 0.0 unknown
No description available.
CVE-2022-30790 0.0 unknown
CVE-2022-30790. Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552.
CVE-2022-43378 0.0 unknown
No description available.
CVE-2020-10245 0.0 unknown
CVE-2020-10245. CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control runtime systems, has a buffer overflow.
CVE-2021-22702 0.0 unknown
No description available.
CVE-2020-17438 7.0 high
The function in open-iscsi and uIP that reassembles fragmented packets does not validate the total length of an incoming packet specified in its IP header, as well as the fragmentation offset value specified in the IP header. This could lead to memory corruption.CVE-2020-17438 has been assigned to this vulnerability. A CVSS v3 base score of 7.0 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H).
CVE-2020-7549 0.0 unknown
No description available.
CVE-2025-9317 0.0 unknown
The vulnerability, if exploited, could allow a miscreant with read access to Edge Project files or Edge Offline Cache files to reverse engineer Edge users' app-native or Active Directory passwords through computational brute-forcing of weak hashes.
CVE-2025-1059 0.0 unknown
CVE-2025-1059. CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause communications to stop when malicious packets are sent to the webserver of the device.
CVE-2020-7500 0.0 unknown
No description available.
CVE-2020-7491 10.0 critical
A legacy debug port account in TCMs installed in Tricon system Versions 10.2.0 through 10.5.3 is visible on the network and could allow inappropriate access.CVE-2020-7491 has been assigned to this vulnerability. A CVSS v3 base score of 10.0 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
CVE-2020-14509 0.0 unknown
CVE-2020-14509. Multiple memory corruption vulnerabilities exist where the packet parser mechanism does not verify length fields. An attacker could send specially crafted packets to exploit these vulnerabilities.
CVE-2018-7776 0.0 unknown
No description available.
CVE-2019-1223 0.0 unknown
No description available.
CVE-2023-37553 0.0 unknown
CVE-2023-37553. In multiple versions of multiple CODESYS products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition.
CVE-2021-22775 0.0 unknown
No description available.
CVE-2022-24312 9.8 critical
A vulnerability exists that could cause modification of an existing file by adding data at the end of the file or creating a new file in the context of the data server. This could potentially lead to remote code execution when an attacker sends a specially crafted message.CVE-2022-24312 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2020-7474 0.0 unknown
No description available.
CVE-2022-22807 0.0 unknown
No description available.
CVE-2020-7507 0.0 unknown
No description available.
CVE-2020-7519 0.0 unknown
No description available.
CVE-2023-6032 0.0 unknown
No description available.
CVE-2024-5056 0.0 unknown
CVE-2024-5056. CWE-552: Files or Directories Accessible to External Parties vulnerability exists which may prevent user to update the device firmware and prevent proper behavior of the webserver when specific files or directories are removed from the filesystem.
CVE-2021-22791 0.0 unknown
No description available.
CVE-2019-6848 0.0 unknown
No description available.
CVE-2020-7560 0.0 unknown
No description available.
CVE-2022-22809 0.0 unknown
No description available.
CVE-2021-22716 7.8 high
The affected product is vulnerable to Improper Privilege Management, which could allow remote code execution when an unprivileged user modifies a file.CVE-2021-22716 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
CVE-2020-11908 0.0 unknown
Improper null termination in DHCP component when handling a packet sent by an unauthorized network attacker. This vulnerability may allow exposure of sensitive information.
CVE-2021-22793 0.0 unknown
No description available.
CVE-2021-22783 0.0 unknown
No description available.
CVE-2021-22737 0.0 unknown
No description available.
CVE-2023-3670 0.0 unknown
CVE-2023-3670. In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe directory permissions would allow an attacker with local access to the workstation to place potentially harmful and disguised scripts that could be executed by legitimate users.
CVE-2023-37551 0.0 unknown
CVE-2023-37551. In multiple Codesys products in multiple versions, after successful authentication as a user, specially crafted network communication requests can utilize the CmpApp component to download files with any file extensions to the controller. In contrast to the regular file download via CmpFileTransfer, no filtering of certain file types is performed here. As a result, the integrity of the CODESYS control runtime system may be compromised by the files loaded onto the controller.
CVE-2024-6407 0.0 unknown
CVE-2024-6407. CWE-200: Information Exposure vulnerability exists that could cause disclosure of credentials when a specially crafted message is sent to the device.
CVE-2020-10664 0.0 unknown
No description available.
CVE-2021-22725 0.0 unknown
No description available.
CVE-2021-22756 7.8 high
Exploitation of this vulnerability could result in disclosure of information or remote code execution due to lack of user-supplied data validation when a malicious CGF file is imported to IGSS Definition.CVE-2021-22756 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2023-3001 0.0 unknown
A deserialization of untrusted data vulnerability that could cause an interpretation of malicious payload data exists in the Dashboard module, which could lead to arbitrary code execution if an attacker gets the user to open a malicious file.
CVE-2018-7846 0.0 unknown
CVE-2018-7846. A trust boundary violation vulnerability on connection to the controller exists which could cause unauthorized access by conducting a brute force attack on Modbus protocol to the controller.
CVE-2023-37548 0.0 unknown
CVE-2023-37548. In multiple CODESYS products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition.
CVE-2022-22810 0.0 unknown
No description available.
CVE-2022-34760 0.0 unknown
No description available.
CVE-2022-30552 0.0 unknown
CVE-2022-30552. Das U-Boot 2022.01 has a Buffer Overflow.
CVE-2021-22746 0.0 unknown
No description available.
CVE-2020-11907 0.0 unknown
Improper handling of length parameter inconsistency in TCP component, from a packet sent by an unauthorized network attacker.
CVE-2025-8449 0.0 unknown
CVE-2025-8449. CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service when an authenticated user sends a specially crafted request to a specific endpoint from within the BMS network.
CVE-2025-54924 0.0 unknown
CVE-2025-54924. CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized access to sensitive data when an attacker sends a specially crafted document to a vulnerable endpoint.
CVE-2021-22718 7.8 high
The affected product is vulnerable to Path Traversal, which could allow remote code execution when restoring project files.CVE-2021-22718 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2025-6788 0.0 unknown
CVE-2025-6788. CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that exposes TGML diagram resources to the wrong control sphere, providing other authenticated users with potentially inappropriate access to TGML diagrams.
CVE-2022-42970 0.0 unknown
Schneider Electric APC Easy UPS Online versions 2.5-GA and prior are missing authentication for the updatePassword endpoint implemented in the LoginAction.updatePassword method. An unauthenticated user could exploit this vulnerability to modify administrator passwords.CVE-2022-42970 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2020-28215 7.7 high
The affected product is vulnerable to a missing authorization vulnerability, which may allow an attacker to gain access to sensitive information, cause a denial-of-service condition, and remotely execute arbitrary code when access control checks are not applied consistently.CVE-2020-28215 has been assigned to this vulnerability. A CVSS v3 base score of 7.7 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H).
CVE-2022-34756 0.0 unknown
No description available.
CVE-2021-22730 0.0 unknown
No description available.
CVE-2021-30188 9.8 critical
A crafted request may cause a stack-based buffer overflow in the affected CODESYS products, resulting in a denial-of-service condition or remote code execution.CVE-2021-30188 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2022-32748 0.0 unknown
No description available.
CVE-2024-12476 0.0 unknown
The affected product is vulnerable to an improper restriction of XML external entity reference vulnerability that could cause information disclosure, impacts to workstation integrity and potential remote code execution on the compromised computer, when a specifically crafted XML file is imported in the Web Designer configuration tool.
CVE-2022-22805 0.0 unknown
No description available.
CVE-2023-29413 0.0 unknown
A vulnerability exists that could cause a denial-of-service condition when accessed by an unauthenticated user on the Schneider UPS Monitor service.
CVE-2021-22811 6.8 medium
A vulnerability could cause script execution when the request of a privileged account accessing the vulnerable web page is intercepted.CVE-2021-22811 has been assigned to this vulnerability. A CVSS v3 base score of 6.8 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N).
CVE-2021-22752 7.8 high
Exploitation of this vulnerability could result in loss of data or remote code execution due to missing size checks when a malicious WSP (Workspace) file is being parsed by IGSS Definition.CVE-2021-22752 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2021-22780 7.1 high
An insufficiently protected credentials vulnerability exists that could cause unauthorized access to a project file protected by a password when this file is shared with untrusted sources. An attacker may bypass the password protection and be able to view and modify a project file.CVE-2021-22780 has been assigned to this vulnerability. A CVSS v3 base score of 7.1 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
CVE-2019-8961 0.0 unknown
No description available.
CVE-2021-22819 0.0 unknown
No description available.
CVE-2023-25555 0.0 unknown
No description available.
CVE-2023-37546 0.0 unknown
CVE-2023-37546. In multiple CODESYS products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition.
CVE-2018-7771 0.0 unknown
No description available.
CVE-2024-37040 0.0 unknown
CVE-2024-37040. CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability exists that could allow a user with access to the device’s web interface to cause a fault on the device when sending a malformed HTTP request.
CVE-2025-54925 0.0 unknown
CVE-2025-54925. CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized access to sensitive data when an attacker configures the application to access a malicious url.
CVE-2019-1040 0.0 unknown
No description available.
CVE-2021-22771 0.0 unknown
No description available.
CVE-2024-8884 0.0 unknown
CVE-2024-8884. CWE-200: Information Exposure vulnerability exists that could cause exposure of credentials when attacker has access to application on network over http.
CVE-2020-7559 0.0 unknown
No description available.
CVE-2021-22764 0.0 unknown
CVE-2021-22764. CWE-287: Improper Authentication vulnerability exists that could cause loss of connectivity to the device via Modbus TCP protocol when an attacker sends a specially crafted HTTP request.
CVE-2021-22720 6.5 medium
The affected product is vulnerable to Path Traversal, which could allow remote code execution when restoring a project.CVE-2021-22720 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
CVE-2019-12260 0.0 unknown
This vulnerability could lead to a buffer overflow of up to a full TCP receive window (by default, 10k-64k depending on version). The buffer overflow happens in the task calling recv()/recvfrom()/recvmsg(). Applications that pass a buffer equal to or larger than a full TCP window are not susceptible to this attack. Applications passing a stack-allocated variable as a buffer are the easiest to exploit. The most likely outcome is a crash of the application reading from the affected socket, which could result in remote code execution.. CVE-2019-12260 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).The most likely outcome is a crash of the application reading from the affected socket, which could result in remote code execution.
CVE-2019-6830 0.0 unknown
CVE-2019-6830. An uncaught exception vulnerability exists, which could cause a possible denial of service when sending an appropriately timed HTTP request to the controller.
CVE-2020-7499 0.0 unknown
No description available.
CVE-2024-11737 0.0 unknown
CVE-2024-11737. CWE-20: Improper Input Validation vulnerability exists that could lead to a denial of service and a loss of confidentiality, integrity of the controller when an unauthenticated crafted Modbus packet is sent to the device.
CVE-2018-7833 0.0 unknown
No description available.
CVE-2022-30235 0.0 unknown
No description available.
CVE-2023-7032 0.0 unknown
A deserialization of untrusted data vulnerability exists in Schneider Electric Easergy Studio versions prior to v9.3.5 that could allow an attacker logged in with a user level account to gain higher privileges by providing a harmful serialized object.
CVE-2021-22803 9.8 critical
By sending constructed messages on the network, an attacker could write arbitrary files to folders in context of the DC module that could lead to remote code execution.CVE-2021-22803 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2025-11566 0.0 unknown
CVE-2025-11566. CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker on the local network to gain access to the user account by performing an arbitrary number of authentication attempts with different credentials on the /REST/shutdownnow endpoint.
CVE-2025-0814 0.0 unknown
CVE-2025-0814. CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the network services running on the product when malicious IEC61850-MMS packets are sent to the device. The core functionality of the breaker remains intact during the attack.
CVE-2023-25547 0.0 unknown
No description available.
CVE-2020-7511 0.0 unknown
No description available.
CVE-2018-7768 0.0 unknown
No description available.
CVE-2024-8933 0.0 unknown
CVE-2024-8933. CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause retrieval of password hash that could lead to denial of service and loss of confidentiality and integrity of controllers. To be successful, the attacker needs to inject themself inside the logical network while a valid user uploads or downloads a project file into the controller.
CVE-2021-29241 0.0 unknown
CVE-2021-29241. CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS).
CVE-2020-7488 0.0 unknown
No description available.
CVE-2025-3112 0.0 unknown
CVE-2025-3112. CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause Denial of Service when an authenticated malicious user sends manipulated HTTPS Content-Length header to the webserver.
CVE-2021-21830 0.0 unknown
A heap-based buffer overflow vulnerability exists in the XML Decompression LabelDict::Load functionality of AT&T Labs ' Xmill 0.7. A specially crafted XML file can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.CVE-2021-21830 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2023-28003 0.0 unknown
No description available.
CVE-2021-22801 7.8 high
The affected product has an issue with privilege management, which could cause an arbitrary command execution when the software is configured with specially crafted event actions.CVE-2021-22801 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2023-27984 0.0 unknown
A vulnerability in Schneider Electric Custom Reports could result in macro execution if a malicious report file is opened by an unsuspecting user, potentially leading to remote code execution. CVE-2023-27984 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2025-50122 0.0 unknown
CVE-2025-50122. CWE-331: Insufficient Entropy vulnerability exists that could cause root password discovery when the password generation algorithm is reverse engineered with access to installation or upgrade artifacts.
CVE-2024-5560 0.0 unknown
CVE-2024-5560. CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service of the device’s web interface when an attacker sends a specially crafted HTTP request.
CVE-2021-22767 0.0 unknown
No description available.
CVE-2020-7497 6.3 medium
A vulnerability exists that could cause arbitrary application execution when the computer starts.CVE-2020-7497 has been assigned to this vulnerability. A CVSS v3 base score of 6.3 has been calculated; the CVSS vector string is (AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).
CVE-2024-9002 0.0 unknown
CVE-2024-9002. CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity, and availability of the workstation when non-admin authenticated user tries to perform privilege escalation by tampering with the binaries.
CVE-2024-5557 0.0 unknown
No description available.
CVE-2022-0223 0.0 unknown
No description available.
CVE-2024-28219 0.0 unknown
In _imagingcms.c in Pillow prior to 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.
CVE-2023-37200 0.0 unknown
No description available.
CVE-2024-11425 0.0 unknown
CVE-2024-11425. CWE-131: Incorrect Calculation of Buffer Size vulnerability exists that could cause Denial-of-Service of the product when an unauthenticated user is sending a crafted HTTPS packet to the webserver.
CVE-2021-22808 7.8 high
This vulnerability may cause arbitrary code execution when a malicious *.gd1 configuration file is loaded into the GUIcon tool.CVE-2021-22808 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2025-54923 0.0 unknown
CVE-2025-54923. CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution and compromise of system integrity when authenticated users send crafted data to a network-exposed service that performs unsafe deserialization.
CVE-2020-1472 0.0 unknown
No description available.
CVE-2022-24317 5.3 medium
A vulnerability exists that could cause information exposure when an attacker sends a specific message.CVE-2022-24317 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
CVE-2020-7548 0.0 unknown
No description available.
CVE-2025-3898 0.0 unknown
CVE-2025-3898. CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated malicious user sends HTTPS request containing invalid data type to the webserver.
CVE-2023-27977 0.0 unknown
A vulnerability in Schneider Electric Data Server could grant an unauthorized user access to delete files in the IGSS project report directory if specific crafted messages are sent to the Data Server TCP port. CVE-2023-27977 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L).
CVE-2023-25619 0.0 unknown
No description available.
CVE-2021-30062 0.0 unknown
No description available.
CVE-2020-7496 3.3 low
A remote attacker can trick a victim to open a specially crafted project file and gain unauthorized write access to the target system.CVE-2020-7496 has been assigned to this vulnerability. A CVSS v3 base score of 3.3 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).
CVE-2020-7501 0.0 unknown
No description available.
CVE-2022-34755 0.0 unknown
No description available.
CVE-2018-7766 0.0 unknown
No description available.
CVE-2018-7804 0.0 unknown
No description available.
CVE-2020-7538 7.5 high
A vulnerability exists that could cause a crash of the PLC simulator present in EcoStruxure Control Expert software when receiving a specially crafted request over Modbus.CVE-2020-7538 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
CVE-2020-7556 7.8 high
An out-of-bounds write vulnerability could cause remote code execution when a malicious CGF (Configuration Group File) is imported to IGSS Definition.CVE-2020-7556 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2020-9403 0.0 unknown
No description available.
CVE-2020-11911 0.0 unknown
The affected product is vulnerable to improper access control, which may allow an attacker to change one specific configuration value.
CVE-2023-22611 0.0 unknown
No description available.
CVE-2025-2442 0.0 unknown
CVE-2025-2442. CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could potentially lead to unauthorized access which could result in the loss of confidentially, integrity and availability when a malicious user, having physical access, sets the radio to the factory default mode.
CVE-2018-7810 0.0 unknown
No description available.
CVE-2021-22797 7.8 high
When a malicious project file is loaded on the engineering workstation software, it deploys a malicious script to execute arbitrary code in unauthorized locations.CVE-2021-22797has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2019-1224 0.0 unknown
No description available.
CVE-2023-4516 0.0 unknown
A missing authentication for critical function vulnerability that could allow a local attacker to change the update source exists in the IGSS Update Service, which could lead to remote code execution the attacker force an update containing malicious content.
CVE-2022-47384 0.0 unknown
CVE-2022-47384. An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
CVE-2018-7494 0.0 unknown
No description available.
CVE-2021-22781 6.2 medium
An insufficiently protected credentials vulnerability exists that could cause a leak of SMTP credentials used for mailbox authentication when an attacker can access a project file.CVE-2021-22781 has been assigned to this vulnerability. A CVSS v3 base score of 6.2 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
CVE-2018-7850 0.0 unknown
CVE-2018-7850. A reliance on untrusted inputs in a security decision vulnerability exists which could cause invalid information displayed in Unity Pro software.
CVE-2025-2875 0.0 unknown
CVE-2025-2875. CWE-610: Externally Controlled Reference to a Resource in Another Sphere vulnerability exists that could cause a loss of confidentiality when an unauthenticated attacker manipulates controller’s webserver URL to access resources.
CVE-2018-7845 0.0 unknown
CVE-2018-7845. An out-of-bounds read vulnerability exists, which could cause the disclosure of unexpected data from the controller when reading specific memory blocks in the controller over Modbus.
CVE-2022-32518 0.0 unknown
No description available.
CVE-2019-11135 0.0 unknown
No description available.
CVE-2020-12525 7.3 high
M&M Software fdtCONTAINER component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage. Note: This vulnerability could cause local code execution on the engineering workstation when a malicious project file is loaded into the engineering software.CVE-2020-12525 has been assigned to this vulnerability. A CVSS v3 base score of 7.3 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).
CVE-2025-46819 0.0 unknown
CVE-2025-46819. Additional information about CVE-2025-46819 can be found here: https://www.cve.org/CVERecord?id=CVE-2025-46819
CVE-2021-21868 0.0 unknown
CVE-2021-21868. An unsafe deserialization vulnerability exists in the ObjectManager.plugin Project.get_MissingTypes() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.
CVE-2025-5740 0.0 unknown
CVE-2025-5740. CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file writes when an authenticated user on the web server manipulates file path.
CVE-2020-11906 0.0 unknown
Improper input validation CWE-20 in ethernet link layer component from a packet sent by an unauthorized user.
CVE-2019-6842 0.0 unknown
No description available.
CVE-2020-7490 0.0 unknown
No description available.
CVE-2020-11910 0.0 unknown
Improper input validation in ICMPv4 component when handling a packet sent by an unauthorized network attacker. This vulnerability may allow out-of-bounds read.
CVE-2023-29412 0.0 unknown
Prior versions of Schneider Electric APC Easy UPS Online contain an OS Command Injection vulnerability that could cause remote code execution when manipulating internal methods through Java RMI interface.
CVE-2018-7240 0.0 unknown
No description available.
CVE-2025-5743 0.0 unknown
CVE-2025-5743. CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote control over the charging station when an authenticated user modifies configuration parameters on the web server.
CVE-2024-11999 0.0 unknown
CVE-2024-11999. CWE-1104: Use of Unmaintained Third-Party Components exists that could cause complete control of the device when an authenticated user installs malicious code into HMI product.
CVE-2022-24318 0.0 unknown
No description available.
CVE-2020-11896 0.0 unknown
Improper handling of length parameter inconsistency in IPv4/UDP component when handling a packet sent by an unauthorized network attacker. This vulnerability may result in remote code execution.
CVE-2021-22779 9.8 critical
An authentication bypass by spoofing vulnerability exists that could cause unauthorized access in read and write mode to the controller by spoofing the Modbus communication between the engineering software and the controller. CVE-2021-22779 has been assigned to this vulnerability. A CVSS v3 base score of 9.8has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).. --------- End Update A Part 2 of 2 --------CVE-2021-22779 has been assigned to this vulnerability. A CVSS v3 base score of 9.8has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2021-22728 0.0 unknown
No description available.
CVE-2022-0221 0.0 unknown
An improper restriction of XML external entity reference vulnerability exists that could result in information disclosure when opening a malicious solution file provided by an attacker with SCADAPack Workbench. This could be exploited to pass data from local files to a remote system controlled by an attacker.CVE-2022-0221 has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).
CVE-2023-1548 0.0 unknown
No description available.
CVE-2021-22823 0.0 unknown
No description available.
CVE-2020-7513 0.0 unknown
No description available.
CVE-2020-7570 6.4 medium
CVE-2020-7570. An improper neutralization of an input during webpage generation vulnerability could allow an authenticated remote user to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a stored cross-site scripting attack against other WebReport users.CVE-2020-7570 has been assigned to this vulnerability. A CVSS v3 base score of 6.4 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L).
CVE-2019-0803 0.0 unknown
No description available.
CVE-2018-12130 0.0 unknown
CVE-2018-12130. Microarchitectural Fill Buffer Data Sampling (MFBDS): Fill buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. Additional information about the vulnerabilities can be found in the INTEL website: [INTEL-SA-00233](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00233.html)
CVE-2022-32517 0.0 unknown
No description available.
CVE-2022-34753 0.0 unknown
No description available.
CVE-2024-8070 0.0 unknown
CVE-2024-8070. CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that exposes test credentials in the firmware binary.
CVE-2025-0813 0.0 unknown
The Schneider Electric EcoStruxure Power Automation System User Interface (EPAS-UI) is vulnerable to authentication bypass. This occurs when an unauthorized user, without permission rights, has physical access to the EPAS-UI computer and is able to reboot the workstation and interrupt the normal boot process.
CVE-2020-16233 0.0 unknown
CVE-2020-16233. An attacker could send a specially crafted packet that could have the server send back packets containing data from the heap.
CVE-2020-7510 0.0 unknown
No description available.
CVE-2019-19193 0.0 unknown
No description available.
CVE-2020-11901 0.0 unknown
Improper input validation in DNS resolver component when handling a packet sent by an unauthorized network attacker. This vulnerability may result in remote code execution.
CVE-2022-34759 0.0 unknown
No description available.
CVE-2026-0667 0.0 unknown
CVE-2026-0667. CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when communicating over the Modbus TCP protocol.
CVE-2022-41669 0.0 unknown
No description available.
CVE-2026-1227 0.0 unknown
CVE-2026-1227. An improper restriction of XML external entity reference vulnerability exists that could result in unauthorized disclosure of local files, unauthorized interaction with the EBO system, or denial-of-service conditions. This occurs when a local user uploads a maliciously crafted TGML graphics file to the EBO server from Workstation.
CVE-2023-37550 0.0 unknown
CVE-2023-37550. In multiple CODESYS products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition.
CVE-2024-5679 0.0 unknown
CVE-2024-5679. CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, or kernel memory leak when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
CVE-2021-22703 0.0 unknown
No description available.
CVE-2023-3669 0.0 unknown
CVE-2023-3669. A missing Brute-Force protection in CODESYS Development System prior to 3.5.19.20 allows a local attacker to have unlimited attempts of guessing the password within an import dialog.
CVE-2025-59287 0.0 unknown
CVE-2025-59287. Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
CVE-2021-22790 0.0 unknown
No description available.
CVE-2025-6438 0.0 unknown
CVE-2025-6438. CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause manipulation of SOAP API calls and XML external entities injection resulting in unauthorized file access when the server is accessed via the network using an application account.
CVE-2015-7937 0.0 unknown
Stack-based buffer overflow in the GoAhead Web Server on Schneider Electric Modicon M340 PLC BMXNOx and BMXPx devices allows remote attackers to execute arbitrary code via a long password in HTTP Basic Authentication data.
CVE-2021-22782 6.2 medium
A missing encryption of sensitive data vulnerability exists that could cause an information leak allowing disclosure of network and process information, credentials, or intellectual property when an attacker can access a project file.CVE-2021-22782 has been assigned to this vulnerability. A CVSS v3 base score of 6.2 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
CVE-2018-7772 0.0 unknown
No description available.
CVE-2020-7520 0.0 unknown
No description available.
CVE-2020-7509 0.0 unknown
No description available.
CVE-2019-12258 0.0 unknown
An attacker with the source and destination TCP-port and IP-addresses of a session can inject invalid TCP segments into the flow, causing the TCP-session to be reset. An application will see this as an ECONNRESET error message when using the socket after such an attack. The most likely outcome is a crash of the application reading from the affected socket.. CVE-2019-12258 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).The most likely outcome is a crash of the application reading from the affected socket.
CVE-2025-54927 0.0 unknown
CVE-2025-54927. CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause unauthorized access to sensitive files when an authenticated attackers uses a crafted path input that is processed by the system.
CVE-2022-34763 0.0 unknown
No description available.
CVE-2021-22799 3.8 low
An insufficient entropy vulnerability exists, which could cause unintended connection from an internal network to an external network when an attacker manages to decrypt the SESU proxy password from the registry.CVE-2021-22799 has been assigned to this vulnerability. A CVSS v3 base score of 3.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N).
CVE-2019-12259 0.0 unknown
An attacker residing on the LAN may choose to hijack a DHCP-client session that requests an IPv4 address. The attacker can send a multicast IP address in the DHCP offer/ack message, which the victim system then incorrectly assigns. This vulnerability can be combined with CVE-2019-12259 to create a denial-of-service condition.. CVE-2019-12264 has been assigned to this vulnerability. A CVSS v3 base score of 7.1 has been calculated; the CVSS vector string is (AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).This vulnerability can be combined with CVE-2019-12259 to create a denial-of-service condition.
CVE-2021-22741 0.0 unknown
No description available.
CVE-2021-22821 0.0 unknown
No description available.
CVE-2022-32514 0.0 unknown
No description available.
CVE-2021-22806 0.0 unknown
No description available.
CVE-2020-11899 0.0 unknown
Improper input validation in IPv6 component when handling a packet sent by an unauthorized network attacker. This vulnerability may allow out-of-bounds read and a possible denial of service.
CVE-2021-22822 0.0 unknown
No description available.
CVE-2022-47388 0.0 unknown
CVE-2022-47388. An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
CVE-2020-7568 3.1 low
An exposure of sensitive information to an unauthorized actor vulnerability exists that could allow non-sensitive information disclosure when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller.CVE-2020-7568 has been assigned to this vulnerability. A CVSS v3 base score of 3.1 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
CVE-2021-30064 0.0 unknown
No description available.
CVE-2022-30236 0.0 unknown
No description available.
CVE-2019-8960 0.0 unknown
No description available.
CVE-2020-7564 6.3 medium
A classic buffer overflow vulnerability exists which could cause write access and the execution of commands when uploading a specially crafted file on the controller over FTP. CVE-2020-7564 has been assigned to this vulnerability. A CVSS v3 base score of 6.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:H).
CVE-2020-7546 0.0 unknown
No description available.
CVE-2019-6829 0.0 unknown
CVE-2019-6829. An uncaught exception vulnerability exists which could cause a possible denial of service when writing to specific memory addresses in the controller over Modbus.
CVE-2022-47386 0.0 unknown
CVE-2022-47386. An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
CVE-2022-30232 0.0 unknown
No description available.
CVE-2021-22753 7.8 high
Exploitation of this vulnerability could result in loss of data or remote code execution due to missing length checks when a malicious WSP file is being parsed by IGSS Definition.CVE-2021-22753 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2023-37555 0.0 unknown
CVE-2023-37555. In multiple versions of multiple CODESYS products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition.
CVE-2023-37554 0.0 unknown
CVE-2023-37554. In multiple versions of multiple CODESYS products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition.
CVE-2020-27337 9.1 critical
An out-of-bounds write in the IPv6 component may allow an unauthenticated user to potentially cause a possible denial-of-service via network access.CVE-2020-27337 has been assigned to this vulnerability. A CVSS v3 base score of 9.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).
CVE-2019-6809 0.0 unknown
CVE-2019-6809. An uncaught exception vulnerability exists, which could cause a possible denial of service when reading invalid data from the controller.
CVE-2020-7537 0.0 unknown
No description available.
CVE-2024-37037 0.0 unknown
CVE-2024-37037. CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability exists that could allow an authenticated user with access to the device’s web interface to corrupt files and impact device functionality when sending a crafted HTTP request.
CVE-2021-22698 7.8 high
When a malicious SSD file is uploaded and improperly parsed, an attacker could cause a use-after-free condition or stack-based buffer overflow resulting in remote code execution.
CVE-2019-9008 0.0 unknown
CVE-2019-9008. An issue was discovered in 3S-Smart CODESYS V3 through 3.5.12.30. A user with low privileges can take full control over the runtime.
CVE-2023-5987 0.0 unknown
No description available.
CVE-2021-22735 0.0 unknown
No description available.
CVE-2023-5629 0.0 unknown
No description available.
CVE-2022-34762 0.0 unknown
No description available.
CVE-2020-7493 8.6 high
An attacker could exploit an SQL injection vulnerability by enticing a user to open a maliciously crafted project file.CVE-2020-7493 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
CVE-2021-22729 0.0 unknown
No description available.
CVE-2021-22721 0.0 unknown
No description available.
CVE-2020-14519 0.0 unknown
CVE-2020-14519. This vulnerability could allow an attacker to use an internal API via a specifically crafted Java Script payload, which may allow alteration or creation of license files.
CVE-2018-7848 0.0 unknown
CVE-2018-7848. An information exposure vulnerability exists, which could cause the disclosure of SNMP information when reading files from the controller over Modbus.
CVE-2020-25066 9.8 critical
A vulnerability in Treck HTTP Server components allow an attacker to cause a denial-of-service condition. This vulnerability may also result in arbitrary code execution.CVE-2020-25066 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2020-7561 10.0 critical
The affected product is vulnerable to a missing authentication for critical function vulnerability, which may allow an attacker to expose information, cause a denial-of-service condition, and remotely execute arbitrary code.CVE-2020-7561 has been assigned to this vulnerability. A CVSS v3 base score of 10.0 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H).
CVE-2018-7830 0.0 unknown
No description available.
CVE-2020-7517 0.0 unknown
No description available.
CVE-2021-22723 0.0 unknown
No description available.
CVE-2023-37552 0.0 unknown
CVE-2023-37552. In multiple versions of multiple CODESYS products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition.
CVE-2020-35685 7.5 high
TCP ISNs are insufficiently randomized, which may result in TCP spoofing by an attacker.CVE-2020-35685 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
CVE-2020-7536 0.0 unknown
No description available.
CVE-2020-7529 0.0 unknown
No description available.
CVE-2021-22800 0.0 unknown
No description available.
CVE-2018-7831 0.0 unknown
No description available.
CVE-2020-28209 2.0 low
CVE-2020-28209. An unquoted search path vulnerability could allow any local Windows user with write permissions on at least one of the subfolders of the connect agent service binary path to gain the privilege of the user who started the service. By default, the Enterprise Server and Enterprise Central is always installed at a location requiring Administrator privileges, so this vulnerability is only valid if the application has been installed on a non-secure location. CVE-2020-28209 has been assigned to this vulnerability. A CVSS v3 base score of 2.0 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N).
CVE-2020-7481 0.0 unknown
No description available.
CVE-2024-12399 0.0 unknown
CVE-2024-12399. CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause partial loss of confidentiality, loss of integrity and availability of the HMI when attacker performs man in the middle attack by intercepting the communication.
CVE-2022-42973 0.0 unknown
Schneider Electric APC Easy UPS Online versions 2.5-GA and prior use hard-coded MySQL database credentials. A local unauthorized user with access to the database could use the select into dumpfile operation to create arbitrary files, which could be used to execute commands with system privileges.CVE-2022-42973 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
CVE-2023-25551 0.0 unknown
No description available.
CVE-2023-37196 0.0 unknown
No description available.
CVE-2021-22813 6.8 medium
A vulnerability could cause arbitrary script execution when a privileged account clicks on a malicious URL specifically crafted for the NMC pointing to an edit policy file.CVE-2021-22813 has been assigned to this vulnerability. A CVSS v3 base score of 6.8 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N).
CVE-2019-12257 0.0 unknown
DHCP packets may go past the local area network (LAN) via DHCP-relays, but are otherwise confined to the LAN. The DHCP-client may be used by VxWorks and in the bootrom. Bootrom, using DHCP/BOOTP, is only vulnerable during the boot-process. This vulnerability may be used to overwrite the heap, which could result in a later crash when a task requests memory from the heap. This vulnerability can result in remote code execution.CVE-2019-12257 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2020-28216 7.6 high
The affected product is vulnerable to a missing encryption of sensitive data vulnerability, which may allow an attacker to read network traffic over HTTP protocol.CVE-2020-28216 has been assigned to this vulnerability. A CVSS v3 base score of 7.6 has been calculated; the CVSS vector string is (AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
CVE-2022-32526 0.0 unknown
No description available.
CVE-2019-1182 0.0 unknown
No description available.
CVE-2022-43377 0.0 unknown
No description available.
CVE-2019-1226 0.0 unknown
No description available.
CVE-2021-22759 7.8 high
Exploitation of this vulnerability could result in loss of data or remote code execution due to use of unchecked input data when a malicious CGF file is imported to IGSS Definition.CVE-2021-22759 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2023-25549 0.0 unknown
No description available.
CVE-2021-22714 0.0 unknown
No description available.
CVE-2024-6528 0.0 unknown
A Cross-site Scripting  vulnerability exists  where an attacker could cause a victim's browser run arbitrary JavaScript when they visit a page containing the injected payload.
CVE-2022-47389 0.0 unknown
CVE-2022-47389. An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
CVE-2025-2440 0.0 unknown
CVE-2025-2440. CWE-922: Insecure Storage of Sensitive Information vulnerability exists that could potentially lead to unauthorized access of confidential data when a malicious user, having physical access and advanced information on the file system, sets the radio in factory default mode.
CVE-2025-8448 0.0 unknown
CVE-2025-8448. CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause unauthorized access to sensitive credential data when an attacker is able to capture local SMB traffic between a valid user within the BMS network and the vulnerable products.
CVE-2023-37547 0.0 unknown
CVE-2023-37547. In multiple CODESYS products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition.
CVE-2020-28210 4.3 medium
CVE-2020-28210. An improper neutralization of an input during webpage generation vulnerability could allow an attacker to inject HTML and JavaScript code into the user's browser. CVE-2020-28210 has been assigned to this vulnerability. A CVSS v3 base score of 4.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).
CVE-2020-7563 6.3 medium
An out-of-bounds write vulnerability exists which could cause corruption of data, a crash, or code execution when uploading a specially crafted file on the controller over FTP. CVE-2020-7563 has been assigned to this vulnerability. A CVSS v3 base score of 6.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:H).
CVE-2024-6352 0.0 unknown
CVE-2024-6352. A CWE-120: A buffer overflow vulnerability exists that could cause a denial of service when a malicious device joins the network.
CVE-2021-21828 0.0 unknown
In the command-line-parsing HandleFileArg functionality of AT&T Labs ' Xmill 0.7, an attacker could trigger the vulnerability by using a specially crafted command-line argument that can lead to code execution.CVE-2021-21828 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2019-12262 0.0 unknown
An attacker residing on the LAN can send reverse-ARP responses to the victim system to assign unicast IPv4 addresses to the target.CVE-2019-12262 has been assigned to this vulnerability. A CVSS v3 base score of 7.1 has been calculated; the CVSS vector string is (AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).
CVE-2022-37300 0.0 unknown
No description available.
CVE-2018-7769 0.0 unknown
No description available.
CVE-2019-6833 7.4 high
When the device receives a high rate of frames, the HMI may temporarily freeze. When the attack stops, the buffered commands are processed by the HMI.CVE-2019-6833 has been assigned to this vulnerability. A CVSS v3 base score of 7.4 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H).
CVE-2022-22724 0.0 unknown
No description available.
CVE-2020-7515 0.0 unknown
No description available.
CVE-2021-22805 5.3 medium
An issue exists that could allow disclosure and read access of arbitrary files in the context of the user running IGSS, due to missing validation of user supplied data in network messages.CVE-2021-22805 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).
CVE-2020-7479 7.8 high
The affected product could allow a local user to execute processes that otherwise require escalation privileges when sending local network commands to the IGSS update service.CVE-2020-7479 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
CVE-2020-7553 7.8 high
An out-of-bounds write vulnerability could cause remote code execution when a malicious CGF (Configuration Group File) is imported to IGSS Definition.CVE-2020-7553 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2023-37557 0.0 unknown
CVE-2023-37557. After successful authentication as a user in multiple CODESYS products in multiple versions, specific crafted remote communication requests can cause the CmpAppBP component to overwrite a heap-based buffer, which can lead to a denial-of-service condition.
CVE-2022-34764 0.0 unknown
No description available.
CVE-2018-7855 0.0 unknown
CVE-2018-7855. An uncaught exception vulnerability exists, which could cause a denial of service when sending invalid breakpoint parameters to the controller over Modbus.
CVE-2022-38138 0.0 unknown
CVE-2022-38138 . A vulnerability exists in the 3rd party library included in the product versions listed as affected in this advisory. An attacker could exploit the vulnerability by sending a specially crafted message to the system node, causing the node to stop or become inaccessible.
CVE-2020-7504 0.0 unknown
No description available.
CVE-2022-24319 0.0 unknown
No description available.
CVE-2023-25556 0.0 unknown
No description available.
CVE-2020-7555 7.8 high
An out-of-bounds write vulnerability could cause remote code execution when a malicious CGF (Configuration Group File) file is imported to IGSS Definition.CVE-2020-7555 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2021-22732 0.0 unknown
No description available.
CVE-2021-22795 9.1 critical
The affected product is vulnerable to an OS command injection, which may allow an attacker to remotely execute code over the network.CVE-2021-22795 has been assigned to this vulnerability. A CVSS v3 base score of 9.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
CVE-2022-30233 0.0 unknown
No description available.
CVE-2023-25550 0.0 unknown
No description available.
CVE-2020-7495 3.3 low
An attacker could exploit this path traversal vulnerability by getting a user to visit a malicious page or open a malicious file.CVE-2020-7495 has been assigned to this vulnerability. A CVSS v3 base score of 3.3 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).
CVE-2021-22712 7.8 high
This vulnerability could result in arbitrary read or write conditions due to an unchecked pointer address when a malicious CGF file is imported into an IGSS Definition.CVE-2021-22712 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2018-12126 0.0 unknown
No description available.
CVE-2025-5296 0.0 unknown
CVE-2025-5296. CWE-59: Improper Link Resolution Before File Access ('Link Following') vulnerability exists that could cause arbitrary data to be written to protected locations, potentially leading to escalation of privilege, arbitrary file corruption, exposure of application and system information or persistent denial of service when a low-privileged attacker tampers with the installation folder.
CVE-2022-46680 0.0 unknown
A cleartext transmission of sensitive information vulnerability exists that could cause disclosure of sensitive information, denial of service, or modification of data if an attacker is able to intercept network traffic.
CVE-2023-3953 0.0 unknown
No description available.
CVE-2025-46817 0.0 unknown
CVE-2025-46817. Additional information about CVE-2025-46817 can be found here: https://www.cve.org/CVERecord?id=CVE-2025-46817
CVE-2022-34761 0.0 unknown
No description available.
CVE-2020-7533 0.0 unknown
No description available.
CVE-2022-32523 0.0 unknown
No description available.
CVE-2025-3899 0.0 unknown
CVE-2025-3899. CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in Certificates page on Webserver that could cause an unvalidated data injected by authenticated malicious user leading to modify or read data in a victim’s browser.
CVE-2025-3905 0.0 unknown
CVE-2025-3905. CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists impacting PLC system variables that could cause an unvalidated data injected by authenticated malicious user leading to modify or read data in a victim’s browser.
CVE-2020-7052 0.0 unknown
CVE-2020-7052. CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition.
CVE-2022-37301 0.0 unknown
No description available.
CVE-2020-25184 7.8 high
ISaGRAF Runtime stores the password in plaintext in a file that is in the same directory as the executable file. ISaGRAF Runtime reads the file and saves the data in a variable without any additional modification. A local, unauthenticated attacker could compromise the user passwords, resulting in information disclosure.CVE-2020-25184 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
CVE-2020-13987 8.2 high
The function in open-iscsi, uIP-Contiki-OS, and uIP that parses incoming transport layer packets (TCP/UDP) does not check the length fields of packet headers against the data available in the packets. Given arbitrary lengths, an out-of-bounds memory read may be performed during the checksum computation.CVE-2020-13987 has been assigned to this vulnerability. A CVSS v3 base score of 8.2 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).
CVE-2018-7242 0.0 unknown
No description available.
CVE-2018-7853 0.0 unknown
CVE-2018-7853. An uncaught exception vulnerability exists, which could cause denial of service when reading invalid physical memory blocks in the controller over Modbus.
CVE-2021-22754 7.8 high
Exploitation of this vulnerability could result in loss of data or remote code execution due to lack of proper validation of user-supplied data when a malicious CGF file is imported to IGSS Definition.CVE-2021-22754 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2020-7535 0.0 unknown
No description available.
CVE-2021-22744 0.0 unknown
No description available.
CVE-2024-2051 0.0 unknown
No description available.
CVE-2021-22719 8.8 high
The affected product is vulnerable to Path Traversal, which could allow remote code execution when a file is uploaded.CVE-2021-22719 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
CVE-2019-6843 0.0 unknown
No description available.
CVE-2020-25178 7.5 high
ISaGRAF Workbench communicates with ISaGRAF Runtime using TCP/IP. This communication protocol provides various file system operations, as well as the uploading of applications. Data is transferred over this protocol unencrypted, which could allow a remote unauthenticated attacker to upload, read, and delete files.CVE-2020-25178 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2020-11914 0.0 unknown
Improper input validation in ARP component when handling a packet sent by an unauthorized network attacker. This vulnerability may allow out-of-bounds read.
CVE-2020-7476 0.0 unknown
No description available.
CVE-2020-7541 0.0 unknown
No description available.
CVE-2024-10498 0.0 unknown
An improper restriction of operations within the bounds of a memory buffer vulnerability exists that could allow an unauthorized attacker to modify configuration values outside of the normal range when the attacker sends specific Modbus write packets to the device, which could result in invalid data or loss of web interface functionality.
CVE-2021-22758 7.8 high
Exploitation of this vulnerability could result in loss of data or remote code execution due to lack of validation of user-supplied input data when a malicious CGF file is imported to IGSS Definition.CVE-2021-22758 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2021-22820 0.0 unknown
No description available.
CVE-2022-47385 0.0 unknown
CVE-2022-47385. An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpAppForce Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
CVE-2023-3663 0.0 unknown
CVE-2023-3663. In CODESYS Development System versions from 3.5.11.20 and before 3.5.19.20 a missing integrity check might allow an unauthenticated remote attacker to manipulate the content of notifications received via HTTP by the CODESYS notification server.
CVE-2025-0816 0.0 unknown
CVE-2025-0816. CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the product when malicious IPV6 packets are sent to the device.
CVE-2022-47380 0.0 unknown
CVE-2022-47380. An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
CVE-2021-22768 0.0 unknown
No description available.
CVE-2024-37038 0.0 unknown
CVE-2024-37038. CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perform unauthorized file and firmware uploads when crafting custom web requests.
CVE-2025-6625 0.0 unknown
CVE-2025-6625. CWE-20: Improper Input Validation vulnerability exists that could cause a Denial Of Service when specific crafted FTP command is sent to the device.
CVE-2023-37197 0.0 unknown
No description available.
CVE-2020-35198 0.0 unknown
CVE-2020-35198. An issue was discovered in Wind River VxWorks 7. The memory al-locator has a possible integer overflow in calculating a memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer size specified by the arguments, leading to memory corruption.
CVE-2019-6807 0.0 unknown
CVE-2019-6807. An uncaught exception vulnerability exists which could cause a possible denial of service when writing sensitive application variables to the controller over Modbus.
CVE-2025-3116 0.0 unknown
CVE-2025-3116. CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated malicious user sends special malformed HTTPS request containing improper formatted body data to the controller.
CVE-2020-7525 0.0 unknown
No description available.
CVE-2021-4104 0.0 unknown
No description available.
CVE-2021-22748 0.0 unknown
No description available.
CVE-2020-25182 6.7 medium
ISaGRAF Runtime searches for and loads DLLs as dynamic libraries. Uncontrolled loading of dynamic libraries could allow a local, unauthenticated attacker to execute arbitrary code. This vulnerability only affects ISaGRAF Runtime when running on Microsoft Windows systems.CVE-2020-25182 has been assigned to this vulnerability. A CVSS v3 base score of 6.7 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
CVE-2021-22704 0.0 unknown
No description available.
CVE-2021-22766 0.0 unknown
No description available.
CVE-2021-22792 0.0 unknown
No description available.
CVE-2021-22707 0.0 unknown
No description available.
CVE-2020-28220 0.0 unknown
No description available.
CVE-2020-7557 7.8 high
An out-of-bounds read vulnerability could cause remote code execution when a malicious CGF (Configuration Group File) is imported to IGSS Definition.CVE-2020-7557 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2021-22774 0.0 unknown
No description available.
CVE-2021-31400 7.5 high
The TCP urgent data processing function may invoke a panic function, which may result in an infinite loop.CVE-2021-31400 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
CVE-2020-7521 9.8 critical
A vulnerability exists when accessing a vulnerable method of `FileUploadServlet` that may lead to uploading executable files to non-specified directories.CVE-2020-7521 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2020-7512 0.0 unknown
No description available.
CVE-2021-21814 0.0 unknown
Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line. filepattern is passed directly to strlen to determine the ending location of the char* passed in by the user, no checks are done to see if the passed in char* is longer than the staticly sized buffer data is memcpy-d into, but after the memcpy a null byte is written to what is assumed to be the end of the buffer to terminate the char*, but without length checks, this null write occurs at an arbitrary offset from the buffer. An attacker can provide malicious input to trigger this vulnerability.CVE-2021-21814 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
CVE-2021-22814 6.8 medium
A vulnerability could cause arbitrary script execution when a malicious file is read and displayed.CVE-2021-22814 has been assigned to this vulnerability. A CVSS v3 base score of 6.8 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N).
CVE-2021-22794 9.1 critical
The affected product is vulnerable to directory traversal, which may allow an attacker to remotely execute code.CVE-2021-22794 has been assigned to this vulnerability. A CVSS v3 base score of 9.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
CVE-2022-4224 0.0 unknown
CVE-2022-4224. In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files and OS resources or DoS the device.
CVE-2024-8401 0.0 unknown
CVE-2024-8401. CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when an authenticated attacker modifies folder names within the context of the product.
CVE-2022-45198 0.0 unknown
Versions of Pillow before 9.2.0 improperly handle highly compressed GIF data (data amplification).
CVE-2023-5217 0.0 unknown
A heap buffer overflow in vp8 encoding in libvpx, used by Google Chrome versions prior to 117.0.5938.132 and libvpx Version 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2021-22761 7.8 high
Exploitation of this vulnerability could result in disclosure of information or remote code execution due to missing length check on user supplied data when a malicious CGF file is imported to IGSS Definition.CVE-2021-22761 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2021-22826 0.0 unknown
No description available.
CVE-2023-1049 0.0 unknown
Schneider Electric EcoStruxure operator Terminal Expert versions 3.3 SP1 and prior are vulnerable to a code injection attack that could allow an attacker to execute arbitrary code and gain access to all information on the machine.
CVE-2020-7542 0.0 unknown
No description available.
CVE-2023-3662 0.0 unknown
CVE-2023-3662. In CODESYS Development System versions from 3.5.17.0 and prior to 3.5.19.20 a vulnerability allows for execution of binaries from the current working directory in the users context .
CVE-2020-0610 0.0 unknown
No description available.
CVE-2019-12261 0.0 unknown
The impact of this vulnerability is a buffer overflow of up to a full TCP receive window (by default, 10k-64k depending on version). The buffer overflow happens in the task calling recv()/recvfrom()/recvmsg(). Applications that pass a buffer equal to or larger than a full TCP window are not susceptible to this attack. Applications passing a stack-allocated variable as a buffer are the easiest to exploit. The most likely outcome is a crash of the application reading from the affected socket, which could result in remote code execution.. CVE-2019-12261 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).The most likely outcome is a crash of the application reading from the affected socket, which could result in remote code execution.
CVE-2022-22808 0.0 unknown
No description available.
CVE-2025-46818 0.0 unknown
CVE-2025-46818. Additional information about CVE-2025-46818 can be found here: https://www.cve.org/CVERecord?id=CVE-2025-46818
CVE-2022-42972 0.0 unknown
Schneider Electric APC Easy UPS Online versions 2.5-GA and prior run the Tomcat instance with SYSTEM privileges. NT AUTHORITY\Authenticated Users could create new files in the Tomcat web root directory and could create and execute a maliciously crafted JSP file to escalate privileges and execute commands with system privileges.CVE-2022-42972 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
CVE-2018-7770 0.0 unknown
No description available.
CVE-2020-11912 0.0 unknown
Improper input validation in TCP component when handling a packet sent by an unauthorized network attacker. This vulnerability may allow out-of-bounds read.
CVE-2023-27976 0.0 unknown
No description available.
CVE-2021-22743 0.0 unknown
No description available.
CVE-2025-2223 0.0 unknown
CVE-2025-2223. CWE-20: Improper Input Validation vulnerability exists that could cause a loss of Confidentiality, Integrity and Availability of engineering workstation when a malicious project file is loaded by a user from the local system.
CVE-2020-7475 0.0 unknown
No description available.
CVE-2020-7566 7.1 high
A small space of random values vulnerability exists that could allow the attacker to break the encryption keys when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller.CVE-2020-7566 has been assigned to this vulnerability. A CVSS v3 base score of 7.1 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2021-21827 0.0 unknown
A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7. Within `DecodeTreeBlock` which is called during the decompression of an XMI file, a UINT32 is loaded from the file and used as trusted input as the length of a buffer. An attacker can provide a malicious file to trigger this vulnerability.CVE-2021-21827 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2020-7530 0.0 unknown
No description available.
CVE-2021-21869 0.0 unknown
CVE-2021-21869. An unsafe deserialization vulnerability exists in the Engine.plugin ProfileInformation ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.
CVE-2019-6841 0.0 unknown
No description available.
CVE-2024-5559 0.0 unknown
CVE-2024-5559. CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists that could cause denial of service, device reboot, or an attacker gaining full control of the relay when a specially crafted reset token is entered into the front panel of the device.
CVE-2024-10511 0.0 unknown
CVE-2024-10511. CWE-287: Improper Authentication vulnerability exists that could cause Denial of access to the web interface when someone on the local network repeatedly requests the /accessdenied URL.
CVE-2025-3916 0.0 unknown
A CWE-121 Stack-based Buffer Overflow vulnerability exists that could cause local attackers being able to exploit these issues to potentially execute arbitrary code while the end user opens a malicious project file (SSD file) provided by the attacker.
CVE-2020-8597 9.8 critical
CVE-2020-8597. The version of pppd shipped with this product has a vulnerability that may allow an unauthenticated remote attacker to cause a stack buffer overflow, which may allow arbitrary code execution on the target system.
CVE-2020-14517 0.0 unknown
CVE-2020-14517. Protocol encryption can be easily broken and the server accepts external connections, which may allow an attacker to remotely communicate with the CodeMeter API.
CVE-2023-27982 0.0 unknown
A vulnerability in Schneider Electric Data Server could cause manipulation of dashboard files in the IGSS project report directory when an attacker sends specific crafted messages to the Data Server TCP port. This could lead to remote code execution if an unsuspecting user opens the malicious dashboard file. CVE-2023-27982 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2025-9996 0.0 unknown
A OS command injection vulnerability exists that could cause the execution of any shell command when executing a netstat command using BLMon Console in anSSH session.
CVE-2020-11898 0.0 unknown
Improper handling of length parameter inconsistency in IPv4/ICMPv4 component when handling a packet sent by an unauthorized network attacker. This vulnerability may result in out-of-bounds read.
CVE-2022-4046 0.0 unknown
CVE-2022-4046. The CODESYS Control runtime system does not restrict the memory access. An improper restriction of operations within the bounds of a memory buffer allows an attacker with access to the drive with user privileges to gain full access of the drive.
CVE-2022-24310 9.8 critical
A vulnerability exists that could cause heap-based buffer overflow, leading to denial of service and potentially remote code execution when an attacker sends multiple specially crafted messages.CVE-2022-24310 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2021-22739 0.0 unknown
No description available.
CVE-2021-22770 0.0 unknown
No description available.
CVE-2022-0715 0.0 unknown
No description available.
CVE-2021-22755 7.8 high
Exploitation of this vulnerability could result in disclosure of information or remote code execution due to lack of sanity checks on user-supplied data when a malicious CGF file is imported to IGSS Definition.CVE-2021-22755 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2022-30234 0.0 unknown
No description available.
CVE-2021-22802 9.8 critical
The affected product is vulnerable to remote code execution, due to missing length check on user supplied data, when a constructed message is received on the network.CVE-2021-22802 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2020-27336 3.7 low
Improper input validation in the IPv6 component may allow an unauthenticated user to cause an out-of-bounds read of up to three bytes via network access.CVE-2020-27336 has been assigned to this vulnerability. A CVSS v3 base score of 3.7 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
CVE-2022-22726 0.0 unknown
No description available.
CVE-2024-0568 0.0 unknown
No description available.
CVE-2023-5630 0.0 unknown
No description available.
CVE-2020-7482 0.0 unknown
No description available.
CVE-2021-22824 0.0 unknown
No description available.
CVE-2021-22762 7.8 high
Exploitation of this vulnerability could result in remote code execution when a malicious CGF or WSP file is being parsed by IGSS Definition.CVE-2021-22762 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2020-11913 0.0 unknown
Improper input validation in IPv6 component when handling a packet sent by an unauthorized network attacker. This vulnerability may allow out-of-bounds read.
CVE-2025-0815 0.0 unknown
CVE-2025-0815. CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the product when malicious ICMPV6 packets are sent to the device.
CVE-2021-30065 0.0 unknown
No description available.
CVE-2018-12127 0.0 unknown
No description available.
CVE-2022-47382 0.0 unknown
CVE-2022-47382. An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
CVE-2025-11565 0.0 unknown
CVE-2025-11565. CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause elevated system access when a Web Admin user on the local network tampers with the POST /REST/UpdateJRE request payload.
CVE-2022-34758 5.1 medium
An Improper Input Validation vulnerability exists in Easergy P5 devices that cause the device watchdog function to be disabled if the attacker had access to privileged user credentials. CVE-2022-34758 has been assigned to this vulnerability. A CVSS v3 base score of 5.1 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L).
CVE-2019-12256 0.0 unknown
This vulnerability resides in the IPv4 option parsing and may be triggered by IPv4 packets containing invalid options. The most likely outcome of triggering this defect is that the tNet0 task crashes. This vulnerability can result in remote code execution.CVE-2019-12256 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2024-8935 0.0 unknown
CVE-2024-8935. CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss of confidentiality and integrity of controllers when conducting a Man-In-The-Middle attack between the controller and the engineering workstation while a valid user is establishing a communication session. This vulnerability is inherent to Diffie Hellman algorithm which does not protect against Man-In-The-Middle attacks.
CVE-2021-22804 7.5 high
An issue exists that could allow disclosure and read access of arbitrary files in the context of the user running IGSS, due to missing validation of user supplied data in network messages.CVE-2021-22804 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
CVE-2021-22807 7.8 high
This vulnerability may cause arbitrary code execution when a malicious *.gd1 configuration file is loaded into the GUIcon tool.CVE-2021-22807 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2020-7484 7.5 high
A vulnerability related to the "password" feature in TriStation 1131 Versions 1.0 through 4.12.0 could allow a denial of service attack if the user is not following documented guidelines pertaining to dedicated TriStation 1131 connection and key-switch protection.CVE-2020-7484 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
CVE-2022-32521 0.0 unknown
No description available.
CVE-2023-37559 0.0 unknown
CVE-2023-37559. After successful authentication as a user in multiple CODESYS products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of-service condition.
CVE-2018-7842 0.0 unknown
CVE-2018-7842. An authentication bypass by spoofing vulnerability exists which could cause an elevation of privilege by conducting a brute force attack on Modbus parameters sent to the controller.
CVE-2020-28218 6.3 medium
The affected product is vulnerable due to an improper restriction of rendered UI layers or frames vulnerability, which may allow an attacker to trick a user into initiating an unintended action.CVE-2020-28218 has been assigned to this vulnerability. A CVSS v3 base score of 6.3 has been calculated; the CVSS vector string is (AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:L).
CVE-2020-7528 0.0 unknown
No description available.
CVE-2020-11909 0.0 unknown
Improper input validation in IPv4 component when handling a packet sent by an unauthorized network attacker.
CVE-2019-6808 0.0 unknown
CVE-2019-6808. An improper access control vulnerability exists, which could cause a remote code execution by overwriting configuration settings of the controller over Modbus.
CVE-2022-32529 0.0 unknown
No description available.
CVE-2022-32512 0.0 unknown
No description available.
CVE-2020-1020 0.0 unknown
No description available.
CVE-2018-7241 0.0 unknown
No description available.
CVE-2019-6849 0.0 unknown
No description available.
CVE-2025-50123 0.0 unknown
CVE-2025-50123. CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote command execution by a privileged account when the server is accessed via a console and through exploitation of the hostname input.
CVE-2018-7843 0.0 unknown
CVE-2018-7843. An uncaught exception vulnerability exists which could cause denial of service when reading memory blocks with an invalid data size or with an invalid data offset in the controller over Modbus.
CVE-2024-5313 0.0 unknown
No description available.
CVE-2020-35684 7.5 high
The code that parses TCP packets relies on an unchecked value of the IP payload size to compute the length of the TCP payload within the TCP checksum computation function, which may result in an out-of-bounds read.CVE-2020-35684 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
CVE-2021-22812 6.8 medium
A vulnerability could cause arbitrary script execution when a privileged account clicks on a malicious URL specifically crafted for the NMC.CVE-2021-22812 has been assigned to this vulnerability. A CVSS v3 base score of 6.8 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N).
CVE-2018-7852 0.0 unknown
CVE-2018-7852. An uncaught exception vulnerability exists which could cause denial of service when an invalid private command parameter is sent to the controller over Modbus.
CVE-2020-7550 7.8 high
An improper restriction of operations within the bounds of a memory buffer vulnerability could cause remote code execution when a malicious CGF (Configuration Group File) is imported to IGSS Definition.CVE-2020-7550 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2021-22825 6.5 medium
An attacker could access the system with elevated privileges when a privileged account clicks on a malicious URL that compromises the security token. CVE-2021-22825 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:L).. --------- End Update A Part 3 of 3 ---------CVE-2021-22825 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:L).
CVE-2021-22818 0.0 unknown
No description available.
CVE-2025-2441 0.0 unknown
CVE-2025-2441. CWE-1188: Incorrect Initialization of Resource vulnerability exists that could lead to loss of confidentiality when a malicious user, having physical access, sets the radio in factory default mode where the product does not correctly initialize all data.
CVE-2021-22734 0.0 unknown
No description available.
CVE-2022-24315 7.5 high
A vulnerability exists that could cause denial of service when an attacker repeatedly sends a specially crafted message.CVE-2022-24315 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
CVE-2020-7567 7.1 high
A missing encryption of sensitive data vulnerability exists that could allow the attacker to find the password hash when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller and has broken the encryption keys.CVE-2020-7567 has been assigned to this vulnerability. A CVSS v3 base score of 7.1 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2020-11902 0.0 unknown
Improper input validation in IPv6 over IPv4 tunneling component when handling a packet sent by an unauthorized network attacker. This vulnerability may allow out-of-bounds read.
CVE-2025-3117 0.0 unknown
CVE-2025-3117. CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists impacting configuration file paths that could cause an unvalidated data injected by authenticated malicious user leading to modify or read data in a victim’s browser.
CVE-2022-2463 0.0 unknown
A crafted malicious .7z exchange file may allow an attacker to gain the privileges of the ISaGRAF Workbench software when opened. If the software is running at the SYSTEM level, then the attacker will gain admin level privileges. User interaction is required for this exploit to be successful.CVE-2022-2463 has been assigned to this vulnerability. A CVSS v3 base score of 6.1 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L).
CVE-2019-6844 0.0 unknown
No description available.
CVE-2019-6847 0.0 unknown
No description available.
CVE-2023-5402 0.0 unknown
Schneider Electric's SpaceLogic C-Bus Toolkit product is vulnerable due to improper privilege management, which could cause remote code execution when the transfer command is used over the network.
CVE-2021-21863 0.0 unknown
CVE-2021-21863. A unsafe deserialization vulnerability exists in the ComponentModel Profile.FromFile() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.
CVE-2021-22817 0.0 unknown
No description available.
CVE-2024-8936 0.0 unknown
CVE-2024-8936. CWE-20: Improper Input Validation vulnerability exists that could lead to tampering a parameter of the controller memory after a successful Man In The Middle attack followed by Read Physical Memory operation leading to loss of confidentiality of controller memory.
CVE-2022-22812 0.0 unknown
No description available.
CVE-2020-7545 0.0 unknown
No description available.
CVE-2023-6409 0.0 unknown
CVE-2023-6409. A CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to a project file protected with application password when opening the file with EcoStruxure Control Expert.
CVE-2022-41670 0.0 unknown
No description available.
CVE-2021-22745 0.0 unknown
No description available.
CVE-2022-34754 0.0 unknown
No description available.
CVE-2021-22827 0.0 unknown
No description available.
CVE-2023-50447 0.0 unknown
Pillow Version 10.1.0 allows PIL.ImageMath.eval arbitrary code execution via the environment parameter. This is a different vulnerability from CVE-2022-22817, which pertains to the expression parameter.
CVE-2020-7524 0.0 unknown
No description available.
CVE-2020-7514 0.0 unknown
No description available.
CVE-2025-11567 0.0 unknown
CVE-2025-11567. CWE-276: Incorrect Default Permissions vulnerability exists that could cause elevated system access when the target installation folder is not properly secured.
CVE-2022-41671 0.0 unknown
No description available.
CVE-2021-22777 0.0 unknown
No description available.
CVE-2021-22787 0.0 unknown
No description available.
CVE-2020-0609 0.0 unknown
No description available.
CVE-2021-22765 0.0 unknown
No description available.
CVE-2021-22788 0.0 unknown
No description available.
CVE-2020-11897 0.0 unknown
Improper handling of length parameter inconsistency in IPv6 component when handling a packet sent by an unauthorized network attacker. This vulnerability may result in possible out-of-bounds write.
CVE-2022-24313 9.8 critical
A vulnerability exists that could cause a stack-based buffer overflow potentially leading to remote code execution when an attacker sends a specially crafted message.CVE-2022-24313 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2020-7562 6.3 medium
An out-of-bounds read vulnerability exists which could cause a segmentation fault or a buffer overflow when uploading a specially crafted file on the controller over FTP. CVE-2020-7562 has been assigned to this vulnerability. A CVSS v3 base score of 6.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:H).
CVE-2019-11091 0.0 unknown
No description available.
CVE-2024-6918 0.0 unknown
CVE-2024-6918. CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause a crash of the Accutech Manager when receiving a specially crafted request over port 2536/TCP.
CVE-2020-0796 0.0 unknown
No description available.
CVE-2020-7483 5.3 medium
A vulnerability related to the "password" feature in TriStation 1131 Versions 1.0 through 4.12.0 could cause certain data to be visible on the network when the feature was enabled.CVE-2020-7483 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N).
CVE-2020-7478 7.5 high
The affected product could allow a remote unauthenticated attacker to read arbitrary files on the device.CVE-2020-7478 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
CVE-2023-22610 0.0 unknown
No description available.
CVE-2021-33485 0.0 unknown
CVE-2021-33485. CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow.
CVE-2023-6408 0.0 unknown
CVE-2023-6408. A CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a denial of service and loss of confidentiality, integrity of controllers when conducting a Man in the Middle attack.
CVE-2021-22705 0.0 unknown
No description available.
CVE-2021-21815 0.0 unknown
A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs' Xmill 0.7. Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line. filepattern is passed directly to strcpy copying the path provided by the user into a staticly sized buffer without any length checks resulting in a stack-buffer overflow. An attacker can provide malicious input to trigger this vulnerability.CVE-2021-21815 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
CVE-2020-7480 0.0 unknown
No description available.
CVE-2019-9009 0.0 unknown
CVE-2019-9009. An issue was discovered in 3S-Smart CODESYS before 3.5.15.0 . Crafted network packets cause the Control Runtime to crash.
CVE-2022-24323 0.0 unknown
No description available.
CVE-2021-22772 0.0 unknown
No description available.
CVE-2020-7518 0.0 unknown
No description available.
CVE-2024-10106 0.0 unknown
CVE-2024-10106. A CWE-120: A buffer overflow vulnerability exists that could cause a denial of service when a malicious device joins the network.
CVE-2020-25176 9.1 critical
Some commands used by the ISaGRAF eXchange Layer (IXL) protocol perform various file operations in the file system. Since the parameter pointing to the file name is not checked for reserved characters, it is possible for a remote, unauthenticated attacker to traverse an application 's directory, which could lead to remote code execution.CVE-2020-25176 has been assigned to this vulnerability. A CVSS v3 base score of 9.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
CVE-2021-22699 0.0 unknown
No description available.
CVE-2023-37199 0.0 unknown
No description available.
CVE-2020-7522 9.8 critical
A vulnerability exists when accessing a vulnerable method of `SoundUploadServlet` that may lead to uploading executable files to non-specified directories.CVE-2020-7522 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2021-34527 0.0 unknown
No description available.
CVE-2022-22813 0.0 unknown
No description available.
CVE-2019-6855 0.0 unknown
No description available.
CVE-2022-22731 0.0 unknown
No description available.
CVE-2020-7506 0.0 unknown
No description available.
CVE-2023-5399 0.0 unknown
Schneider Electric's SpaceLogic C-Bus Toolkit product contains a path traversal vulnerability, which could cause tampering of files on the personal computer running C-Bus when using the File Command.
CVE-2021-45046 0.0 unknown
CVE-2021-45046. The fix to address CVE-2021-44228 was incomplete in certain non-default configurations, when the logging configuration uses a non-default Pattern Layout with a Context Lookup (for example, ${ctx:loginId}). This could allow attackers with control over Thread Context Map (MDC) input data to craft malicious input data using a JNDI Lookup pattern, resulting in an information leak and remote code execution in some environments and local code execution in all environments.
CVE-2021-22747 0.0 unknown
No description available.
CVE-2021-22740 0.0 unknown
No description available.
CVE-2025-1058 0.0 unknown
CVE-2025-1058. CWE-494: Download of Code Without Integrity Check vulnerability exists that could render the device inoperable when malicious firmware is downloaded.
CVE-2023-25620 0.0 unknown
No description available.
CVE-2024-10083 0.0 unknown
CVE-2024-10083. CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of engineering workstation when specific driver interface is invoked locally by an authenticated user with crafted input.
CVE-2018-7849 0.0 unknown
CVE-2018-7849. An uncaught exception vulnerability exists which could cause a possible denial of service due to improper data integrity check when sending files to the controller over Modbus.
CVE-2021-21867 0.0 unknown
CVE-2021-21867. An unsafe deserialization vulnerability exists in the ObjectManager.plugin ObjectStream.ProfileByteArray functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.
CVE-2020-7498 0.0 unknown
No description available.
CVE-2020-27338 5.9 medium
An issue was discovered in Treck IPv6. An out-of-bound read in the DHCPv6 client component may allow an unauthenticated user to cause a possible denial-of-service via adjacent network access.CVE-2020-27338 has been assigned to this vulnerability. A CVSS v3 base score of 5.9 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H).
CVE-2024-12703 0.0 unknown
CVE-2024-12703. CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote code execution on workstation when a non-admin authenticated user opens a malicious project file.
CVE-2022-32525 0.0 unknown
No description available.
CVE-2021-22742 0.0 unknown
No description available.
CVE-2020-7531 0.0 unknown
No description available.
CVE-2023-27983 0.0 unknown
A vulnerability in Schneider Electric Data Server TCP interface could allow deletion of reports from the IGSS project report directory. CVE-2023-27983 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L).
CVE-2020-7508 0.0 unknown
No description available.
CVE-2020-14513 0.0 unknown
CVE-2020-14513. CodeMeter and the software using it may crash while processing a specifically crafted license file due to unverified length fields.
CVE-2020-7516 0.0 unknown
No description available.
CVE-2020-7492 0.0 unknown
No description available.
CVE-2021-22815 5.3 medium
A vulnerability could allow the troubleshooting archive to be accessed.CVE-2021-22815 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
CVE-2022-47381 0.0 unknown
CVE-2022-47381. An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
CVE-2022-22806 0.0 unknown
No description available.
CVE-2020-11903 0.0 unknown
Possible out-of-bounds read in DHCP component when handling a packet sent by an unauthorized network attacker. This vulnerability may allow exposure of sensitive information.
CVE-2018-7764 0.0 unknown
No description available.
CVE-2025-50124 0.0 unknown
CVE-2025-50124. CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation when the server is accessed by a privileged account via a console and through exploitation of a setup script.
CVE-2021-22778 8.6 high
An insufficiently protected credentials vulnerability exists that could cause protected derived function blocks to be read or modified by unauthorized users when accessing a project file. CVE-2021-22778 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).. --------- Begin Update A Part 2 of 2 --------CVE-2021-22778 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
CVE-2022-32747 0.0 unknown
No description available.
CVE-2021-30186 7.5 high
A crafted request may cause a heap-based buffer overflow in the affected CODESYS products, resulting in a denial-of-service condition.CVE-2021-30186 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
CVE-2021-22733 0.0 unknown
No description available.
CVE-2019-12263 0.0 unknown
This vulnerability relies on a race-condition between the network task (tNet0) and the receiving application. It is very difficult to trigger the race on a system with a single CPU-thread enabled, and there is no way to reliably trigger a race on SMP targets.CVE-2019-12263 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2020-1350 0.0 unknown
No description available.
CVE-2021-22751 7.8 high
Exploitation of this vulnerability could result in disclosure of information or execution of arbitrary code due to lack of input validation when a malicious CGF (Configuration Group File) is imported to IGSS Definition.CVE-2021-22751 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2020-7523 0.0 unknown
No description available.
CVE-2022-45788 0.0 unknown
The affected components contain a vulnerability that could cause arbitrary code execution, a denial-of-service condition, and loss of confidentiality & integrity when a malicious project file is loaded onto the controller.
CVE-2024-9005 0.0 unknown
CVE-2024-9005. CWE-502: Deserialization of Untrusted Data vulnerability exists that could allow code to be remotely executed on the server when unsafely deserialized data is posted to the web server.
CVE-2024-37036 0.0 unknown
CVE-2024-37036. CWE-787: Out-of-bounds Write vulnerability exists that could result in an authentication bypass when sending a malformed POST request and particular configuration parameters are set.
CVE-2023-2569 0.0 unknown
No description available.
CVE-2019-13538 8.6 high
The system displays active library content without checking the validity, which may allow the contents of manipulated libraries to be displayed or executed. The issue also exists for source libraries, but 3S-Smart Software Solutions GmbH strongly recommends distributing compiled libraries only.CVE-2019-13538 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
CVE-2024-8937 0.0 unknown
CVE-2024-8937. CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause potential arbitrary code execution after a successful Man In The Middle attack followed by sending crafted Modbus command to tamper with a function call used for authentication process.
CVE-2023-29411 0.0 unknown
A vulnerability exists that could allow changes to administrative credentials, leading to potential remote code execution without requiring prior authentication on the Java RMI interface.
CVE-2021-22763 0.0 unknown
CVE-2021-22763. CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could allow an attacker administrator level access to a device.
CVE-2021-22750 7.8 high
Exploitation of this vulnerability could result in loss of data or remote code execution due to missing length checks when a malicious CGF file is imported to IGSS Definition.CVE-2021-22750 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2023-5391 0.0 unknown
A deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by sending a specifically crafted packet to the application.
CVE-2022-22732 0.0 unknown
No description available.
CVE-2021-30195 7.5 high
A crafted request may cause a buffer over-read in the affected CODESYS products, resulting in a denial-of-service condition.CVE-2021-30195 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
CVE-2020-28219 0.0 unknown
No description available.
CVE-2021-45105 0.0 unknown
CVE-2021-45105. Apache Log4j2 versions 2.0-alpha1 through 2.16.0 did not protect from uncontrolled recursion from self-referential lookups, when the logging configuration uses a non-default Pattern Layout with a Context Lookup (for example, $${ctx:loginId}). This could allow attackers with control over Thread Context Map (MDC) input data to craft malicious input data that contains a recursive lookup, resulting in a denial of service condition.
CVE-2018-7774 0.0 unknown
No description available.
CVE-2021-22697 7.8 high
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior) that could allow a use-after-free condition which could result in remote code execution when a malicious SSD file is uploaded and improperly parsed.
CVE-2022-1467 0.0 unknown
Windows OS can be configured to overlay a language bar on top of any application. When this OS functionality is enabled, the OS language bar UI will be viewable in the browser alongside the InTouch Access Anywhere and Plant SCADA Access Anywhere applications. It is possible to manipulate the Windows OS language bar to launch an OS command prompt, resulting in a context-escape from application into OS.CVE-2022-1467 has been assigned to this vulnerability. A CVSS v3 base score of 7.4 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L).
CVE-2018-7847 0.0 unknown
CVE-2018-7847. An improper access control vulnerability exists which could cause denial of service or potential code execution by overwriting configuration settings of the controller over Modbus.
CVE-2021-21812 0.0 unknown
A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs ' Xmill 0.7. Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line. filepattern is passed directly to strcpy copying the path provided by the user into a static sized buffer without any length checks resulting in a stack-buffer overflow. An attacker can provide malicious input to trigger these vulnerabilities.CVE-2021-21812 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
CVE-2020-7569 4.6 medium
CVE-2020-7569. An unrestricted upload of a file with dangerous type vulnerability could allow an authenticated remote user to upload arbitrary files due to incorrect verification of user supplied files and achieve remote code execution.CVE-2020-7569 has been assigned to this vulnerability. A CVSS v3 base score of 4.6 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L).
CVE-2022-24316 5.3 medium
A vulnerability exists that could cause information exposure when an attacker sends a specially crafted message.CVE-2022-24316 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
CVE-2018-7811 0.0 unknown
No description available.
CVE-2019-12255 0.0 unknown
An attacker can either hijack an existing TCP session and inject bad TCP segments or establish a new TCP session on any TCP port listened to by the target. This vulnerability could lead to a buffer overflow of up to a full TCP receive-window (by default, 10k-64k depending on version). The buffer overflow occurs in the task calling recv()/recvfrom()/recvmsg(). Applications that pass a buffer equal to or larger than a full TCP window are not susceptible to this attack. Applications passing a stack-allocated variable as a buffer are the easiest to exploit. The most likely outcome is a crash of the application reading from the affected socket, which could result in remote code execution.. CVE-2019-12255 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).Applications that pass a buffer equal to or larger than a full TCP window are not susceptible to this attack. Applications passing a stack-allocated variable as a buffer are the easiest to exploit. The most likely outcome is a crash of the application reading from the affected socket, which could result in remote code execution.
CVE-2023-6407 0.0 unknown
A path traversal vulnerability exists that could cause arbitrary file deletion upon service restart when accessed by a local and low-privileged attacker.
CVE-2021-22786 0.0 unknown
No description available.
CVE-2023-27975 0.0 unknown
CVE-2023-27975. A CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized access to the project file in EcoStruxure™ Control Expert when a local user tampers with the memory of the engineering workstation.
CVE-2019-6846 0.0 unknown
No description available.
CVE-2021-21810 0.0 unknown
A memory corruption vulnerability exists in the XML-parsing ParseAttribs functionality of AT&T Labs ' Xmill 0.7. A specially crafted XML file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.CVE-2021-21810 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2021-22701 0.0 unknown
No description available.
CVE-2022-32522 0.0 unknown
No description available.
CVE-2020-7552 7.8 high
An improper restriction of operations within the bounds of a memory buffer vulnerability could cause remote code execution when a malicious CGF (Configuration Group File) is imported to IGSS Definition.CVE-2020-7552 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2018-7777 0.0 unknown
No description available.
CVE-2020-7565 7.1 high
An inadequate encryption strength vulnerability exists that could allow the attacker to break the encryption key when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller.CVE-2020-7565 has been assigned to this vulnerability. A CVSS v3 base score of 7.1 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2025-49844 0.0 unknown
CVE-2025-49844. Additional information about CVE-2025-49844 can be found here: https://www.cve.org/CVERecord?id=CVE-2025-49844
CVE-2022-47379 0.0 unknown
CVE-2022-47379. An authenticated, remote attacker may use a out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into memory which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
CVE-2022-32524 0.0 unknown
No description available.
CVE-2021-31166 0.0 unknown
No description available.
CVE-2023-5984 0.0 unknown
No description available.
CVE-2020-7526 0.0 unknown
No description available.
CVE-2023-25548 0.0 unknown
No description available.
CVE-2020-7527 0.0 unknown
No description available.
CVE-2023-28355 0.0 unknown
CVE-2023-28355. The PLC application code executed by the CODESYS Control Runtime contains a checksum. This enables the CODESYS development system to check at login whether its loaded project matches the PLC application code executed on the controller. This checksum is not sufficient to reliably detect PLC application code that has been modified in memory or boot application files that have been manipulated.
CVE-2018-7767 0.0 unknown
No description available.
CVE-2020-7543 0.0 unknown
No description available.
CVE-2023-35945 0.0 unknown
Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy's HTTP/2 codec may leak a header map and bookkeeping structures upon receiving RST_STREAM immediately followed by the GOAWAY frames from an upstream server. In nghttp2, cleanup of pending requests due to receipt of the GOAWAY frame skips de-allocation of the bookkeeping structure and pending compressed header. The error return [code path] is taken if the connection is already marked for not sending more requests due to GOAWAY frame. The clean-up code is right after the return statement, causing a memory leak. This results in denial of service through memory exhaustion. This vulnerability was patched in Versions 1.26.3, 1.25.8, 1.24.9, 1.23.11.
CVE-2021-22749 5.3 medium
This vulnerability could cause an information leak concerning the current RTU configuration including communication parameters dedicated to telemetry when a specially crafted HTTP request is sent to the web server of the module.CVE-2021-22749 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
CVE-2018-7763 0.0 unknown
No description available.
CVE-2021-22708 0.0 unknown
No description available.
CVE-2021-22713 0.0 unknown
No description available.
CVE-2024-7322 0.0 unknown
CVE-2024-7322. A CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service when a malicious device joins the network.
CVE-2020-7502 0.0 unknown
No description available.
CVE-2020-28217 6.7 medium
The affected product is vulnerable to a missing encryption of sensitive data vulnerability, which may allow an attacker to read network traffic over IEC60870-5-104 protocol.CVE-2020-28217 has been assigned to this vulnerability. A CVSS v3 base score of 6.7 has been calculated; the CVSS vector string is (AV:P/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L).
CVE-2022-24320 0.0 unknown
No description available.
CVE-2024-2658 0.0 unknown
CVE-2024-2658
CVE-2020-28895 0.0 unknown
In Wind River VxWorks, memory allocator has a possible overflow in calculating the memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer size specified by the arguments, leading to memory corruption.
CVE-2022-47390 0.0 unknown
CVE-2022-47390. An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
CVE-2021-44832 0.0 unknown
CVE-2021-44832. Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to code execution attacks if the JDBC Appender is being used and configured to allow the use of protocols other than Java. This could allow attackers with permission to modify the logging configuration file to execute code via a data source referencing a JNDI URI. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.
CVE-2022-32527 0.0 unknown
No description available.
CVE-2025-5741 0.0 unknown
CVE-2025-5741. CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file reads from the charging station. The exploitation of this vulnerability does require an authenticated session of the web server.
CVE-2023-37545 0.0 unknown
CVE-2023-37545. In multiple CODESYS products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition.
CVE-2024-5681 0.0 unknown
CVE-2024-5681. CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service, privilege escalation, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
CVE-2020-7532 0.0 unknown
No description available.
CVE-2020-0938 0.0 unknown
No description available.
CVE-2020-7494 7.7 high
An attacker could exploit this path traversal vulnerability by getting a user to visit a malicious page or open a malicious file.CVE-2020-7494 has been assigned to this vulnerability. A CVSS v3 base score of 7.7 has been calculated; the CVSS vector string is (AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).
CVE-2023-27979 0.0 unknown
A vulnerability in Schneider Electric Data Server could allow an unauthorized user to rename files in the IGSS project report directory. This could lead to a denial-of-service condition if an attacker sends specific crafted messages to the Data Server TCP port. CVE-2023-27979 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L).
CVE-2020-35683 7.5 high
The code that parses ICMP packets relies on an unchecked value of the IP payload size to compute the ICMP checksum, which may result in an out-of-bounds read.CVE-2020-35683 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
CVE-2019-6850 0.0 unknown
No description available.
CVE-2021-22784 6.5 medium
An improper authentication issue exists and could allow an attacker to use a crafted webpage that can enable remote access to the system.CVE-2021-22784 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N).
CVE-2018-7854 0.0 unknown
CVE-2018-7854. An uncaught exception vulnerability exists which could cause a denial of service when sending invalid debug parameters to the controller over Modbus.
CVE-2018-7856 0.0 unknown
CVE-2018-7856. An uncaught exception vulnerability exists which could cause a possible denial of service when writing invalid memory blocks to the controller over Modbus.
CVE-2023-25552 0.0 unknown
No description available.
CVE-2020-14515 0.0 unknown
CVE-2020-14515. There is an issue in the license-file signature checking mechanism, which could allow attackers to build arbitrary license files, including forging a valid license file as if it were a valid license file of an existing vendor. Only CmActLicense update files with CmActLicense Firm Code are affected.
CVE-2020-7477 0.0 unknown
No description available.
CVE-2021-30066 0.0 unknown
No description available.
CVE-2020-7489 0.0 unknown
No description available.
CVE-2018-7765 0.0 unknown
No description available.
CVE-2022-32513 0.0 unknown
No description available.
CVE-2021-31401 7.5 high
An attacker could send a specially crafted IP packet to trigger an integer overflow due to the lack of IP length validation.CVE-2021-31401 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
CVE-2022-24321 0.0 unknown
No description available.
CVE-2022-24314 7.5 high
A vulnerability exists that could cause memory leaks potentially resulting in denial of service when an attacker repeatedly sends a specially crafted message.CVE-2022-24314 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
CVE-2022-34757 0.0 unknown
No description available.
CVE-2024-2050 0.0 unknown
No description available.
CVE-2022-2465 0.0 unknown
ISaGRAF Workbench does not limit the objects that can be deserialized. This vulnerability allows attackers to craft a malicious serialized object that, if opened by a local user in ISaGRAF Workbench, may result in remote code execution. This vulnerability requires user interaction to be successfully exploited.CVE-2022-2465 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
CVE-2022-32519 0.0 unknown
No description available.
CVE-2025-2222 0.0 unknown
CVE-2025-2222. CWE-552: Files or Directories Accessible to External Parties vulnerability over https exists that could leak information and potential privilege escalation following man in the middle attack.
CVE-2019-1181 0.0 unknown
No description available.
CVE-2021-22722 0.0 unknown
No description available.
CVE-2022-26507 0.0 unknown
A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file could lead to remote code execution.CVE-2022-26507 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2021-22731 0.0 unknown
No description available.
CVE-2019-6858 0.0 unknown
No description available.
CVE-2022-24322 0.0 unknown
No description available.
CVE-2021-22156 0.0 unknown
No description available.
CVE-2022-22725 8.8 high
A buffer copy without checking size of input vulnerability exists in Easergy P3 devices that could lead to a buffer overflow, causing program crashes and arbitrary code execution when specially crafted packets are sent to the device over the network. Protection functions and tripping functions via GOOSE can be impacted. CVE-2022-22725 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2021-21813 0.0 unknown
Within the function HandleFileArg, the argument filepattern is under control of the user who passes it in from the command line. filepattern is passed directly to memcpy copying the path provided by the user into a staticly sized buffer without any length checks resulting in a stack-buffer overflow.CVE-2021-21813 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
CVE-2022-32530 0.0 unknown
No description available.
CVE-2021-30063 0.0 unknown
No description available.
CVE-2022-47383 0.0 unknown
CVE-2022-47383. An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
CVE-2022-2988 0.0 unknown
No description available.
CVE-2020-7554 7.8 high
An improper restriction of operations within the bounds of a memory buffer vulnerability could cause remote code execution when a malicious CGF (Configuration Group File) is imported to IGSS Definition.CVE-2020-7554 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2020-9404 0.0 unknown
No description available.
CVE-2023-29414 0.0 unknown
No description available.
CVE-2021-22769 8.5 high
This vulnerability may allow disclosure of device configuration information to any authenticated user when a specially crafted request is sent to the device.CVE-2021-22769 has been assigned to this vulnerability. A CVSS v3 base score of 8.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
CVE-2020-7558 7.8 high
An out-of-bounds write vulnerability could cause remote code execution when a malicious CGF (Configuration Group File) is imported to IGSS Definition.CVE-2020-7558 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2024-8518 0.0 unknown
An Improper Input Validation vulnerability exists that could cause a crash of the Zelio Soft 2 application if a specially crafted project file is loaded by an application user.
CVE-2024-10575 0.0 unknown
CVE-2024-10575. CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access when enabled on the network and potentially impacting connected devices.
CVE-2024-11139 0.0 unknown
CVE-2024-11139. CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could allow local attackers to exploit these issues to potentially execute arbitrary code when opening a malicious project file.
CVE-2021-44228 10.0 critical
The affected product does not properly validate user input, allowing an attacker to enter malicious input and potentially gain remote code execution.CVE-2021-44228 has been assigned to this vulnerability. A CVSS v3 base score of 10.0 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
CVE-2024-9409 0.0 unknown
CVE-2024-9409. CWE-400: An Uncontrolled Resource Consumption vulnerability exists that could cause the device to become unresponsive resulting in communication loss when a large amount of IGMP packets is present in the network.
CVE-2025-1070 0.0 unknown
CVE-2025-1070. CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could render the device inoperable when a malicious file is downloaded.
CVE-2025-13845 0.0 unknown
CVE-2025-13845. A use-after-free vulnerability may allow remote code execution when an end user imports a malicious SSD project file into Rapsody.
CVE-2019-1222 0.0 unknown
No description available.
CVE-2021-22757 7.8 high
Exploitation of this vulnerability could result in disclosure of information or remote code execution due to lack of validation on user-supplied input data when a malicious CGF file is imported to IGSS Definition.CVE-2021-22757 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVE-2021-22796 0.0 unknown
No description available.
CVE-2023-0595 0.0 unknown
No description available.
CVE-2018-7857 0.0 unknown
CVE-2018-7857. An uncaught exception vulnerability exists, which could cause a possible denial of service when writing out of bounds variables to the controller over Modbus.
CVE-2021-22798 0.0 unknown
No description available.
CVE-2021-29240 0.0 unknown
CVE-2021-29240. The Package Manager of CODESYS Development System 3 before 3.5.17.0 does not check the validity of packages before installation and may be used to install CODESYS packages with malicious content.
CVE-2022-4062 0.0 unknown
No description available.
CVE-2020-28212 0.0 unknown
No description available.
CVE-2021-22738 0.0 unknown
No description available.
CVE-2020-7573 5.0 medium
CVE-2020-7573. An improper access control vulnerability could allow a remote attacker access to restricted web resources due to improper access control.CVE-2020-7573 has been assigned to this vulnerability. A CVSS v3 base score of 5.0 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L).
CVE-2022-0222 0.0 unknown
No description available.
CVE-2022-22722 7.5 high
If an attacker were to obtain the SSH cryptographic key for the device and take active control of the local operational network connected to this product, they could observe and manipulate traffic associated with product configuration. This could result in information disclosure. CVE-2022-22722 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVE-2024-8422 0.0 unknown
A Use After Free vulnerability exists that could cause arbitrary code execution, denial-of-service and loss of confidentiality & integrity if an application user opens a malicious Zelio Soft 2 project file.
CVE-2020-7547 0.0 unknown
No description available.
CVE-2020-6996 7.5 high
A specially crafted message may cause a stack-based buffer overflow. Authentication is not required to exploit this vulnerability.CVE-2020-6996 has been assigned to this vulnerability. A CVSS v3 base score of 7.5has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
CVE-2022-30238 0.0 unknown
No description available.
CVE-2022-2464 0.0 unknown
Crafted malicious files can allow an attacker to traverse the file system when opened by ISaGRAF Workbench. If successfully exploited, an attacker could overwrite existing files and create additional files with the same permissions of the ISaGRAF Workbench software. User interaction is required for this exploit to be successful.CVE-2022-2464 has been assigned to this vulnerability. A CVSS v3 base score of 7.7 has been calculated; the CVSS vector string is (AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).

// Affected Products (571)

Vendor Product Asset Type Purdue Level Firmware
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
2023
Schneider Electric Unknown engineering_workstation
L3
2024
Siemens Unknown network_device -- --
Schneider Electric Unknown network_device -- --
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Schneider Electric Unknown dcs
L2
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown hmi
L2
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown hmi
L2
--
Schneider Electric Unknown hmi
L2
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Software, LLC Unknown scada_server
L2
vers:all/*
Schneider Electric Software, LLC Unknown engineering_workstation
L3
vers:all/*
Schneider Electric Software, LLC Unknown engineering_workstation
L3
vers:all/*
Schneider Electric Unknown rtu
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown rtu
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Software, LLC Unknown safety_system
L1
--
Schneider Electric Unknown network_device -- --
Schneider Electric Unknown network_device -- --
Schneider Electric Unknown network_device -- --
Schneider Electric Unknown network_device -- --
Schneider Electric Unknown network_device -- --
Schneider Electric Unknown network_device -- --
Schneider Electric Unknown network_device -- --
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown dcs
L2
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
2020_R2
Schneider Electric Unknown engineering_workstation
L3
2020_R2
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Software, LLC Unknown network_device -- --
Schneider Electric Software, LLC Unknown plc
L1
vers:all/*
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Siemens Unknown scada_server
L2
--
Siemens Unknown plc
L1
--
Siemens Unknown plc
L1
--
Siemens Unknown plc
L1
--
Siemens Unknown plc
L1
--
Schneider Electric Unknown engineering_workstation
L3
2024_CU3
Rockwell Automation Unknown plc
L1
vers:all/*
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Software, LLC Unknown hmi
L2
--
Schneider Electric Software, LLC Unknown engineering_workstation
L3
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
2020_R2
Schneider Electric Unknown engineering_workstation
L3
2020_R2
Schneider Electric Unknown engineering_workstation
L3
2023_v4.8.0.5715
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown rtu
L1
--
Schneider Electric Unknown rtu
L1
--
Schneider Electric Unknown scada_server
L2
--
Siemens Unknown hmi
L2
--
Siemens Unknown historian
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
2022
Schneider Electric Unknown engineering_workstation
L3
2023
CODESYS, GmbH Unknown engineering_workstation
L3
--
CODESYS, GmbH Unknown plc
L1
--
Schneider Electric Software, LLC Unknown plc
L1
vers:all/*
Schneider Electric Software, LLC Unknown plc
L1
vers:all/*
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Software, LLC Unknown engineering_workstation
L3
3.1 SP1
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Software, LLC Unknown plc
L1
vers:all/*
Schneider Electric Software, LLC Unknown plc
L1
vers:all/*
Schneider Electric Unknown hmi
L2
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Software, LLC Unknown scada_server
L2
--
Schneider Electric Unknown scada_server
L2
--
CODESYS, GmbH Unknown engineering_workstation
L3
--
Schneider Electric Unknown plc
L1
BMXNOC0401
Schneider Electric Software, LLC Unknown engineering_workstation
L3
--
Siemens Unknown network_device -- --
Schneider Electric Unknown hmi
L2
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Software, LLC Unknown hmi
L2
vers:all/*
Schneider Electric Software, LLC Unknown hmi
L2
vers:all/*
Schneider Electric Software, LLC Unknown hmi
L2
vers:all/*
Schneider Electric Software, LLC Unknown hmi
L2
vers:all/*
Schneider Electric Software, LLC Unknown hmi
L2
vers:all/*
Schneider Electric Software, LLC Unknown hmi
L2
vers:all/*
Schneider Electric Software, LLC Unknown hmi
L2
vers:all/*
Schneider Electric Software, LLC Unknown hmi
L2
vers:all/*
Schneider Electric Software, LLC Unknown scada_server
L2
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown rtu
L1
--
Schneider Electric Unknown plc
L1
vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- --
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- vers:all/*
Siemens Unknown network_device -- vers:all/*
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown scada_server
L2
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Siemens Unknown network_device -- --
Schneider Electric Unknown rtu
L1
--
Schneider Electric Unknown rtu
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown scada_server
L2
--
Schneider Electric Unknown scada_server
L2
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
3S-Smart Software Solutions GmbH Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown scada_server
L2
--
Schneider Electric Unknown engineering_workstation
L3
--
AVEVA Software, LLC Unknown scada_server
L2
vers:all/*
AVEVA Software, LLC Unknown historian
L3
vers:all/*
Schneider Electric Software, LLC Unknown plc
L1
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown scada_server
L2
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
2025
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown scada_server
L2
--
Schneider Electric Unknown engineering_workstation
L3
--
Schneider Electric Unknown engineering_workstation
L3
1.21.0.6
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--
Schneider Electric Unknown plc
L1
--

// Remediations (1336)

Patch: Version v1.5 of PowerChute™ Serial Shutdown includes a fix for this vulnerability and is available f
Version v1.5 of PowerChute™ Serial Shutdown includes a fix for this vulnerability and is available for download here: • Windows: https://www.se.com/ww/en/download/document/SPD-PCSS_WIN_EN/ Specific instructions and hardening guidelines for these mitigations can be found in the [Security Handbook](https://download.schneider-electric.com/files?p_Doc_Ref=SPD_CCON-PCSSSH_EN).
Patch: Version v1.5 of PowerChute™ Serial Shutdown includes a fix for this vulnerability and is available f
Version v1.5 of PowerChute™ Serial Shutdown includes a fix for this vulnerability and is available for download here: • Linux: https://www.se.com/ww/en/download/document/SPD-PCSS_LNX_EN/ Specific instructions and hardening guidelines for these mitigations can be found in the [Security Handbook](https://download.schneider-electric.com/files?p_Doc_Ref=SPD_CCON-PCSSSH_EN).
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • Restrict network access to P7 service endpoints (ports 8080 and 3702) • Monitor and alert on anomalous SOAP requests targeting wsApp • Limit administrative access and apply least privilege principles for all users interacting with P7.
Patch: Version V02.004.001 of PowerLogicTM P7 includes a fix for this vulnerability and is available for d
Version V02.004.001 of PowerLogicTM P7 includes a fix for this vulnerability and is available for download here: • Contact Schneider Electric’s Customer Care Center to download this firmware. • Reboot needed: Yes
Patch: Version 11.06.37 of Saitel DP Remote Terminal Unit & Controller includes a fix for this vulnerabil
Version 11.06.37 of Saitel DP Remote Terminal Unit & Controller includes a fix for this vulnerability and is available for download here: • Contact Schneider Electric’s Customer Care Center to download this firmware. • Reboot needed: Yes
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • Ensure strict credential controls, even for low privilege users. • Ensure isolation and credentials are in place, as per the product’s security recommendations.
Patch: Version 11.06.32 of EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller includes
Version 11.06.32 of EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller includes a fix for this vulnerability and is available for download here: • Contact Schneider Electric’s Customer Care Center to download this firmware. • Reboot needed: Yes
Mitigation: For customers who do not require SNMP Contact Schneider Electric's [Customer Care Center](https:/
For customers who do not require SNMP Contact Schneider Electric's [Customer Care Center](https://www.se.com/ww/en/work/support/contacts.jsp) to upgrade the Firmware to a version without SNMP functionality. If customers choose not to apply the upgrade provided above, they should immediately apply the following mitigations to reduce the risk of exploit: * Use relays only in a protected network environment, * Use firewalls to protect and separate the control system network from other networks, * Use VPN (Virtual Private Networks) tunnels if remote access is required. For customers who require SNMP Please immediately apply the following mitigations to reduce the risk of exploit: * Use relays only in a protected network environment, * Use firewalls to protect and separate the control system network from other networks, * Use VPN (Virtual Private Networks) tunnels if remote access is required.
Patch: v9.1.2 of EcoStruxure™ IT Data Center Expert includes a fix for this vulnerability and is available
v9.1.2 of EcoStruxure™ IT Data Center Expert includes a fix for this vulnerability and is available for download here: https://www.se.com/en/product-range/61851-ecostruxure-it-data- center-expert/#software-and-firmware
Patch: Modicon Controller M251 Firmware version 5.4.13.12 delivered with EcoStruxure™ Machine Expert v2.5
Modicon Controller M251 Firmware version 5.4.13.12 delivered with EcoStruxure™ Machine Expert v2.5.0.1 includes a fix for this vulnerability and can be installed through Schneider Electric Software Installer available here: https://www.se.com/ww/en/download/document/ESEMACS10_INSTALLER/ On the engineering workstation install v2.5.0.1 of EcoStruxure™ Machine Expert. For help refer to Schneider Electric Software Installer User Guide available here: https://www.se.com/ww/en/download/document/EIO0000005500/ Update Modicon Controller M251 to the latest Firmware and perform reboot. For instructions refer to Modicon M251 Logic Controller, Programming Guide: https://www.se.com/ww/en/download/document/EIO0000003089/
Patch: Modicon Controller M262 Firmware version 5.4.10.12 delivered with EcoStruxure™ Machine Expert v2.5
Modicon Controller M262 Firmware version 5.4.10.12 delivered with EcoStruxure™ Machine Expert v2.5 includes a fix for this vulnerability and can be installed through Schneider Electric Software Installer available here: https://www.se.com/ww/en/download/document/ESEMACS10_INSTALLER/ On the engineering workstation install v2.5.0.1 of EcoStruxure™ Machine Expert. For help refer to Schneider Electric Software Installer User Guide available here: https://www.se.com/ww/en/download/document/EIO0000005500/ Update Modicon Controller M262 to the latest Firmware and perform reboot. For instructions refer to Modicon M262 Logic/Motion Controller, Programming Guide: https://www.se.com/ww/en/download/document/EIO0000003651/
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from public internet or untrusted networks. • Filter ports and IP through the embedded firewall. • Use encrypted communication links. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide product specific hardening guidelines
Patch: Modicon Controller M241 Firmware version 5.4.13.12 delivered with EcoStruxure™ Machine Expert v2.5
Modicon Controller M241 Firmware version 5.4.13.12 delivered with EcoStruxure™ Machine Expert v2.5.0.1 includes a fix for this vulnerability and can be installed through Schneider Electric Software Installer available here: https://www.se.com/ww/en/download/document/ESEMACS10_INSTALLER/ On the engineering workstation install v2.5.0.1 of EcoStruxure™ Machine Expert. For help refer to Schneider Electric Software Installer User Guide available here: https://www.se.com/ww/en/download/document/EIO0000005500/ Update Modicon Controller M241 to the latest Firmware and perform reboot. For instructions refer to Modicon M241 Logic Controller, Programming Guide: https://www.se.com/ww/en/download/document/EIO0000003059/
Patch: Version 002.006.000 of EcoStruxure Panel Server includes a fix for this vulnerability and is availa
Version 002.006.000 of EcoStruxure Panel Server includes a fix for this vulnerability and is available for download here: • https://www.se.com/ww/en/download/document/PAS600_Fir mware_Package/ • Reboot needed: Yes
Patch: Version 002.006.000 of EcoStruxure Panel Server includes a fix for this vulnerability and is availa
Version 002.006.000 of EcoStruxure Panel Server includes a fix for this vulnerability and is available for download here: • https://www.se.com/ww/en/download/document/PAS800_Fir mware_Package/ • Reboot needed: Yes
Patch: Version 002.006.000 of EcoStruxure Panel Server includes a fix for this vulnerability and is availa
Version 002.006.000 of EcoStruxure Panel Server includes a fix for this vulnerability and is available for download here: • https://www.se.com/ww/en/download/document/PAS800V2_F irmware_Package/ • Reboot needed: Yes
Patch: Version 002.006.000 of EcoStruxure Panel Server includes a fix for this vulnerability and is availa
Version 002.006.000 of EcoStruxure Panel Server includes a fix for this vulnerability and is available for download here: • https://www.se.com/ww/en/download/document/PAS400_Fir mware_Package/ • Reboot needed: Yes
Patch: Version 002.006.000 of EcoStruxure Panel Server includes a fix for this vulnerability and is availa
Version 002.006.000 of EcoStruxure Panel Server includes a fix for this vulnerability and is available for download here: • https://www.se.com/ww/en/download/document/PAS600V2_ Firmware_Package/ • Reboot needed: Yes
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from public internet or untrusted networks. • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Deactivate the Webserver after use when not needed. • Use encrypted communication links. • Setup network segmentation and implement a firewall to block all unauthorized access to ports 80/HTTP and 443/HTTPS. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide product specific hardening guidelines.
Patch: Modicon Controller M251 Firmware version 5.4.13.12 delivered with EcoStruxure™ Machine Expert v2.5
Modicon Controller M251 Firmware version 5.4.13.12 delivered with EcoStruxure™ Machine Expert v2.5.0.1 includes a fix for this vulnerability and can be installed through Schneider Electric Software Installer available here: https://www.se.com/ww/en/download/document/ESEMACS10_INSTALLER/ On the engineering workstation install v2.5.0.1 of EcoStruxure™ Machine Expert. For help refer to Schneider Electric Software Installer User Guide available here: https://www.se.com/ww/en/download/document/EIO0000005500/ Update Modicon Controller M251 to the latest Firmware and perform reboot. For instructions refer to Modicon M251 Logic Controller, Programming Guide: https://www.se.com/us/en/download/document/EIO0000003089/
Mitigation: • Use controllers and devices only in a protected environment to minimize network exposure and ens
• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from public internet or untrusted networks. • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Deactivate the Webserver after use when not needed. • Use encrypted communication links. • Setup network segmentation and implement a firewall to block all unauthorized access to ports 80/HTTP and 443/HTTPS. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide product specific hardening guidelines.
Patch: Modicon Controller M241 Firmware version 5.4.13.12 delivered with EcoStruxure™ Machine Expert v2.5
Modicon Controller M241 Firmware version 5.4.13.12 delivered with EcoStruxure™ Machine Expert v2.5.0.1 includes a fix for this vulnerability and can be installed through Schneider Electric Software Installer available here: https://www.se.com/ww/en/download/document/ESEMACS10_INSTALLER/ On the engineering workstation install v2.5.0.1 of EcoStruxure™ Machine Expert. For help refer to Schneider Electric Software Installer User Guide available here: https://www.se.com/ww/en/download/document/EIO0000005500/ Update Modicon Controller M241 to the latest Firmware and perform reboot. For instructions refer to Modicon M241 Logic Controller, Programming Guide: https://www.se.com/ww/en/download/document/EIO0000003059/
Patch: Customers should upgrade to EcoStruxure Power Monitoring Expert (PME) 2023 R2. Once upgraded, Hotfix
Customers should upgrade to EcoStruxure Power Monitoring Expert (PME) 2023 R2. Once upgraded, Hotfix_282807 - for 2023R2 is available for EcoStruxure Power Monitoring Expert (PME) that includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for assistance.
Patch: Customers should upgrade to EcoStruxure Power Monitoring Expert (PME) 2023 R2. Once upgraded, Hotfix
Customers should upgrade to EcoStruxure Power Monitoring Expert (PME) 2023 R2. Once upgraded, Hotfix_282807 - for 2023R2 is available for EcoStruxure Power Monitoring Expert (PME) that includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for assistance.
Patch: Customers should upgrade to EcoStruxure Power Monitoring Expert (PME) 2024 R3. Contact Schneider Ele
Customers should upgrade to EcoStruxure Power Monitoring Expert (PME) 2024 R3. Contact Schneider Electric’s Customer Care Center for assistance.
Patch: Hotfix_279338_Release_2024R2 is available for EcoStruxure Power Monitoring Expert (PME) that include
Hotfix_279338_Release_2024R2 is available for EcoStruxure Power Monitoring Expert (PME) that includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center to download this hotfix. No reboot required.
Patch: Hotfix_282807 - for 2023R2 is available for EcoStruxure Power Monitoring Expert (PME) that includes
Hotfix_282807 - for 2023R2 is available for EcoStruxure Power Monitoring Expert (PME) that includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center to download this hotfix. No reboot required.
Mitigation: Hitachi Energy recommends implementing security practices and firewall configurations to help protec
Hitachi Energy recommends implementing security practices and firewall configurations to help protect process control networks from external attacks. Such practices include ensuring that process control systems are physically protected from unauthorized access, have no direct Internet connections, and are separated from other networks by a firewall system that minimizes exposed ports, and any additional ports should be evaluated on a case-by-case basis. Process control systems should not be used for web browsing, instant messaging, or email. Portable computers and removable storage media should be thoroughly scanned for malware before being connected to a control system. Organizations should enforce proper password policies and procedures.
Patch: Update to V8.2 or later version
Update to V8.2 or later version
Patch: Update to V10.0 or later version
Update to V10.0 or later version
Mitigation: The default RADIUS configuration is not vulnerable. However, if the RADIUS Server Message Authentica
The default RADIUS configuration is not vulnerable. However, if the RADIUS Server Message Authenticator option is disabled, the product becomes vulnerable.We advise keeping this parameter in its default (enabled) state.This parameter can be configured via CLI and SNMP:MCSESM*, MCSESP* CLI: radius server auth modify <index> msgauth MIB: hm2AgentRadiusServerMsgAuth
Mitigation: The default RADIUS configuration is not vulnerable. However, if the RADIUS Server Message Authentica
The default RADIUS configuration is not vulnerable. However, if the RADIUS Server Message Authenticator option is disabled, the product becomes vulnerable.We advise keeping this parameter in its default (enabled) state.This parameter can be configured via CLI and SNMP:MCSESR* CLI: radius server auth modify <index> msgauth MIB: hm2AgentRadiusServerMsgAuth
Mitigation: The default RADIUS configuration is not vulnerable. However, if the RADIUS Server Message Authentica
The default RADIUS configuration is not vulnerable. However, if the RADIUS Server Message Authenticator option is disabled, the product becomes vulnerable.We advise keeping this parameter in its default (enabled) state.This parameter can be configured via CLI and SNMP:TCSESM* CLI: radius server msgauthMIB: hmAgentRadiusServerMsgAuth
Patch: Update to V2.50 or later version
Update to V2.50 or later version
Patch: Update to V16.51 or later version
Update to V16.51 or later version
Patch: Update to V2.70 or later version
Update to V2.70 or later version
Patch: Update to V9.83 or later version
Update to V9.83 or later version
Patch: Update to V6.20 or later version
Update to V6.20 or later version
Patch: Update to V2.83 or later version
Update to V2.83 or later version
Patch: Update to V2.20.0 or later version
Update to V2.20.0 or later version
Patch: Update to V10.0 or later version
Update to V10.0 or later version
Mitigation: Restrict access to the networks where RADIUS messages are exchanged (e.g., send RADIUS traffic via m
Restrict access to the networks where RADIUS messages are exchanged (e.g., send RADIUS traffic via management network or a dedicated VLAN)
Mitigation: Configure the RADIUS server to require the presence of a Message-Authenticator attribute in all Acces
Configure the RADIUS server to require the presence of a Message-Authenticator attribute in all Access-Request packets from RADIUS client devices that support it
Patch: Update to V4.22 or later version
Update to V4.22 or later version
Patch: Update to V9.68 or later version
Update to V9.68 or later version
Patch: Update to V8.90 or later V8.xx version
Update to V8.90 or later V8.xx version
Mitigation: Configure the RADIUS server to require the presence of a Message-Authenticator attribute in all Acces
Configure the RADIUS server to require the presence of a Message-Authenticator attribute in all Access-Request packets from RADIUS client devices that support it
Mitigation: Restrict access to the networks where RADIUS messages are exchanged (e.g., send RADIUS traffic via m
Restrict access to the networks where RADIUS messages are exchanged (e.g., send RADIUS traffic via management network or a dedicated VLAN)
Patch: Update to V5.6 or later version
Update to V5.6 or later version
Patch: Update to V4.6 or later version
Update to V4.6 or later version
Patch: Update to V6.6.0 or later version
Update to V6.6.0 or later version
Patch: Update to V4.3.11 or later version
Update to V4.3.11 or later version
Patch: Update to V8.2 or later version
Update to V8.2 or later version
Patch: Update to V3.2 or later version
Update to V3.2 or later version
Patch: Update to V5.10.0 or later version
Update to V5.10.0 or later version
Patch: Update to V3.2 or later version
Update to V3.2 or later version
Patch: Update to V4.3.11 or later version
Update to V4.3.11 or later version
Patch: Update to V1.0 SP2 Update 4 or later version
Update to V1.0 SP2 Update 4 or later version
Patch: Update to V4.1.9 or later version
Update to V4.1.9 or later version
Patch: Update to V1.3 or later version
Update to V1.3 or later version
Patch: Update to V3.0.0 or later version
Update to V3.0.0 or later version
Patch: Update to V5.10.0 or later version
Update to V5.10.0 or later version
Patch: Update to V2.17.0 or later version
Update to V2.17.0 or later version
Patch: Update to V3.2 or later version
Update to V3.2 or later version
Patch: Update to V6.6.0 or later version
Update to V6.6.0 or later version
Patch: Update to V5.6 or later version
Update to V5.6 or later version
Patch: Update to V3.2 or later version
Update to V3.2 or later version
Patch: Update to V3.0.0 or later version
Update to V3.0.0 or later version
Patch: Update to V4.1.9 or later version
Update to V4.1.9 or later version
Patch: Update to V1.0 SP2 Update 4 or later version
Update to V1.0 SP2 Update 4 or later version
Mitigation: Configure the RADIUS server to require the presence of a Message-Authenticator attribute in all Acces
Configure the RADIUS server to require the presence of a Message-Authenticator attribute in all Access-Request packets from RADIUS client devices that support it
Patch: Update to V4.3.11 or later version
Update to V4.3.11 or later version
Patch: Update to V3.2 or later version
Update to V3.2 or later version
Patch: Update to V4.6 or later version
Update to V4.6 or later version
Patch: Update to V1.3 or later version
Update to V1.3 or later version
Patch: Update to V4.3.11 or later version
Update to V4.3.11 or later version
Patch: Update to V2.17.0 or later version
Update to V2.17.0 or later version
Mitigation: Restrict access to the networks where RADIUS messages are exchanged (e.g., send RADIUS traffic via m
Restrict access to the networks where RADIUS messages are exchanged (e.g., send RADIUS traffic via management network or a dedicated VLAN)
Patch: Update to V5.10.0 or later version
Update to V5.10.0 or later version
Patch: Update to V1.0 SP2 Update 4 or later version
Update to V1.0 SP2 Update 4 or later version
Patch: Update to V5.10.0 or later version
Update to V5.10.0 or later version
Patch: Update to V3.2 or later version
Update to V3.2 or later version
Patch: Update to FOX61x R18, then enable the RADIUS Message-Authenticator option in both the FOX61x and RAD
Update to FOX61x R18, then enable the RADIUS Message-Authenticator option in both the FOX61x and RADIUS Server configurations. Refer to the Technical User Documentation at https://publisher.hitachienergy.com/preview?DocumentID=1KHW029042&LanguageCode=en&DocumentPartId=R18&Action=launch.
Mitigation: Enable the RADIUS Message-Authenticator option in both the FOX61x and RADIUS Server configurations.
Enable the RADIUS Message-Authenticator option in both the FOX61x and RADIUS Server configurations. Refer to the Technical User Documentation at https://publisher.hitachienergy.com/preview?DocumentID=1KHW029042&LanguageCode=en&DocumentPartId=R18&Action=launch.
Mitigation: If the upgrade is not possible, apply general mitigation factors with segmentation of FOX management
If the upgrade is not possible, apply general mitigation factors with segmentation of FOX management traffic to minimize the risk.
Mitigation: For more information, see the associated Hitachi Energy cybersecurity advisory 8DBD000225 Radius MD5
For more information, see the associated Hitachi Energy cybersecurity advisory 8DBD000225 Radius MD5 Vulnerability in Hitachi Energy FOX61x product at https://publisher.hitachienergy.com/preview?DocumentID=8DBD000225&LanguageCode=en or https://publisher.hitachienergy.com/preview?DocumentID=8DBD000225-CSAF&LanguageCode=en&DocumentPartId=&Action=Launch .
Patch: Update to XMC20 R18 and then enable the RADIUS Message-Authenticator option in both the XMC20 and RA
Update to XMC20 R18 and then enable the RADIUS Message-Authenticator option in both the XMC20 and RADIUS server configurations. Refer to the Technical User Documentation at https://publisher.hitachienergy.com/preview?DocumentID=1KHW029001&LanguageCode=en&DocumentPartId=R18&Action=launch.
Mitigation: Hitachi Energy recommends implementing security practices and firewall configurations to help protec
Hitachi Energy recommends implementing security practices and firewall configurations to help protect process control networks from external attacks. Such practices include ensuring that process control systems are physically protected from unauthorized access, have no direct Internet connections, and are separated from other networks by a firewall system that minimizes exposed ports, and any additional ports should be evaluated on a case-by-case basis. Process control systems should not be used for web browsing, instant messaging, or email. Portable computers and removable storage media should be thoroughly scanned for malware before being connected to a control system. Organizations should enforce proper password policies and procedures.
Mitigation: Enable the RADIUS Message-Authenticator option in both the XMC20 and RADIUS server configurations. R
Enable the RADIUS Message-Authenticator option in both the XMC20 and RADIUS server configurations. Refer to the Technical User Documentation at https://publisher.hitachienergy.com/preview?DocumentID=1KHW029001&LanguageCode=en&DocumentPartId=R18&Action=launch.
Mitigation: If the upgrade is not possible, apply general mitigation factors with segmentation of FOX management
If the upgrade is not possible, apply general mitigation factors with segmentation of FOX management traffic to minimize the risk.
Mitigation: For more information, see the associated Hitachi Energy cybersecurity advisory 8DBD000233 RADIUS MD5
For more information, see the associated Hitachi Energy cybersecurity advisory 8DBD000233 RADIUS MD5 Vulnerability in Hitachi Energy XMC20 product available in PDF format here https://publisher.hitachienergy.com/preview?DocumentID=8DBD000233&LanguageCode=en&DocumentPartId=&Action=launch or JSON format here https://publisher.hitachienergy.com/preview?DocumentID=8DBD000233-CSAF&LanguageCode=en&DocumentPartId=&Action=Launch.
Mitigation: For more information, see the associated Hitachi Energy PSIRT security advisory 8DBD000230 RADIUS vu
For more information, see the associated Hitachi Energy PSIRT security advisory 8DBD000230 RADIUS vulnerability in Hitachi Energy AFS, AFR and AFF series products.
Mitigation: All affected products: Set the RADIUS configuration to default which enables the RADIUS server messa
All affected products: Set the RADIUS configuration to default which enables the RADIUS server message authenticator option.
Patch: AFR 677, AFS 650, AFS 655, AFS 670, AFS 675, AFS 677: Command to enable Message Authenticator option
AFR 677, AFS 650, AFS 655, AFS 670, AFS 675, AFS 677: Command to enable Message Authenticator option: For AFS65x, AFS67x, AFR67x CLI: radius server msgauth MIB: hmAgentRadiusServerMsgAuth
Patch: AFF 660, AFF 665, AFS 660-B/C/S, AFS 665-B/S, AFS 670: Command to enable Message Authenticator optio
AFF 660, AFF 665, AFS 660-B/C/S, AFS 665-B/S, AFS 670: Command to enable Message Authenticator option: For AFS66x, AFS670 v2.0, AFF66x CLI: radius server auth modify msgauth MIB: hm2AgentRadiusServerMsgAuth
Mitigation: Hitachi Energy has identified the following recommended immediate actions:
Hitachi Energy has identified the following recommended immediate actions:
Patch: Update to V6.20 or later version
Update to V6.20 or later version
Patch: Update to V9.68 or later version
Update to V9.68 or later version
Patch: Update to V2.70 or later version
Update to V2.70 or later version
Patch: Update to V8.90 or later V8.xx version
Update to V8.90 or later V8.xx version
Patch: Update to V2.50 or later version
Update to V2.50 or later version
Patch: Update to V9.68 or later version
Update to V9.68 or later version
Mitigation: Restrict access to the networks where RADIUS messages are exchanged (e.g., send RADIUS traffic via m
Restrict access to the networks where RADIUS messages are exchanged (e.g., send RADIUS traffic via management network or a dedicated VLAN)
Patch: Update to V4.22 or later version
Update to V4.22 or later version
Patch: Update to V16.51 or later version
Update to V16.51 or later version
Mitigation: Configure the RADIUS server to require the presence of a Message-Authenticator attribute in all Acces
Configure the RADIUS server to require the presence of a Message-Authenticator attribute in all Access-Request packets from RADIUS client devices that support it
Patch: Update to V9.83 or later version
Update to V9.83 or later version
Patch: Update to V8.90 or later V8.xx version
Update to V8.90 or later V8.xx version
Patch: Update to V9.83 or later version
Update to V9.83 or later version
Patch: Update to V2.20.0 or later version
Update to V2.20.0 or later version
Patch: Update to V2.83 or later version
Update to V2.83 or later version
Patch: Update Fortigate NGFW to V7.4.7. Contact customer support to receive patch and update information
Update Fortigate NGFW to V7.4.7. Contact customer support to receive patch and update information
Patch: Update Fortigate NGFW to V7.4.7. Contact customer support to receive patch and update information
Update Fortigate NGFW to V7.4.7. Contact customer support to receive patch and update information
Patch: Upgrade Palo Alto Networks Virtual NGFW V11.1.4-h1. Contact customer support to receive patch and up
Upgrade Palo Alto Networks Virtual NGFW V11.1.4-h1. Contact customer support to receive patch and update information
Mitigation: Configure the RADIUS server to require the presence of a Message-Authenticator attribute in all Acces
Configure the RADIUS server to require the presence of a Message-Authenticator attribute in all Access-Request packets from RADIUS client devices that support it
Mitigation: Customers can resolve this issue by configuring the in-use SSH profile to contain at least one ciphe
Customers can resolve this issue by configuring the in-use SSH profile to contain at least one cipher and at least one MAC algorithm, which removes support for CHACHA20-POLY1305 and all Encrypt-then-MAC algorithms available (ciphers with -etm in the name) in PAN-OS software. See Palo Alto Networks' upstream documentation https://security.paloaltonetworks.com/CVE-2023-48795 for additional guidance.
Mitigation: Restrict access to the networks where RADIUS messages are exchanged (e.g., send RADIUS traffic via m
Restrict access to the networks where RADIUS messages are exchanged (e.g., send RADIUS traffic via management network or a dedicated VLAN)
Mitigation: If users choose not to apply the remediation provided above, they should immediately apply the follo
If users choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: The vulnerability is attacked with manipulated data from external sources to the DCS computers. Examples for these are: * Configuration taglists * DirectAccess Scripts * Any partial or full Galaxy backups * Library files * Code snippets * ASCII files of any sort * Generally, any file getting from outside the DCS computer on a DCS computer. Only use data from trusted sources, check for correct file name endings on data files, check for reasonable file sizes for any files coming to the system, and check structured data for any fields or columns which might be unexpected. Check for unusual manipulations of data within data files and reject files containing unexpected data or structures. Use secure communication channels and encrypt communications when communicating outside the site network. Avoid and ban removable media (e.g. USB sticks or drives) Minimize count of users with engineering or administrative rights to DCS computers and ensure all interactions on DCS computers are executed with minimal user access rights. Consequently, isolating Foxboro DCS computers will help minimizing the risk of this vulnerability being exploited.
Patch: Version CS 8.1 of EcoStruxure Foxboro DCS includes a fix for this vulnerability and is available thr
Version CS 8.1 of EcoStruxure Foxboro DCS includes a fix for this vulnerability and is available through [https://buyautomation.se.com/](https://buyautomation.se.com/) CS 8.1 requires FX-V3 licenses, standard upgrade procedures apply. A reboot is required for workstations and servers. Depending on the existing system version, online upgrade without production interruption might be possible. Schneider Electric recommends you work with your local field service representative or technical service consultant for further information.
Patch: CPU866e Firmware version 11.06.37 includes a fix for this vulnerability and is available for downl
CPU866e Firmware version 11.06.37 includes a fix for this vulnerability and is available for download. Contact Schneider Electric’s Customer Care Center to download this firmware. A reboot is needed to complete the firmware upgrade
Patch: Version 11.08.03 of PowerLogic™ T500 includes a fix for this vulnerability Contact Schneider Electr
Version 11.08.03 of PowerLogic™ T500 includes a fix for this vulnerability Contact Schneider Electric’s Customer Care Center to download this firmware. A reboot is needed to complete the firmware upgrade
Patch: Version P439.678.700 Easergy MiCOM P439 includes a fix for this vulnerability. Contact Schneider Ele
Version P439.678.700 Easergy MiCOM P439 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device.
Patch: Version P139.678.700 Easergy MiCOM P139 includes a fix for this vulnerability. Contact Schneider Ele
Version P139.678.700 Easergy MiCOM P139 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device.
Patch: Version V02.503.101 of PowerLogic™ P5 includes a fix for this vulnerability Contact Schneider Elec
Version V02.503.101 of PowerLogic™ P5 includes a fix for this vulnerability Contact Schneider Electric’s Customer Care Center to download this firmware.
Patch: Version 6.4.610.500.101 of EPAS Gateway includes a fix for this vulnerability. Contact Schneider E
Version 6.4.610.500.101 of EPAS Gateway includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center to download this software
Patch: Version P632.678.700 Easergy MiCOM P632 includes a fix for this vulnerability. Contact Schneider Ele
Version P632.678.700 Easergy MiCOM P632 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device.
Patch: EPO 2024 CU 3 of EcoStruxure™ Power Operation includes a fix for this vulnerability and is availab
EPO 2024 CU 3 of EcoStruxure™ Power Operation includes a fix for this vulnerability and is available for download here: • https://community.se.com/t5/EcoStruxure-PowerOperation/Power-Operation-2024-CU3-is-HERE/td-p/534769 Reboot needed: yes
Patch: HUe Firmware version 11.06.31 includes a fix for this vulnerability and is available for download
HUe Firmware version 11.06.31 includes a fix for this vulnerability and is available for download here: . Contact Schneider Electric’s Customer Care Center to download this software. A reboot is needed to complete the firmware upgrade
Patch: EPO 2022 CU 7 of EcoStruxure™ Power Operation includes a fix for this vulnerability and is availab
EPO 2022 CU 7 of EcoStruxure™ Power Operation includes a fix for this vulnerability and is available for download here: • https://community.se.com/t5/EcoStruxure-PowerOperation/Power-Operation-2022-CU7-is-Now-Available/tdp/524787 Reboot needed: yes
Patch: Version P138.677.701 Easergy MiCOM P138 includes a fix for this vulnerability. Contact Schneider Ele
Version P138.677.701 Easergy MiCOM P138 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device.
Patch: Version 1.1.18 of Easergy C5 includes a fix for this vulnerability. Contact Schneider Electric’s C
Version 1.1.18 of Easergy C5 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device. Reboot is required
Patch: Version 2.9.5 of PowerLogic™ T300 includes a fix for this vulnerability Contact Schneider Electric’
Version 2.9.5 of PowerLogic™ T300 includes a fix for this vulnerability Contact Schneider Electric’s Customer Care Center to download this firmware. A reboot is needed to complete the firmware upgrade
Patch: Version P634.680.701 Easergy MiCOM P634 includes a fix for this vulnerability. Contact Schneider Ele
Version P634.680.701 Easergy MiCOM P634 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device.
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit:• Ensure P30 operates within a physically or logically segmented internal network. Access to this network should be tightly controlled using standard security mechanisms such as firewalls, intrusion detection systems (IDS), and other relevant protective measures. • Reduce the “Minimum inactivity period” using the CAE tool to shorten session timeout durations and minimize the risk of unauthorized access due to inactive sessions.
Mitigation: Schneider Electric is establishing a remediation plan for a future version of the Easergy MiCOM P4
Schneider Electric is establishing a remediation plan for a future version of the Easergy MiCOM P40 Series model numbers with Protocol Option bit as G, H or L. P_ 4_ _ _ _ _ G_ _ _ _ _ M P_ 4_ _ _ _ _ H_ _ _ _ _ M P_ 4_ _ _ _ _ L _ _ _ _ _ M P_ 4_ _ _ _ _ G_ _ _ _ _ L P_ 4_ _ _ _ _ H_ _ _ _ _ L P_ 4_ _ _ _ _ L _ _ _ _ _ L A future version will include a fix for this vulnerability. We will update this document when the remediation is available. Until then, customers should immediately apply the following mitigations to reduce the risk of exploit: • Ensure P40 operates within a physically or logically segmented internal network. Access to this network should be tightly controlled using standard security mechanisms such as firewalls, intrusion detection systems (IDS), and other relevant protective measures. • Reduce the “Minimum inactivity period” using the CAE tool to shorten session timeout durations and minimize the risk of unauthorized access due to inactive sessions
Patch: Version 3.0.4 of EPAS-UI includes a fix for this vulnerability. Contact Schneider Electric’s Custo
Version 3.0.4 of EPAS-UI includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center to download this software.
Patch: Version C434.679.700 Easergy MiCOM C434 includes a fix for this vulnerability. Contact Schneider Ele
Version C434.679.700 Easergy MiCOM C434 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device.
Patch: Version V02.003.001 of PowerLogic™ P7 includes a fix for this vulnerability Contact Schneider Elect
Version V02.003.001 of PowerLogic™ P7 includes a fix for this vulnerability Contact Schneider Electric’s Customer Care Center to download this firmware.
Patch: Version 64.2025.0.14 of iPMFLS includes a fix for this vulnerability. Contact Schneider Electric’s
Version 64.2025.0.14 of iPMFLS includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device.
Patch: Version P633.678.700 Easergy MiCOM P633 includes a fix for this vulnerability. Contact Schneider Ele
Version P633.678.700 Easergy MiCOM P633 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device.
Patch: Version P539.678.700 Easergy MiCOM P539 includes a fix for this vulnerability. Contact Schneider Ele
Version P539.678.700 Easergy MiCOM P539 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device.
Mitigation: Schneider Electric is establishing a remediation plan for all future versions of the following mode
Schneider Electric is establishing a remediation plan for all future versions of the following models of the Easergy MiCOM P30: P437 P532 P631 P634 P436 P438 P638 Future versions will include a fix for this vulnerability. We will update this document when the remediation is available. Until then, customers should immediately apply the following mitigations to reduce the risk of exploit: • Ensure P30 operates within a physically or logically segmented internal network. Access to this network should be tightly controlled using standard security mechanisms such as firewalls, intrusion detection systems (IDS), and other relevant protective measures. • Reduce the “Minimum inactivity period” using the CAE tool to shorten session timeout durations and minimize the risk of unauthorized access due to inactive sessions
Patch: Version P633.680.701 Easergy MiCOM P633 includes a fix for this vulnerability. Contact Schneider Ele
Version P633.680.701 Easergy MiCOM P633 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device.
Patch: Version D7.34 of MiCOM C264 includes a fix for this vulnerability. Contact Schneider Electric’s Cu
Version D7.34 of MiCOM C264 includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for information on how to contact your local Application Center to update the device. Reboot is required
Patch: v9.1 of EcoStruxure IT Data Center Expert includes a fix for this vulnerability and is available for
v9.1 of EcoStruxure IT Data Center Expert includes a fix for this vulnerability and is available for download here: https://www.se.com/en/product-range/61851-ecostruxure-it-data-center-expert/#software-and-firmware
Mitigation: For more information see the associated Schneider Electric CPCERT security advisory SEVD-2026-069-0
For more information see the associated Schneider Electric CPCERT security advisory SEVD-2026-069-05 Use of Hard-coded Credentials vulnerability in EcoStruxure IT Data Center Expert PDF Version https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-069-05&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-069-05.pdf
Mitigation: If users choose not to apply the remediation provided above, they should immediately apply the follo
If users choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • Harden the DCE instance according to the cybersecurity best practices documented in the EcoStruxure IT Data Center Expert Security Handbook • Ensure the SOCKS Proxy is disabled as in the default configuration.
Mitigation: For more information see the associated Schneider Electric CPCERT security advisory SEVD-2026-069-0
For more information see the associated Schneider Electric CPCERT security advisory SEVD-2026-069-05 Use of Hard-coded Credentials vulnerability in EcoStruxure IT Data Center Expert CSAF Version https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-069-05&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-069-05.json
Patch: Version v25.0.1 of EcoStruxure™ Automation Expert includes a fix for this vulnerability and is ava
Version v25.0.1 of EcoStruxure™ Automation Expert includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/23643079-ecostruxure-automation-expert/
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: Solution and archive files must be stored within the user’s home directory or in any location protected by appropriate Windows file‑system access controls to prevent unauthorized access in multi‑user environments. Users who choose to store files outside their home directory are responsible for applying restrictive Windows permissions to secure those locations. Before opening any solution or archive file, users are required to verify its authenticity and ensure that it has not been modified by unauthorized users. For detailed mitigation steps, refer to the User Manual - https://product-help.se.com/EcoStruxure%20Automation%20Expert/25.0/Offer%20Guides/en-US/EAE_UM?t=EAE_UM%2FSolutionIntegrity-FE037ED3.html%3Frhhlterm%3Dundefined%253Frhsearch%253Dundefined&theme=Help
Mitigation: Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite
Starting from Festo Automation Suite version 2.8.0.138, Codesys is no longer bundled with the suite and must be downloaded and installed separately by the customer. To mitigate this vulnerability customers are advised to: Download the latest, patched version of Codesys directly from the official Codesys website. Follow the installation and update instructions provided by Codesys to ensure all security fixes are applied. Regularly monitor Codesys security advisories and apply updates promptly. Maintain the Festo Automation Suite connector up to date by installing FAS updates as released by Festo.
Mitigation: Additionally, we encourage the customer to implement our suggested security best practices to minimi
Additionally, we encourage the customer to implement our suggested security best practices to minimize risk of the vulnerability.
Mitigation: Rockwell Automation recommends users with the affected software apply the following risk mitigations
Rockwell Automation recommends users with the affected software apply the following risk mitigations, if possible:
Mitigation: Additional information can be found in the CODESYS Advisory.
Additional information can be found in the CODESYS Advisory.
Mitigation: Customers can use Stakeholder-Specific Vulnerability Categorization to generate more environment-spe
Customers can use Stakeholder-Specific Vulnerability Categorization to generate more environment-specific prioritization.
Mitigation: Upgrade to CODESYS version 3.5.19.2 which has been released to mitigate these issues.
Upgrade to CODESYS version 3.5.19.2 which has been released to mitigate these issues.
Mitigation: • Ensure usage of user management and password features. User rights are enabled by default and forc
• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.
Patch: PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix f
PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.
Patch: Vijeo Designer Basic v2.0 HotFix 2 includes a fix for this vulnerability. Please contact your Schne
Vijeo Designer Basic v2.0 HotFix 2 includes a fix for this vulnerability. Please contact your Schneider Electric Customer Care Center to obtain the installer. To complete the update, connect to Harmony HMI and download the firmware using Vijeo Designer Basic.
Patch: Version 3.1.5.82 includes a fix for this vulnerability and can be download here: https://www.se.c
Version 3.1.5.82 includes a fix for this vulnerability and can be download here: https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 As an alternative, contact your Schneider Electric Customer Care Center to obtain the firmware. To complete the update, connect to M310 and download the firmware using EcoStruxureTM Motion Expert.
Patch: Version 6.3 HF3 of Vijeo Designer includes a fix for this vulnerability and can be updated through
Version 6.3 HF3 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. As an alternative, please contact your Schneider Electric Customer Care Center to obtain the Hot Fix. For additional detail please refer to the supplied help file in Hot Fix. On the engineering workstation, update to v6.3 HF3 of Vijeo Designer.
Mitigation: Customers should immediately apply the following mitigations to reduce the risk of exploitation: • E
Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.
Patch: Version 6.3 SP2 of Vijeo Designer includes a fix for this vulnerability and can be updated through
Version 6.3 SP2 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware As an alternative, please contact your Schneider Electric Customer Care Center to obtain the Fix. For additional details, please refer to the supplied help file in Hot Fix. On the engineering workstation, update to v6.3 SP2 of Vijeo Designer.
Patch: Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the
Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.
Patch: Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerab
Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.
Patch: SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through t
SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application.
Patch: Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerab
Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.
Patch: Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the
Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.
Mitigation: • Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type
• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp
Patch: Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerab
Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.
Patch: Version 8.2 of EcoStruxure™ IT Data Center Expert includes fixes for these vulnerabilities and is a
Version 8.2 of EcoStruxure™ IT Data Center Expert includes fixes for these vulnerabilities and is available upon request from Schneider Electric’s Customer Care Center.
Mitigation: Ensure that the principals of least privilege are being followed so that only those with need have
Ensure that the principals of least privilege are being followed so that only those with need have account access and that the level of their respective account authorization aligns with their role, including Privileged Accounts as described in the Data Center Expert Security Handbook. • Verify SHA1 checksums of upgrade bundles prior to executing upgrades as described in the Upgrades section of the Data Center Expert Security Handbook.. • Delete any existing “logcapture” archives present on the system and do not create any new “logcapture” archives. Existing archives can be deleted from the https://server_ip/capturelogs web page after authenticating.
Mitigation: Ensure that the principals of least privilege are being followed so that only those with need have
Ensure that the principals of least privilege are being followed so that only those with need have account access and that the level of their respective account authorization aligns with their role, including Privileged Accounts as described in the Data Center Expert Security Handbook. • Verify SHA1 checksums of upgrade bundles prior to executing upgrades as described in the Upgrades section of the Data Center Expert Security Handbook.. • Delete any existing “logcapture” archives present on the system and do not create any new “logcapture” archives. Existing archives can be deleted from the https://server_ip/capturelogs web page after authenticating.
Patch: Version 8.2 of EcoStruxure™ IT Data Center Expert includes fixes for these vulnerabilities and is a
Version 8.2 of EcoStruxure™ IT Data Center Expert includes fixes for these vulnerabilities and is available upon request from Schneider Electric’s Customer Care Center.
Mitigation: For versions prior to 3.2, fixes are now available in the form of a hotfix patch. Please refer to SE
For versions prior to 3.2, fixes are now available in the form of a hotfix patch. Please refer to SEVD-2020-315-04 for specific information about how to apply the patch.
Mitigation: Schneider Electric recommends users upgrade to Version 3.2 of EBO as it is not impacted by any of th
Schneider Electric recommends users upgrade to Version 3.2 of EBO as it is not impacted by any of these vulnerabilities. For assistance in upgrading, contact Schneider Electric Customer Care Center or your Schneider Electric representative.
Mitigation: Customers should immediately apply the following mitigations to reduce the risk of exploit: * Fir
Customers should immediately apply the following mitigations to reduce the risk of exploit: * Firewall configuration & logs: o Setup network segmentation and implement a firewall to block all unauthorized access to HTTP ports o Check the access log periodically * Password: o Choose a strong password o Do not share your password o Change your password periodically Customers should also consider upgrading to the replacement product offering EVLink Pro AC https://www.se.com/ww/en/product-range/23107242-evlink-pro-ac/#products to resolve these issues.
Mitigation: For more information, see Schneider Electric security notification SEVD-2020-315-03
For more information, see Schneider Electric security notification SEVD-2020-315-03
Mitigation: Users should also consider upgrading to the latest product offering IGSS v15 to resolve this issue.
Users should also consider upgrading to the latest product offering IGSS v15 to resolve this issue.
Mitigation: Avoid importing CGF files from untrusted sources
Avoid importing CGF files from untrusted sources
Mitigation: Schneider Electric has provided a new version of the IGSS Definition module to address these vulnera
Schneider Electric has provided a new version of the IGSS Definition module to address these vulnerabilities. Users are recommended to update to IGSS Version 14.0.0.20248
Patch: Hotfix_279338_Release_2024R2 is available for EcoStruxure Power Monitoring Expert (PME) 2024 R2 that
Hotfix_279338_Release_2024R2 is available for EcoStruxure Power Monitoring Expert (PME) 2024 R2 that includes a fix for the vulnerabilities CVE-2025-54924, CVE-2025-54925, CVE-2025-54926, CVE-2025-54927 and CVE-2025-54923. Contact Schneider Electric’s Customer Care Center for assistance applying this hotfix. In addition to applying the hotfixes noted above, you are encouraged to review the mitigations listed below.
Patch: Customers should upgrade to the latest product offering EcoStruxure Power Monitoring Expert (PME) 20
Customers should upgrade to the latest product offering EcoStruxure Power Monitoring Expert (PME) 2024 R2 and apply Hotfix_279338_Release_2024R2 that includes a fix for the vulnerabilities CVE-2025-54924, CVE-2025-54925, CVE-2025-54926, CVE-2025-54927 and CVE-2025-54923. Contact Schneider Electric’s Customer Care Center for assistance with obtaining EcoStruxure Power Monitoring Expert (PME) 2024 R2 and help applying this hotfix. In addition to applying the hotfix noted above, you are encouraged to review the mitigations listed below.
Patch: Hotfix_279338_Release_2024R2 is available for EcoStruxure Power Monitoring Expert (PME) 2024 R2 that
Hotfix_279338_Release_2024R2 is available for EcoStruxure Power Monitoring Expert (PME) 2024 R2 that includes a fix for the vulnerabilities CVE-2025-54924, CVE-2025-54925, CVE-2025-54926, CVE-2025-54927 and CVE-2025-54923. Contact Schneider Electric’s Customer Care Center to determine if you are running EcoStruxure Power Monitoring Expert (PME) 2024 OR EcoStruxure Power Monitoring Expert (PME) 2024 R2 as part of your solution. Customers running either of these versions of PME can work with Schneider Electric’s Customer Care Center for assistance to upgrade PME and/or apply the hotfix. Note: Customers who are running EcoStruxure Power Monitoring Expert (PME) 2024 should upgrade to EcoStruxure Power Monitoring Expert (PME) 2024 R2 then apply the hotfix.
Patch: Customers should upgrade to EcoStruxure Power Monitoring Expert (PME) 2023 R2 and apply Hotfix_19976
Customers should upgrade to EcoStruxure Power Monitoring Expert (PME) 2023 R2 and apply Hotfix_199767_release and Hotfix_273686_release.12.0 that includes a fix for the vulnerabilities CVE-2025-54924, CVE-2025-54925, and CVE-2025-54927. Contact Schneider Electric’s Customer Care Center for assistance applying these hotfixes. In addition to applying the hotfixes noted above, you are encouraged to review the mitigations listed below.
Mitigation: Johnson Controls
Johnson Controls
Mitigation: Pepperl+Fuchs
Pepperl+Fuchs
Mitigation: Eaton
Eaton
Mitigation: ABB
ABB
Mitigation: Green Hills Software
Green Hills Software
Mitigation: Schneider Electric
Schneider Electric
Mitigation: DIGI International
DIGI International
Mitigation: Caterpillar
Caterpillar
Mitigation: Treck recommends users apply the latest version of the affected products:
Treck recommends users apply the latest version of the affected products:
Mitigation: Smiths Medical
Smiths Medical
Mitigation: Treck TCP/IP: Update to 6.0.1.67 or later versions
Treck TCP/IP: Update to 6.0.1.67 or later versions
Mitigation: Baxter
Baxter
Mitigation: BD
BD
Mitigation: Rockwell
Rockwell
Mitigation: Miele
Miele
Mitigation: IDEC Corporation
IDEC Corporation
Mitigation: B.Braun
B.Braun
Mitigation: CareStream
CareStream
Mitigation: Opto 22
Opto 22
Mitigation: To obtain patches, email Treck at [email protected]
To obtain patches, email Treck at [email protected]
Mitigation: For more detailed information on the vulnerabilities and the mitigating controls, please see the Tre
For more detailed information on the vulnerabilities and the mitigating controls, please see the Treck advisory.
Mitigation: Additional vendors affected by the reported vulnerabilities have also released security advisories r
Additional vendors affected by the reported vulnerabilities have also released security advisories related to their affected products. Those advisories are as follows:
Mitigation: Schneider Electric recommends users use appropriate patching methodologies when applying these patch
Schneider Electric recommends users use appropriate patching methodologies when applying these patches to their systems. They strongly recommend the use of back-ups and evaluating the impact of these patches in a test and development environment or on an offline infrastructure. Contact Schneider Electric's Customer Care Center for assistance removing a patch.
Mitigation: Version 15.0.0.22021 of IGSS Data Server includes corrections for these vulnerabilities and is avail
Version 15.0.0.22021 of IGSS Data Server includes corrections for these vulnerabilities and is available for download through IGSS Master > Update IGSS Software.
Mitigation: Place all controllers in locked cabinets and never leave them in the “Program” mode.
Place all controllers in locked cabinets and never leave them in the “Program” mode.
Mitigation: Never allow mobile devices that have connected to any other network besides the intended network to
Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.
Mitigation: Minimize network exposure for all control system devices and systems and ensure they are not accessi
Minimize network exposure for all control system devices and systems and ensure they are not accessible from the Internet.
Mitigation: Never connect programming software to any network other than the network intended for that device.
Never connect programming software to any network other than the network intended for that device.
Mitigation: Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc., be
Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc., before use in the terminals or any node connected to these networks.
Mitigation: Follow the general security recommendations below and verify devices are isolated on a private netwo
Follow the general security recommendations below and verify devices are isolated on a private network and that firewalls are configured with strict boundaries for devices that require remote access.
Mitigation: For more information see Schneider Electric's security notification: SEVD-2022-039-01
For more information see Schneider Electric's security notification: SEVD-2022-039-01
Mitigation: Install physical controls so no unauthorized personnel can access your industrial control and safety
Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.
Mitigation: Locate control and safety system networks and remote devices behind firewalls and isolate them from
Locate control and safety system networks and remote devices behind firewalls and isolate them from the network.
Mitigation: If users choose not to apply the remediation provided above, they should immediately apply the follo
If users choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit:
Mitigation: When remote access is required, use secure methods, such as virtual private networks (VPNs). Recogni
When remote access is required, use secure methods, such as virtual private networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.
Mitigation: If users choose not to apply the remediation provided above, they should immediately apply the follo
If users choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: For CVE-2025-13845: - Only open projects from trusted sources - Ensure use of malware scans before opening any externally created Project
Patch: Versions FR V2.8.1.0401, ESP V2.8.5.0301, PT V2.8.7.0101, INT(EN) V2.8.4.0401, and NL V2.8.2.000 of
Versions FR V2.8.1.0401, ESP V2.8.5.0301, PT V2.8.7.0101, INT(EN) V2.8.4.0401, and NL V2.8.2.000 of EcoStruxure Power Build Rapsody includes a fix for the CVE-2025-13845 vulnerability and are available for download here: https://www.se.com/ww/en/product-country-selector/?pageType=product-range&sourceId=2309 Restart the service after installing the new version.
Patch: Versions BEL(NL)V2.8.3.0201 and BEL(FR) V2.8.8.0201 of EcoStruxure Power Build Rapsody include a fix
Versions BEL(NL)V2.8.3.0201 and BEL(FR) V2.8.8.0201 of EcoStruxure Power Build Rapsody include a fix for the CVE-2025-13845 vulnerability, reach out to the Schneider Electric Customer Care Center for assistance.
Mitigation: Minimize network exposure for all control system devices and systems and ensure they are not accessi
Minimize network exposure for all control system devices and systems and ensure they are not accessible from the Internet.
Mitigation: Scan all methods of mobile data exchange with the isolated network, such as CDs, USB drives, etc., b
Scan all methods of mobile data exchange with the isolated network, such as CDs, USB drives, etc., before use in the terminals or any node connected to these networks.
Patch: The only known method for an attacker to exploit these vulnerabilities is to create a malicious GUIc
The only known method for an attacker to exploit these vulnerabilities is to create a malicious GUIcon *.gd1 configuration file and then trick a user into opening it with the GUIcon software. The mitigation for these vulnerabilities is to ensure any GUIcon *.gd1 file loaded into the tool is from a trusted source.
Mitigation: Never allow mobile devices that have connected to any other network besides the intended network to
Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.
Mitigation: Place all controllers in locked cabinets and never leave them in the “Program” mode.
Place all controllers in locked cabinets and never leave them in the “Program” mode.
Mitigation: For more information about these issues, please refer to the original Schneider Electric publication
For more information about these issues, please refer to the original Schneider Electric publication SEVD-2021-313-07
Mitigation: Locate control and safety system networks and remote devices behind firewalls and isolate them from
Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.
Mitigation: Install physical controls to prevent unauthorized personnel from accessing industrial control and sa
Install physical controls to prevent unauthorized personnel from accessing industrial control and safety systems, components, peripheral equipment, and networks.
Mitigation: Never connect programming software to any network other than the network intended for that device.
Never connect programming software to any network other than the network intended for that device.
Mitigation: When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recogni
When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.
Mitigation: For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices docume
For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document.
Mitigation: Schneider Electric has provided Version 15.0.0.21042 of the IGSS Definition module: Def.exe to addre
Schneider Electric has provided Version 15.0.0.21042 of the IGSS Definition module: Def.exe to address these vulnerabilities. The update is available for download through IGSS Master > Update IGSS Software or from the Schneider Electric support page.
Mitigation: Avoid importing CGF files from untrusted sources.
Avoid importing CGF files from untrusted sources.
Mitigation: For more information, see the Schneider Electric security notification.
For more information, see the Schneider Electric security notification.
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • Harden the DCE instance according to the cybersecurity best practices documented in the EcoStruxure™ IT Data Center Expert Security Handbook
Patch: Version 9.0 of EcoStruxure™ IT Data Center Expert includes fixes for these vulnerabilities and is
Version 9.0 of EcoStruxure™ IT Data Center Expert includes fixes for these vulnerabilities and is available upon request from Schneider Electric’s Customer Care Center.
Mitigation: Harden the workstation running EcoStruxure Process Expert.
Harden the workstation running EcoStruxure Process Expert.
Mitigation: EcoStruxure Control Expert V15.1 HF001 or later.
EcoStruxure Control Expert V15.1 HF001 or later.
Mitigation: Compute a hash of the project files and regularly check the consistency of this hash to verify integ
Compute a hash of the project files and regularly check the consistency of this hash to verify integrity before usage.
Mitigation: See the Schneider Electric Security Notification, number SEVD-2021-222-02 for more information.
See the Schneider Electric Security Notification, number SEVD-2021-222-02 for more information.
Mitigation: AT&T Labs have stated this software is longer supported and recommends vendors to move away from usi
AT&T Labs have stated this software is longer supported and recommends vendors to move away from using it.
Mitigation: Users using Unity Pro should consider migrating to EcoStruxure Control Expert.
Users using Unity Pro should consider migrating to EcoStruxure Control Expert.
Mitigation: Only open project files received from trusted sources.
Only open project files received from trusted sources.
Mitigation: Securely store the project files and restrict access to trusted users.
Securely store the project files and restrict access to trusted users.
Mitigation: SCADAPack RemoteConnect for R2.7.3 or later (Users no longer need to update the RemoteConnect applic
SCADAPack RemoteConnect for R2.7.3 or later (Users no longer need to update the RemoteConnect application when a Control Expert update is present.)
Mitigation: Harden the workstation running EcoStruxure Control Expert or Unity Pro.
Harden the workstation running EcoStruxure Control Expert or Unity Pro.
Mitigation: Use secure communication channels when exchanging files over the network,.
Use secure communication channels when exchanging files over the network,.
Mitigation: Harden the workstation running SCADAPackRemoteConnect for x70
Harden the workstation running SCADAPackRemoteConnect for x70
Mitigation: EcoStruxure Process Expert V2021 or later.
EcoStruxure Process Expert V2021 or later.
Patch: Spacelabs also encourages users and administrators to review the Microsoft Security Advisory and the
Spacelabs also encourages users and administrators to review the Microsoft Security Advisory and the Microsoft Customer Guidance for CVE-2019-0708 and apply the appropriate mitigation measures as soon as possible.
Patch: Spacelabs has determined the recommended remediation is to update to the newest release v1.2.1 or la
Spacelabs has determined the recommended remediation is to update to the newest release v1.2.1 or later. All deployed XTR hardware appliances are capable of update and should be updated. Many Spacelabs products are appliances and users are not intended to perform updates on them. Products or systems that are obsolete or are not able to be patched may use this alternate mitigation step to help protect against BlueKeep:
Patch: For additional information about this vulnerability, please see the Spacelabs Security Advisory.
For additional information about this vulnerability, please see the Spacelabs Security Advisory.
Patch: If you own an XTR device or have any questions about this security advisory, please contact Spacelab
If you own an XTR device or have any questions about this security advisory, please contact Spacelabs at 1-800-522-7025 and select 2 for technical support. XTR is an appliance that has no user interface, so your service representative can help you to determine the installed version of software on your XTR product and will work to coordinate updates as needed.
Patch: Version SV3.65 of Modicon M340 firmware includes a fix for these vulnerabilities and is available f
Version SV3.65 of Modicon M340 firmware includes a fix for these vulnerabilities and is available for download here: https://www.se.com/ww/en/product-range/1468- modicon-m340
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit:• Setup network segmentation and implement a firewall to block all unauthorized access to port 502/TCP • Configure the Access Control List following the recommendations of the user manuals: “Modicon M340 for Ethernet Communications Modules and Processors User Manual” chapter “Messaging Configuration Parameters”: https://www.se.com/ww/en/download/document/31007131K01000/ • Consider use of external firewall devices such as EAGLE40-07 from Belden to establish VPN connections. For more details refer to “Modicon Controller Systems Cybersecurity, User Guide”: https://www.se.com/ww/en/download/document/EIO0000001999/ • Ensure the M340 CPU is running with the memory protection activated by configuring the input bit to a physical input, for more details refer to the following guideline “Modicon Controller Systems Cybersecurity, User Guide” chapter “Controler Memory Protection”: https://www.se.com/ww/en/download/document/EIO0000001999/
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit:• Setup network segmentation and implement a firewall to block all unauthorized access to port 502/TCP • Configure the Access Control List following the recommendations of the user manuals: “Momentum for EcoStruxure™ Control Expert -171CBU78090, 171CBU98090, 171CBU98091 Processors, User Guide” in the section “Controlling Access”:https://www.se.com/ww/en/download/document/HRB44124/• Consider use of external firewall devices such as EAGLE40-07 from Belden to establish VPN connections. For more details refer to “Modicon Controller Systems Cybersecurity, User Guide”:https://www.se.com/ww/en/download/document/EIO0000001999/
Patch: Version SV2.80 of Modicon Momentum firmware includes a fix for these vulnerabilities and is availabl
Version SV2.80 of Modicon Momentum firmware includes a fix for these vulnerabilities and is available for download here: https://www.se.com/ww/en/product-range/535-modicon-momentum
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit:• Setup network segmentation and implement a firewall to block all unauthorized access to port 502/TCP • Configure the Access Control List following the recommendations of the user manuals: “MC80 Programmable Logic Controller(PLC), User Manual” in the section “Access Control List (ACL)”: https://www.se.com/ww/en/download/document/EIO0000002071/ • Consider use of external firewall devices such as EAGLE40-07 from Belden to establish VPN connections. For more details refer to “Modicon Controller Systems Cybersecurity, User Guide”: https://www.se.com/ww/en/download/document/EIO0000001999/
Patch: Version SV2.1 of Modicon MC80 firmware includes a fix for these vulnerabilities and is available for
Version SV2.1 of Modicon MC80 firmware includes a fix for these vulnerabilities and is available for download here: https://www.se.com/ww/en/product-range/62396-modicon-mc80
Mitigation: Schneider Electric recommends users update to Version 15.0.0.21141 of the IGSS Definition module: De
Schneider Electric recommends users update to Version 15.0.0.21141 of the IGSS Definition module: Def.exe includes fixes for these vulnerabilities and is available for download through IGSS Master > Update IGSS Software, or at the link above.
Mitigation: If users choose not to apply the remediation provided above, they should immediately apply the follo
If users choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploitation:
Mitigation: Avoid importing CGF and WSP files from untrusted sources.
Avoid importing CGF and WSP files from untrusted sources.
Mitigation: Please see Schneider Electric's publication SEVD-2021-159-01 for more information.
Please see Schneider Electric's publication SEVD-2021-159-01 for more information.
Patch: ABB recommends that customers apply a firmware update as soon as possible to the latest firmware, i.
ABB recommends that customers apply a firmware update as soon as possible to the latest firmware, i.e. LAAAB v. 5.07 and higher, for the affected products. ABB has addressed the CODESYS Runtime System vulnerabilities by disabling the IEC online programming communication by default. As a result, CODESYS communication between affected products and the ABB Automation Builder or ABB Drive Application Builder tools is disabled. It should be noted that the CODESYS application continues to run on the Drive and if it is necessary to establish communication with CODESYS RTS, for example to debug the CODESYS application, this is possible through the drive parameter configuration. Open the user lock via the "96.02 Pass code" parameter and make sure that bit 9 "Enable online IEC programming" is set to TRUE in the "96.102 User lock functionality" parameter. IMPORTANT: After this task, be sure to disable CODESYS communication by setting the bit back to FALSE. A future firmware update is planned to update the CODESYS RTS library, which will further strengthen defenses for the vulnerabilities mentioned above. For situations where firmware update is not feasible, please refer to “Workarounds” section.
Workaround: For situations where firmware update is not feasible, please refer to ‘Workarounds’ section guidance
For situations where firmware update is not feasible, please refer to ‘Workarounds’ section guidance
Patch: In latest firmware versions for the affected products, ABB has mitigated the CODESYS Runtime System
In latest firmware versions for the affected products, ABB has mitigated the CODESYS Runtime System vulnerabilities. IEC online programming communication is disabled by default. As a result, CODESYS tools communication with the drive is disabled. ABB recommends that customers apply the firmware update at earliest convenience. For situations where firmware update is not feasible, please refer to ‘Workarounds’ section guidance
Workaround: If the drive or power controller is in an exploitable configuration, ABB recommends immediately appl
If the drive or power controller is in an exploitable configuration, ABB recommends immediately applying the mitigations described in the Workarounds section.
Workaround: For situations where firmware update is not feasible, please refer to ‘Workarounds’ section guidance
For situations where firmware update is not feasible, please refer to ‘Workarounds’ section guidance
Patch: In latest firmware versions for the affected products, ABB has mitigated the CODESYS Runtime System
In latest firmware versions for the affected products, ABB has mitigated the CODESYS Runtime System vulnerabilities. IEC online programming communication is disabled by default. As a result, CODESYS tools communication with the drive is disabled. ABB recommends that customers apply the firmware update at earliest convenience. For situations where firmware update is not feasible, please refer to ‘Workarounds’ section guidance
Workaround: If the drive or power controller is in an exploitable configuration, ABB recommends immediately appl
If the drive or power controller is in an exploitable configuration, ABB recommends immediately applying the mitigations described in the Workarounds section.
Patch: ABB recommends that customers apply a firmware update as soon as possible to the latest firmware, i.
ABB recommends that customers apply a firmware update as soon as possible to the latest firmware, i.e. LAAAB v. 5.07 and higher, for the affected products. ABB has addressed the CODESYS Runtime System vulnerabilities by disabling the IEC online programming communication by default. As a result, CODESYS communication between affected products and the ABB Automation Builder or ABB Drive Application Builder tools is disabled. It should be noted that the CODESYS application continues to run on the Drive and if it is necessary to establish communication with CODESYS RTS, for example to debug the CODESYS application, this is possible through the drive parameter configuration. Open the user lock via the "96.02 Pass code" parameter and make sure that bit 9 "Enable online IEC programming" is set to TRUE in the "96.102 User lock functionality" parameter. IMPORTANT: After this task, be sure to disable CODESYS communication by setting the bit back to FALSE. A future firmware update is planned to update the CODESYS RTS library, which will further strengthen defenses for the vulnerabilities mentioned above. For situations where firmware update is not feasible, please refer to “Workarounds” section.
Patch: Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerab
Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.
Mitigation: As the identified vulnerability requires file write access on the machine on which FoxRTU Station i
As the identified vulnerability requires file write access on the machine on which FoxRTU Station is installed, proper file system access control restrictions should be implemented to prevent unauthorized users from editing FoxRTU Station project files or placing malicious DLLs in accessible directories. • Store the project files in a secure storage and restrict the access to only trusted users • When exchanging files over the network, use secure communication protocols • Encrypt project files when stored • Only open project files received from trusted source • Compute a hash of the project files and regularly check the consistency of this hash to verify the integrity before usage • Follow workstation, network and site-hardening guidelines in the Recommended Cybersecurity Best Practices available here: https://www.se.com/us/en/download/document/7EN52- 0390/ • To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securit y-notifications.jsp
Patch: Version 9.3.0 of FoxRTU Station includes a fix for this vulnerability. Please contact your local Se
Version 9.3.0 of FoxRTU Station includes a fix for this vulnerability. Please contact your local Service Representative or Schneider Electric Process Automation Global Customer Support Center for information on how to download and install this fix: Process Automation | Global Customer Support (se.com) Please follow the instructions in Chapter 12 of User Guide B0780AE rev. P, “Security: Securing a Project” to encrypt and password protect project files.
Patch: Version SV3.60 of BMXNOE0100 includes a fix for this vulnerability and is available for download he
Version SV3.60 of BMXNOE0100 includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product/BMXNOE0100/network-module-modicon-m340- modbus-tcp-1-x-rj45-flash-memory-card/
Patch: Version SV3.70 of Modicon M340 includes a fix for this vulnerability and is available for download h
Version SV3.70 of Modicon M340 includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/1468-modicon-m340/#software-and-firmware
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • Set up network segmentation and implement a firewall to block all unauthorized access to FTP port 21/TCP on the devices. • Disable FTP service via EcoStruxureTM Control Expert. This is disabled by default when a new application is created. • Disable Web server service via EcoStruxureTM Control Expert. This is disabled by default when a new application is created. • Configure the Access Control List following the recommendation on the “Modicon Controllers System Cybersecurity”https://download.schneider-electric.com/files?p_Doc_Ref=EIO0000001999&p_enDocType=User+guide&p_File_Name=EIO0000001999-12_Modicon_Controller_Cybersecurity.pdf
Patch: Version SV6.80 of BMXNOE0110 includes a fix for this vulnerability and is available for download he
Version SV6.80 of BMXNOE0110 includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product/BMXNOE0110/ethernet-tcp-ip-network-modulemodicon-m340-automation-platform-flash-memory-card-internal-ram-16-mb-1-x-rj45- 10-100/
Patch: Version SV1.70IR26 of BMXNOR0200H includes a fix for this vulnerability and is available for downlo
Version SV1.70IR26 of BMXNOR0200H includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product/BMXNOR0200H/ethernet-serial-rtu-module-2-x-rj45/
Patch: Firmware version C3414-500-S02K5_P9 of SAGE RTU includes a fix for these vulnerabilities and is avai
Firmware version C3414-500-S02K5_P9 of SAGE RTU includes a fix for these vulnerabilities and is available for download here:https://www.se.com/us/en/download/document/C3414-500-S02K5_P9_Firmware/
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: * Ensuring that debug mode is off will prevent the credentials from being improperly exposed.
Patch: Version V2.1 or later of EcoStruxure Panel Server includes a fix for this vulnerability and is avail
Version V2.1 or later of EcoStruxure Panel Server includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/40739468-ecostruxure-panel-server/?parent-subcategory-id=4160#software-and-firmware Customers should download EcoStruxure Power Commission Software version 2.33.0 or later, and version V2.1 or later of EcoStruxure Panel Server firmware to complete the upgrade process.
Mitigation: When remote access is required, use secure methods such as virtual private networks. Recognize that
When remote access is required, use secure methods such as virtual private networks. Recognize that VPNs may have vulnerabilities and should therefore be updated to the most current version available. Also recognize that VPNs are only as secure as the connected devices.
Mitigation: Install physical controls so no unauthorized personnel can access industrial control and safety syst
Install physical controls so no unauthorized personnel can access industrial control and safety systems, components, peripheral equipment, and networks.
Mitigation: Scan all methods of mobile data exchange with the isolated network, such as CDs, USB drives, etc., b
Scan all methods of mobile data exchange with the isolated network, such as CDs, USB drives, etc., before use in the terminals or nodes connected to these networks.
Mitigation: Schneider Electric continues to recommend users always implement the instructions in the “Security C
Schneider Electric continues to recommend users always implement the instructions in the “Security Considerations,”
Mitigation: Minimize network exposure for all control system devices and systems and ensure that they are not ac
Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.
Mitigation: Schneider Electric released TriStation v4.9.1 and v4.10.1 on May 30, 2013 and 4.13.0 on January 26,
Schneider Electric released TriStation v4.9.1 and v4.10.1 on May 30, 2013 and 4.13.0 on January 26, 2015 to address these issues. Tricon v10.5.0 was released on August 13, 2009 and v10.5.4 on February 2, 2012 to address the issues.
Mitigation: Ensure the cybersecurity features in Triconex solutions are always enabled.
Ensure the cybersecurity features in Triconex solutions are always enabled.
Mitigation: Locate control and safety system networks and remote devices behind firewalls and isolate them from
Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.
Mitigation: Configure operator stations to display an alarm whenever the Tricon key switch is in the “PROGRAM” m
Configure operator stations to display an alarm whenever the Tricon key switch is in the “PROGRAM” mode.
Mitigation: Secure all TriStation engineering workstations and never connect to any network other than the safet
Secure all TriStation engineering workstations and never connect to any network other than the safety network.
Mitigation: Always deploy safety systems on isolated networks.
Always deploy safety systems on isolated networks.
Mitigation: Please see the Schneider Electric Security Bulletin - SESB-2020-105-01 for more details of these vul
Please see the Schneider Electric Security Bulletin - SESB-2020-105-01 for more details of these vulnerabilities in legacy Triconex products.
Mitigation: Place all controllers in locked cabinets and never leave them in the “Program” mode.
Place all controllers in locked cabinets and never leave them in the “Program” mode.
Mitigation: Schneider Electric notified customers of updated product availability via direct-to-customer notific
Schneider Electric notified customers of updated product availability via direct-to-customer notification and fixed versions of these offers are available for download here.
Mitigation: Never allow laptops that have connected to any other network besides the intended network to connect
Never allow laptops that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.
Mitigation: Customers should immediately apply the following mitigations to reduce the risk of exploit: T
Customers should immediately apply the following mitigations to reduce the risk of exploit: To keep your Zigbee network safe and prevent unauthorized access: • Restrict device access: Do not allow unknown devices to join your network. • Review hub settings: Check how your Zigbee hub manages device pairing. • Control network availability: Only open the network when adding new devices and close it immediately after. • Use install codes and avoid the well-known key: Whenever possible, use unique install codes for added security. Replace default keys with secure, unique keys.
Mitigation: To mitigate the risks associated with Modbus/ weaknesses, users should immediately: • Set up network
To mitigate the risks associated with Modbus/ weaknesses, users should immediately: • Set up network segmentation and implement a firewall to block all unauthorized access to port 502/TCP • Configure the Access Control List feature as mentioned in “Quantum using EcoStruxure Control Expert - TCP/IP Configuration, User Manual” in chapter “Software Settings for Ethernet Communication / Messaging / Quantum NOE Ethernet Messaging Configuration”: https://www.se.com/ww/en/download/document/33002467K01000/
Mitigation: It is recommended to apply the following mitigations to reduce the risk of exploitation: • Set up
It is recommended to apply the following mitigations to reduce the risk of exploitation: • Set up an application password in the project properties • Set up network segmentation and implement a firewall to block all unauthorized access to port 502/TCP • Configure the Access Control List following the recommendations of the user manuals: o “Modicon M340 for Ethernet Communications Modules and Processors User Manual” in chapter “Messaging Configuration Parameters”: https://www.se.com/ww/en/download/document/31007131K01000/ • Set up a secure communication according to the following guideline “Modicon Controllers Platform Cyber Security Reference Manual,” in chapter “Setup secured communications”: https://www.se.com/ww/en/download/document/EIO0000001999/ • Consider use of external firewall devices such as EAGLE40-07 from Belden to establish VPN connections for M340 & M580 architectures. For more details refer to the chapter “How to protect M580 and M340 architectures with EAGLE40 using VPN”: https://www.se.com/ww/en/download/document/EIO0000001999/
Mitigation: It is recommended to apply the following mitigations to reduce the risk of exploitation: • Set up an
It is recommended to apply the following mitigations to reduce the risk of exploitation: • Set up an application password in the project properties • Set up network segmentation and implement a firewall to block all unauthorized access to port 502/TCP • Configure the Access Control List following the recommendations of the user manuals: https://www.se.com/ww/en/download/document/EIO0000001578/ • Set up a secure communication according to the following guideline “Modicon Controllers Platform Cyber Security Reference Manual,” in chapter “Setup secured communications”: https://www.se.com/ww/en/download/document/EIO0000001999/ NOTE: Use a BMENOC module and follow the instructions to configure IPSEC feature as described in the guideline “Modicon M580 - BMENOC03.1 Ethernet Communications Schneider Electric Security Notification Module, Installation and Configuration Guide” in the chapter “Configuring IPSEC communications”: https://www.se.com/ww/en/download/document/HRB62665/ OR • Use a BMENUA0100 module and follow the instructions to configure IPSEC feature as described in the chapter “Configuring the BMENUA0100 Cybersecurity Settings”: https://www.se.com/ww/en/download/document/PHA83350 OR • Consider using external firewall devices such as EAGLE40-07 from Belden to establish VPN connections for M340 and M580 architectures. For more details refer to the chapter “How to protect M580 and M340 architectures with EAGLE40 using VPN”: https://www.se.com/ww/en/download/document/EIO0000001999/ • Ensure the M580 CPU is running with the memory protection activated by configuring the input bit to a physical input, for more details refer to the following guideline “Modicon Controllers Platform Cyber Security Reference Manual”, “CPU Memory Protection section”: https://www.schneider-electric.com/en/download/document/EIO0000001999/ NOTE: The CPU memory protection cannot be configured with M580 Hot Standby CPUs. In such cases, use IPsec encrypted communication.
Patch: Version sv4.20 of Modicon M580 includes a fix for this vulnerability and is available for download h
Version sv4.20 of Modicon M580 includes a fix for this vulnerability and is available for download here: STEP 1: Update software and firmware. • On the engineering workstation, update to EcoStruxure Control Expert v16.0: https://www.se.com/ww/en/product-range/548-ecostruxure-control-expert-unity-pro/#software-and-firmware • On the Modicon M580 controller, update to firmware SV4.20 or above: https://www.se.com/ww/en/product-range/62098-modicon-m580-epac/#software-and-firmware STEP 2: Update projects in EcoStruxure Control Expert by: • Setting up an application password in the project properties • Changing the version of the controller firmware to match the new firmware version of the target controller STEP 3: Rebuild and transfer projects in EcoStruxure Control Expert: • Rebuild all current projects
Patch: Version sv3.60 of Modicon M340 includes a fix for this vulnerability and is available for download h
Version sv3.60 of Modicon M340 includes a fix for this vulnerability and is available for download here: STEP 1: Update software and firmware • On the engineering workstation, update to EcoStruxure Control Expert v16.0 or later: https://www.se.com/ww/en/product-range/548-ecostruxure-control-expert-unity-pro/#software-and-firmware • On the Modicon M340 controller, update to firmware v3.60 or above: https://www.se.com/ww/en/product-range/1468- modicon-m340/#software-and-firmware STEP 2: Update projects in EcoStruxure Control Expert by: • Setting up an application password in the project properties • Changing the version of the controller firmware to match the new firmware version of the target controller STEP 3: Rebuild and transfer projects in EcoStruxure Control Expert: • Rebuild all current projects • Transfer them to Modicon controllers
Patch: Version 2.2 of ATV6000 drives includes a fix for this vulnerability and is available upon request fr
Version 2.2 of ATV6000 drives includes a fix for this vulnerability and is available upon request from Schneider Electric's [Customer Care Center](https://www.se.com/us/en/work/support/contacts.jsp).
Mitigation: Schneider Electric is establishing a remediation plan for all future versions of • ILC992 InterLink
Schneider Electric is establishing a remediation plan for all future versions of • ILC992 InterLink Converter • VW3A3720 & VW3A3721 Altivar Process Communication Modules that will include a fix for this vulnerability. We will update this document when the remediation is available. Until then, customers should immediately apply the following mitigations to reduce the risk of exploit: • End user cybersecurity awareness and workstation protections • Deactivate the Webserver after use when not needed. • Setup network segmentation and implement a firewall to block all unauthorized access to port 80/HTTP • Use VPN (Virtual Private Networks) tunnels if remote access is required.
Patch: Version 25.0 of VW3A3530D: ATVdPAC module includes a fix for this vulnerability and is available u
Version 25.0 of VW3A3530D: ATVdPAC module includes a fix for this vulnerability and is available upon request from Schneider Electric's [Customer Care Center](https://www.se.com/us/en/work/support/contacts.jsp).
Patch: The version 4.5 of ATV340 drives includes a fix for this vulnerability and is available for download
The version 4.5 of ATV340 drives includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/63441-altivar-machine-atv340/#software-and-firmware
Patch: The version 4.5 of ATV9xx drives includes a fix for this vulnerability and is available for download
The version 4.5 of ATV9xx drives includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/63124-altivar-process-atv900/#software-and-firmware
Patch: The version 1.2ie05 of ATS490 drives includes a fix for this vulnerability and is available for down
The version 1.2ie05 of ATS490 drives includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/download/document/ATS490-Firmware/
Patch: The version 4.5 of ATV6xx drives includes a fix for this vulnerability and is available for download
The version 4.5 of ATV6xx drives includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/62317-altivar-process-atv600/#software-and-firmware
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • End user cybersecurity awareness and workstation protections • Deactivate the Webserver after use when not needed. • Setup network segmentation and implement a firewall to block all unauthorized access to port 80/HTTP • Use VPN (Virtual Private Networks) tunnels if remote access is required.
Mitigation: As the identified vulnerabilities require local user account access, EcoStruxureTM Foxboro DCS work
As the identified vulnerabilities require local user account access, EcoStruxureTM Foxboro DCS workstations should be installed in a secure location to prevent physical access by unauthorized personnel, and appropriate password protections put in place to prevent remote access by unauthorized personnel. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications. jsp
Patch: Patch HF97872598 available for v9.5 to v9.8 of EcoStruxureTM Foxboro DCS Core Control Services incl
Patch HF97872598 available for v9.5 to v9.8 of EcoStruxureTM Foxboro DCS Core Control Services includes a fix for these vulnerabilities. Please contact your local Service Representative or Schneider Electric Process Automation Global Customer Support Center for information on how to download and install this fix:
Mitigation: Schneider Electric is establishing a remediation plan for all future versions of EcoStruxure Modicon
Schneider Electric is establishing a remediation plan for all future versions of EcoStruxure Modicon Communication Server that will include a fix for this vulnerability. We will update this document when the remediation is available. Until then, customers should immediately apply the following mitigations to reduce the risk of exploit: * Set the “Security Policy” to Basic256-Sha256 (default value indicated by unchecked “Security Policy” setting) used for secure communication between OPC UA client & server based on OPC UA standard. * Ensure that the “Anonymous user token” setting remains unchecked (unchecked by default) to prevent anonymous authentication. * Set “User authentication” setting (checked by default) used to authenticate & authorize OPC UA client. * Set “X509 user token” setting (checked by default) used to authenticate & authorize OPC UA client. For more details, refer to “EcoStruxure Modicon Server User Guide” chapter “Security Settings”: https://www.se.com/fr/fr/download/document/EIO0000004083/ * Follow workstation, network and site-hardening guidelines in the “Recommended Cybersecurity Best Practices”: https://www.se.com/ww/en/download/document/7EN52-0390/
Patch: Version SV2.01 SP3 of EcoStruxure OPC UA Server Expert includes a fix for this vulnerability and is
Version SV2.01 SP3 of EcoStruxure OPC UA Server Expert includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/66388-ecostruxure-opc-ua-server-expert/#software-and-firmware
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: * Set the “Security Policy” to Basic256-Sha256 (default value indicated by unchecked “Security Policy” setting) used for secure communication between OPC UA client & server based on OPC UA standard. * Ensure that the “Anonymous user token” setting remains unchecked (unchecked by default) to prevent anonymous authentication. * Set “User authentication” setting (checked by default) used to authenticate & authorize OPC UA client. * Set “X509 user token” setting (checked by default) used to authenticate & authorize OPC UA client. For more details, refer to “EcoStruxure OPC UA Server Expert User Guide” chapter “Security Management”: https://www.se.com/ww/en/download/document/MFR53158/ * Follow workstation, network and site-hardening guidelines in the “Recommended Cybersecurity Best Practices”: https://www.se.com/ww/en/download/document/7EN52-0390/
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit:• Recommended to apply application whitelisting at system level to allow execution of authenticated applications. More details available here: https://www.se.com/ww/en/download/document/EIO0000004778/ • Recommended to allow access to the system only to the required users.
Patch: Version 2025 of EcoStruxure™ Process Expert includes a fix for this vulnerability and is available
Version 2025 of EcoStruxure™ Process Expert includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/65406-ecostruxure-process-expert
Patch: Version 2025 of EcoStruxure™ Process Expert for AVEVA System Platform includes a fix for this vulner
Version 2025 of EcoStruxure™ Process Expert for AVEVA System Platform includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/55570689-ecostruxure-process-expert-for-aveva-system-platform/#software-and-firmware
Mitigation: 3-Phase Uninterruptible Power Supply (UPS) using NMC2 including Symmetra PX 250/500 (SYPX) Network M
3-Phase Uninterruptible Power Supply (UPS) using NMC2 including Symmetra PX 250/500 (SYPX) Network Management Card 2 (NMC2) (See SEVD-2021-313-03 on what specific models are mitigated): Update to v7.0.4 or later of the NMC2 SYPX application. Contact a Schneider Electric support team for SYPX application upgrade.
Mitigation: Never allow mobile devices that have connected to any other network besides the intended network to
Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.
Mitigation: APC 3-Phase Power Distribution Products using NMC2: Update to v7.0.4 or later of the NMC2 RPP applic
APC 3-Phase Power Distribution Products using NMC2: Update to v7.0.4 or later of the NMC2 RPP application.
Mitigation: When remote access is required, use secure methods, such as virtual private networks (VPNs). Recogni
When remote access is required, use secure methods, such as virtual private networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.
Mitigation: Release notes
Release notes
Mitigation: If a debug.tar file is generated via Web or CLI, ensure it is deleted after retrieval.
If a debug.tar file is generated via Web or CLI, ensure it is deleted after retrieval.
Mitigation: For the products not listed above, Schneider Electric is in the process of establishing a remediatio
For the products not listed above, Schneider Electric is in the process of establishing a remediation plan for affected NMC2 and NMC3 offers.
Mitigation: Network Management Card 2 (NMC2) Cooling Products (See SEVD-2021-313-03 on what specific series are
Network Management Card 2 (NMC2) Cooling Products (See SEVD-2021-313-03 on what specific series are mitigated): Update to v7.0.4 or later of the NMC2 of the cooling applications. Contact a Schneider Electric support team for upgrades.
Mitigation: SUMX (SmartUPS & Galaxy 3500)
SUMX (SmartUPS & Galaxy 3500)
Mitigation: 1-Phase Uninterruptible Power Supply (UPS) using NMC3: Update to v1.5 or later of the NMC3 SU and SY
1-Phase Uninterruptible Power Supply (UPS) using NMC3: Update to v1.5 or later of the NMC3 SU and SY applications
Mitigation: 1-Phase Uninterruptible Power Supply (UPS) using NMC2: Update to v7.04 or later.
1-Phase Uninterruptible Power Supply (UPS) using NMC2: Update to v7.04 or later.
Mitigation: SY (Single Phase Symmetra)
SY (Single Phase Symmetra)
Mitigation: Never connect programming software to any network other than the network for the devices that it is
Never connect programming software to any network other than the network for the devices that it is intended for.
Mitigation: NMC users should not trust links provided from sources that have not been verified as authentic.
NMC users should not trust links provided from sources that have not been verified as authentic.
Mitigation: Ensure the workstation where the browser is being used is secured.
Ensure the workstation where the browser is being used is secured.
Mitigation: RPDU2G (direct download)
RPDU2G (direct download)
Mitigation: Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. bef
Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.
Mitigation: Galaxy RPP
Galaxy RPP
Mitigation: Install physical controls so no unauthorized personnel can access your industrial control and safety
Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.
Mitigation: APC Rack Power Distribution Units (PDU) using NMC2: Update to v7.0.6 or later of the NMC2 RPDU2G app
APC Rack Power Distribution Units (PDU) using NMC2: Update to v7.0.6 or later of the NMC2 RPDU2G application.
Mitigation: Locate control and safety system networks and remote devices behind firewalls and isolate them from
Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.
Mitigation: SUMX & SY Release notes
SUMX & SY Release notes
Mitigation: Update to v7.0.4 or later of the NMC2 SYPX application. Contact a Schneider Electric support team fo
Update to v7.0.4 or later of the NMC2 SYPX application. Contact a Schneider Electric support team for SYPX application upgrade.
Mitigation: Minimize network exposure for all control system devices and systems and ensure they are not accessi
Minimize network exposure for all control system devices and systems and ensure they are not accessible from the Internet.
Mitigation: SUMX (SmartUPS & Galaxy 3500)
SUMX (SmartUPS & Galaxy 3500)
Mitigation: SY (Single Phase Symmetra)
SY (Single Phase Symmetra)
Mitigation: Install physical controls so no unauthorized personnel can access industrial control and safety syst
Install physical controls so no unauthorized personnel can access industrial control and safety systems, components, peripheral equipment, and networks.
Mitigation: Minimize network exposure for all control system devices and systems and ensure that they are not ac
Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.
Mitigation: Refer to Schneider Electric's security bulletin SEVD-2020-315-05 for specific mitigation details.
Refer to Schneider Electric's security bulletin SEVD-2020-315-05 for specific mitigation details.
Mitigation: Never allow mobile devices that have connected to any other network, besides the intended network, t
Never allow mobile devices that have connected to any other network, besides the intended network, to connect to the safety or control networks without proper sanitation.
Mitigation: Scan all methods of mobile data exchange with the isolated network (e.g., CDs, USB drives, etc.) bef
Scan all methods of mobile data exchange with the isolated network (e.g., CDs, USB drives, etc.) before use in the terminals or any node connected to these networks.
Mitigation: When remote access is required, use secure methods such as virtual private networks (VPNs). Recogniz
When remote access is required, use secure methods such as virtual private networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.
Mitigation: Locate control and safety system networks and remote devices behind firewalls and isolate them from
Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.
Patch: Within the Modicon M221 application, the user must: Disable all unused protocols, especially program
Within the Modicon M221 application, the user must: Disable all unused protocols, especially programming protocol, as described in section “Configuring Ethernet Network” of EcoStruxure Machine Expert - Basic online help for the M221 PLC. This action will prevent unintended remote programming access.;Set a password to protect the project.;Set a password for read access on the controller.;Set a different password for write access on the controller.
Mitigation: For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices docume
For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document.
Mitigation: Place all controllers in locked cabinets and never leave them in the “Program” mode.
Place all controllers in locked cabinets and never leave them in the “Program” mode.
Mitigation: Never connect programming software to any network other than the network for which the devices were
Never connect programming software to any network other than the network for which the devices were intended.
Mitigation: Set up network segmentation and implement a firewall to block all unauthorized access to Port 502/TC
Set up network segmentation and implement a firewall to block all unauthorized access to Port 502/TCP.
Mitigation: Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel onl
Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.
Mitigation: Only build and run applications from trusted sources.
Only build and run applications from trusted sources.
Mitigation: Only build and run applications from trusted sources.
Only build and run applications from trusted sources.
Mitigation: Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel onl
Limit access to the interactive shell of the additional GNU/Linux subssytem to trusted personnel only.
Patch: Update Fortigate NGFW to V7.4.3. Contact customer support to receive patch and update information.
Update Fortigate NGFW to V7.4.3. Contact customer support to receive patch and update information.
Patch: Update to V1.1 or later version
Update to V1.1 or later version
Patch: Update to V3.0 or later version
Update to V3.0 or later version
Patch: Update to V1.0 SP2 Update 3 or later version
Update to V1.0 SP2 Update 3 or later version
Mitigation: Scan all methods of mobile data exchange with the isolated network, such as CDs, USB drives, etc., b
Scan all methods of mobile data exchange with the isolated network, such as CDs, USB drives, etc., before use in terminals or any nodes connected to these networks.
Mitigation: For users of waveform analysis and ETAP simulation features, Schneider Electric recommends all deplo
For users of waveform analysis and ETAP simulation features, Schneider Electric recommends all deployments of EPO only accept connections from localhost in PostgresSQL. Contact Schneider Electric's Customer Care Center at https://www.se.com/us/en/work/support/contacts.jsp for information on how to modify PostgreSQL. Additionally, Schneider Electric recommends users manually uninstall PostgreSQL 14.10 and update to PostgreSQL 14.17 or higher.
Mitigation: Place all controllers in locked cabinets and never leave them in the "Program" mode.
Place all controllers in locked cabinets and never leave them in the "Program" mode.
Mitigation: For more information, see the associated Schneider Electric security advisory SEVD-2025-189-03: EcoS
For more information, see the associated Schneider Electric security advisory SEVD-2025-189-03: EcoStruxure Power Operation PDF version(https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-189-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-189-03.pdf), or CSAF version](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-189-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2025-189-03.json).
Mitigation: When remote access is required, use secure methods such as virtual private networks (VPNs). Recogniz
When remote access is required, use secure methods such as virtual private networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.For more information, refer to the Schneider Electric recommended cybersecurity best practices document.
Mitigation: Minimize network exposure for all control system devices and systems, ensuring they are not accessib
Minimize network exposure for all control system devices and systems, ensuring they are not accessible from the Internet.
Mitigation: Never connect programming software to any network other than the one intended for that device.
Never connect programming software to any network other than the one intended for that device.
Mitigation: Never allow mobile devices that have connected to any network other than the intended network to con
Never allow mobile devices that have connected to any network other than the intended network to connect to safety or control networks without proper sanitation.
Mitigation: For more information, refer to the Schneider Electric recommended cybersecurity best practices docum
For more information, refer to the Schneider Electric recommended cybersecurity best practices document at https://www.se.com/us/en/download/document/7EN52-0390/ .
Mitigation: For more information, see the associated Schneider Electric security advisory SEVD-2025-189-03: EcoS
For more information, see the associated Schneider Electric security advisory SEVD-2025-189-03: EcoStruxure Power Operation PDF version(https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-189-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-189-03.pdf), or CSAF version](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-189-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2025-189-03.json).
Mitigation: Schneider Electric strongly recommends adhering to the following industry cybersecurity best practic
Schneider Electric strongly recommends adhering to the following industry cybersecurity best practices: Locate control and safety system networks and remote devices behind firewalls, and isolate them from the business network. Install physical controls to prevent unauthorized personnel from accessing industrial control and safety systems, components, peripheral equipment, and networks. Place all controllers in locked cabinets and never leave them in the "Program" mode. Never connect programming software to any network other than the one intended for that device. Scan all methods of mobile data exchange with the isolated network, such as CDs, USB drives, etc., before use in terminals or any nodes connected to these networks. Never allow mobile devices that have connected to any network other than the intended network to connect to safety or control networks without proper sanitation. Minimize network exposure for all control system devices and systems, ensuring they are not accessible from the Internet. When remote access is required, use secure methods such as virtual private networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.
Mitigation: Install physical controls to prevent unauthorized personnel from accessing industrial control and sa
Install physical controls to prevent unauthorized personnel from accessing industrial control and safety systems, components, peripheral equipment, and networks.
Mitigation: If waveform analysis and ETAP simulation features are not used, uninstall PostgreSQL,OR
If waveform analysis and ETAP simulation features are not used, uninstall PostgreSQL,OR
Mitigation: Schneider Electric recommends users to employ appropriate patching methodologies when applying these
Schneider Electric recommends users to employ appropriate patching methodologies when applying these patches to their systems. They strongly recommend making backups and evaluating the impact of these patches in a test and development environment or on offline infrastructure. Contact Schneider Electric's Customer Care Center at https://www.se.com/us/en/work/support/contacts.jsp for assistance removing a patch.
Mitigation: EcoStruxure Power Operation 2022 CU7 includes an updated version of PostgreSQL and is available for
EcoStruxure Power Operation 2022 CU7 includes an updated version of PostgreSQL and is available for download here: https://community.se.com/t5/EcoStruxure-Power-Operation/v2022-Release-amp-Updates-Install-Procedure/m-p/491544#M7322
Mitigation: If users choose not to apply the remediation mentioned above, Schneider Electric recommends the foll
If users choose not to apply the remediation mentioned above, Schneider Electric recommends the following:
Patch: Locate control and safety system networks and remote devices behind firewalls, and isolate them from
Locate control and safety system networks and remote devices behind firewalls, and isolate them from the business network.
Patch: When remote access is required, use secure methods, such as virtual private networks (VPNs).
When remote access is required, use secure methods, such as virtual private networks (VPNs).
Patch: Strip report output from Excel output. In the System Configuration module under Reports, stripping o
Strip report output from Excel output. In the System Configuration module under Reports, stripping of macros for the output engine can be enabled, reducing the risk of distributing an unsafe report.
Patch: Scan all methods of mobile data exchange with the isolated network before use in the terminals or no
Scan all methods of mobile data exchange with the isolated network before use in the terminals or nodes connected to these networks.
Patch: Place all controllers in locked cabinets, and do not leave them in the “Program” mode.
Place all controllers in locked cabinets, and do not leave them in the “Program” mode.
Patch: Minimize network exposure for all control system devices and systems and ensure that they are not ac
Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the internet.
Patch: For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices docume
For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document.
Patch: Only connect programming software to the network intended for that device.
Only connect programming software to the network intended for that device.
Patch: Verify that devices are isolated on a private network and that firewalls are configured with strict
Verify that devices are isolated on a private network and that firewalls are configured with strict boundaries for devices that require remote access.Schneider Electric strongly recommends the following industry cybersecurity best practices.
Patch: For more information, see Schneider Electric security notification SEVD-2023-073-04.
For more information, see Schneider Electric security notification SEVD-2023-073-04.
Patch: Install physical controls to help prevent unauthorized users from accessing industrial control and s
Install physical controls to help prevent unauthorized users from accessing industrial control and safety systems, components, peripheral equipment, and networks.
Patch: Properly sanitize mobile devices that have connected to another network before connecting to the int
Properly sanitize mobile devices that have connected to another network before connecting to the intended network.
Patch: Ensure that the System Configuration module under Files, automatic backup is enabled for file backup
Ensure that the System Configuration module under Files, automatic backup is enabled for file backup.
Patch: Additionally, if patching is not feasible, Schneider Electric recommends the following mitigations t
Additionally, if patching is not feasible, Schneider Electric recommends the following mitigations to reduce the risk of vulnerability exploitation:
Patch: Schneider Electric recommends that users use appropriate patching methodologies when applying these
Schneider Electric recommends that users use appropriate patching methodologies when applying these patches to their systems. Schneider Electric recommends the use of back-ups and impact evaluating these patches in a test, development, or offline infrastructure environment, is strongly recommended. Users can contact Schneider Electric’s Customer Care Center for additional assistance.
Patch: Read the Security Guideline for IGSS on securing an IGSS SCADA-installation.
Read the Security Guideline for IGSS on securing an IGSS SCADA-installation.
Patch: Version 16.0.0.23041 of IGSS Data Server, Dashboard and Custom Reports (RMS) includes corrections an
Version 16.0.0.23041 of IGSS Data Server, Dashboard and Custom Reports (RMS) includes corrections and mitigations for these vulnerabilities and is available for download through IGSS Master > Update IGSS Software; the update is also available directly from Schneider Electric.
Mitigation: Consider using proper network infrastructure controls, such as firewalls, UTM devices, VPN, or other
Consider using proper network infrastructure controls, such as firewalls, UTM devices, VPN, or other security appliances.
Mitigation: Rockwell Automation recommends users of affected versions evaluate the mitigations provided and appl
Rockwell Automation recommends users of affected versions evaluate the mitigations provided and apply the appropriate mitigations to deployed products. Users are encouraged to combine this guidance with the general security guidelines for a comprehensive defense-in-depth strategy.
Mitigation: Locate control systems behind firewalls.
Locate control systems behind firewalls.
Mitigation: Reference Rockwell Automation.
Reference Rockwell Automation.
Mitigation: Rockwell Automation recommends users update to ISaGRAF Runtime 5 Version 5.72.00. End users are enco
Rockwell Automation recommends users update to ISaGRAF Runtime 5 Version 5.72.00. End users are encouraged to restrict or block access on TCP 1131 and TCP 1132 from outside the industrial control system. Confirm the least-privilege user principle is followed and user/service account access to Runtime's folder location is granted with a minimum amount of rights needed.
Mitigation: Refer to the Converged Plantwide Ethernet (CPwE) Design and Implementation Guide for best practices
Refer to the Converged Plantwide Ethernet (CPwE) Design and Implementation Guide for best practices deploying network segmentation and broader defense-in-depth strategies.
Mitigation: Ensure the least-privilege user principle is followed, and user/service account access to Runtime's
Ensure the least-privilege user principle is followed, and user/service account access to Runtime's folder location is granted with a minimum amount of rights, as needed.
Mitigation: Isolate control systems from other networks when possible.
Isolate control systems from other networks when possible.
Mitigation: Please see publications from Rockwell Automation and Schneider Electric, Xylem, or contact GE for fu
Please see publications from Rockwell Automation and Schneider Electric, Xylem, or contact GE for further information about how to mitigate these vulnerabilities in additional affected products.
Mitigation: Minimize network exposure for all control system devices.
Minimize network exposure for all control system devices.
Mitigation: Employ proper network segmentation and security controls.
Employ proper network segmentation and security controls.
Mitigation: Install physical controls so no unauthorized personnel can access your industrial control and safety
Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.
Mitigation: Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. bef
Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.
Mitigation: To ensure you are informed of all updates, including details on affected products and remediation pl
To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric's security notification service.
Mitigation: When exchanging files over the network, use secure communication protocols.
When exchanging files over the network, use secure communication protocols.
Mitigation: Minimize network exposure for all control system devices and systems and ensure that they are not ac
Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.
Mitigation: Never allow mobile devices that have connected to any other network besides the intended network to
Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.
Mitigation: Compute hash of the project files and regularly check the consistency of this hash to verify the int
Compute hash of the project files and regularly check the consistency of this hash to verify the integrity before usage.
Mitigation: Place all controllers in locked cabinets and never leave them in the "Program" mode.
Place all controllers in locked cabinets and never leave them in the "Program" mode.
Mitigation: Locate control and safety system networks and remote devices behind firewalls and isolate them from
Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.
Mitigation: Schneider Electric is establishing a remediation plan for all future versions of EcoStruxture Power
Schneider Electric is establishing a remediation plan for all future versions of EcoStruxture Power Design - Ecodial that will include a fix for this vulnerability. Until then, customers should immediately apply the following mitigations to reduce the risk of exploit:
Mitigation: Delete the accounts of people who no longer need access to the application and the computer running
Delete the accounts of people who no longer need access to the application and the computer running the application following the principle of least privilege.
Mitigation: Store the hash information in a separate location from where the project file is stored.
Store the hash information in a separate location from where the project file is stored.
Mitigation: When sharing or receiving project files with another user, the hash information should be provided o
When sharing or receiving project files with another user, the hash information should be provided over a separate, out of band channel.
Mitigation: Never connect programming software to any network other than the network intended for that device.
Never connect programming software to any network other than the network intended for that device.
Mitigation: For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices docume
For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document.
Mitigation: When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recogni
When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.
Mitigation: Schneider Electric strongly recommends the following industry cybcersecurity best practices.
Schneider Electric strongly recommends the following industry cybcersecurity best practices.
Mitigation: Harden the workstation running the application.
Harden the workstation running the application.
Mitigation: Only open project files received from a trusted source.
Only open project files received from a trusted source.
Mitigation: If users choose not to apply the remediation provided above they should immediately apply the follow
If users choose not to apply the remediation provided above they should immediately apply the following mitigations to reduce the risk of exploit: Use an allow list for this application. Turn on the workstation’s firewall. Use an antivirus program. Secure the workstation from unauthorized personnel.
Mitigation: Please see Schneider Electric’s publication SEVD-2021-103-01 for more information.
Please see Schneider Electric’s publication SEVD-2021-103-01 for more information.
Mitigation: Schneider Electric recommends users update to the latest version available. A reboot will be needed
Schneider Electric recommends users update to the latest version available. A reboot will be needed after the update.
Mitigation: Schneider Electric recommends users to update the affected product to the latest version. See Schnei
Schneider Electric recommends users to update the affected product to the latest version. See Schneider Electric's security advisory for more information.
Mitigation: Schneider Electric is establishing a remediation plan for all future versions of ASCO 5310 Single-C
Schneider Electric is establishing a remediation plan for all future versions of ASCO 5310 Single-Channel Remote Annunciator and ASCO 5350 Eight Channel Remote Annunciator that may include a fix for these vulnerabilities. We will update this document when the remediation is available. Until then, customers should immediately apply the following mitigations to reduce the risk of exploit: • Use remote annunciator devices only in a protected environment to minimize network exposure and ensure that they are not accessible from public internet or untrusted networks. • Change default password to help prevent unauthorized access to device settings and information. • Setup network segmentation and implement a firewall to block all unauthorized access to the annunciator port 80/HTTP. • For more details on the ASCO 5310 refer to “Installation Manual | ASCO 5310 ATS Remote Annunciator” which can be found here: https://www.se.com/ww/en/product-range/66129-asco-5310-singlechannelremote-annunciator/-documents • For more details on the ASCO 5350 refer to “Installation Manual | ASCO 5350 ATS Remote Annunciator” which can be found here: https://www.se.com/ww/en/product-range/66130-asco-5350-eight-channelremote-annunciator/-documents To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/security-notifications.jsp
Mitigation: Schneider Electric has prepared Version 3.1 Service Pack 1B of the EcoStruxure Operator Terminal Exp
Schneider Electric has prepared Version 3.1 Service Pack 1B of the EcoStruxure Operator Terminal Expert product with a fix for this vulnerability. This fix is also available through Schneider Electric Software Update (SESU). If users choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit:
Mitigation: Use Windows PC with UEFI technology. Users can identify if their PC uses the UEFI technology by usin
Use Windows PC with UEFI technology. Users can identify if their PC uses the UEFI technology by using the following system command: msinfo32.exe provided by Microsoft Windows. This command provides the system information. The section BIOS mode displays either “UEFI” or “LEGACY”. If the value is UEFI, the PC is not vulnerable, if the value is LEGACY then the PC is vulnerable.
Mitigation: If the value is UEFI, the PC is not vulnerable, if the value is LEGACY then the PC is vulnerable.
If the value is UEFI, the PC is not vulnerable, if the value is LEGACY then the PC is vulnerable.
Mitigation: Use EcoStruxure Operator Terminal Expert runtime software only on a trusted workstation.
Use EcoStruxure Operator Terminal Expert runtime software only on a trusted workstation.
Mitigation: For further information please refer to SEVD-2020-315-02.
For further information please refer to SEVD-2020-315-02.
Mitigation: Harden workstation following the best cybersecurity practices (antivirus, updated operating systems,
Harden workstation following the best cybersecurity practices (antivirus, updated operating systems, strong password policies, application white listing software, etc.) by following Schneider Electric's best practices guidelines.
Mitigation: Modicon M580 CPU (part numbers BMEP* and BMEH*): Set up network segmentation and implement a firewal
Modicon M580 CPU (part numbers BMEP* and BMEH*): Set up network segmentation and implement a firewall to block all unauthorized access to port 502/TCP.
Mitigation: For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices docume
For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document.
Mitigation: Minimize network exposure for all control system devices and systems and ensure that they are not ac
Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.
Mitigation: EcoStruxure Process Expert: Set up a VPN between the Modicon PLC controllers and the engineering wor
EcoStruxure Process Expert: Set up a VPN between the Modicon PLC controllers and the engineering workstation containing EcoStruxureTM Control.
Mitigation: Schneider Electric strongly recommends the following industry cybersecurity best practices:
Schneider Electric strongly recommends the following industry cybersecurity best practices:
Mitigation: EcoStruxure Control Expert: Set up a VPN between the Modicon PLC controllers and the engineering wor
EcoStruxure Control Expert: Set up a VPN between the Modicon PLC controllers and the engineering workstation containing EcoStruxureTM Control.
Mitigation: Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc., be
Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc., before use in the terminals or any node connected to these networks.
Mitigation: Never allow mobile devices that have connected to any other network besides the intended network to
Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.
Mitigation: Modicon M580 CPU (part numbers BMEP* and BMEH*): Configure the access control list following the rec
Modicon M580 CPU (part numbers BMEP* and BMEH*): Configure the access control list following the recommendations of the user manuals: Modicon M580, Hardware, Reference Manual.
Mitigation: Modicon M340 CPU (part numbers BMXP34*): Configure the access control list following the recommendat
Modicon M340 CPU (part numbers BMXP34*): Configure the access control list following the recommendations of the user manuals: Modicon M340 for Ethernet Communications Modules and Processors user manual in chapter "Messaging Configuration Parameters".
Mitigation: Modicon M580 CPU (part numbers BMEP* and BMEH*): Set up an application password in the project prope
Modicon M580 CPU (part numbers BMEP* and BMEH*): Set up an application password in the project properties.
Patch: EcoStruxure Process Expert: Version [V2021](https://www.se.com/ww/en/product-range/65406- ecostruxur
EcoStruxure Process Expert: Version [V2021](https://www.se.com/ww/en/product-range/65406- ecostruxure-process-expert/#software-and-firmware) is available for download and is not impacted by this vulnerability as the affected component has been removed from this version.
Mitigation: Modicon M340 CPU (part numbers BMXP34*): Set up network segmentation and implement a firewall to blo
Modicon M340 CPU (part numbers BMXP34*): Set up network segmentation and implement a firewall to block all unauthorized access to port 502/TCP.
Mitigation: EcoStruxure Control Expert: Harden the workstation running EcoStruxure Control Expert.
EcoStruxure Control Expert: Harden the workstation running EcoStruxure Control Expert.
Mitigation: When remote access is required, use secure methods, such as virtual private networks (VPNs). Recogni
When remote access is required, use secure methods, such as virtual private networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.
Mitigation: Never connect programming software to any network other than the network intended for that device.
Never connect programming software to any network other than the network intended for that device.
Mitigation: Install physical controls so no unauthorized personnel can access your industrial control and safety
Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.
Mitigation: EcoStruxure Process Expert: Harden the workstation running EcoStruxure Process Expert.
EcoStruxure Process Expert: Harden the workstation running EcoStruxure Process Expert.
Mitigation: Locate control and safety system networks and remote devices behind firewalls and isolate them from
Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.
Mitigation: For more information, see Schneider Electric's security advisory SEVD-2023-010-06.
For more information, see Schneider Electric's security advisory SEVD-2023-010-06.
Mitigation: Modicon M340 CPU (part numbers BMXP34*): Consider the use of external firewall devices such as EAGLE
Modicon M340 CPU (part numbers BMXP34*): Consider the use of external firewall devices such as EAGLE40-07 from Belden to establish VPN connections for M340 & M580 architectures. For more details refer to Modicon Controllers Platform - Cyber Security, Reference Manual chapter "How to protect M580 and M340 architectures with EAGLE40 using VPN".
Mitigation: Modicon M340 CPU (part numbers BMXP34*): Set up a secure communication according to the following gu
Modicon M340 CPU (part numbers BMXP34*): Set up a secure communication according to the following guideline "Modicon Controllers Platform Cyber Security Reference Manual," in chapter "Set up secured communications".
Mitigation: Modicon M340 CPU (part numbers BMXP34*): Set up an application password in the project properties.
Modicon M340 CPU (part numbers BMXP34*): Set up an application password in the project properties.
Mitigation: Schneider Electric has released the following remediations and mitigations for users to implement:
Schneider Electric has released the following remediations and mitigations for users to implement:
Mitigation: Modicon M580 CPU (part numbers BMEP* and BMEH*): Use a BMENUA0100 module and follow the instructions
Modicon M580 CPU (part numbers BMEP* and BMEH*): Use a BMENUA0100 module and follow the instructions to configure IPSEC feature as described in M580 - BMENUA0100 OPC UA Embedded Module, Installation and Configuration Guide chapter "Configuring the BMENUA0100 Cybersecurity Settings".
Mitigation: Place all controllers in locked cabinets and never leave them in the "Program" mode.
Place all controllers in locked cabinets and never leave them in the "Program" mode.
Mitigation: Modicon M580 CPU (part numbers BMEP* and BMEH*): Setup a secure communication following recommended
Modicon M580 CPU (part numbers BMEP* and BMEH*): Setup a secure communication following recommended guidelines in Modicon Controllers Platform - Cyber Security Reference Manual chapter "Setup secured communications".
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • Allow only admin user to configure windows service by restricting execute permission of sc.exe windows utility. • McAfee Application and Change Control software for application control to allow execution of whitelisted applications only. Refer to the Cybersecurity Application Note available https://www.se.com/ww/en/download/document/EIO0000004778/
Patch: Version v4.8.0.5715 of EcoStruxure Process Expert 2023 Software Package includes a fix for this vuln
Version v4.8.0.5715 of EcoStruxure Process Expert 2023 Software Package includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/65406-ecostruxure-processexpert/#software-and-firmware. Uninstall Previous Version 2023 (v4.8.0.5115) before installing Version 2023 (v4.8.0.5715). Version string could be found on engineering server console.
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit:• Allow execute permission for service control Windows utility only to admin user.• McAfee Application and Change Control software for application control to allow execution of whitelisted applications only. Refer to the Cybersecurity Application Note available https://www.se.com/ww/en/download/document/EIO0000004778/
Patch: Version 2025 of EcoStruxure Process Expert for AVEVA System Platform 2025 Software Package includes
Version 2025 of EcoStruxure Process Expert for AVEVA System Platform 2025 Software Package includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/55570689-ecostruxure-process-expert-for-aveva-system-platform/#software-and-firmware
Mitigation: Install physical controls so no unauthorized personnel can access industrial control and safety syst
Install physical controls so no unauthorized personnel can access industrial control and safety systems, components, peripheral equipment, and networks.
Mitigation: Schneider Electric recommends users using Easergy P5 upgrade to v01.402.101 and users using Easergy
Schneider Electric recommends users using Easergy P5 upgrade to v01.402.101 and users using Easergy P3 upgrade to version 30.205. These firmware upgrades include a fix for the identified vulnerabilities and are available upon request from Schneider Electric's Customer Care Center.
Mitigation: For more information see Schneider Electric's security notifications: SEVD-2022-011-03, SEVD-2022-01
For more information see Schneider Electric's security notifications: SEVD-2022-011-03, SEVD-2022-011-04
Mitigation: Disable the GOOSE service of the product to reduce the risk of exposure. If GOOSE is needed for the
Disable the GOOSE service of the product to reduce the risk of exposure. If GOOSE is needed for the application, use it only in a secure local area network.
Mitigation: Locate control and safety system networks and remote devices behind firewalls and isolate them from
Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.
Mitigation: Schneider Electric recommends users use appropriate patching methodologies when applying these patch
Schneider Electric recommends users use appropriate patching methodologies when applying these patches to their systems. Schneider Electric recommends the use of backups and an evaluation of the impact of these patches in a test and development environment or on an offline infrastructure. Contact Schneider Electric's Customer Care Center for assistance removing a patch.
Mitigation: Never allow mobile devices that have connected to any other network besides the intended network to
Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.
Mitigation: Place all controllers in locked cabinets and never leave them in the “Program” mode.
Place all controllers in locked cabinets and never leave them in the “Program” mode.
Mitigation: When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recogni
When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand VPNs are only as secure as the connected devices.
Mitigation: Never connect programming software to any network other than a network intended to for the devices.
Never connect programming software to any network other than a network intended to for the devices.
Mitigation: Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc., be
Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc., before use in the terminals or any node connected to these networks.
Mitigation: When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recogni
When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand VPNs are only as secure as the connected devices.
Mitigation: Minimize network exposure for all control system devices and systems and ensure they are not accessi
Minimize network exposure for all control system devices and systems and ensure they are not accessible from the Internet.
Mitigation: TrendMicro IPS
TrendMicro IPS
Mitigation: Woodward
Woodward
Mitigation: Sonicwall Firewalls
Sonicwall Firewalls
Mitigation: Xylem
Xylem
Mitigation: Siemens (SIPROTEC 5)
Siemens (SIPROTEC 5)
Mitigation: Xerox Printers
Xerox Printers
Mitigation: Avaya
Avaya
Mitigation: Siemens (RUGGEDCOM)
Siemens (RUGGEDCOM)
Mitigation: Wind River has identified the following specific workarounds and mitigations users can apply to redu
Wind River has identified the following specific workarounds and mitigations users can apply to reduce risk:
Mitigation: Siemens (Power Meters)
Siemens (Power Meters)
Mitigation: Schneider Electric
Schneider Electric
Mitigation: Additional vendors affected by the reported vulnerabilities have also released security advisories r
Additional vendors affected by the reported vulnerabilities have also released security advisories related to their affected products. Those advisories are as follows:
Mitigation: All affected products: To obtain patches, email [email protected] and indicate the VxWorks major v
All affected products: To obtain patches, email [email protected] and indicate the VxWorks major version for which you need source patches.
Mitigation: Mitsubishi Electric
Mitsubishi Electric
Mitigation: IDEC Corporation
IDEC Corporation
Mitigation: TRON Forum reports they only publish the specification for ITRON RTOS. Various implementations are u
TRON Forum reports they only publish the specification for ITRON RTOS. Various implementations are used by many users world-wide and are created by various implementors (some commercial, and some academic and some government) according the specification document. TRON Forum, the caretaker of the ITRON specification, has not endorsed the use of any particular TCP/IP stack including one from Interpeak. The choice of TCP/IP stack is up to the RTOS vendor and application developers, and thus each application user needs to check whether TCP/IP stack developed by Interpeak is used inside their application. TRON Forum will send out a preliminary warning to members by mailing list to notify implementors of the reported vulnerabilities.
Mitigation: Green Hills Software has proactively informed affected users and offers consulting services to imple
Green Hills Software has proactively informed affected users and offers consulting services to implement mitigations.
Mitigation: Rockwell Automation
Rockwell Automation
Mitigation: Microsoft states they have no history of support or integration work to include IPnet and have not r
Microsoft states they have no history of support or integration work to include IPnet and have not released a version of ThreadX bundled with IPnet. Microsoft does caution that some hardware makers could have used ThreadX and a custom set IPnet in the hardware.
Mitigation: NetApp
NetApp
Mitigation: All affected products: For more detailed information on the vulnerabilities and the mitigating contr
All affected products: For more detailed information on the vulnerabilities and the mitigating controls, please see the Wind River advisory at: https://www.windriver.com/security/announcements/tcp-ip-network-stack-ipnet-urgent11/
Mitigation: ExtremeNetworks
ExtremeNetworks
Mitigation: Enea has no IPNet customers on support contract in the United States.
Enea has no IPNet customers on support contract in the United States.
Mitigation: ABB
ABB
Mitigation: ZebOS by IP Infusion has not yet responded to CISA inquiries.
ZebOS by IP Infusion has not yet responded to CISA inquiries.
Mitigation: All affected products: To obtain patches, email [email protected] and indicate the VxWorks major v
All affected products: To obtain patches, email [email protected] and indicate the VxWorks major version for which you need source patches.
Mitigation: Belden Industrial Devices
Belden Industrial Devices
Patch: Enea has no IPNet customers on support contract in the United States.
Enea has no IPNet customers on support contract in the United States.
Patch: Wind River has produced controls and patches to mitigate the reported vulnerabilities. To obtain pat
Wind River has produced controls and patches to mitigate the reported vulnerabilities. To obtain patches, email [email protected] and indicate the VxWorks major version for which you need source patches.
Patch: TRON Forum reports they only publish the specification for ITRON RTOS. Various implementations are u
TRON Forum reports they only publish the specification for ITRON RTOS. Various implementations are used by many users world-wide and are created by various implementors (some commercial, and some academic and some government) according the specification document. TRON Forum, the caretaker of the ITRON specification, has not endorsed the use of any particular TCP/IP stack including one from Interpeak. The choice of TCP/IP stack is up to the RTOS vendor and application developers, and thus each application user needs to check whether TCP/IP stack developed by Interpeak is used inside their application. TRON Forum will send out a preliminary warning to members by mailing list to notify implementors of the reported vulnerabilities.
Patch: Microsoft states they have no history of support or integration work to include IPnet and have not r
Microsoft states they have no history of support or integration work to include IPnet and have not released a version of ThreadX bundled with IPnet. Microsoft does caution that some hardware makers could have used ThreadX and a custom set IPnet in the hardware.
Patch: Green Hills Software has proactively informed affected users and offers consulting services to imple
Green Hills Software has proactively informed affected users and offers consulting services to implement mitigations.
Patch: Additional vendors affected by the reported vulnerabilities have also released security advisories r
Additional vendors affected by the reported vulnerabilities have also released security advisories related to their affected products. Those advisories are as follows:
Patch: For more detailed information on the vulnerabilities and the mitigating controls, please see the Win
For more detailed information on the vulnerabilities and the mitigating controls, please see the Wind River advisory.
Patch: Update to V4.41 or later version
Update to V4.41 or later version
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • Implement strong access controls to limit system access to authorized personnel. • Use multi factor authentication if using EBO version 7.0 or later. • Use firewalls to segregate networks and protect the building management system. • Regularly monitor system activity. • Ensure you are following [EBO hardening guidelines](https://ecostruxure-building-help.se.com/bms/Topics/show.castle?id=14923&productversion=7.1&locale=en-US).
Mitigation: For more information see the associated Schneider Electric security advisory SEVD-2026-041-02, title
For more information see the associated Schneider Electric security advisory SEVD-2026-041-02, titled "Multiple Vulnerabilities on EcoStruxure Building Operation Workstation and EcoStruxure Building Operation WebStation". • PDF Version: [https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-041-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-041-02.pdf](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-041-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-041-02.pdf) • CSAF Version: [https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-041-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-041-02.json](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-041-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-041-02.json).
Patch: The following versions of EcoStruxure Building Operation Workstation and EcoStruxure Building Operat
The following versions of EcoStruxure Building Operation Workstation and EcoStruxure Building Operation WebStation includes a fix for CVE-2026-1226: • 6.0.4.7000 (CP5) Step 1: Locate the appropriate version for your system here: https://www.se.com/myschneider/documentsDownloadCenter/detail?id=EBO-Patch-v6-0 Step 2: Download ‘EcoStruxure Building Operation Patch v6.0‘ Step 3: Follow the installation instructions provided in the accompanying readme file. Additionally, ensure you are following the [EBO hardening guidelines](https://ecostruxure-building-help.se.com/bms/Topics/show.castle?id=14923&productversion=7.1&locale=en-US).
Patch: The following versions of EcoStruxure Building Operation Workstation and EcoStruxure Building Operat
The following versions of EcoStruxure Building Operation Workstation and EcoStruxure Building Operation WebStation include a fix for CVE-2026-1226:  • 7.0.2 Step 1: Navigate to this link: https://www.se.com/myschneider/documentsDownloadCenter/detail?id=EBO-Patch-v7-0 Step 2: Download 'EcoStruxure Building Operation Patch v7.0' Step 3: Follow the installation instructions provided in the accompanying readme file. Additionally, ensure you are following the [EBO hardening guidelines](https://ecostruxure-building-help.se.com/bms/Topics/show.castle?id=14923&productversion=7.1&locale=en-US).
Mitigation: Schneider Electric is establishing a remediation plan for the Saitel DP RTU product that will inclu
Schneider Electric is establishing a remediation plan for the Saitel DP RTU product that will include a fix for this vulnerability. We will update this document when the remediation is available. Until then, customers should immediately apply the following mitigations to reduce the risk of exploit: • Limit physical or console access to trusted users only • Enforce password policy (strong password and update password regularly). Password updates can be applied using the EcoStruxure™ Cybersecurity Admin Expert tool, or device webpage. Customers should also consider upgrading to the latest product offering PowerLogic™ T500 Substation Controller
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • Limit physical or console access to trusted users only • Ensure that configuration files used by privileged daemons are owned by root, not writable by nonprivileged users, and set to minimum permissions when technically feasible to prevent unauthorized modification.
Patch: HUe Firmware version 11.06.30 includes a fix for this vulnerability and is available for download h
HUe Firmware version 11.06.30 includes a fix for this vulnerability and is available for download here: https://se.com/ww/en/product-countryselector/?pageType=productrange&sourceId=62685#software-and-firmware
Mitigation: Schneider Electric’s Modicon Quantum and Quantum Safety controllers have reached their end of life a
Schneider Electric’s Modicon Quantum and Quantum Safety controllers have reached their end of life and are no longer commercially available. They have been replaced by the Modicon M580 or M580 Safety ePAC controller, our most current product offer. Customers should strongly consider migrating to the Modicon M580 ePAC. Please contact your local Schneider Electric technical support for more information. To mitigate the risks associated with Modbus/ weaknesses, users should immediately: • Set up network segmentation and implement a firewall to block all unauthorized access to port 502/TCP • Configure the Access Control List feature as mentioned in “Quantum using EcoStruxure Control Expert - TCP/IP Configuration, User Manual” in chapter “Software Settings for Ethernet Communication / Messaging / Quantum NOE Ethernet Messaging Configuration”: https://www.se.com/ww/en/download/document/33002467K01000/
Mitigation: Schneider Electric’s Modicon Premium controllers have reached their end of life and are no longer co
Schneider Electric’s Modicon Premium controllers have reached their end of life and are no longer commercially available. They have been replaced by the Modicon M580 ePAC controller, our most current product offer. Customers should strongly consider migrating to the Modicon M580 ePAC. Please contact your local Schneider Electric technical support for more information. To mitigate the risks associated with Modbus/ weaknesses, users should immediately: • Set up network segmentation and implement a firewall to block all unauthorized access to port 502/TCP • Configure the Access Control List following the recommendations of the user manual “Premium and Atrium using EcoStruxure Control Expert - Ethernet Network Modules, User Manual” in chapters “Connection configuration parameters / TCP/IP Services Configuration Parameters / Connection Configuration Parameters”: https://www.se.com/ww/en/download/document/35006192K01000/
Patch: Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download
Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download here: 140CPU67861 [C] - https://www.schneider-electric.com/en/download/document/Quantum_140CPU67861_SV3.60
Patch: Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download
Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download here: 140CPU67160 [C] - https://www.schneider-electric.com/en/download/document/Quantum_140CPU67160_SV3.60
Patch: Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download
Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download here: 140CPU67260 [C] - https://www.schneider-electric.com/en/download/document/Quantum_140CPU67260_SV3.60
Patch: Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download
Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download here: 140CPU67261 [C] - https://www.schneider-electric.com/en/download/document/Quantum_140CPU67261_SV3.60
Patch: Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download
Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download here: 140CPU67261 [C] - https://www.schneider-electric.com/en/download/document/Quantum_140CPU67261_SV3.60
Patch: Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download
Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download here: 140CPU65150 [C] & 140CPU65160 [C] - https://www.schneider-electric.com/en/download/document/Quantum_140CPU651X0_SV3.60
Patch: Please contact your Schneider Electric customer support to get Premium V3.20 firmware. TSXP57104M
Please contact your Schneider Electric customer support to get Premium V3.20 firmware. TSXP57104M [C] TSXP57154M [C] TSXP571634M [C] TSXP57204M [C] TSXP572634M [C] TSXP57254M [C] TSXP57304M [C] TSXP573634M [C] TSXP57354M [C] TSXP574634M [C] TSXP57454M [C] TSXP575634M [C] TSXP57554M [C] TSXP576634M [C] TSXH5724M [C] TSXH5744M [C]
Patch: Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download
Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download here: 140CPU65860 [C] - https://www.schneider-electric.com/en/download/document/Quantum_140CPU65860_SV3.60
Mitigation: To mitigate the risks associated with Modbus/ weaknesses, users should immediately: • Set up netwo
To mitigate the risks associated with Modbus/ weaknesses, users should immediately: • Set up network segmentation and implement a firewall to block all unauthorized access to port 502/TCP • Configure the Access Control List following the recommendations of the user manual “Premium and Atrium using EcoStruxure Control Expert - Ethernet Network Modules, User Manual” in chapters “Connection configuration parameters / TCP/IP Services Configuration Parameters / Connection Configuration Parameters”: https://www.se.com/ww/en/download/document/35006192K01000/
Mitigation: Schneider Electric has identified the following specific workarounds and mitigations users can apply
Schneider Electric has identified the following specific workarounds and mitigations users can apply to reduce risk:
Patch: (CVE-2024-10498) Schneider Electric Power Logic HDPM6000 Versions 0.62.7 and prior: Version v0.62.11
(CVE-2024-10498) Schneider Electric Power Logic HDPM6000 Versions 0.62.7 and prior: Version v0.62.11 and newer of HDPM6000 includes a fix for these vulnerabilities and is available for download here. A device restart will occur as part of the firmware update process if conducted through the web user interface. If the upgrade is performed using the HDPM6000 Manager software, the device will need to be restarted manually to apply the update.
Patch: (CVE-2024-10498) Schneider Electric Power Logic HDPM6000 Versions 0.62.7 and prior: If users choose
(CVE-2024-10498) Schneider Electric Power Logic HDPM6000 Versions 0.62.7 and prior: If users choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: Ensure that the device is not accessible via the Modbus protocol outside the local network segment by applying appropriate firewalls configuration and controls, and that access to the network segment is protected and controlled.
Mitigation: For more information, please see Schneider Electric's advisory.
For more information, please see Schneider Electric's advisory.
Patch: Update to V2.17.1 or later version
Update to V2.17.1 or later version
Mitigation: Festo has identified the following specific workarounds and mitigations users can apply to reduce ri
Festo has identified the following specific workarounds and mitigations users can apply to reduce risk:
Mitigation: For more information see the associated Festo SE & Co. KG security advisory FSA-202202 FSA-202202: F
For more information see the associated Festo SE & Co. KG security advisory FSA-202202 FSA-202202: Festo: Controller CECC-S,LK,D family <= 2.3.8.1 - multiple vulnerabilities in CODESYS V3 runtime system - HTML, FSA-202202: Festo: Controller CECC-S,LK,D family <= 2.3.8.1 - multiple vulnerabilities in CODESYS V3 runtime system - CSAF.
Mitigation: The following product versions have been fixed:
The following product versions have been fixed:
Mitigation: (CVE-2018-20026, CVE-2019-9010¸ CVE-2010-5250, CVE-2019-9008, CVE-2019-18858, CVE-2019-13548, CVE-20
(CVE-2018-20026, CVE-2019-9010¸ CVE-2010-5250, CVE-2019-9008, CVE-2019-18858, CVE-2019-13548, CVE-2019-13542, CVE-2019-9009, CVE-2019-9012, CVE-2020-7052, CVE-2019-13532, CVE-2018-20025, CVE-2018-10612, CVE-2017-3735) (Product Group: Festo Firmware (R05 (17.06.2016) = 2.3.8.0) installed on Festo Hardware Controller CECC-D(All versions), Festo Firmware (R06 (11.10.2016) = 2.3.8.1) installed on Festo Hardware Controller CECC-LK(All versions), Festo Firmware (R05 (17.06.2016) = 2.3.8.0) installed on Festo Hardware Controller CECC-S(All versions)): Update to version 2.4.2.0. This also fixes CODESYS Advisory 2017-01, CODESYS Advisory 2017-03, CODESYS Advisory 2017-06, CODESYS Advisory 2017-07, CODESYS Advisory 2017-09, CODESYS Advisory 2018-04, CODESYS Advisory 2018-05, CODESYS Advisory 2018-07, CODESYS Advisory 2018-11.
Mitigation: For more information see the associated Festo SE & Co. KG security advisory FSA-202202 FSA-202202: F
For more information see the associated Festo SE & Co. KG security advisory FSA-202202 FSA-202202: Festo: Controller CECC-S,LK,D family <= 2.3.8.1 - multiple vulnerabilities in CODESYS V3 runtime system - HTML, FSA-202202: Festo: Controller CECC-S,LK,D family <= 2.3.8.1 - multiple vulnerabilities in CODESYS V3 runtime system - CSAF.
Patch: Additional vendors affected by the reported vulnerabilities have also released security advisories r
Additional vendors affected by the reported vulnerabilities have also released security advisories related to their affected products. Those advisories are as follows:
Mitigation: For more information, see AVEVA's Security Bulletin AVEVA-2025-006 or AVEVA's bulletins page.
For more information, see AVEVA's Security Bulletin AVEVA-2025-006 or AVEVA's bulletins page.
Mitigation: The following general defensive measures are recommended:
The following general defensive measures are recommended:
Patch: If passwords are being used as function parameters inside project documents (such as scripts or work
If passwords are being used as function parameters inside project documents (such as scripts or worksheets), it is recommended to remove those passwords and use project tags instead. For more information on tags refer to AVEVA Edge "Technical Reference Manual" > Tags and the Tag Database > About Tags and the Project Database.
Mitigation: For more information, see AVEVA's Security Bulletin AVEVA-2025-006 or AVEVA's bulletins page.
For more information, see AVEVA's Security Bulletin AVEVA-2025-006 or AVEVA's bulletins page.
Patch: Apply data-protection at the project level with a strong master password. For configuration step-by-
Apply data-protection at the project level with a strong master password. For configuration step-by-step refer to AVEVA Edge "Technical Reference Manual" > Project Overview > Configuring Additional Project Settings > Options Tab > Data Protection.
Mitigation: For projects that cannot be migrated (e.g. backups or transient copies), evaluate the risk of potent
For projects that cannot be migrated (e.g. backups or transient copies), evaluate the risk of potential password leakage from these files and implement stricter read access controls to protect these unsafe files.
Patch: Apply AVEVA Edge 2023 R2 P01 Security Update and migrate old project files.
Apply AVEVA Edge 2023 R2 P01 Security Update and migrate old project files.
Mitigation: Maintain a trusted chain-of-custody on project files during creation, modification, distribution, an
Maintain a trusted chain-of-custody on project files during creation, modification, distribution, and use.
Patch: Important: Edge project migration from older versions to 2023 R2 P01 is one-way due to the change in
Important: Edge project migration from older versions to 2023 R2 P01 is one-way due to the change in password hashing algorithms.
Mitigation: For information on how to reach AVEVA support for your product, please refer to this link: AVEVA Cu
For information on how to reach AVEVA support for your product, please refer to this link: AVEVA Customer Support.
Mitigation: Access Control Lists should be applied to all folders where users will save and load project files.
Access Control Lists should be applied to all folders where users will save and load project files.
Patch: Require AVEVA Edge users to change their passwords.
Require AVEVA Edge users to change their passwords.
Mitigation: AVEVA recommends that organizations evaluate the impact of this vulnerability based on their operati
AVEVA recommends that organizations evaluate the impact of this vulnerability based on their operational environment, architecture, and product implementation.
Mitigation: Users using the affected product versions should take the following actions to mitigate the risk of
Users using the affected product versions should take the following actions to mitigate the risk of exploit:
Patch: Version 2023.1 Patch 1 of EcoStruxure Machine SCADA Expert includes a fix for this vulnerability and
Version 2023.1 Patch 1 of EcoStruxure Machine SCADA Expert includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/63734-ecostruxure-machine-scada-expert/#software-and-firmware For additional details please refer to the supplied ReadMe help file in Version 2023.1 Patch 1
Patch: Version 2023.1 Patch 1 of Pro-face BLUE Open Studio includes a fix for this vulnerability and is ava
Version 2023.1 Patch 1 of Pro-face BLUE Open Studio includes a fix for this vulnerability and is available for download here: https://www.proface.com/en/hmi_design_studio/bos/page/installer For additional details please refer to the supplied Release Notes file in Version 2023.1 Patch 1
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • Access Control Lists should be applied to all folders where users will save and load project files. • Maintain a trusted chain-of-custody on project files during creation, modification, distribution, backups, and use. • Apply data-protection at the project level with a strong master password. For configuration step-by-step refer to “Technical Reference Manual” > Project Overview > Configuring Additional Project Settings > Options Tab > Data Protection. • If passwords are being used as function parameters inside project documents (such as scripts or worksheets), it is recommended to remove those passwords and use project tags instead. For more information on tags refer to “Technical Reference Manual” > Tags and the Tag Database > About Tags and the Project Database.
Patch: CAPE 14 installations installed from material dated 2020-09-15 or later are not affected, as they co
CAPE 14 installations installed from material dated 2020-09-15 or later are not affected, as they contain a fixed version of CodeMeter Runtime
Patch: Update to V10.2 Upd1 or later version
Update to V10.2 Upd1 or later version
Mitigation: All products affected by CVE-2020-14513 or CVE-2020-14515: Do not import license files from untruste
All products affected by CVE-2020-14513 or CVE-2020-14515: Do not import license files from untrusted sources.
Mitigation: SIMATIC WinCC OA V3.17: Update to V3.17 P007 or later version to fix all issues. For patch levels <
SIMATIC WinCC OA V3.17: Update to V3.17 P007 or later version to fix all issues. For patch levels < P007, the following measures apply: CVE-2020-14509, CVE-2020-14517, and CVE-2020-16233 are already mitigated by default, as no external connections to port 22350/tcp are allowed. Additionally, an update to SIMATIC WinCC OA version V3.17 P006 partially fixes CVE-2020-14517. CVE-2020-14519: Disable the WebSockets API of CodeMeter Runtime.
Patch: Update to Process Historian 2019 SP1 Update 1 contained in PCS neo V3.0 SP1 Update 1
Update to Process Historian 2019 SP1 Update 1 contained in PCS neo V3.0 SP1 Update 1
Mitigation: SICAM 230 To fix all issues for existing installations, update SICAM 230 to V8.00 or later version.
SICAM 230 To fix all issues for existing installations, update SICAM 230 to V8.00 or later version. Then update CodeMeter Runtime to V7.10a: Download the package from WIBU Systems User Software website. Install it on SICAM 230 systems according to the procedure documented in chapter 9 of COPA-DATA Security Vulnerability Announcement 2020_1.
Mitigation: If CAPE 14 was initially installed using earlier material, see the recommendations from section Work
If CAPE 14 was initially installed using earlier material, see the recommendations from section Workarounds and Mitigations
Mitigation: For earlier versions see the recommendations from section Workarounds and Mitigations
For earlier versions see the recommendations from section Workarounds and Mitigations
Patch: Update to V3.17 P007 or later version
Update to V3.17 P007 or later version
Mitigation: SIMIT Simulation Platform (Versions >= V10.0 and < V10.2 Upd1): To fix all issues for existing inst
SIMIT Simulation Platform (Versions >= V10.0 and < V10.2 Upd1): To fix all issues for existing installations, update CodeMeter Runtime to V7.10a: Download from the WIBU Systems User Software website and install on the SIMIT system.
Mitigation: Update to SICAM 230 V8.00 or later version. Install WIBU Systems CodeMeter Runtime V7.10a to fix all
Update to SICAM 230 V8.00 or later version. Install WIBU Systems CodeMeter Runtime V7.10a to fix all issues
Patch: Update to V1.0 SP1 or later version
Update to V1.0 SP1 or later version
Patch: Update to Information Server 2019 SP1 Update 1 contained in PCS neo V3.0 SP1 Update 1
Update to Information Server 2019 SP1 Update 1 contained in PCS neo V3.0 SP1 Update 1
Mitigation: PSS CAPE Protection Simulation Platform (if initally installed from material dated earlier than 2020
PSS CAPE Protection Simulation Platform (if initally installed from material dated earlier than 2020-09-15): Update CodeMeter Runtime to V7.10a: Download the package from https://www.psscape.com/codemeter and install it the same way as previous versions documented in the PSS CAPE 14 Installation Manual. Contact PSS®CAPE Support at [email protected] if you need assistance with patching affected systems.
Mitigation: SINEC INS (Versions < V1.0 SP1 only): Update CodeMeter Runtime to V7.10a: Download the package "Cod
SINEC INS (Versions < V1.0 SP1 only): Update CodeMeter Runtime to V7.10a: Download the package "CodeMeter User Runtime for Linux, version 7.10a, Driver-only" from the WIBU Systems User Software website. Install it on the system which runs SINEC INS by executing the following command: sudo dpkg --force-depends --force-confnew -i codemeter-lite_7.10.4196.501_amd64.deb
Mitigation: See also the recommendations from section Workarounds and Mitigations
See also the recommendations from section Workarounds and Mitigations
Patch: Update to V3.0 SP1 Update 1 or later version
Update to V3.0 SP1 Update 1 or later version
Patch: For more information on products dependent on the affected CodeMeter see the following vendor securi
For more information on products dependent on the affected CodeMeter see the following vendor security advisories:
Patch: Wibu-Systems recommends the following:
Wibu-Systems recommends the following:
Patch: For more information please see Wibu-Systems ' security advisories:
For more information please see Wibu-Systems ' security advisories:
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • Setup network segmentation and implement a firewall to block all unauthorized access to FTP port 21/TCP on the devices. • FTP service is disabled by default. Deactivate the FTP service after use when not needed. • Configure the Access Control List following the recommendations of the user manuals: o “Modicon M340 for Ethernet Communications Modules and Processors User Manual” in chapter “Messaging Configuration Parameters”: https://www.se.com/ww/en/download/document/31 007131K01000/
Patch: Version SV6.80 of BMXNOE0110 includes a fix for this vulnerability and is available for download he
Version SV6.80 of BMXNOE0110 includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product/BMXNOE0110/ethernet-tcp-ip-network-module-modicon-m340-automation-platform-flash-memory-card-internal-ram-16-mb-1-x-rj45-10-100/
Patch: Version SV3.70 of Modicon M340 includes a fix for this vulnerability and is available for download h
Version SV3.70 of Modicon M340 includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/1468-modicon-m340/#software-and-firmware
Patch: Version SV3.60 of BMXNOE0100 includes a fix for this vulnerability and is available for download he
Version SV3.60 of BMXNOE0100 includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product/BMXNOE0100/network-module-modicon-m340-modbus-tcp-1-x-rj45-flash-memory-card
Mitigation: The Wiser Home Controller WHC-5918A product has been discontinued and is out of support. Customers
The Wiser Home Controller WHC-5918A product has been discontinued and is out of support. Customers should consider upgrading to the latest product offering, C-Bus, Home Controller, SpaceLogic IP, Free Standing, 24V DC, 5200WHC2, or removing the Wiser Home Controller WHC-5918A from service.
Mitigation: Locate control and safety system networks and remote devices behind firewalls and isolate them from
Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.
Mitigation: Place all controllers in locked cabinets and never leave them in the "Program" mode.
Place all controllers in locked cabinets and never leave them in the "Program" mode.
Mitigation: Install physical controls so no unauthorized personnel can access your industrial control and safety
Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.
Mitigation: Never connect programming software to any network other than the network intended for that device.
Never connect programming software to any network other than the network intended for that device.
Mitigation: Schneider Electric provided version 16.0.0.23212 of Dashboard to address these vulnerabilities.
Schneider Electric provided version 16.0.0.23212 of Dashboard to address these vulnerabilities.
Mitigation: Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. bef
Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.
Mitigation: Never allow mobile devices that have connected to any network besides the intended network to connec
Never allow mobile devices that have connected to any network besides the intended network to connect to the safety or control networks without proper sanitation.
Mitigation: Follow the general security recommendation below and verify that devices are isolated on a private n
Follow the general security recommendation below and verify that devices are isolated on a private network and firewalls are configured with strict boundaries for devices that require remote access.
Mitigation: If users choose not to apply the remediation provided above, they should immediately apply the follo
If users choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit:
Mitigation: Minimize network exposure for all control system devices and systems and ensure that they are not ac
Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the internet.
Mitigation: Schneider Electric security notification SEVD-2023-255-01.
Schneider Electric security notification SEVD-2023-255-01.
Mitigation: For more information, see:
For more information, see:
Mitigation: Schneider Electric security notification SEVD-2023-164-02 and
Schneider Electric security notification SEVD-2023-164-02 and
Mitigation: Disable the IGSS Update Service as an Administrator, and only enable it while installing new updates
Disable the IGSS Update Service as an Administrator, and only enable it while installing new updates.
Mitigation: Review and implement the security guideline for IGSS on securing an IGSS SCADAinstallation.
Review and implement the security guideline for IGSS on securing an IGSS SCADAinstallation.
Mitigation: Schneider Electric recommends the following industry cybersecurity best practices:
Schneider Electric recommends the following industry cybersecurity best practices:
Mitigation: When remote access is required, use secure methods, such as virtual private networks (VPNs). Recogni
When remote access is required, use secure methods, such as virtual private networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.
Mitigation: The update is available for download through IGSS Master > Update IGSS Software or from the Schneide
The update is available for download through IGSS Master > Update IGSS Software or from the Schneider Electric support page.
Patch: The following versions of Enterprise Server, Enterprise Central, Workstation include a fix for these
The following versions of Enterprise Server, Enterprise Central, Workstation include a fix for these vulnerabilities: • 7.0.2.348 Step1: Locate the appropriate version for your system on the [EcoExpert Software Center](https://ecoxpert.se.com/software-center/building-automation/ebo-system/building-operation-2025-version-7.0). Step 2: Follow the installation instructions provided in the accompanying readme file. Additionally, ensure you are following the [EBO hardening guidelines](https://ecostruxure-building-help.se.com/bms/Topics/show.castle?id=14923&productversion=7).
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: * Implement strong access controls to limit system access to authorized personnel. Use multi factor authentication if using EBO version 7.0 or later * Use firewalls to segregate networks and protect the building management system * Regularly monitor system activity * Ensure you are following [EBO hardening guidelines](https://ecostruxure-building-help.se.com/bms/Topics/show.castle?id=14923&productversion=7).
Patch: The following versions of Enterprise Server, Enterprise Central, Workstation include a fix for these
The following versions of Enterprise Server, Enterprise Central, Workstation include a fix for these vulnerabilities: • 5.0.3.17009 (CP16) Step1: Locate the appropriate version for your system on the [EcoExpert Software Center](https://ecoxpert.se.com/de/software-center/building-automation/ebo-system/building-operation-2023-version-5.0). Step 2: Follow the installation instructions provided in the accompanying readme file. Additionally, ensure you are following the [EBO hardening guidelines](https://ecostruxure-building-help.se.com/bms/Topics/show.castle?id=14923&productversion=7).
Patch: The following versions of Enterprise Server, Enterprise Central, Workstation include a fix for these
The following versions of Enterprise Server, Enterprise Central, Workstation include a fix for these vulnerabilities: • 6.0.4.10001 (CP8) Step1: Locate the appropriate version for your system on the [EcoExpert Software Center](https://ecoxpert.se.com/de/software-center/building-automation/ebo-system/building-operation-2024-version-6.0). Step 2: Follow the installation instructions provided in the accompanying readme file. Additionally, ensure you are following the [EBO hardening guidelines](https://ecostruxure-building-help.se.com/bms/Topics/show.castle?id=14923&productversion=7).
Patch: Hotfix_199767_release and Hotfix_273686_release.12.0 are available for EcoStruxure Power Monitoring
Hotfix_199767_release and Hotfix_273686_release.12.0 are available for EcoStruxure Power Monitoring Expert (PME) that includes a fix for the vulnerabilities CVE-2025-54924, CVE-2025-54925, and CVE-2025-54927. Contact Schneider Electric’s Customer Care Center for assistance applying these hotfixes. In addition to applying the hotfixes noted above, you are encouraged to review the mitigations listed below.
Mitigation: EcoStruxure Power Monitoring Expert (PME) 2022 version has reached its end of life and is no longer
EcoStruxure Power Monitoring Expert (PME) 2022 version has reached its end of life and is no longer supported. Customers should immediately apply the following mitigations to reduce the risk of exploit for CVE-2025-54924, CVE-2025-54925, and CVE-2025-54927:• Ensure your deployment of PME has followed the cybersecurity hardening guidelines provided with the product. https://product-help.schneider-electric.com/EcoStruxure/Power-Monitoring-Expert-2024/content/2_planning/cybersecurity/cyber-planningrecactions.htm • Ensure PME is running in an isolated network • Deploy and configure the Windows firewall to limit access to appropriate network segments. • Enforce complex password policies. • Review Server Access Permissions • Conduct an audit of all Windows-authenticated users who currently have access to PME. Repeat this audit of your system periodically. • Identify all accounts with access rights, especially those with elevated privileges or remote access. • Limit access to essential users only. • Revoke access for any user accounts that are not critical for system functionality or daily operations. • Apply the principle of least privilege to ensure users have only the access necessary for their role(s). Customers should also consider upgrading to the latest product offering EcoStruxure Power Monitoring Expert (PME) 2024 R2 to resolve this issue.
Patch: Hotfix_199767 and Hotfix_273686_release.12.0 is available for EcoStruxure Power Monitoring Expert (P
Hotfix_199767 and Hotfix_273686_release.12.0 is available for EcoStruxure Power Monitoring Expert (PME) 2023R2 that includes a fix for the vulnerabilities CVE-2025-54924, CVE-2025-54925, and CVE-2025-54927. Contact Schneider Electric’s Customer Care Center to determine if you are running EcoStruxure Power Monitoring Expert (PME) 2023R2 as part of your solution. Customers running this version of PME can work with Schneider Electric’s Customer Care Center for assistance applying this hotfix. OR Contact Schneider Electric’s Customer Care Center to determine if you are running EcoStruxure Power Monitoring Expert (PME) 2023 as part of your solution. Customers running this version of PME can work with Schneider Electric’s Customer Care Center for assistance upgrading to EcoStruxure Power Monitoring Expert (PME) 2023 R2 and then help applying the hotfix.
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: Ensure your deployment of PME has followed the cybersecurity hardening guidelines provided with the product. https://product-help.schneider-electric.com/EcoStruxure/Power-Monitoring-Expert-2024/content/2_planning/cybersecurity/cyber-planningrecactions.htm Ensure PME is running in an isolated network. Deploy and configure the Windows firewall to limit access to appropriate network segments. Enforce complex password policies. Review Server Access Permissions: Conduct an audit of all Windows-authenticated users who currently have access to PME. Repeat this audit of your system periodically. Identify all accounts with access rights, especially those with elevated privileges or remote access. Limit access to essential users. Revoke access for any user accounts that are not critical for system functionality or day-to-day operations. Apply the principle of least privilege to ensure users have only the access needed for their role
Patch: Hotfix_256448_Diagrams-Release.13.1.25182.01 available for EcoStruxure™ Power Monitoring Expert (P
Hotfix_256448_Diagrams-Release.13.1.25182.01 available for EcoStruxure™ Power Monitoring Expert (PME) that includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center to download this hotfix.
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigation to reduce the risk of exploit: • We recommend you remove your TGML diagrams from your multitenant managed system or onpremises system and revert to using Vista diagrams.
Patch: Hotfix_256448_Diagrams-Release.13.0.25182.0 available for EcoStruxure™ Power Monitoring Expert (PM
Hotfix_256448_Diagrams-Release.13.0.25182.0 available for EcoStruxure™ Power Monitoring Expert (PME) that includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center to download this hotfix.
Patch: Hotfix_199767 available for EcoStruxure™ Power Monitoring Expert (PME) that includes a fix for thi
Hotfix_199767 available for EcoStruxure™ Power Monitoring Expert (PME) that includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center to download this hotfix.
Patch: Hotfix_199767 is available for EcoStruxure™ Power Monitoring Expert (PME) that includes a fix for
Hotfix_199767 is available for EcoStruxure™ Power Monitoring Expert (PME) that includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center to download this hotfix.
Patch: Hotfix_256448_Diagrams-Release.13.0.25182.01 Contact Schneider Electric’s Customer Care Center to
Hotfix_256448_Diagrams-Release.13.0.25182.01 Contact Schneider Electric’s Customer Care Center to download this hotfix.
Mitigation: Place all controllers in locked cabinets and never leave them in “Program” mode.
Place all controllers in locked cabinets and never leave them in “Program” mode.
Mitigation: Scan all methods of mobile data exchange with the isolated network (e.g., CDs, USB drives, etc.) bef
Scan all methods of mobile data exchange with the isolated network (e.g., CDs, USB drives, etc.) before use in the terminals or any node connected to these networks.
Mitigation: Minimize network exposure for all control system devices and systems and ensure that they are not ac
Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.
Mitigation: Install physical controls so no unauthorized personnel can access industrial control and safety syst
Install physical controls so no unauthorized personnel can access industrial control and safety systems, components, peripheral equipment, and networks.
Mitigation: Never connect programming software to any network other than the network for which the devices are i
Never connect programming software to any network other than the network for which the devices are intended.
Mitigation: Refer to Schneider Electric's security bulletin SEVD-2020-315-06 for specific mitigation details.
Refer to Schneider Electric's security bulletin SEVD-2020-315-06 for specific mitigation details.
Mitigation: Schneider Electric recommends users upgrade to v2.7.1, which is available from the Schneider Electri
Schneider Electric recommends users upgrade to v2.7.1, which is available from the Schneider Electric Customer Care Center. Alternatively, users may disable port forwarding in the product firewall.
Mitigation: Locate control and safety system networks and remote devices behind firewalls and isolate them from
Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.
Mitigation: For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices docume
For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document.
Mitigation: Never allow mobile devices that have connected to any other network, besides the intended network, t
Never allow mobile devices that have connected to any other network, besides the intended network, to connect to the safety or control networks without proper sanitation.
Mitigation: When remote access is required, use secure methods, such as virtual private networks (VPNs). Recogni
When remote access is required, use secure methods, such as virtual private networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.
Mitigation: Use encrypted communication links.
Use encrypted communication links.
Mitigation: Protect both development and control system operations by using up to date virus detecting solutions
Protect both development and control system operations by using up to date virus detecting solutions.
Mitigation: Please see CODESYS Advisory 2021-06 for more information.
Please see CODESYS Advisory 2021-06 for more information.
Mitigation: Please visit the CODESYS update area for more information on how to obtain the software updates.
Please visit the CODESYS update area for more information on how to obtain the software updates.
Mitigation: Use firewalls to protect and separate the control system network from other networks.
Use firewalls to protect and separate the control system network from other networks.
Mitigation: Use VPN (virtual private network) tunnels if remote access is required.
Use VPN (virtual private network) tunnels if remote access is required.
Mitigation: Use controllers and devices only in a protected environment to minimize network exposure, ensuring t
Use controllers and devices only in a protected environment to minimize network exposure, ensuring they are not accessible from outside.
Patch: CODESYS GmbH has released the following product versions to solve the noted vulnerability issues for
CODESYS GmbH has released the following product versions to solve the noted vulnerability issues for the affected CODESYS products: CODESYS Runtime Toolkit 32-bit full v2.4.7.55, CODESYS PLCWinNT v2.4.7.55. This will also be part of the CODESYS Development System setup v2.3.9.66
Mitigation: For more information and general recommendations for protecting machines and plants, see also the CO
For more information and general recommendations for protecting machines and plants, see also the CODESYS Security Whitepaper.
Mitigation: Limit access to both development and control system by physical means, operating system features, et
Limit access to both development and control system by physical means, operating system features, etc.
Mitigation: Activate and apply user management and password features.
Activate and apply user management and password features.
Mitigation: Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. bef
Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.
Mitigation: When remote access is required, use secure methods, such as virtual private networks (VPNs). Recogni
When remote access is required, use secure methods, such as virtual private networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.
Mitigation: For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices docume
For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document.
Mitigation: Minimize network exposure for all control system devices and systems and ensure that they are not ac
Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.
Mitigation: Compute a hash of the project files and regularly check the consistency of this hash to verify the i
Compute a hash of the project files and regularly check the consistency of this hash to verify the integrity before usage.
Mitigation: Only open project files received from a trusted source.
Only open project files received from a trusted source.
Mitigation: Never allow mobile devices that have connected to any other network besides the intended network to
Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.
Mitigation: Web Designer tool project file is based on XML language with specific parameters. To ensure the inte
Web Designer tool project file is based on XML language with specific parameters. To ensure the integrity of this file please follow the recommendations below:
Mitigation: Never connect programming software to any network other than the network intended for that device.
Never connect programming software to any network other than the network intended for that device.
Mitigation: For more information, see Schneider Electric security notification "SEVD-2025-014-04 Web Server on M
For more information, see Schneider Electric security notification "SEVD-2025-014-04 Web Server on Modicon M340 and BMXNOE0100/0110, BMXNOR0200H communication modules"
Mitigation: When exchanging files over the network, use secure communication protocols.
When exchanging files over the network, use secure communication protocols.
Mitigation: Place all controllers in locked cabinets and never leave them in the "Program" mode.
Place all controllers in locked cabinets and never leave them in the "Program" mode.
Mitigation: Install physical controls so no unauthorized personnel can access your industrial control and safety
Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.
Mitigation: Encrypt project file (XML configuration file) when stored and restrict the access to only trusted us
Encrypt project file (XML configuration file) when stored and restrict the access to only trusted users.
Mitigation: Locate control and safety system networks and remote devices behind firewalls and isolate them from
Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.
Mitigation: Schneider Electric strongly recommends the following industry cybersecurity best practices.
Schneider Electric strongly recommends the following industry cybersecurity best practices.
Mitigation: To ensure you are informed of all updates, including details on affected products and remediation pl
To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric's security notification service here: https://www.se.com/ww/en/work/support/cybersecurity/security-notifications.jsp
Mitigation: PowerChute Serial Shutdown
PowerChute Serial Shutdown
Mitigation: The affected software is being discontinued with the discontinuation of the Easy UPS Online SNMP Car
The affected software is being discontinued with the discontinuation of the Easy UPS Online SNMP Cards (APV9601, APVS9601) managed by this software. Fixed versions notwithstanding, Schneider Electric recommends users to migrate to the PowerChute series of software, including PowerChute Serial Shutdown and PowerChute Network Shutdown. For more information, please see the following sites:
Patch: Schneider Electric Easy UPS Online Monitoring Software: Version 2.6-GS or later
Schneider Electric Easy UPS Online Monitoring Software: Version 2.6-GS or later
Mitigation: Schneider Electric strongly recommends users follow cybersecurity industry best practices, including
Schneider Electric strongly recommends users follow cybersecurity industry best practices, including:
Mitigation: Schneider Electric recommends users update their affected devices to the following versions or later
Schneider Electric recommends users update their affected devices to the following versions or later:
Mitigation: Only connecting programming software to the network intended for that device.
Only connecting programming software to the network intended for that device.
Mitigation: Properly sanitizing mobile devices that have connected to another network before connecting to the i
Properly sanitizing mobile devices that have connected to another network before connecting to the intended network.
Mitigation: Placing all controllers in locked cabinets, and do not leave them in the "Program" mode.
Placing all controllers in locked cabinets, and do not leave them in the "Program" mode.
Mitigation: PowerChute Network Shutdown
PowerChute Network Shutdown
Mitigation: For more information, refer to the Schneider Electric Recommended Cybersecurity Best Practices docum
For more information, refer to the Schneider Electric Recommended Cybersecurity Best Practices document.
Mitigation: Using secure methods, such as virtual private networks (VPNs), when remote access is required.
Using secure methods, such as virtual private networks (VPNs), when remote access is required.
Patch: Schneider Electric became aware of a public PoC detailing an exploit for prior versions of the APC E
Schneider Electric became aware of a public PoC detailing an exploit for prior versions of the APC Easy UPS Online Monitoring Software, and strongly recommends all users take the defensive actions listed in this advisory.
Mitigation: Users can contact Schneider Electric's Customer Care Center for additional assistance.
Users can contact Schneider Electric's Customer Care Center for additional assistance.
Mitigation: Scanning all methods of mobile data exchange with the isolated network before use in the terminals o
Scanning all methods of mobile data exchange with the isolated network before use in the terminals or nodes connected to these networks.
Mitigation: Installing physical controls to help prevent unauthorized users from accessing industrial control an
Installing physical controls to help prevent unauthorized users from accessing industrial control and safety systems, components, peripheral equipment, and networks.
Mitigation: Locating control and safety system networks and remote devices behind firewalls and isolating them f
Locating control and safety system networks and remote devices behind firewalls and isolating them from the business network.
Mitigation: For more information, see Schneider Electric security notification SEVD-2023-101-04
For more information, see Schneider Electric security notification SEVD-2023-101-04
Mitigation: Schneider Electric recommends that users use appropriate patching methodologies when applying these
Schneider Electric recommends that users use appropriate patching methodologies when applying these patches to their systems and impact evaluate these patches in a test, development, or offline infrastructure environment. Schneider Electric strongly recommends the use of backups.
Mitigation: Minimizing network exposure for all control system devices and systems and ensure that they are not
Minimizing network exposure for all control system devices and systems and ensure that they are not accessible from the internet.
Patch: APC Easy UPS Online Monitoring Software: Version 2.6-GA or later
APC Easy UPS Online Monitoring Software: Version 2.6-GA or later
Mitigation: Schneider Electric provides detailed mitigation information for each of the affected products in the
Schneider Electric provides detailed mitigation information for each of the affected products in their own advisory, for more information about these issues, please refer to the original Schneider Electric publication SEVD-2021-194-01.
Patch: Customer can uninstall System Monitor application using installer available for download here: htt
Customer can uninstall System Monitor application using installer available for download here: https://www.proface.com/en/product/ipc/ps5000/download Customers should use appropriate patching methodologies when applying these patches to their systems. We strongly recommend the use of back-ups and evaluating the impact of these patches in a Test and Development environment or on an offline infrastructure. Contact Schneider Electric’s Customer Care Center if you need assistance removing a patch. Please follow the steps described in the guideline attached as a .pdf in the downloaded uninstaller guide.We strongly recommend the use of back-ups and evaluating the impact of this uninstaller in a Test and Development environment or on an offline infrastructure. Contact Schneider Electric’s Customer Care Center if you need assistance.
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • Stop the system monitor if not required by turning off the services as specified in user guide: Pro-face PS5000 legacy industrial PC Series User Manual • Setup network segmentation and implement a firewall to block all unauthorized access to configured HTTP/HTTPS ports.
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • Stop the system monitor if not required by turning off the services as specified in user guide: o Harmony Industrial PC Series User Manual • Setup network segmentation and implement a firewall to block all unauthorized access to configured HTTP/HTTPS ports.
Patch: Customer can uninstall System Monitor application using installer available for download here: htt
Customer can uninstall System Monitor application using installer available for download here: https://www.se.com/ww/en/product-range/61054- harmony-industrial-pc/#software-and-firmware Customers should use appropriate patching methodologies when applying these patches to their systems. We strongly recommend the use of back-ups and evaluating the impact of these patches in a Test and Development environment or on an offline infrastructure. Contact Schneider Electric’s Customer Care Center if you need assistance removing a patch. Please follow the steps described in the guideline attached as a .pdf in the downloaded uninstaller guide. We strongly recommend the use of back-ups and evaluating the impact of this uninstaller in a Test and Development environment or on an offline infrastructure. Contact Schneider Electric’s Customer Care Center if you need assistance.
Patch: Version 2.8.3 of the PowerLogic PM5560, 5563, 5580 firmware includes fixes for these vulnerabilitie
Version 2.8.3 of the PowerLogic PM5560, 5563, 5580 firmware includes fixes for these vulnerabilities. The version update files are available for download here: https://www.se.com/ww/en/product-range/61281-powerlogicpm5000-power-meters/?parent-subcategoryid=4125&filter=business-2-building-automation-and-control - software-and-firmware If customers choose not to apply the remediation provided above, they should immediately apply the following mitigation to reduce the risk of exploit: Customers should consider blocking HTTP access to the device at the firewall level or disable the HTTP web service to reduce the risk of exposure.
Patch: Version 10.7.3 of the PowerLogic PM5561 firmware includes fixes for these vulnerabilities. The vers
Version 10.7.3 of the PowerLogic PM5561 firmware includes fixes for these vulnerabilities. The version update files are available for download here: https://www.se.com/ww/en/product-range/61281-powerlogicpm5000-power-meters/?parent-subcategoryid=4125&filter=business-2-building-automation-andcontrol#software-and-firmware If customers choose not to apply the remediation provided above, they should immediately apply the following mitigation to reduce the risk of exploit: Customers should consider blocking HTTP access to the device at the firewall level or disable the HTTP web service to reduce the risk of exposure.
Patch: PowerLogic PM8ECC has reached end of service and is no longer supported. Customers should immediate
PowerLogic PM8ECC has reached end of service and is no longer supported. Customers should immediately apply the following mitigation to reduce the risk of exploit: Customers should consider blocking HTTP access to the device at the firewall level once commissioning is complete to reduce the risk of exposure. Additionally, Customers should ensure the General security Recommendations listed below are in place.
Patch: Version 4.3.5 of the PowerLogic PM5562 firmware includes fixes for these vulnerabilities. The versi
Version 4.3.5 of the PowerLogic PM5562 firmware includes fixes for these vulnerabilities. The version update files are available for download here: https://www.se.com/ww/en/product-range/61281-powerlogicpm5000/12146169702-basic-multifunction-metering/?selectednode-id=12146169702&N=brand=se%26countrycode=UK%26language-code=en%26node-id=12146169702 - software-and-firmware If customers choose not to apply the remediation provided above, they should immediately apply the following mitigation to reduce the risk of exploit: Customers should consider blocking HTTP access to the device at the firewall level or disable the HTTP web service to reduce the risk of exposure.
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of ex * Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from public internet or untrusted networks. * Filter ports and IP through the embedded firewall. * Set up network segmentation and implement a firewall to block all unauthorized access to port 502/TCP. * Disable all unused protocols (default configuration). * For more details refer to “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment User Guide”: https://www.se.com/ww/en/download/document/EIO0000004242/
Patch: Modicon M241/M251 Firmware version 5.2.11.29 includes a fix for this vulnerability and can be update
Modicon M241/M251 Firmware version 5.2.11.29 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application that is part of EcoStruxure Machine Expert: https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ By using Controller Assistant update Modicon Controller M241/M251 to the latest Firmware and perform reboot.
Patch: Modicon M258/LMC058 Firmware version 5.0.4.19 includes a fix for this vulnerability and can be downl
Modicon M258/LMC058 Firmware version 5.0.4.19 includes a fix for this vulnerability and can be downloaded here: https://www.se.com/ww/en/product-range/2730-modicon-m258-compact-plc-for-machine-automation/#software-and-firmware By using Controller Assistant from EcoStruxureTM Machine Expert update Modicon Controller M258/LMC058 and perform reboot.
Patch: Easergy Studio: Version 9.3.6 of Easergy Studio includes a fix for this vulnerability and is availab
Easergy Studio: Version 9.3.6 of Easergy Studio includes a fix for this vulnerability and is available via SESU (Schneider Electric Software Update).
Mitigation: Customers of Schneider Electric should use appropriate patching methodologies when applying these pa
Customers of Schneider Electric should use appropriate patching methodologies when applying these patches to their systems. Schneider Electric strongly recommend the use of back-ups and evaluating the impact of these patches in a Test and Development environment or on an offline infrastructure. Contact Schneider Electric's Customer Care Center if assistance is needed in removing a patch.
Mitigation: If customers choose not to apply the remediation provided above, they should immediatelyapply Schnei
If customers choose not to apply the remediation provided above, they should immediatelyapply Schneider Electric's General Security Recommendations to reduce the risk of exploit. For more information, see Schneider Electric SEVD-2024-009-02.
Mitigation: Schneider Electric has released the following mitigations/fixes for the following products:
Schneider Electric has released the following mitigations/fixes for the following products:
Mitigation: Follow the general security recommendation below and verify devices are isolated on a private networ
Follow the general security recommendation below and verify devices are isolated on a private network and firewalls are configured with strict boundaries for devices that require remote access.
Mitigation: Only accept incoming connections from machines, which names have been added as a station in the IGSS
Only accept incoming connections from machines, which names have been added as a station in the IGSS System Configuration module by setting the registry key called “MatchWinName” to 1 under: “HKEY_CURRENT_USER\SOFTWARE\SchneiderElectric\IGSS32\V15.00.00\DC_HKLM\”
Mitigation: If users choose not to apply the remediation provided above, they should immediately apply the follo
If users choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit:
Mitigation: For more information see Schneider Electric's security notification: SEVD-2021-285-03
For more information see Schneider Electric's security notification: SEVD-2021-285-03
Mitigation: Schneider Electric recommends users update to Version 15.0.0.21244 of the IGSS DC module. Please not
Schneider Electric recommends users update to Version 15.0.0.21244 of the IGSS DC module. Please note, dc.exe includes fixes for these vulnerabilities and is available for download through IGSS Master > Update IGSS Software or at the IGSS update link.
Mitigation: Users should employ appropriate patching methodologies. Schneider Electric strongly recommends the u
Users should employ appropriate patching methodologies. Schneider Electric strongly recommends the use of backups as well as an evaluation of the impact of these patches in a test and development environment or an offline infrastructure. Contact Schneider Electric's Customer Care Center if you need assistance removing a patch.
Patch: Version v1.4 of PowerChute™ Serial Shutdown includes a fix for this vulnerability and is available
Version v1.4 of PowerChute™ Serial Shutdown includes a fix for this vulnerability and is available for download here: • Windows: https://www.se.com/ww/en/download/document/SPD PCSS_WIN_EN/
Patch: Version v1.4 of PowerChute™ Serial Shutdown includes a fix for this vulnerability and is available f
Version v1.4 of PowerChute™ Serial Shutdown includes a fix for this vulnerability and is available for download here: Linux: https://www.se.com/ww/en/download/document/SPD PCSS_LNX_EN/
Patch: Version 004.010.000 of Enerlin'X IFE and eIFE includes a fix for this vulnerability. Download the
Version 004.010.000 of Enerlin'X IFE and eIFE includes a fix for this vulnerability. Download the latest version of the EcoStruxure Power Commission tool available here: https://www.se.com/ww/en/product-range/62980-ecostruxure-powercommission/#overview to install the latest firmware version of the Enerlin'X IFE and eIFE.
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: Customers should immediately apply the following mitigations to reduce the risk of exploit: * Use devices only in a protected environment to minimize network exposure and ensure that they are not accessible from public internet or untrusted networks. * Setup network segmentation and implement a firewall to block all unauthorized access to ports supported by the product and listed in the user guide: https://www.se.com/ww/en/download/document/DOCA0084EN/ Configure the Access Control List following the recommendations of the Cybersecurity Guide: https://www.se.com/ww/en/download/document/DOCA0122EN/ and the user guide: https://www.se.com/ww/en/download/document/DOCA0084EN/ To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric's security notification service here: https://www.se.com/en/work/support/cybersecurity/security-notifications.jsp
Mitigation: Schneider Electric is establishing a remediation plan for all future versions of Modicon MC80 that w
Schneider Electric is establishing a remediation plan for all future versions of Modicon MC80 that will include a fix for CVE-2024-8933. We will update this document when the remediation is available. Until then, customers should immediately apply the following mitigations to reduce the risk of exploit: • Setup network segmentation and implement a firewall to block all unauthorized access to port 502/TCP • Configure the Access Control List following the recommendations of the user manuals: “MC80 Programmable Logic Controller(PLC), User Manual” in the section “Access Control List (ACL)”: https://www.se.com/ww/en/download/document/EIO0000002071/ • Consider use of external firewall devices such as EAGLE40-07 from Belden to establish VPN connections. For more details refer to “Modicon Controller Systems Cybersecurity, User Guide”: https://www.se.com/ww/en/download/document/EIO0000001999/
Mitigation: Customers should immediately apply the following mitigations to reduce the risk of exploit: • Setup
Customers should immediately apply the following mitigations to reduce the risk of exploit: • Setup network segmentation and implement a firewall to block all unauthorized access to port 502/TCP • Configure the Access Control List following the recommendations of the user manuals: “Momentum for EcoStruxure™ Control Expert - 171CBU78090, 171CBU98090, 171CBU98091 Processors, User Guide” in the section “Controlling Access”: https://www.se.com/ww/en/download/document/HRB44124/ • Consider use of external firewall devices such as EAGLE40-07 from Belden to establish VPN connections. For more details refer to “Modicon Controller Systems Cybersecurity, User Guide”: https://www.se.com/ww/en/download/document/EIO0000001999/
Mitigation: Customers should immediately apply the following mitigations to reduce the risk of exploit: • Setup
Customers should immediately apply the following mitigations to reduce the risk of exploit: • Setup network segmentation and implement a firewall to block all unauthorized access to port 502/TCP • Configure the Access Control List following the recommendations of the user manuals: “Momentum for EcoStruxure™ Control Expert - 171CBU78090, 171CBU98090, 171CBU98091 Processors, User Guide” in the section “Controlling Access”: https://www.se.com/ww/en/download/document/HRB44124/ • Consider use of external firewall devices such as EAGLE40-07 from Belden to establish VPN connections. For more details refer to “Modicon Controller Systems Cybersecurity, User Guide”: https://www.se.com/ww/en/download/document/EIO0000001999/
Mitigation: Customers should immediately apply the following mitigations to reduce the risk of exploit: • Setup
Customers should immediately apply the following mitigations to reduce the risk of exploit: • Setup network segmentation and implement a firewall to block all unauthorized access to port 502/TCP • Configure the Access Control List following the recommendations of the user manuals: “Modicon M340 for Ethernet Communications Modules and Processors User Manual” in chapter “Messaging Configuration Parameters”: https://www.se.com/ww/en/download/document/31007131K01000/ • Consider use of external firewall devices such as EAGLE40-07 from Belden to establish VPN connections. For more details refer to “Modicon Controller Systems Cybersecurity, User Guide”: https://www.se.com/ww/en/download/document/EIO0000001999/ • Ensure the M340 CPU is running with the memory protection activated by configuring the input bit to a physical input, for more details refer to the following guideline “Modicon Controller Systems Cybersecurity, User Guide” chapter “Controler Memory Protection”: https://www.se.com/ww/en/download/document/EIO0000001999/
Patch: Version 3.70 of Modicon M340 includes a fix for this vulnerability and is available for download her
Version 3.70 of Modicon M340 includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/1468-modicon-m340/#software-and-firmware
Patch: EcoStruxure™ Control Expert V16.2 HF003 includes a fix for this vulnerability and is available for d
EcoStruxure™ Control Expert V16.2 HF003 includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/548-ecostruxure-control-expert-unity-pro/#software-and-firmware
Patch: Versions from 5.3.9.18 of Modicon Controllers M262 include a fix for these vulnerabilities and can
Versions from 5.3.9.18 of Modicon Controllers M262 include a fix for these vulnerabilities and can be downloaded here: https://www.se.com/ww/en/product-range/65771-logic-motion-controllermodicon-m262/#software-and-firmware •Use the Controller Assistant feature of EcoStruxure™ Automation Expert – Motion v24.1or EcoStruxure™ Machine Expert v2.3 to update the M262 firmware and perform a reboot. •EcoStruxure™ Automation Expert – Motion V24.1 is available via the Schneider Electric Software Installer: https://www.se.com/ww/en/download/document/ESEMACS10_INSTALLER. • Additional information is available in the Quick Start Guide, chapter “EcoStruxure™ Automation Expert Platform Installation”.
Patch: Version 5.3.12.51 of Modicon Controllers M241 includes a fix for these vulnerabilities and can be
Version 5.3.12.51 of Modicon Controllers M241 includes a fix for these vulnerabilities and can be downloaded here: M241:https://www.se.com/ww/en/product-range/62129-modicon-m241-micro-plc/#software-and-firmware •Use the Controller Assistant feature of EcoStruxure™ Automation Expert – Motion v24.1 or EcoStruxure™ Machine Expert v2.3 to update the M241 firmware and perform a reboot. •EcoStruxure™ Automation Expert – Motion V24.1 is available via the Schneider Electric Software Installer: https://www.se.com/ww/en/download/document/ESEMACS10_INSTALLER. • Additional information is available in the Quick Start Guide, chapter “EcoStruxure™ Automation Expert Platform Installation”.
Patch: Version 5.3.12.51 of Modicon Controllers M251 includes a fix for these vulnerabilities and can be
Version 5.3.12.51 of Modicon Controllers M251 includes a fix for these vulnerabilities and can be downloaded here: M251:https://www.se.com/ww/en/product-range/62130-modicon-m251-micro-plc-with-dual-channel-comm/#software-and-firmware •Use the Controller Assistant feature of EcoStruxure™ Automation Expert – Motion v24.1 or EcoStruxure™ Machine Expert v2.3 to update the M251 firmware and perform a reboot. •EcoStruxure™ Automation Expert – Motion V24.1 is available via the Schneider Electric Software Installer: https://www.se.com/ww/en/download/document/ESEMACS10_INSTALLER. • Additional information is available in the Quick Start Guide, chapter “EcoStruxure™ Automation Expert Platform Installation”.
Patch: Harden the workstation running ConneXium Network Manager (CNM) Software.
Harden the workstation running ConneXium Network Manager (CNM) Software.
Mitigation: STEP 2: Set up the “Edit Password” in the CNM software. The “Edit Mode” is enabled by default. Users
STEP 2: Set up the “Edit Password” in the CNM software. The “Edit Mode” is enabled by default. Users must activate the edit protection by switching to “Run mode” before exiting the application. Please refer to the chapter “Edit Mode” of the CNM user manual (packaged in the .iso file).
Mitigation: Use session without administrator rights when it is not necessary.
Use session without administrator rights when it is not necessary.
Mitigation: STEP 1: Download and run the CNM Alarms Disabler Tool.
STEP 1: Download and run the CNM Alarms Disabler Tool.
Mitigation: For more information see Schneider Electric's security notification: SEVD-2021-285-02
For more information see Schneider Electric's security notification: SEVD-2021-285-02
Mitigation: Usage: Place the disabler tool and the .cxn project file in the same directory. In a shell prompt, a
Usage: Place the disabler tool and the .cxn project file in the same directory. In a shell prompt, and in the chosen directory, execute the following command: disabler -projectfile {source project filename} -resultfile {converted project filename}
Mitigation: Schneider Electric also recommends users should use appropriate patching methodologies when applying
Schneider Electric also recommends users should use appropriate patching methodologies when applying these patches to their systems. We strongly recommend the use of back-ups and evaluating the impact of these patches in a Test and Development environment or on an offline infrastructure. Contact Schneider Electric's Customer Care Center if you need assistance removing a patch.
Mitigation: Important: The converter secures and modifies the CNM database and stores it in a new project file.
Important: The converter secures and modifies the CNM database and stores it in a new project file. Before a database coming from an untrusted source is loaded into CNM, users must run the converter. Note the original database is not modified. Therefore, if the original database needs to be loaded once more, it must be converted first.
Mitigation: Do not load .cxn files received from untrusted sources.
Do not load .cxn files received from untrusted sources.
Mitigation: For more information on these vulnerabilities and updates, please see SEVD-2020-133-04
For more information on these vulnerabilities and updates, please see SEVD-2020-133-04
Mitigation: User's password in the application should be configured as a strong password according with the “use
User's password in the application should be configured as a strong password according with the “use complex password” function described in the section titled “Security / Settings / use complex password.”
Mitigation: Schneider Electric recommends users update to EcoStruxure Operator Terminal Expert Version 3.1 Servi
Schneider Electric recommends users update to EcoStruxure Operator Terminal Expert Version 3.1 Service Pack 1A. Schneider Electric offers two methods to get the update
Mitigation: Only accept project files from trusted users.
Only accept project files from trusted users.
Mitigation: Manage your project file securely to avoid information disclosure or unexpected modifications of dat
Manage your project file securely to avoid information disclosure or unexpected modifications of data.
Mitigation: Harden workstation following the best cybersecurity practices (antivirus, updated operating systems,
Harden workstation following the best cybersecurity practices (antivirus, updated operating systems, strong password policies, application whitelisting software, etc.) and secure network using Schneider Electric's Cybersecurity Best Practices.
Mitigation: Use EcoStruxure Operator Terminal Expert software only on a trusted workstation.
Use EcoStruxure Operator Terminal Expert software only on a trusted workstation.
Mitigation: Do not execute EcoStruxure Operator Terminal Expert software with Windows administrator privileges.
Do not execute EcoStruxure Operator Terminal Expert software with Windows administrator privileges.
Mitigation: Use project password when saving the project file.
Use project password when saving the project file.
Patch: Version 9.3.4 and later of Easergy Studio includes a fix for this vulnerability. The fix was releas
Version 9.3.4 and later of Easergy Studio includes a fix for this vulnerability. The fix was released in December 2022, and it is recommended that customers use the latest version available: https://www.se.com/ww/en/download/document/Easergy_Studio_Installer/
Mitigation: • Follow EVlink Pro AC cybersecurity guide https://www.se.com/ww/en/download/document/GEX5261101/
• Follow EVlink Pro AC cybersecurity guide https://www.se.com/ww/en/download/document/GEX5261101/
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit.• Setup network segmentation and implement a firewall to block all unauthorized access to port 443/TCP
Patch: SV4.02.01 of BMENOR2200H firmware includes a fix for this vulnerability and is available here: h
SV4.02.01 of BMENOR2200H firmware includes a fix for this vulnerability and is available here: https://www.se.com/ww/en/product/BMENOR2200H/communication-module-modicon-m580-iec-608705101-104-dnp3-for-severe-environments/
Mitigation: • Setup network segmentation and implement a firewall to block all unauthorized access to port 443
• Setup network segmentation and implement a firewall to block all unauthorized access to port 443/TCP • Configure the Access Control List following the recommendations of the user manuals: “Modicon M580, Hardware, Reference Manual”: https://www.se.com/ww/en/download/document/EIO0000001578/
Patch: V1.3.10 of EVLink Pro AC firmware includes a fix for this vulnerability and is available here: ht
V1.3.10 of EVLink Pro AC firmware includes a fix for this vulnerability and is available here: https://www.se.com/ww/en/product-range/23107242-evlink-pro-ac/#software-and-firmware
Patch: SV4.21 of Modicon M580 firmware includes a fix for this vulnerability and is available for downloa
SV4.21 of Modicon M580 firmware includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/62098-modicon-m580-epac/#software-and-firmware
Patch: SV4.30 of Modicon M580 firmware includes a fix for this vulnerability and is available for downloa
SV4.30 of Modicon M580 firmware includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/62098-modicon-m580-epac/#software-and-firmware
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: * Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from public internet or untrusted networks. * Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. * Deactivate the Webserver after use when not needed. * Use encrypted communication links. * Setup network segmentation and implement a firewall to block all unauthorized access to ports 80/HTTP and 443/HTTPS. * Use VPN (Virtual Private Networks) tunnels if remote access is required. * The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” https://download.schneider-electric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242 provide product specific hardening guidelines.
Patch: Harden the engineering workstation running PLC Simulator for EcoStruxure Control Expert
Harden the engineering workstation running PLC Simulator for EcoStruxure Control Expert
Mitigation: In the option dialog box of the PLC simulator, set the listening IP Address to 127.0.0.1 (localhost)
In the option dialog box of the PLC simulator, set the listening IP Address to 127.0.0.1 (localhost), which will prevent remote network connections to the PLC simulator.
Mitigation: Schneider Electric recommends using appropriate patching methodologies when applying these patches.
Schneider Electric recommends using appropriate patching methodologies when applying these patches. It also strongly recommends the use of back-ups and evaluating the impact of these patches in a test and development environment or on offline infrastructure. Contact Schneider Electric's Customer Care Center for assistance removing a patch.
Mitigation: Set up network segmentation and implement a firewall to block all unauthorized access to Port 502/TC
Set up network segmentation and implement a firewall to block all unauthorized access to Port 502/TCP
Mitigation: Please see Schneider Electric Security Notification number SEVD-2020-315-07 for more information.
Please see Schneider Electric Security Notification number SEVD-2020-315-07 for more information.
Mitigation: Follow workstation, network, and site-hardening guidelines in the Cybersecurity Best Practices guide
Follow workstation, network, and site-hardening guidelines in the Cybersecurity Best Practices guide.
Mitigation: Schneider Electric has released Version 15.0 of the EcoStruxure Control Expert software to mitigate
Schneider Electric has released Version 15.0 of the EcoStruxure Control Expert software to mitigate this vulnerability. It is available for download on the Schneider Electric website.
Mitigation: If users choose not to apply the remediation provided above, they should immediately apply the follo
If users choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit:
Mitigation: The default listening IP address is: 0.0.0.0. The default setting exposes the PLC to the vulnerabili
The default listening IP address is: 0.0.0.0. The default setting exposes the PLC to the vulnerability described in this advisory.
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • Trio™ Data Radios should be installed in a secure location to prevent physical access by unauthorized personnel and securely disposed when decommissioned. • Firmware loaded in Trio™ Data Radios should be confirmed using the hash published with the release notes and following the instructions in Section 10 Part J – Firmware Updating and Maintenance in the Trio Q Series Data Radio User Manual This section provides information on how to download, install, and verify the new firmware version.
Patch: Version v2.7.2 of the TRIO™ Q Data Radio firmware includes fixes for the identified vulnerabilitie
Version v2.7.2 of the TRIO™ Q Data Radio firmware includes fixes for the identified vulnerabilities and is available for download here: https://www.se.com/ww/en/product-range/61419-trio-licensed-radios/#software-andfirmware Instructions should be followed from Section 10 Part J – Firmware Updating and Maintenance in the Trio Q Series Data Radio User Manual This section provides information on how to download, install, and verify the new firmware version.
Mitigation: To stay informed of all updates, including details on affected products and remediation plans, subsc
To stay informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric's security notification service.
Patch: Users still using Unity Pro should strongly consider migrating to EcoStruxure Control Expert. Please
Users still using Unity Pro should strongly consider migrating to EcoStruxure Control Expert. Please contact the local Schneider Electric technical support for more information.
Mitigation: Start the software without administrator rights to prevent the copying of extracted files in critica
Start the software without administrator rights to prevent the copying of extracted files in critical system folders.
Mitigation: Compute a checksum on all project files and check the consistency of the checksum to verify the inte
Compute a checksum on all project files and check the consistency of the checksum to verify the integrity before usage.
Mitigation: When exchanging the files over the network, use secure communication protocols.
When exchanging the files over the network, use secure communication protocols.
Mitigation: Store project files in a secure storage location and limit access to the files to only trusted users
Store project files in a secure storage location and limit access to the files to only trusted users.
Patch: Harden the workstations running EcoStruxure Control Expert, EcoStruxure Process Expert, or SCADAPack
Harden the workstations running EcoStruxure Control Expert, EcoStruxure Process Expert, or SCADAPack RemoteConnect.
Patch: Versions 5.3.12.48 of Modicon Controllers M251 include a fix for this vulnerability and can be downl
Versions 5.3.12.48 of Modicon Controllers M251 include a fix for this vulnerability and can be downloaded here: M251:https://www.se.com/ww/en/product-range/62130-modicon-m251-micro-plc-with-dual-channel-comm/#software-and-firmware * Use the Controller Assistant feature of EcoStruxure™ Automation Expert - Motion V24.1 or EcoStruxure™ Machine Expert V2.3 to update the M241/M251 firmware and perform a reboot. * EcoStruxure™ Automation Expert - Motion V24.1 and EcoStruxure™ Machine Expert V2.3 are available via the Schneider Electric Software Installer: https://www.se.com/ww/en/download/document/ESEMACS10_INSTALLER * Additional information is available in the Quick Start Guide, chapter “EcoStruxure™ Automation Expert Platform Installation”.
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from public internet or untrusted networks. • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Deactivate the Webserver after use when not needed. • Use encrypted communication links when available. • Setup network segmentation and implement a firewall to block all unauthorized access to ports 80/HTTP and 443/HTTPS. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide product specific hardening guidelines. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp
Patch: Modicon M258/LMC058 Firmware version 5.0.4.19 includes a fix for this vulnerability and can be downl
Modicon M258/LMC058 Firmware version 5.0.4.19 includes a fix for this vulnerability and can be downloaded here: https://www.se.com/ww/en/product-range/2730-modicon-m258-compact-plc-for-machine-automation/#software-and-firmware By using Controller Assistant from EcoStruxureTM Machine Expert update Modicon Controller M258/LMC058 and perform reboot.
Patch: Versions 5.3.12.48 of Modicon Controllers M241 include a fix for this vulnerability and can be downl
Versions 5.3.12.48 of Modicon Controllers M241 include a fix for this vulnerability and can be downloaded here: M241:https://www.se.com/ww/en/product-range/62129-modicon-m241-micro-plc/#software-and-firmware * Use the Controller Assistant feature of EcoStruxure™ Automation Expert - Motion V24.1 or EcoStruxure™ Machine Expert V2.3 to update the M241/M251 firmware and perform a reboot. * EcoStruxure™ Automation Expert - Motion V24.1 and EcoStruxure™ Machine Expert V2.3 are available via the Schneider Electric Software Installer: https://www.se.com/ww/en/download/document/ESEMACS10_INSTALLER * Additional information is available in the Quick Start Guide, chapter “EcoStruxure™ Automation Expert Platform Installation”.
Mitigation: Use appropriate means to protect the project storage from unauthorized manipulation.
Use appropriate means to protect the project storage from unauthorized manipulation.
Mitigation: Exchange project data only via secure exchange services.
Exchange project data only via secure exchange services.
Mitigation: The CERT@VDE advisory for M&M Software also recommends the following mitigation practices:
The CERT@VDE advisory for M&M Software also recommends the following mitigation practices:
Mitigation: Emerson has published a notification (EMR.RMT20004.Rev3) for this vulnerability in RTIS. RTIS users
Emerson has published a notification (EMR.RMT20004.Rev3) for this vulnerability in RTIS. RTIS users should review this notification for additional information specific to RTIS. CERT@VDE has published an advisory (VDE-2021-001) for this vulnerability in PEPPERL+FUCHS PACTware. CERT@VDE has published an advisory (VDE-2021-002) for this vulnerability in Weidmüller FDT/DTM Software with WI Manager. Mitsubishi Electric has published advisory 2020-020 concerning the vulnerability in MELSOFT FieldDeviceConfigurator.
Patch: Update the fdtCONTAINER component/fdtCONTAINER application to a version (fdtCONTAINER component: 3.7
Update the fdtCONTAINER component/fdtCONTAINER application to a version (fdtCONTAINER component: 3.7 or newer, fdtCONTAINER application: 4.7 or newer) that provides a secure deserialization of the project data with an updated serialization technology. This will break the compatibility to existing, non-manipulated project files.
Patch: Update the fdtCONTAINER component/fdtCONTAINER application to a version that provides a more secure
Update the fdtCONTAINER component/fdtCONTAINER application to a version that provides a more secure deserialization of the project data. This version will still use a deprecated serialization technology but will fix the currently known attack vector and will be compatible with existing, non-manipulated project files.
Mitigation: Do not open project data from an unknown source.
Do not open project data from an unknown source.
Mitigation: Reduce the user rights of the host application to the necessary minimum.
Reduce the user rights of the host application to the necessary minimum.
Patch: Patch ProLeiT-2025-001 includes a fix to reduce the risk of exploit: • Install the patch to disabl
Patch ProLeiT-2025-001 includes a fix to reduce the risk of exploit: • Install the patch to disable the eval commands in Redis on: o Application Server o VisuHub o Engineering Workstations o Workstation with emergency mode functionality • The patch ProLeiT-2025-001 is available via ProLeiT Support: https://www.proleit.com/support/ • Force usage of secure Redis configuration templates in system settings as documented in the patch manual. • Restart all patched Servers and Workstations
Mitigation: Customers should immediately apply the following mitigations to reduce the risk of exploit: • Use
Customers should immediately apply the following mitigations to reduce the risk of exploit: • Use HMI only in a protected environment to minimize network exposure and ensure that they are not accessible from public internet or untrusted networks. • Setup network segmentation and implement a firewall to block all unauthorized access. • Restrict usage of unverifiable portable media • Restricting the application access to limit the transfer of Firmware to HMIScanning of software/files for rootkits before usage and verifying the digital signature. • When exchanging files over the network, use secure communication protocols.
Workaround: Implement Security recommendations according to the product manual
Implement Security recommendations according to the product manual
Patch: Schneider Electric is establishing a remediation plan for all future versions of SCADAPack Workbench
Schneider Electric is establishing a remediation plan for all future versions of SCADAPack Workbench that will include a fix for this vulnerability.
Patch: Do not open untrusted files with SCADAPack Workbench.
Do not open untrusted files with SCADAPack Workbench.
Mitigation: For more information see Schneider Electric's security notification SEVD-2022-087-01
For more information see Schneider Electric's security notification SEVD-2022-087-01
Mitigation: Ensure the least-privilege user principle is followed, and user/service account access to shared res
Ensure the least-privilege user principle is followed, and user/service account access to shared resources (such as a database) is only granted with a minimum number of rights as needed.
Patch: Run SCADAPack Workbench as a User, not as an Administrator, to minimize the impact of malicious code
Run SCADAPack Workbench as a User, not as an Administrator, to minimize the impact of malicious code on the infected system.
Patch: Restrict communication from workstations running SCADAPack Workbench to external systems.
Restrict communication from workstations running SCADAPack Workbench to external systems.
Mitigation: Provide training and awareness programs to educate users on the warning signs of a phishing or socia
Provide training and awareness programs to educate users on the warning signs of a phishing or social engineering attack.
Mitigation: For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices docume
For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document.
Mitigation: Employ data loss prevention tools to help mitigate risk.
Employ data loss prevention tools to help mitigate risk.
Patch: The recommendation is to upgrade to latest Foxboro server (V95, H94) and workstations (Dell D96): Pl
The recommendation is to upgrade to latest Foxboro server (V95, H94) and workstations (Dell D96): Please contact your local Service Representative or Schneider Electric Process Automation Global Customer Support Center for information on how to migrate to new hardware.https://pasupport.schneider-electric.com/home2020.asp?code=i1swrtYD1O7YcWYkLo5iZJHxEEY9U-agDBBtcLSP7EXks
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: The BIOS, OS security patches are applied to significantly reduce the exploit possibility. Additional information is available here: https://se.my.site.com/PAkb/s/article/KA000127385 Several layers of defense-in-depth mechanisms available in the recommended security architecture of DCS system, including the computers themselves, and by following the General Security Recommendations specified below mitigate this vulnerability. https://pasupport.schneider-electric.com/Content/Documents/IASeries/b0700_lastrev/b0700hz_f.pdf
Patch: For already connected products, version 2.0.6.0.0 of EVlink Home Smart includes a fix for this vuln
For already connected products, version 2.0.6.0.0 of EVlink Home Smart includes a fix for this vulnerability and has been deployed to automatically upgrade all charging stations connected to the Wiser application. Make sure the charging station is connected to the Wiser application to ensure the new version is downloaded and installed. For new installations, a fix for this vulnerability is enforced through eSetup commissioning application. The installed firmware version can be verified through Wiser application (refer to the settings page for the charging station).
Patch: For already connected products, version 1.13.4 of Schneider Charge includes a fix for this vulnerab
For already connected products, version 1.13.4 of Schneider Charge includes a fix for this vulnerability and has been deployed to automatically upgrade all charging stations connected to the Wiser application. Make sure the charging station is connected to the Wiser application to ensure the new version is downloaded and installed. For new installations, a fix for this vulnerability is enforced through eSetup commissioning application. The installed firmware version can be verified through either Wiser application (refer to the settings page for the charging station), or the third-party supervision application.
Mitigation: Never allow mobile devices that have connected to any other network besides the intended network to
Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.
Mitigation: If users choose not to apply the remediation provided above, they should immediately apply the follo
If users choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: Please strictly follow all the instructions below: Step 1: Login with Admin privileges Step 2: Go to the folder C:\MCIS\Bin Step 3: Rename the file ‘MCIS.chm' to ‘MCIS.old' Note: to see file extensions, activate the visualization of file name extensions in Windows Explorer ‘View' options. Step 4: Restart the machine.
Mitigation: Version 2.10 of EcoStruxure Power Automation System User Interface(EPAS-UI) includes a fix for this
Version 2.10 of EcoStruxure Power Automation System User Interface(EPAS-UI) includes a fix for this vulnerability and is available by contacting Schneider Electric's Customer Care Center.
Mitigation: Never connect programming software to any network other than the network intended for that device.
Never connect programming software to any network other than the network intended for that device.
Mitigation: Place all controllers in locked cabinets and never leave them in the "Program" mode.
Place all controllers in locked cabinets and never leave them in the "Program" mode.
Mitigation: Locate control and safety system networks and remote devices behind firewalls and isolate them from
Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.
Mitigation: For more information see the associated Schneider Electric CPCERT security advisory EPAS-UI & EcoSUI
For more information see the associated Schneider Electric CPCERT security advisory EPAS-UI & EcoSUI - SEVD-2025-070-02 PDF Version, EPAS-UI & EcoSUI - SEVD-2025-070-02 CSAF Version.
Mitigation: Schneider Electric strongly recommends the following industry cybersecurity best practices:
Schneider Electric strongly recommends the following industry cybersecurity best practices:
Mitigation: For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices docume
For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document.
Mitigation: For more information see the associated Schneider Electric CPCERT security advisory EPAS-UI & EcoSUI
For more information see the associated Schneider Electric CPCERT security advisory EPAS-UI & EcoSUI - SEVD-2025-070-02 PDF Version, EPAS-UI & EcoSUI - SEVD-2025-070-02 CSAF Version.
Mitigation: Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. bef
Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.
Mitigation: Install physical controls so no unauthorized personnel can access your industrial control and safety
Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.
Mitigation: Minimize network exposure for all control system devices and systems and ensure that they are not ac
Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.
Mitigation: Schneider Electric has identified the following specific remediations and workarounds users can appl
Schneider Electric has identified the following specific remediations and workarounds users can apply to reduce risk:
Mitigation: When remote access is required, use secure methods, such as virtual private networks (VPNs). Recogni
When remote access is required, use secure methods, such as virtual private networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.
Mitigation: Follow the information according to SCADAPack™ Security Guidelines in section 8.3 Secured Communic
Follow the information according to SCADAPack™ Security Guidelines in section 8.3 Secured Communication. Also, apply the following standard practices to reduce the risk of exploit • Setup network segmentation and implement the RTU firewall service to block all unauthorized access to services. • Disable the logic debug service.
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: Follow the information according to SCADAPack™ Security Guidelines in section 8.3 Secured Communication. Also, apply the following standard practices to reduce the risk of exploit: • Setup network segmentation and implement the RTU firewall service to block all unauthorized access to services • Disable the logic debug service.
Patch: Version R3.4.2 of RemoteConnect includes a fix for this vulnerability and is available for downloa
Version R3.4.2 of RemoteConnect includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/download/document/RemoteConnect/
Patch: Version R3.4.2 (Firmware version 9.12.2) of SCADAPack™ 47x and SCADAPack™ 47xi includes a fix for t
Version R3.4.2 (Firmware version 9.12.2) of SCADAPack™ 47x and SCADAPack™ 47xi includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/download/document/RemoteConnect/
Patch: CODESYS recommends users update the CODESYS Development System to version 3.5.19.20.
CODESYS recommends users update the CODESYS Development System to version 3.5.19.20.
Mitigation: Alternatively, users may find further information on obtaining the software update in the (CODESYS U
Alternatively, users may find further information on obtaining the software update in the (CODESYS Update area.)[https://www.codesys.com/download/]
Mitigation: For more information, please see the advisory CERT@VDE published for CODESYS at:(https://cert.vde.co
For more information, please see the advisory CERT@VDE published for CODESYS at:(https://cert.vde.com/en-us/advisories/vde-2023-023)[https://cert.vde.com/en-us/advisories/vde-2023-023]
Patch: The CODESYS Development System can be downloaded and installed directly with the CODESYS Installer o
The CODESYS Development System can be downloaded and installed directly with the CODESYS Installer or be downloaded from the CODESYS Store.
Patch: Patch KB5070884 from Microsoft includes a fix for this vulnerability and is available for download
Patch KB5070884 from Microsoft includes a fix for this vulnerability and is available for download directly from WSUS. Reboot may be required to complete patch update. Customers should contact and work with [Global Customer Support](https://pasupport.se.com/home) to verify update has been completed.
Patch: Patch KB5070882 from Microsoft includes a fix for this vulnerability and is available for download
Patch KB5070882 from Microsoft includes a fix for this vulnerability and is available for download directly from WSUS. Reboot may be required to complete patch update. Customers should contact and work with [Global Customer Support](https://pasupport.se.com/home) to verify update has been completed.
Mitigation: Schneider Electric recommends blocking Port 80 using a firewall as a temporary workaround.
Schneider Electric recommends blocking Port 80 using a firewall as a temporary workaround.
Mitigation: Install firmware newer than January 16, 2016.
Install firmware newer than January 16, 2016.
Mitigation: See Schneider Electric Security Notification SEVD-2021-313-02 for more information.
See Schneider Electric Security Notification SEVD-2021-313-02 for more information.
Mitigation: If SESU is not installed, download SESU (automatic download) and follow the installation instruction
If SESU is not installed, download SESU (automatic download) and follow the installation instructions.
Mitigation: Install physical controls so no unauthorized personnel can access your industrial control and safety
Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.
Mitigation: Minimize network exposure for all control system devices and systems and ensure they are not accessi
Minimize network exposure for all control system devices and systems and ensure they are not accessible from the Internet.
Mitigation: Place all controllers in locked cabinets and never leave them in the “Program” mode.
Place all controllers in locked cabinets and never leave them in the “Program” mode.
Mitigation: Never allow mobile devices that have connected to any other network besides the intended network to
Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.
Mitigation: Locate control and safety system networks and remote devices behind firewalls and isolate them from
Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.
Mitigation: When remote access is required, use secure methods, such as virtual private networks (VPNs), recogni
When remote access is required, use secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN are only as secure as the connected devices.
Mitigation: Never connect programming software to any network other than the network intended for that device.
Never connect programming software to any network other than the network intended for that device.
Mitigation: Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. bef
Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.
Mitigation: If SESU is installed (assuming SESU is configured as “managed product” inside the SESU application)
If SESU is installed (assuming SESU is configured as “managed product” inside the SESU application) it will indicate a security update is available. Click to download and install the new SESU version.
Mitigation: Configure the access control list via Ecostruxure Control Expert programming tool.
Configure the access control list via Ecostruxure Control Expert programming tool.
Mitigation: Schneider Electric is establishing a remediation plan to fix these vulnerabilities in current and fu
Schneider Electric is establishing a remediation plan to fix these vulnerabilities in current and future versions of Modicon PAC controllers. Schneider Electric will update SEVD-2020-315-01 when the remediation is available.
Mitigation: Disable FTP via UnityPro / Ecostruxure Control Expert. This is disabled by default when a new applic
Disable FTP via UnityPro / Ecostruxure Control Expert. This is disabled by default when a new application is created.
Mitigation: Schneider Electric's Modicon Premium and Modicon Quantum controllers have reached their end of life
Schneider Electric's Modicon Premium and Modicon Quantum controllers have reached their end of life and are no longer commercially available. They have been replaced by the Modicon M580 ePAC controller.
Mitigation: Set up network segmentation and implement a firewall to block all unauthorized access to Port 21/TCP
Set up network segmentation and implement a firewall to block all unauthorized access to Port 21/TCP.
Mitigation: For further information please refer to Modicon Controllers Platform - CyberSecurity, Reference Manu
For further information please refer to Modicon Controllers Platform - CyberSecurity, Reference Manual and SEVD-2020-315-01
Mitigation: Treck recommends users apply the latest version of the affected products (Treck TCP/IP 6.0.1.68 or l
Treck recommends users apply the latest version of the affected products (Treck TCP/IP 6.0.1.68 or later versions). To obtain patches, email [email protected]
Mitigation: Treck recommends users who cannot apply the latest patches to implement firewall rules to filter out
Treck recommends users who cannot apply the latest patches to implement firewall rules to filter out packets that contain a negative content length in the HTTP header.
Mitigation: For more detailed information on the vulnerabilities and the mitigating controls, please see the Tre
For more detailed information on the vulnerabilities and the mitigating controls, please see the Treck advisory.
Mitigation: Apply the principle of least privilege to limit access to the computer running the Rapsody software.
Apply the principle of least privilege to limit access to the computer running the Rapsody software.
Mitigation: Schneider Electric reports fixes will be available in the first half of 2021. Until then, Schneider
Schneider Electric reports fixes will be available in the first half of 2021. Until then, Schneider recommends affected users immediately apply the following mitigations to reduce the risk of exploit:
Mitigation: Install antivirus on the computer and keep it up to date.
Install antivirus on the computer and keep it up to date.
Mitigation: All updates, including details on affected products and remediation plans, can be found by subscribi
All updates, including details on affected products and remediation plans, can be found by subscribing to Schneider Electric's security notification service.
Mitigation: Install application whitelisting software on the computer to block the execution of malicious code.
Install application whitelisting software on the computer to block the execution of malicious code.
Mitigation: For more information see the Schneider Electric advisory.
For more information see the Schneider Electric advisory.
Mitigation: For more information see the associated Festo SE & Co. KG security advisory FSA-202202 FSA-202202: F
For more information see the associated Festo SE & Co. KG security advisory FSA-202202 FSA-202202: Festo: Controller CECC-S,LK,D family <= 2.3.8.1 - multiple vulnerabilities in CODESYS V3 runtime system - HTML, FSA-202202: Festo: Controller CECC-S,LK,D family <= 2.3.8.1 - multiple vulnerabilities in CODESYS V3 runtime system - CSAF.
Mitigation: For more information see the associated Festo SE & Co. KG security advisory FSA-202202 FSA-202202: F
For more information see the associated Festo SE & Co. KG security advisory FSA-202202 FSA-202202: Festo: Controller CECC-S,LK,D family <= 2.3.8.1 - multiple vulnerabilities in CODESYS V3 runtime system - HTML, FSA-202202: Festo: Controller CECC-S,LK,D family <= 2.3.8.1 - multiple vulnerabilities in CODESYS V3 runtime system - CSAF.
Mitigation: SICAM 230 To fix all issues for existing installations, update SICAM 230 to V8.00 or later version.
SICAM 230 To fix all issues for existing installations, update SICAM 230 to V8.00 or later version. Then update CodeMeter Runtime to V7.10a: Download the package from WIBU Systems User Software website. Install it on SICAM 230 systems according to the procedure documented in chapter 9 of COPA-DATA Security Vulnerability Announcement 2020_1.
Patch: Update to V2.1.6 or later version
Update to V2.1.6 or later version
Patch: Update to V3.0.4 or later version
Update to V3.0.4 or later version
Patch: Update to V1.2.0 or later version
Update to V1.2.0 or later version
Patch: Update to V2.0.0 or later version
Update to V2.0.0 or later version
Patch: Additional vendors affected by the reported vulnerabilities have also released security advisories r
Additional vendors affected by the reported vulnerabilities have also released security advisories related to their affected products. Those advisories are as follows:
Patch: HCC recommends users apply release v4.3 or later to mitigate these vulnerabilities. For more informa
HCC recommends users apply release v4.3 or later to mitigate these vulnerabilities. For more information, contact HCC.
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: For customers requiring the use of Pro-face Remote HMI, Schneider Electric recommends using following mitigations: * Use of [Pro-face Connect solution](https://www.proface.com/en/product/soft/proface_connect/top) or any other VPN solutions for securing the remote access by encrypting the communication between Pro-face Remote HMI and Pro-face GP-ProEX. * Always connect the products to only trusted networks and follow the [Pro-face Cybersecurity Guidelines](https://www.proface.com/en/download/manual/cybersecurity_guide) * Set up a connection password. For more details refer to the [GP-Pro EX V4.0 Reference Manual](https://www.pro-face.com/otasuke/files/manual/gpproex/new/refer/gpproex.htm#t=mergedProjects%2Fremote%2Fremote_sg_remotehmi.htm&rhsearch=Remote%20HMI&rhhlterm=Remote%20HMI&ux=search) in section “Remote Viewer - Pro-face Remote HMI” For customers not using the Pro-face Remote HMI Schneider Electric recommends using following mitigations to reduce the risk of exploit: * Disable the Pro-face Remote HMI feature (deactivated by default). For more details refer to the [GP-Pro EX V4.0 Reference Manual](https://www.pro-face.com/otasuke/files/manual/gpproex/new/refer/gpproex.htm#t=mergedProjects%2Fmaintenance%2Fmaintenance_sg_remotemonitor.htm%23BMK_ProfaceRemoteHMI&rhsearch=Remote%20HMI) section “Pro-face Remote HMI Settings”
Patch: Version 5.00.100 release of GP-ProEX includes a fix for this vulnerability. Please contact your [Pro
Version 5.00.100 release of GP-ProEX includes a fix for this vulnerability. Please contact your [Pro-face Customer Care Center](https://www.proface.com/en/contact) to obtain the fix.
Patch: Version 1.70.000 of Pro-face Remote HMI includes a fix for this vulnerability and is available for d
Version 1.70.000 of Pro-face Remote HMI includes a fix for this vulnerability and is available for download in [Apple App Store](https://apps.apple.com/) and [Google Play Store](https://play.google.com/).
Patch: Schneider Electric Modicon Controllers M262 Versions prior to v5.2.8.26: Modicon Controller M262 Fir
Schneider Electric Modicon Controllers M262 Versions prior to v5.2.8.26: Modicon Controller M262 Firmware version 5.2.8.26 delivered with EcoStruxure Machine Expert v2.2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2.2 of EcoStruxure Machine Expert. Update Modicon Controller M262 to the latest Firmware and perform reboot
Mitigation: Users should immediately apply the following mitigations to reduce the risk of exploit: Use control
Users should immediately apply the following mitigations to reduce the risk of exploit: Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from public internet or untrusted networks. Ensure application of user management and password features. User rights are enabled by default and forced to create a strong password at first use. Deactivate the Webserver after use, when not needed. Use encrypted communication links. Setup network segmentation and implement a firewall to block all unauthorized access to port 80/HTTP and 443/HTTPS. Use VPN (Virtual Private Networks) tunnels if remote access is required. The "Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment" provide product specific chapters to ensure you are informed of all updates, including details on affected products and remediation plans. Subscribe to Schneider Electric's security notification service here.
Mitigation: Schneider Electric Modicon Controllers Version prior to v5.2.11.24: Modicon Controller M241 Firmware
Schneider Electric Modicon Controllers Version prior to v5.2.11.24: Modicon Controller M241 Firmware version 5.2.11.24 delivered with EcoStruxure Machine Expert v2.2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2.2 of EcoStruxure Machine Expert. Update Modicon Controller M241 to the latest Firmware and perform reboot
Mitigation: If users choose not to apply the remediation provided above they should immediately apply the follow
If users choose not to apply the remediation provided above they should immediately apply the following mitigations to reduce the risk of exploit:
Patch: Schneider Electric Modicon Controllers Version prior to v5.2.11.24, Schneider Electric Modicon Contr
Schneider Electric Modicon Controllers Version prior to v5.2.11.24, Schneider Electric Modicon Controllers M258 / LMC058 All versions , Schneider Electric Modicon Controllers M262 Versions prior to v5.2.8.26, Schneider Electric Modicon Controllers Version prior to v5.2.11.24: Modicon Controller M262 Firmware version 5.2.8.26 delivered with EcoStruxure Machine Expert v2.2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machineexpert-software/ On the engineering workstation, update to v2.2.2 of EcoStruxure Machine Expert. By using Controller Assistant from EcoStruxureTM Machine Expert update Modicon Controller M258/LMC058 and perform reboot .
Mitigation: Schneider Electric Modicon Controllers Version prior to v5.2.11.24: Modicon Controller M251 Firmware
Schneider Electric Modicon Controllers Version prior to v5.2.11.24: Modicon Controller M251 Firmware version 5.2.11.24 delivered with EcoStruxure Machine Expert v2.2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2.2 of EcoStruxure Machine Expert. Update Modicon Controller M251 to the latest Firmware and perform reboot
Mitigation: Schneider Electric has identified the following specific workarounds and mitigations users can apply
Schneider Electric has identified the following specific workarounds and mitigations users can apply to reduce risk:
Mitigation: For more information, refer to the Schneider Electric Recommended Cybersecurity Best Practices docum
For more information, refer to the Schneider Electric Recommended Cybersecurity Best Practices document and the associated Schneider Electric Security Notification SEVD-2024-191-04 in PDF and CSAF.
Mitigation: For more information, refer to the Schneider Electric Recommended Cybersecurity Best Practices docum
For more information, refer to the Schneider Electric Recommended Cybersecurity Best Practices document and the associated Schneider Electric Security Notification SEVD-2024-191-04 in PDF and CSAF.
Mitigation: Users should observe appropriate patching methodologies when applying these patches to their systems
Users should observe appropriate patching methodologies when applying these patches to their systems. We strongly recommend the use of back-ups and evaluating the impact of these patches in a Test and Development environment or on an offline infrastructure. Contact Schneider Electric's Customer Care Center if you need assistance removing a patch.
Mitigation: For more information, refer to the Schneider Electric Recommended Cybersecurity Best Practices docum
For more information, refer to the Schneider Electric Recommended Cybersecurity Best Practices document and the associated Schneider Electric Security Notification SEVD-2024-191-04 in PDF and CSAF.
Patch: Schneider Electric Modicon Controllers Version prior to v5.2.11.24, Schneider Electric Modicon Contr
Schneider Electric Modicon Controllers Version prior to v5.2.11.24, Schneider Electric Modicon Controllers M258 / LMC058 All versions , Schneider Electric Modicon Controllers M262 Versions prior to v5.2.8.26, Schneider Electric Modicon Controllers Version prior to v5.2.11.24: Modicon Controller M262 Firmware version 5.2.8.26 delivered with EcoStruxure Machine Expert v2.2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machineexpert-software/ On the engineering workstation, update to v2.2.2 of EcoStruxure Machine Expert. By using Controller Assistant from EcoStruxureTM Machine Expert update Modicon Controller M258/LMC058 and perform reboot .
Mitigation: Schneider Electric recommends users set up network segmentation and implement a firewall to block al
Schneider Electric recommends users set up network segmentation and implement a firewall to block all unauthorized access to Ports 44818/TCP, 502/TCP, 6000/TCP, 6002/TCP, 8080/TCP, 8014/TCP, and 6001/TCP.
Mitigation: For more information, see the Schneider Electric security notification.
For more information, see the Schneider Electric security notification.
Mitigation: Keep the infrastructure offline and do not allow Windows login and network access for untrusted peop
Keep the infrastructure offline and do not allow Windows login and network access for untrusted people and sources.
Mitigation: For more information, see the Schneider Electric security notification.
For more information, see the Schneider Electric security notification.
Mitigation: Alternatively, the following workarounds and mitigations can be applied to reduce risk:
Alternatively, the following workarounds and mitigations can be applied to reduce risk:
Mitigation: Disable the IGSS Update service when it is not required installing updates using the service.
Disable the IGSS Update service when it is not required installing updates using the service.
Mitigation: Schneider Electric has provided IGSS14 Version 14.0.0.20009 to address these vulnerabilities. Users
Schneider Electric has provided IGSS14 Version 14.0.0.20009 to address these vulnerabilities. Users are recommended to update to IGSS Version 14.
Patch: The problem is corrected in the product versions: Ekip Com IEC61850 version 3.08 ABB advises users
The problem is corrected in the product versions: Ekip Com IEC61850 version 3.08 ABB advises users of the affected product versions to reach out to their local ABB support team for guidance and recommended actions. Additionally, ABB recommends implementing defensive measures to reduce the risk of vulnerability exploitation, as outlined in the product instruction manual. Please refer to the section “Mitigation factors” for more information.
Mitigation: Triangle Microworks encourages those using the affected library to contact Triangle Microworks Suppo
Triangle Microworks encourages those using the affected library to contact Triangle Microworks Support for mitigation guidance and strategies.
Mitigation: Schneider Electric has released security advisory SEVD-2021-257-03 in response to these vulnerabilit
Schneider Electric has released security advisory SEVD-2021-257-03 in response to these vulnerabilities.
Mitigation: Scan all methods of mobile data exchange with the isolated network (e.g., CDs, USB drives, etc.) bef
Scan all methods of mobile data exchange with the isolated network (e.g., CDs, USB drives, etc.) before use in the terminals or any node connected to these networks.
Mitigation: When remote access is required, use secure methods, such as virtual private networks (VPNs). Recogni
When remote access is required, use secure methods, such as virtual private networks (VPNs). Recognize VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand VPNs are only as secure as the connected devices.
Mitigation: Limit software updates to only those networks where devices targeted by the software updates reside.
Limit software updates to only those networks where devices targeted by the software updates reside.
Mitigation: Place all controllers in locked cabinets and never leave them in “Program” mode.
Place all controllers in locked cabinets and never leave them in “Program” mode.
Mitigation: For more details and assistance on how to protect a user's installation, contact the local Schneider
For more details and assistance on how to protect a user's installation, contact the local Schneider Electric representative or Schneider Electric Industrial Cybersecurity Services.
Mitigation: For further information related to cybersecurity in Schneider Electric's products, visit the company
For further information related to cybersecurity in Schneider Electric's products, visit the company's cybersecurity support portal page.
Mitigation: Schneider Electric has established a remediation plan for future versions of StruxureWare Data Cente
Schneider Electric has established a remediation plan for future versions of StruxureWare Data Center Expert to fix these vulnerabilities. Until the fix is released, users should immediately follow the security hardening guidelines found in Schneider Electric's Data Center Expert Security Handbook to reduce the risk of exploit.
Mitigation: Locate control and safety system networks and remote devices behind firewalls and isolate them from
Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.
Mitigation: Install physical controls so no unauthorized personnel can access industrial control and safety syst
Install physical controls so no unauthorized personnel can access industrial control and safety systems, components, peripheral equipment, and networks.
Mitigation: Do not allow mobile devices that have connected to any other network besides the intended network to
Do not allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.
Mitigation: Minimize network exposure for all control system devices and systems, and ensure they are not access
Minimize network exposure for all control system devices and systems, and ensure they are not accessible from the Internet.
Mitigation: For more information, refer to the Schneider Electric Recommended Cybersecurity Best Practices docum
For more information, refer to the Schneider Electric Recommended Cybersecurity Best Practices document.
Patch: Version 3.0.12 of SESU includes a fix for this vulnerability and is available for download here:
Version 3.0.12 of SESU includes a fix for this vulnerability and is available for download here: https://www.seupdate.schneiderelectric.com/download/SystemConsistency/Soft wareUpdate/SESU_latest_version/SESU_latest _setup_sfx.exe Follow the installation instructions. If a predecessor version of SESU is already installed, then the update to V3.0.12 will be done automatically as a critical update in the background depending on the “automatic” update configuration.
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: SESU Installation Directory (chosen by the customer at installation time) should not be accessible from the network and only by trusted persons.
Mitigation: Place all controllers in locked cabinets and never leave them in the "Program" mode.
Place all controllers in locked cabinets and never leave them in the "Program" mode.
Mitigation: Schneider Electric strongly recommends the following industry cybersecurity best practices:
Schneider Electric strongly recommends the following industry cybersecurity best practices:
Mitigation: Additional configuration steps and supporting software are required to utilize the secure ION featur
Additional configuration steps and supporting software are required to utilize the secure ION feature. Please refer to the relevant product documentation or contact customer care for additional details and support.
Mitigation: Additional configuration steps and supporting software are required to utilize the secure ION featur
Additional configuration steps and supporting software are required to utilize the secure ION feature. Please refer to the relevant product documentation or contact customer care for additional details and support.
Patch: PowerLogic ION9000: Version 4.0.0 is available for download.
PowerLogic ION9000: Version 4.0.0 is available for download.
Patch: PowerLogic PM8000: Version 4.0.0 is available for download.
PowerLogic PM8000: Version 4.0.0 is available for download.
Mitigation: Never allow mobile devices that have connected to any other network besides the intended network to
Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.
Mitigation: When remote access is required, use secure methods, such as virtual private networks (VPNs). Recogni
When remote access is required, use secure methods, such as virtual private networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.
Mitigation: Locate control and safety system networks and remote devices behind firewalls and isolate them from
Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.
Mitigation: Users should use appropriate patching methodologies when applying these patches to their systems. Sc
Users should use appropriate patching methodologies when applying these patches to their systems. Schneider Electric recommends using backups and evaluating the impact of these patches in a "testing and development environment" or on an offline infrastructure.
Mitigation: Install physical controls so no unauthorized personnel can access your industrial control and safety
Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.
Mitigation: Users should contact Schneider Electric for assistance in removing a patch.
Users should contact Schneider Electric for assistance in removing a patch.
Mitigation: Update affected components to current firmware versions for available vulnerability fixes:
Update affected components to current firmware versions for available vulnerability fixes:
Mitigation: For more information, see Schneider Electric's security advisory SEVD-2023-129-03.
For more information, see Schneider Electric's security advisory SEVD-2023-129-03.
Mitigation: Schneider Electric recommends that users ensure devices supporting ION protocol are not exposed to t
Schneider Electric recommends that users ensure devices supporting ION protocol are not exposed to the internet or other untrusted networks. Users should apply the best practices for network hardening as documented in the product user guide and the Schneider Electric Recommended Cybersecurity Best Practices.
Patch: PowerLogic ION7400: Version 4.0.0 is available for download.
PowerLogic ION7400: Version 4.0.0 is available for download.
Mitigation: Never connect programming software to any network other than the network intended for that device.
Never connect programming software to any network other than the network intended for that device.
Mitigation: Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. bef
Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.
Mitigation: Minimize network exposure for all control system devices and systems and ensure that they are not ac
Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the internet.
Mitigation: Users should contact Schneider Electric for assistance in removing a patch.
Users should contact Schneider Electric for assistance in removing a patch.
Patch: PowerLogic ION7400: Version 4.0.0 is available for download.
PowerLogic ION7400: Version 4.0.0 is available for download.
Mitigation: Users should use appropriate patching methodologies when applying these patches to their systems. Sc
Users should use appropriate patching methodologies when applying these patches to their systems. Schneider Electric recommends using backups and evaluating the impact of these patches in a "testing and development environment" or on an offline infrastructure.
Patch: PowerLogic PM8000: Version 4.0.0 is available for download.
PowerLogic PM8000: Version 4.0.0 is available for download.
Mitigation: Schneider Electric has released the following remediations for users to implement:
Schneider Electric has released the following remediations for users to implement:
Patch: PowerLogic ION9000: Version 4.0.0 is available for download.
PowerLogic ION9000: Version 4.0.0 is available for download.
Mitigation: Schneider Electric recommends that users ensure devices supporting ION protocol are not exposed to t
Schneider Electric recommends that users ensure devices supporting ION protocol are not exposed to the internet or other untrusted networks. Users should apply the best practices for network hardening as documented in the product user guide and the Schneider Electric Recommended Cybersecurity Best Practices.
Patch: Update to V4.0 or later version
Update to V4.0 or later version
Patch: Update to V4.4.1 or later version
Update to V4.4.1 or later version
Patch: MID-certified devices do not support firmware updates; V3.2.2 is contained in devices that are label
MID-certified devices do not support firmware updates; V3.2.2 is contained in devices that are labeled as "M22 MID"
Patch: Update to V2.3.0 or later version
Update to V2.3.0 or later version
Patch: Update to V2.3.0 or later version
Update to V2.3.0 or later version
Patch: Update to V4.0 or later version
Update to V4.0 or later version
Patch: MID-certified devices do not support firmware updates; V3.2.2 is contained in devices that are label
MID-certified devices do not support firmware updates; V3.2.2 is contained in devices that are labeled as "M22 MID"
Patch: Update to V4.4.1 or later version
Update to V4.4.1 or later version
Patch: CODESYS recommends users update the CODESYS Development System to version 3.5.19.20.
CODESYS recommends users update the CODESYS Development System to version 3.5.19.20.
Mitigation: Alternatively, users may find further information on obtaining the software update in the (CODESYS U
Alternatively, users may find further information on obtaining the software update in the (CODESYS Update area.)[https://www.codesys.com/download/]
Patch: The CODESYS Development System can be downloaded and installed directly with the CODESYS Installer o
The CODESYS Development System can be downloaded and installed directly with the CODESYS Installer or be downloaded from the CODESYS Store.
Mitigation: For more information, please see the advisory CERT@VDE published for CODESYS at:(https://cert.vde.co
For more information, please see the advisory CERT@VDE published for CODESYS at:(https://cert.vde.com/en-us/advisories/vde-2023-022)[https://cert.vde.com/en-us/advisories/vde-2023-022]
Mitigation: Schneider Electric is establishing a remediation plan for all future versions of • Modicon M340
Schneider Electric is establishing a remediation plan for all future versions of • Modicon M340 • BMXNOR0200H • BMXNGD0100 • BMXNOC401 We will update this document when the remediation is available. Until then, customers should immediately apply the following mitigations to reduce the risk of exploit: • FTP service is disabled by default • Ensure to disable FTP service when not in use • Setup network segmentation and implement a firewall to block all unauthorized access to ports 21/FTP • Use VPN (Virtual Private Networks) tunnels if remote access is required
Patch: Version 6.80 of BMXNOE0110 includes a fix for this vulnerability and is available for download her
Version 6.80 of BMXNOE0110 includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product/BMXNOE0110/ethernettcp-ip-network-module-modicon-m340-automation-platformflash-memory-card-internal-ram-16-mb-1-x-rj45-10-100/ Reboot is needed to complete the firmware upgrade
Patch: Version 3.60 of BMXNOE0100 includes a fix for this vulnerability and is available for download her
Version 3.60 of BMXNOE0100 includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product/BMXNOE0100/networkmodule-modicon-m340-modbus-tcp-1-x-rj45-flash-memorycard/ Reboot is needed to complete the firmware upgrade
Patch: Version SV3.70 of Modicon M340 includes a fix for this vulnerability and is available for download h
Version SV3.70 of Modicon M340 includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/1468-modicon-m340/#software-and-firmware
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • FTP service is disabled by default • Ensure to disable FTP service when not in use • Setup network segmentation and implement a firewall to block all unauthorized access to ports 21/FTP • Use VPN (Virtual Private Networks) tunnels if remote access is required
Patch: Update to 2.2.5.2 version or latest
Update to 2.2.5.2 version or latest
Mitigation: Hitachi Energy PWC600 - See public advisory.
Hitachi Energy PWC600 - See public advisory.
Mitigation: Zephyr Project: Update to 2.5 or later. Patches available for prior supported versions. See the Zep
Zephyr Project: Update to 2.5 or later. Patches available for prior supported versions. See the Zephyr security advisory for more information.
Mitigation: Hitachi Energy GMS600 - See public advisory.
Hitachi Energy GMS600 - See public advisory.
Mitigation: Hitachi Energy RTU500 series CMU - Updates available for some firmware versions - See public advisor
Hitachi Energy RTU500 series CMU - Updates available for some firmware versions - See public advisory.
Mitigation: Hitachi Energy REB500 - See public advisory.
Hitachi Energy REB500 - See public advisory.
Mitigation: Hitachi Energy Relion 670, 650 series and SAM600-IO - See public advisory
Hitachi Energy Relion 670, 650 series and SAM600-IO - See public advisory
Mitigation: Hitachi Energy Modular Switchgear Monitoring System MSM - Protect your network - See public advisory
Hitachi Energy Modular Switchgear Monitoring System MSM - Protect your network - See public advisory.
Patch: Update to V5.2.6 or later version
Update to V5.2.6 or later version
Patch: Update to V5.5.2 or later version
Update to V5.5.2 or later version
Mitigation: Refer to the Mitigation Factors/Workaround Section for the current mitigation strategy.
Refer to the Mitigation Factors/Workaround Section for the current mitigation strategy.
Patch: Update to 2.2.3.5 version or latest
Update to 2.2.3.5 version or latest
Patch: Update to 2.2.1.8 version or latest
Update to 2.2.1.8 version or latest
Patch: Update to 2.2.4.3 version or latest
Update to 2.2.4.3 version or latest
Patch: Update to 2.2.2.5 version or latest
Update to 2.2.2.5 version or latest
Patch: Please contact your Schneider Electric customer support to get Premium V3.20 firmware. TSXP57104M
Please contact your Schneider Electric customer support to get Premium V3.20 firmware. TSXP57104M [C] TSXP57154M [C] TSXP571634M [C] TSXP57204M [C] TSXP572634M [C] TSXP57254M [C] TSXP57304M [C] TSXP573634M [C] TSXP57354M [C] TSXP574634M [C] TSXP57454M [C] TSXP575634M [C] TSXP57554M [C] TSXP576634M [C] TSXH5724M [C] TSXH5744M [C]
Mitigation: Schneider Electric’s Modicon Premium controllers have reached their end of life and are no longer co
Schneider Electric’s Modicon Premium controllers have reached their end of life and are no longer commercially available. They have been replaced by the Modicon M580 ePAC controller, our most current product offer. Customers should strongly consider migrating to the Modicon M580 ePAC. Please contact your local Schneider Electric technical support for more information. To mitigate the risks associated with Modbus/ weaknesses, users should immediately: • Set up network segmentation and implement a firewall to block all unauthorized access to port 502/TCP • Configure the Access Control List following the recommendations of the user manual “Premium and Atrium using EcoStruxure Control Expert - Ethernet Network Modules, User Manual” in chapters “Connection configuration parameters / TCP/IP Services Configuration Parameters / Connection Configuration Parameters”: https://www.se.com/ww/en/download/document/35006192K01000/
Mitigation: Schneider Electric’s Modicon Quantum and Quantum Safety controllers have reached their end of life a
Schneider Electric’s Modicon Quantum and Quantum Safety controllers have reached their end of life and are no longer commercially available. They have been replaced by the Modicon M580 or M580 Safety ePAC controller, our most current product offer. Customers should strongly consider migrating to the Modicon M580 ePAC. Please contact your local Schneider Electric technical support for more information. To mitigate the risks associated with Modbus/ weaknesses, users should immediately: • Set up network segmentation and implement a firewall to block all unauthorized access to port 502/TCP • Configure the Access Control List feature as mentioned in “Quantum using EcoStruxure Control Expert - TCP/IP Configuration, User Manual” in chapter “Software Settings for Ethernet Communication / Messaging / Quantum NOE Ethernet Messaging Configuration”: https://www.se.com/ww/en/download/document/33002467K01000/
Patch: Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download
Version v3.60 of Modicon Quantum includes a fix for this vulnerability and is available for download here: 140CPU67861 [C] - https://www.schneider-electric.com/en/download/document/Quantum_140CPU67861_SV3.60
Mitigation: Customers should immediately apply the following mitigations to reduce the risk of exploit: • Ensu
Customers should immediately apply the following mitigations to reduce the risk of exploit: • Ensure to use simulator default panel option to make PLC simulator accessible only locally. • Modbus network connections are disabled by default on the PLC Simulator present in EcoStruxure Control Expert, mitigating the risk associated to this vulnerability. Note: The PLC Simulator feature is part of the EcoStruxure Control Expert software, and it helps users to review and test their configurations files in a simulation environment. It is not intended to be used as a controller CPU in a production environment.
Patch: Version v15.1 of EcoStruxure Control Expert includes a fix for this vulnerability and is available f
Version v15.1 of EcoStruxure Control Expert includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/548-ecostruxure-control-expert-unity-pro/#software-and-firmware
Mitigation: Schneider Electric recommends users of versions below v2.1 to update to the latest version as soon a
Schneider Electric recommends users of versions below v2.1 to update to the latest version as soon as possible.
Mitigation: Please see the Schneider Electric Security Bulletin - SEVD-2020-224-04 for more details of these vul
Please see the Schneider Electric Security Bulletin - SEVD-2020-224-04 for more details of these vulnerabilities.
Patch: EcoStruxure™ Power Operations 2021 CU3 Hotfix 3 includes a fix for this vulnerability and is availa
EcoStruxure™ Power Operations 2021 CU3 Hotfix 3 includes a fix for this vulnerability and is available for download here: https://community.se.com/t5/EcoStruxure-Power-Operation/v2022- Release-amp-Updates-Install-Procedure/m-p/416561/thread-id/6058 OR Upgrade to latest version of EcoStruxure™ Power Operations. Contact the customer care center for more information. Additionally, EcoStruxure™ Power Operation 2021 with Advanced Reporting utilizes EcoStruxure™ Power Monitoring Expert. You will need to update the version of EcoStruxure™ Power Monitoring Expert installed independently of the EcoStruxure™ Power Operation patch level installed and apply the appropriate EcoStruxure™ Power Monitoring Expert update as outlined above. For assistance in determining the version of PME installed, contact the Schneider Electric Customer Care Center.
Patch: EcoStruxure™ Power Monitoring Expert 2020 is at its end-of-life support. Customers should consider
EcoStruxure™ Power Monitoring Expert 2020 is at its end-of-life support. Customers should consider upgrading to the latest version offering of PME to resolve this issue. Please contact Schneider Electric Customer Care Center for more details.
Patch: EcoStruxure™ Power Operations 2022 CU5 includes a fix for this vulnerability and is available for d
EcoStruxure™ Power Operations 2022 CU5 includes a fix for this vulnerability and is available for download here: https://community.se.com/t5/EcoStruxure-Power-Operation/v2022- Release-amp-Updates-Install-Procedure/m-p/416561/thread-id/6058 OR Upgrade to latest version of EcoStruxure™ Power Operations. Contact the customer care center for more information. Additionally, EcoStruxure™ Power operation 2022 with Advanced Reporting utilizes EcoStruxure™ Power Monitoring Expert. You will need to update the version of EcoStruxure™ Power Monitoring Expert installed independently of the EcoStruxure™ Power Operation patch level installed and apply the appropriate EcoStruxure™ Power Monitoring Expert update as outlined above. For assistance in determining the version of PME installed, contact the Schneider Electric Customer Care Center.
Patch: EcoStruxure™ Power SCADA Operation 2020 (PSO) - Advanced Reporting and Dashboards Module is at its
EcoStruxure™ Power SCADA Operation 2020 (PSO) - Advanced Reporting and Dashboards Module is at its end-of-life support. Customers should consider upgrading to the latest version offering of EPO to resolve this issue. Please contact Schneider Electric Customer Care Center for more details.
Patch: EcoStruxure™ Power Monitoring Expert 2021 CU2 includes a fix for this vulnerability and is availabl
EcoStruxure™ Power Monitoring Expert 2021 CU2 includes a fix for this vulnerability and is available for download here: https://ecoxpert.se.com/software-center/power-monitoringexpert/ power-monitoring-expert-2021 OR EcoStruxure™ Power Monitoring Expert 2022 includes a fix for this vulnerability and is available for download here: https://ecoxpert.se.com/software-center/power-monitoringexpert/ power-monitoring-expert-2022 OR Upgrade to the latest version of EcoStruxure™ Power Monitoring Expert. Contact the customer care center for more information.
Patch: Schneider Electric has released EcoStruxure Operation Terminal Expert v3.4 for users to download.
Schneider Electric has released EcoStruxure Operation Terminal Expert v3.4 for users to download.
Mitigation: For more information, see Schneider Electric's Advisory.
For more information, see Schneider Electric's Advisory.
Mitigation: Customers should use appropriate patching methodologies when applying these patches to their systems
Customers should use appropriate patching methodologies when applying these patches to their systems. We strongly recommend the use of back-ups and evaluating the impact of these patches in a Test and Development environment or on an offline infrastructure. Contact Schneider Electric's Customer Care Center if you need assistance removing a patch.
Patch: The CODESYS Development System can be downloaded and installed directly with the CODESYS Installer o
The CODESYS Development System can be downloaded and installed directly with the CODESYS Installer or be downloaded from the CODESYS Store.
Mitigation: Alternatively, users may find further information on obtaining the software update in the (CODESYS U
Alternatively, users may find further information on obtaining the software update in the (CODESYS Update area.)[https://www.codesys.com/download/]
Mitigation: For more information, please see the advisory CERT@VDE published for CODESYS at: (https://cert.vde.c
For more information, please see the advisory CERT@VDE published for CODESYS at: (https://cert.vde.com/en-us/advisories/vde-2023-021)[https://cert.vde.com/en-us/advisories/vde-2023-021]
Patch: CODESYS recommends users update the CODESYS Development System to version 3.5.19.20.
CODESYS recommends users update the CODESYS Development System to version 3.5.19.20.
Mitigation: Please note that the ConneXium Network Manager product has reached the end of its life and is no lon
Please note that the ConneXium Network Manager product has reached the end of its life and is no longer supported. Customers should immediately apply the following mitigations to reduce the risk of exploit: • Only open project files received from a trusted source. • Compute a hash of the project files and regularly check the consistency of this hash to verify the integrity before usage. • Encrypt project file when stored and restrict the access to only trusted users. • When exchanging files over the network, use secure communication protocols. • Follow workstation, network and site-hardening guidelines in the Recommended Cybersecurity Best Practices available for download here: https://www.se.com/ww/en/download/document/7EN52-0390/
Patch: PowerLogic P5 Wave 4.2.3 P5L30 firmware includes a fix for this vulnerability. Contact Schneider Ele
PowerLogic P5 Wave 4.2.3 P5L30 firmware includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center to download this firmware.
Patch: Version 1.3 of PowerChute Serial Shutdown includes a fix for this vulnerability and is available fo
Version 1.3 of PowerChute Serial Shutdown includes a fix for this vulnerability and is available for download here: https://www.apc.com/us/en/product-range/137943580-powerchute-serialshutdown/#software-and-firmware
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • Do not enable remote access to PCSS Web UI. In the Windows Firewall incoming requests on TCP port 6547 (used by PCSS) are not allowed by default. • Harden the PowerChute Serial Shutdown Agent firewall rule by listing remote computers and/or users for which you want to allow/block remote connections on TCP port 6547. • Specific instructions for these mitigations can be found in the Security Handbook.
Mitigation: Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. bef
Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.
Mitigation: Store the project files in a secure storage and restrict the access to only trusted users.
Store the project files in a secure storage and restrict the access to only trusted users.
Mitigation: Never allow laptops that have connected to any other network besides the intended network to connect
Never allow laptops that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.
Mitigation: Never connect programming software to any network other than the network for the devices that it is
Never connect programming software to any network other than the network for the devices that it is intended.
Patch: EcoStruxure Power Build Rapsody: Version v2.8.2 FR of EcoStruxure Power Build Rapsody includes a fix
EcoStruxure Power Build Rapsody: Version v2.8.2 FR of EcoStruxure Power Build Rapsody includes a fix for this vulnerability and is available for download.
Mitigation: Schneider Electric has identified the following specific workarounds and mitigations users can apply
Schneider Electric has identified the following specific workarounds and mitigations users can apply to reduce risk:
Mitigation: Minimize network exposure for all control system devices and systems, and ensure that they are not a
Minimize network exposure for all control system devices and systems, and ensure that they are not accessible from the Internet.
Mitigation: Locate control and safety system networks and remote devices behind firewalls and isolate them from
Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.
Mitigation: Compute a hash of the project files and regularly check the consistency of this hash to verify the i
Compute a hash of the project files and regularly check the consistency of this hash to verify the integrity before usage.
Mitigation: Encrypt project files when stored.
Encrypt project files when stored.
Mitigation: When exchanging files over the network, use secure communication protocols.
When exchanging files over the network, use secure communication protocols.
Mitigation: When remote access is required, use secure methods, such as virtual private networks (VPNs). Recogni
When remote access is required, use secure methods, such as virtual private networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.
Mitigation: Only open project files received from a trusted source.
Only open project files received from a trusted source.
Mitigation: Install physical controls so no unauthorized personnel can access your industrial control and safety
Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.
Mitigation: For more information, see Schneider Electric security notification SEVD-2025-133-03.
For more information, see Schneider Electric security notification SEVD-2025-133-03.
Mitigation: Schneider Electric strongly recommends the following industry cybersecurity best practices:
Schneider Electric strongly recommends the following industry cybersecurity best practices:
Patch: Harden the workstation running EcoStruxure Power Build Rapsody
Harden the workstation running EcoStruxure Power Build Rapsody
Mitigation: Place all controllers in locked cabinets and never leave them in the "Program" mode.
Place all controllers in locked cabinets and never leave them in the "Program" mode.
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • Store the project files in a secure storage and restrict the access to only trusted users • When exchanging files over the network, use secure communication protocols • Encrypt project files when stored • Only open project files received from trusted source • Compute a hash of the project files and regularly check the consistency of this hash to verify the integrity before usage • Harden the workstation running EcoStruxure™ Power Build Rapsody To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/security-notifications.jsp
Patch: Version v2.8.1 FR of EcoStruxure™ Power Build–Rapsody includes a fix for this vulnerability and is
Version v2.8.1 FR of EcoStruxure™ Power Build–Rapsody includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/2309-ecostruxure-power-buildrapsody/#overview Please reboot after installing the new version.
Patch: Update to V6.3
Update to V6.3
Mitigation: Only use the PPP functionality of the affected devices in trusted environments. This functionality i
Only use the PPP functionality of the affected devices in trusted environments. This functionality is not enabled by default but typically used in internet dial-in or Point-to-Point connection scenarios. At this point the vulnerability could be exploited by a malicious peer.
Mitigation: Install physical controls so no unauthorized personnel can access your industrial control and safety
Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.
Mitigation: Implement firewall rules to restrict SSH connections to the device.
Implement firewall rules to restrict SSH connections to the device.
Mitigation: Schneider Electric strongly recommends the following industry cybersecurity best practices.
Schneider Electric strongly recommends the following industry cybersecurity best practices.
Mitigation: Place all controllers in locked cabinets and never leave them in the "Program" mode.
Place all controllers in locked cabinets and never leave them in the "Program" mode.
Mitigation: If customers are not able to apply these patches, Schneider Electric recommends immediately applying
If customers are not able to apply these patches, Schneider Electric recommends immediately applying the following mitigations to reduce the risk of exploitation:
Mitigation: Schneider Electric has identified the following specific workarounds and mitigations users can apply
Schneider Electric has identified the following specific workarounds and mitigations users can apply to reduce risk:
Mitigation: For more information see the associated Schneider Electric CPCERT security advisory SEVD-2025-252-02
For more information see the associated Schneider Electric CPCERT security advisory SEVD-2025-252-02 Saitel DR & Saitel DP Remote Terminal Unit - SEVD-2025-252-02 PDF Version, Saitel DR & Saitel DP Remote Terminal Unit - SEVD-2025-252-02 CSAF Version.
Mitigation: Ensure users are assigned the least privileged role that still allows them to perform their designat
Ensure users are assigned the least privileged role that still allows them to perform their designated tasks.
Mitigation: Restrict access to BLMon by assigning permissions only to a limited set of user roles.
Restrict access to BLMon by assigning permissions only to a limited set of user roles.
Patch: Schneider Electric Saitel DR RTU Versions 11.06.29 and prior: HUe Firmware version 11.06.30 of Saite
Schneider Electric Saitel DR RTU Versions 11.06.29 and prior: HUe Firmware version 11.06.30 of Saitel DR includes a fix for this vulnerability and is available for download. A reboot is necessary to complete the firmware upgrade.
Mitigation: For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices docume
For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document.
Mitigation: Minimize network exposure for all control system devices and systems and ensure that they are not ac
Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.
Patch: Schneider Electric Saitel DP RTU Versions 11.06.33 and prior: Firmware SM_CPU866e version 11.06.34 o
Schneider Electric Saitel DP RTU Versions 11.06.33 and prior: Firmware SM_CPU866e version 11.06.34 of Saitel DP includes a fix for this vulnerability and is available for download. A reboot is necessary to complete the firmware upgrade.
Mitigation: Schneider Electric recommends that customers use appropriate patching methodologies when applying th
Schneider Electric recommends that customers use appropriate patching methodologies when applying these patches to their systems. They strongly recommend the use of back-ups and evaluating the impact of these patches in a Test and Development environment or on an offline infrastructure. Contact Schneider Electric's Customer Care Center for assistance removing a patch.
Mitigation: Locate control and safety system networks and remote devices behind firewalls and isolate them from
Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.
Mitigation: Never connect programming software to any network other than the network intended for that device.
Never connect programming software to any network other than the network intended for that device.
Mitigation: When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recogni
When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.
Mitigation: Never allow mobile devices that have connected to any other network besides the intended network to
Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.
Mitigation: Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. bef
Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.
Mitigation: For more information see the associated Schneider Electric CPCERT security advisory SEVD-2025-252-02
For more information see the associated Schneider Electric CPCERT security advisory SEVD-2025-252-02 Saitel DR & Saitel DP Remote Terminal Unit - SEVD-2025-252-02 PDF Version, Saitel DR & Saitel DP Remote Terminal Unit - SEVD-2025-252-02 CSAF Version.
Mitigation: Customers should immediately apply the following mitigations to reduce the risk of exploitation: • E
Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.
Mitigation: Minimize network exposure for all control system devices and systems and ensure they are not accessi
Minimize network exposure for all control system devices and systems and ensure they are not accessible from the Internet.
Mitigation: Never connect programming software to any network other than the network for the devices it is inten
Never connect programming software to any network other than the network for the devices it is intended for.
Mitigation: Never allow mobile devices that have connected to any other network besides the intended network to
Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.
Mitigation: Install physical controls so no unauthorized personnel can access industrial control and safety syst
Install physical controls so no unauthorized personnel can access industrial control and safety systems, components, peripheral equipment, and networks.
Mitigation: AP7xxx, AP8xxx, APDU9xxx with NMC3: v1.2.0.2 of the Rack PDU firmware includes a fix for this vulner
AP7xxx, AP8xxx, APDU9xxx with NMC3: v1.2.0.2 of the Rack PDU firmware includes a fix for this vulnerability and is available for download: Rack PDU v1.2.0.2 firmware: Release Notes Device must be rebooted as part of the update process. Verify the firmware version is correct once the update is complete.
Mitigation: Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc., be
Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc., before use in the terminals or any node connected to these networks.
Mitigation: Locate control and safety system networks and remote devices behind firewalls and isolate them from
Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.
Mitigation: AP7xxxx and AP8xxx with NMC2: v7.0.6 of the Rack PDU firmware includes a fix for this vulnerability
AP7xxxx and AP8xxx with NMC2: v7.0.6 of the Rack PDU firmware includes a fix for this vulnerability and is available for download: Rack PDU v7.0.6 firmware: Device must be rebooted as part of the update process. Verify the firmware version is correct once the update is complete.
Mitigation: Discontinue the use of outlet links until the firmware upgrade is applied.
Discontinue the use of outlet links until the firmware upgrade is applied.
Mitigation: When remote access is required, use secure methods, such as virtual private networks (VPNs), recogni
When remote access is required, use secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also, recognize VPN is only as secure as its connected devices.
Mitigation: Place all controllers in locked cabinets and never leave them in the “Program” mode.
Place all controllers in locked cabinets and never leave them in the “Program” mode.
Mitigation: For more information, please see Schneider Electric's security notification: SEVD-2021-348-04
For more information, please see Schneider Electric's security notification: SEVD-2021-348-04
Mitigation: Schneider Electric is establishing a remediation plan for all future versions of Modicon M258/LMC0
Schneider Electric is establishing a remediation plan for all future versions of Modicon M258/LMC058 that will include a fix for this vulnerability. We will update this document when the remediation is available. Until then, customers should immediately apply the following mitigations to reduce the risk of exploit: * Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from public internet or untrusted networks. * Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. * Deactivate the Webserver after use when not needed. * Use encrypted communication links. * Setup network segmentation and implement a firewall to block all unauthorized access to ports 80/HTTP and 443/HTTPS. * Use VPN (Virtual Private Networks) tunnels if remote access is required. * The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” https://download.schneider-electric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242 provide product specific hardening guidelines.
Mitigation: Use of Microsoft AppLocker or other similar allow list application can help mitigate risk. Informati
Use of Microsoft AppLocker or other similar allow list application can help mitigate risk. Information on using AppLocker with Rockwell Automation products is available at Rockwell Automation Knowledgebase Article QA17329 (login required).
Mitigation: Rockwell Automation recommends customers using the affected software to update the affected product
Rockwell Automation recommends customers using the affected software to update the affected product to Version 6.6.10 or later.
Patch: Run ISaGRAF Workbench as a user, instead of as an administrator, to minimize the impact of malicious
Run ISaGRAF Workbench as a user, instead of as an administrator, to minimize the impact of malicious code on the infected system.
Patch: Do not open untrusted .7z exchange files with ISaGRAF Workbench. Employ training and awareness progr
Do not open untrusted .7z exchange files with ISaGRAF Workbench. Employ training and awareness programs to educate users on the warning signs of a phishing or social engineering attack.
Mitigation: Ensure that the least-privilege user principle is followed. Allow user or service account access to
Ensure that the least-privilege user principle is followed. Allow user or service account access to shared resources, such as a database, to be granted with the minimum number of rights necessary.
Mitigation: Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.
Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.
Mitigation: Do not click web links or open attachments in unsolicited email messages.
Do not click web links or open attachments in unsolicited email messages.
Mitigation: Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering
Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.
Mitigation: When remote access is required, use secure methods, such as virtual private networks (VPNs). Recogni
When remote access is required, use secure methods, such as virtual private networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.
Mitigation: By doing this, the vulnerable commands could not then be used to compromise the PC by an external en
By doing this, the vulnerable commands could not then be used to compromise the PC by an external entity as the connection and ultimately the command will not be accepted by SpaceLogic C-Bus Toolkit.
Patch: Schneider Electric has provided a fix to these vulnerabilities and recommends updating the software
Schneider Electric has provided a fix to these vulnerabilities and recommends updating the software to v1.16.4. After installation, it is recommended to reboot the system and verify the version number reflects the new version.
Mitigation: Never connect programming software to any network other than the network intended for that device.
Never connect programming software to any network other than the network intended for that device.
Mitigation: Locate control and safety system networks and remote devices behind firewalls andisolate them from t
Locate control and safety system networks and remote devices behind firewalls andisolate them from the business network.
Mitigation: Install physical controls so no unauthorized personnel can access your industrial control and safety
Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.
Mitigation: Schneider Electric strongly recommends the following industry cybersecurity best practices.
Schneider Electric strongly recommends the following industry cybersecurity best practices.
Mitigation: Never allow mobile devices that have connected to any other network besides the intended network to
Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.
Mitigation: If users choose not to apply the remediation provided , they should immediately apply the following
If users choose not to apply the remediation provided , they should immediately apply the following mitigation to reduce the risk of exploit: Block TCP Port 20023 to SpaceLogic C-Bus Toolkit by using the rules in the PC firewall.
Mitigation: Minimize network exposure for all control system devices and systems and ensure that they are not ac
Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.
Mitigation: Place all controllers in locked cabinets and never leave them in the "Program" mode.
Place all controllers in locked cabinets and never leave them in the "Program" mode.
Mitigation: Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. bef
Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.
Mitigation: For more information, refer to Schneider Electric's Security Bulletin SEVD-2023-283-1
For more information, refer to Schneider Electric's Security Bulletin SEVD-2023-283-1
Mitigation: Enable encryption on application project and store application files in secure location with restri
Enable encryption on application project and store application files in secure location with restricted access only for legitimate users. • Schneider Electric recommends using McAfee Application and Change Control software for application control. Refer to the Cybersecurity Application Note available here. • Follow workstation, network and site-hardening guidelines in the Recommended Cybersecurity Best Practices available for download here.
Mitigation: Setup an application password in the project properties • Setup network segmentation and implement
Setup an application password in the project properties • Setup network segmentation and implement a firewall to block all unauthorized access to port 502/TCP • Configure the Access Control List following the recommendations of the user manuals: “Modicon M340 for Ethernet Communications Modules and Processors User Manual” in chapter “Messaging Configuration Parameters”: https://www.se.com/ww/en/download/document/31007131K01000/ • Setup a secure communication according to the following guideline “Modicon Controllers Platform Cyber Security Reference Manual,” in chapter “Setup secured communications”: https://www.se.com/ww/en/download/document/EIO0000001999/ • Consider use of external firewall devices such as EAGLE40-07 from Belden to establish VPN connections for M340 & M580 architectures. For more details refer to the chapter “How to protect M580 and M340 architectures with EAGLE40 using VPN”: https://www.se.com/ww/en/download/document/EIO0000001999/ • Ensure the M340 CPU is running with the memory protection activated by configuring the input bit to a physical input, for more details refer to the following guideline “Modicon Controllers Platform Cyber Security Reference Manual”, “CPU Memory Protection section”: • https://www.se.com/ww/en/download/document/EIO0000001999/
Mitigation: Setup an application password in the project properties • Setup network segmentation and implement
Setup an application password in the project properties • Setup network segmentation and implement a firewall to block all unauthorized access to port 502/TCP • Configure the Access Control List following the recommendations of the user manuals: “Modicon M580, Hardware, Reference Manual”: https://www.se.com/ww/en/download/document/EIO0000001578/ Setup a secure communication according to the following guideline “Modicon Controllers Platform Cyber Security Reference Manual,” in chapter “Setup secured communications”: https://www.se.com/ww/en/download/document/EIO0000001999/ • use a BMENOC module and follow the instructions to configure IPSEC feature as described in the guideline “Modicon M580 - BMENOC03.1 Ethernet Communications Schneider Electric Security Notification Module, Installation and Configuration Guide” in the chapter “Configuring IPSEC communications”: https://www.se.com/ww/en/download/document/HRB62665/ OR • Use a BMENUA0100 module and follow the instructions to configure IPSEC feature as described in the chapter “Configuring the BMENUA0100 Cybersecurity Settings”: https://www.se.com/ww/en/download/document/PHA83350 OR • Consider use of external firewall devices such as EAGLE40-07 from Belden to establish VPN connections for M340 & M580 architectures. For more details refer to the chapter “How to protect M580 and M340 architectures with EAGLE40 using VPN”: https://www.se.com/ww/en/download/document/EIO0000001999/ • Ensure the M580 CPU is running with the memory protection activated by configuring the input bit to a physical input, for more details refer to the following guideline “Modicon Controllers Platform Cyber Security Reference Manual”, “CPU Memory Protection section”: https://www.schneiderelectric.com/en/download/document/EIO0000001999/ NOTE: The CPU memory protection cannot be configured with M580 Hot Standby CPUs. In such cases, use IPsec encrypted communication.
Mitigation: EcoStruxure Process Expert manages application files within its database in secure way. Do not expo
EcoStruxure Process Expert manages application files within its database in secure way. Do not export & store them outside the application. • Schneider Electric recommends using McAfee Application and Change Control software for application control. Refer to the Cybersecurity Application Note available here. • Follow workstation, network and site-hardening guidelines in the Recommended Cybersecurity Best Practices available for download here.
Patch: Version 16.0 of EcoStruxure Control Expert includes a fix for these vulnerabilities and is availabl
Version 16.0 of EcoStruxure Control Expert includes a fix for these vulnerabilities and is available for download here: https://www.se.com/ww/en/product-range/548- ecostruxure-control-expert-unity-pro/ Reboot the computer after installation is completed
Patch: SV4.20 of Modicon M580 firmware includes a fix for this vulnerability and is available for download
SV4.20 of Modicon M580 firmware includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/62098- modicon-m580-epac/ - software-and-firmware
Patch: Version 15.3 HF008 of EcoStruxure Control Expert includes the fix for these vulnerabilities and are
Version 15.3 HF008 of EcoStruxure Control Expert includes the fix for these vulnerabilities and are available for download here: https://www.se.com/ww/en/product-range/548- ecostruxure-control-expert-unity-pro/
Patch: SV3.60 of Modicon M340 firmware includes a fix for this vulnerability and is available for download
SV3.60 of Modicon M340 firmware includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/1468- modicon-m340
Mitigation: Schneider Electric is establishing a remediation plan for all future versions of EcoStruxure™ Proce
Schneider Electric is establishing a remediation plan for all future versions of EcoStruxure™ Process Expert that will include a fix for this vulnerability. We will update this document when the remediation is available. Until then, customers should immediately apply the following mitigations to reduce the risk of exploit: • Setup an application password in the project properties • Setup network segmentation and implement a firewall to block all unauthorized access to port 502/TCP • Configure the Access Control List following the recommendations of the user manuals: “Modicon M580, Hardware, Reference Manual”: https://www.se.com/ww/en/download/document/EIO0000001578/ • Setup a secure communication according to the following guideline “Modicon Controllers Platform Cyber Security Reference Manual,” in chapter “Setup secured communications”: https://www.se.com/ww/en/download/document/EIO0000001999/ • use a BMENOC module and follow the instructions to configure IPSEC feature as described in the guideline “Modicon M580 - BMENOC03.1 Ethernet Communications Schneider Electric Security Notification Module, Installation and Configuration Guide” in the chapter “Configuring IPSEC communications”: https://www.se.com/ww/en/download/document/HRB62665/ OR • Use a BMENUA0100 module and follow the instructions to configure IPSEC feature as described in the chapter “Configuring the BMENUA0100 Cybersecurity Settings”: https://www.se.com/ww/en/download/document/PHA83350 OR • Consider use of external firewall devices such as EAGLE40-07 from Belden to establish VPN connections for M340 & M580 architectures. For more details refer to the chapter “How to protect M580 and M340 architectures with EAGLE40 using VPN”: https://www.se.com/ww/en/download/document/EIO0000001999/ • Ensure the M580 CPU is running with the memory protection activated by configuring the input bit to a physical input, for more details refer to the following guideline “Modicon Controllers Platform Cyber Security Reference Manual”, “CPU Memory Protection section”: https://www.schneiderelectric.com/en/download/document/EIO0000001999/ NOTE: The CPU memory protection cannot be configured with M580 Hot Standby CPUs. In such cases, use IPsec encrypted communication. • To further reduce the attack surface on Modicon M580 CPU Safety: Ensure the CPU is running in Safety mode and maintenance input is configured to maintain this Safety mode during operation – refer to the document Modicon M580 - Safety System Planning Guide - in the chapter “Operating Mode Transitions”: https://www.se.com/ww/en/download/document/QGH60283/
Mitigation: To ensure remediation of CVE-2025-11567, Customers should immediately apply the following steps. If
To ensure remediation of CVE-2025-11567, Customers should immediately apply the following steps. If PowerChute is installed in a custom folder, ensure that the required permissions are set on the custom folder. NOTE: It is recommended to set administrative permissions on the custom folder. Specific instructions for these mitigations can be found in the [Security Handbook](https://download.schneider-electric.com/files?p_Doc_Ref=SPD_CCON-PCSSSH_EN).
Patch: Version 2.10.0 of Accutech Manager includes a fix for this vulnerability and is available for downl
Version 2.10.0 of Accutech Manager includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/download/document/Accutech_Manager/ Instructions are provided with the software installation package on how to verify software revision.
Mitigation: Setup an application password in the project properties• Setup network segmentation and implement a
Setup an application password in the project properties• Setup network segmentation and implement a firewall to block all unauthorized access to port 502/TCP• Setup a secure communication according to the following guideline “Modicon Controller Systems Cybersecurity, User Guide” in chapter “Set Up Encrypted Communication”:
Mitigation: EcoStruxure Process Expert manages application files within its database in secure way. Do not expo
EcoStruxure Process Expert manages application files within its database in secure way. Do not export & store them outside the application. • Schneider Electric recommends using McAfee Application and Change Control software for application control. Refer to the Cybersecurity Application Note available here. • Follow workstation, network and site-hardening guidelines in the Recommended Cybersecurity Best Practices available for download here.
Mitigation: Setup an application password in the project properties• Setup network segmentation and implement a
Setup an application password in the project properties• Setup network segmentation and implement a firewall to block all unauthorized access to port 502/TCP• Configure the Access Control List following the recommendations of the user manuals:• “Modicon MC80 Programmable Logic Controller (PLC) manual” in the chapter “Access Control List (ACL)”:https://www.se.com/ww/en/download/document/EIO0000002071/Setup a secure communication according to the following guideline “Modicon Controller Systems Cybersecurity, User Guide” in chapter “Set Up Encrypted Communication”:
Patch: Update to V13.3.0.1 or later version
Update to V13.3.0.1 or later version
Patch: Update to V5.1 QU1 or later version
Update to V5.1 QU1 or later version
Patch: Vulnerabilities fixed on central cloud service; no user actions necessary
Vulnerabilities fixed on central cloud service; no user actions necessary
Patch: A hotfix is available; please contact customer support to receive the hotfix
A hotfix is available; please contact customer support to receive the hotfix
Patch: Update Teamcenter to any fix version available for the different version lines of Teamcenter, see ht
Update Teamcenter to any fix version available for the different version lines of Teamcenter, see https://support.sw.siemens.com/en- US/knowledge-base/PL8600700
Patch: Vulnerability CVE-2021-44228 fixed on central cloud service; no user actions necessary
Vulnerability CVE-2021-44228 fixed on central cloud service; no user actions necessary
Patch: Remove the JndiLookup class from the classpath.
Remove the JndiLookup class from the classpath.
Patch: Update to V13.0.1 or later version
Update to V13.0.1 or later version
Patch: Apply the hotfix
Apply the hotfix
Patch: Update to V5.2.6 or later version
Update to V5.2.6 or later version
Patch: Vulnerabilities fixed on central cloud services starting 2021-12-11; no user actions necessary
Vulnerabilities fixed on central cloud services starting 2021-12-11; no user actions necessary
Patch: Update to V12.4.0.12 or later version
Update to V12.4.0.12 or later version
Patch: Download and install the updated TCCS setup from the Siemens Support Center; for details see https:/
Download and install the updated TCCS setup from the Siemens Support Center; for details see https://support.sw.siemens.com/knowledge- base/PL8615527
Patch: Vulnerabilities fixed on central cloud service starting 2021-12-19; no user actions necessary
Vulnerabilities fixed on central cloud service starting 2021-12-19; no user actions necessary
Patch: Update to V10.4.2 or later version
Update to V10.4.2 or later version
Patch: Update to V12.4.1 or later version
Update to V12.4.1 or later version
Patch: Update to V2020.1 SP2202 or later version
Update to V2020.1 SP2202 or later version
Patch: Update to V2000.3400 or later version
Update to V2000.3400 or later version
Patch: Update to VX.2.10 Update 4 or later version
Update to VX.2.10 Update 4 or later version
Patch: Update to V13.2.1.1 or V13.3.0.0 or later version
Update to V13.2.1.1 or V13.3.0.0 or later version
Patch: Simcenter Testlab Data Management team will contact all impacted customer to deploy the mitigation m
Simcenter Testlab Data Management team will contact all impacted customer to deploy the mitigation measures. This action will secure your installation against Log4Shell vulnerability. For further information see: https://support.sw.siemens.com/en-US/knowledge- base/PL8601418
Patch: Remove the JndiLookup class from the classpath. Detailed instructions are available at https://suppo
Remove the JndiLookup class from the classpath. Detailed instructions are available at https://support.industry.siemens.com/cs/ww/en/view/109805562/
Patch: Update to VX.2.7 Update 19 or later version
Update to VX.2.7 Update 19 or later version
Patch: Update to V2008 or later version
Update to V2008 or later version
Patch: Update to V2021.1 SP2202 or later version
Update to V2021.1 SP2202 or later version
Patch: Update to 2022.1-2008 or later version
Update to 2022.1-2008 or later version
Patch: Update to V21Q4 and apply the patch. Please contact your local Siemens representative.
Update to V21Q4 and apply the patch. Please contact your local Siemens representative.
Patch: Update to V4.70 SP9 and apply Security Patch 1. Please contact your local Siemens representative.
Update to V4.70 SP9 and apply Security Patch 1. Please contact your local Siemens representative.
Patch: Update to V4.1.2 or later version
Update to V4.1.2 or later version
Patch: Update to V13.2.0.1 or later version
Update to V13.2.0.1 or later version
Patch: Update to V5.0.11 or later version
Update to V5.0.11 or later version
Patch: Update to V6.3 or later version
Update to V6.3 or later version
Patch: Update to VX.2.10 Update 4 or later version
Update to VX.2.10 Update 4 or later version
Patch: Update to VX.2.8 Update 13 or later version
Update to VX.2.8 Update 13 or later version
Patch: Update to V4.1.1.1 or later version
Update to V4.1.1.1 or later version
Patch: Vulnerabilities fixed with update on 2021-12-16; no user actions necessary
Vulnerabilities fixed with update on 2021-12-16; no user actions necessary
Patch: Update to V13.0.0.2 or later version
Update to V13.0.0.2 or later version
Patch: Update to V2022 SP2202 or later version
Update to V2022 SP2202 or later version
Patch: Update to V13.0.0.9 or later version
Update to V13.0.0.9 or later version
Patch: Apply the patch
Apply the patch
Patch: Update to V2.85.7.5 or later version
Update to V2.85.7.5 or later version
Patch: Vulnerabilities fixed on central cloud services starting 2021-12-10; no user actions necessary
Vulnerabilities fixed on central cloud services starting 2021-12-10; no user actions necessary
Patch: Specific fix versions based on V6.0.2 and V6.0.3 were released and deployed for all affected project
Specific fix versions based on V6.0.2 and V6.0.3 were released and deployed for all affected projects
Patch: Update the driver for the SmartRAID controller to V2.6.6 or later version, available at https://stor
Update the driver for the SmartRAID controller to V2.6.6 or later version, available at https://storage.microsemi.com/en- us/support/raid/sas_raid/asr-3151-4i/
Patch: Update to V3.3.0.7 or later version
Update to V3.3.0.7 or later version
Patch: Update to V4.3.13 or later version
Update to V4.3.13 or later version
Patch: Update to V5.1.5 or later version
Update to V5.1.5 or later version
Patch: Update to V1.7.18 or later version, as provided via cRSP V13.17.2 or later version
Update to V1.7.18 or later version, as provided via cRSP V13.17.2 or later version
Patch: Update to V2008 or later version
Update to V2008 or later version
Patch: Update to V5.1.8 or later version
Update to V5.1.8 or later version
Patch: Update to V1973.4340 or later version
Update to V1973.4340 or later version
Patch: Update to V8.6.2.472 or later version
Update to V8.6.2.472 or later version
Patch: Update the UAA component to V75.8.3
Update the UAA component to V75.8.3
Patch: Update to V2.3.2 or later version; please contact customer support to receive the latest version
Update to V2.3.2 or later version; please contact customer support to receive the latest version
Patch: Update to V13.0.1.2 or later version
Update to V13.0.1.2 or later version
Patch: Update to V4.2.0.2 or later version
Update to V4.2.0.2 or later version
Patch: Update to V2021.2.2 or later version
Update to V2021.2.2 or later version
Patch: Update to V1.5 SP4 and apply the patch
Update to V1.5 SP4 and apply the patch
Patch: Update to V5.0.6 or later version
Update to V5.0.6 or later version
Patch: Update to V13.2.0.6 or later version
Update to V13.2.0.6 or later version
Patch: Update to V2020.1 SP2202 or later version
Update to V2020.1 SP2202 or later version
Patch: Update to V12.3.11 or later version
Update to V12.3.11 or later version
Patch: Remove the JndiLookup class from the classpath. Detailed instructions are available at https://suppo
Remove the JndiLookup class from the classpath. Detailed instructions are available at https://support.industry.siemens.com/cs/ww/en/view/109805602/
Patch: Update to V18.1 or later version to fix CVE-2021-44228
Update to V18.1 or later version to fix CVE-2021-44228
Patch: Update to V13.1.0.1 or later version
Update to V13.1.0.1 or later version
Patch: Update to V12.2.0.18 or later version
Update to V12.2.0.18 or later version
Patch: Update to V13.1.0.8 or later version
Update to V13.1.0.8 or later version
Patch: Update to V5.2.3 or later version
Update to V5.2.3 or later version
Patch: Apply the hotfix
Apply the hotfix
Patch: Update to V2.2.7 or later version; please contact customer support to receive the latest version
Update to V2.2.7 or later version; please contact customer support to receive the latest version
Patch: Update to V12.3.0.15 or later version
Update to V12.3.0.15 or later version
Patch: Find detailed remediation and mitigation information on the EnergyIP docs portal at: https://docs.em
Find detailed remediation and mitigation information on the EnergyIP docs portal at: https://docs.emeter.com/display/public/WELCOME/Energy IP+Security+Advisory+for+Log4Shell+Vulnerability
Patch: HEEDS Connect team will contact all impacted customers to deploy a new log4j version. This action wi
HEEDS Connect team will contact all impacted customers to deploy a new log4j version. This action will secure your installation against Log4Shell vulnerability. For further information see: https://support.sw.siemens.com/en-US/knowledge-base/PL8601661
Patch: Update to V4.0.0.2 or later version
Update to V4.0.0.2 or later version
Patch: Although the Cloud Foundry environment itself is not vulnerable to this exploit, we nevertheless rec
Although the Cloud Foundry environment itself is not vulnerable to this exploit, we nevertheless recommend to upgrade log4j-core to the latest available version if log4j-core is part of your project. https://support.sw.siemens.com/en-US/product/268530510/knowledge- base/PL8600797
Patch: Update to V4.0.3 or later version
Update to V4.0.3 or later version
Patch: Update Teamcenter to any fix version available for the different version lines of Teamcenter, see ht
Update Teamcenter to any fix version available for the different version lines of Teamcenter, see https://support.sw.siemens.com/en- US/knowledge-base/PL8600700
Patch: Update to VX.2.10 Update 4 or later version
Update to VX.2.10 Update 4 or later version
Patch: Update to V1.6 SP1 and apply the patch
Update to V1.6 SP1 and apply the patch
Patch: Update to V3.5 or later version
Update to V3.5 or later version
Patch: Follow the remediation steps documented at https://ask.adaptec.com/app/answers/detail/a_id/17527/
Follow the remediation steps documented at https://ask.adaptec.com/app/answers/detail/a_id/17527/
Patch: Update to V4.3.3 or later version
Update to V4.3.3 or later version
Patch: Apply the hotfix, available for versions V14.1, V15.0, V15.1, V15.1.2, V16.0, V16.0.1, V16.0.2, V16.
Apply the hotfix, available for versions V14.1, V15.0, V15.1, V15.1.2, V16.0, V16.0.1, V16.0.2, V16.1, V16.1.1, V16.1.2
Patch: Update to VX.2.7 Update 19 or later version
Update to VX.2.7 Update 19 or later version
Patch: Update to V12.2.8 or later version
Update to V12.2.8 or later version
Patch: Update to V2019.1 SP2204 or later version
Update to V2019.1 SP2204 or later version
Patch: Vulnerabilities fixed with update on 2021-12-23; no user actions necessary
Vulnerabilities fixed with update on 2021-12-23; no user actions necessary
Patch: Update to VX.2.10 Update 4 or later version
Update to VX.2.10 Update 4 or later version
Mitigation: Specific mitigations and how to apply are described in the SE Controls Security Announcement Inciden
Specific mitigations and how to apply are described in the SE Controls Security Announcement Incident 2021-01, available in the customer portal. https://cep.siemens-energy.com/cep/
Mitigation: Ensure that SPPA-T3000 is set up according to the security concept defined in the SPPA-T3000 securit
Ensure that SPPA-T3000 is set up according to the security concept defined in the SPPA-T3000 security manual
Mitigation: Restrict physical access to the local networks of the solution
Restrict physical access to the local networks of the solution
Mitigation: Open TraceAlertServerPLUS.exe with Zip tool to remove file JndiLookup.class in directory org/apache/
Open TraceAlertServerPLUS.exe with Zip tool to remove file JndiLookup.class in directory org/apache/logging/log4j/core/lookup/. This measure mitigates both CVE-2021-44228 and CVE-2021-45046.
Mitigation: Check file system permissions
Check file system permissions
Mitigation: Review the status of the defense in depth recommendations that apply to your specific deployment and
Review the status of the defense in depth recommendations that apply to your specific deployment and align as needed. Especially the measures on the network layer to prevent accessibility from other network segments
Mitigation: Ensure that TraceAlertServerPLUS does not run with elevated privileges
Ensure that TraceAlertServerPLUS does not run with elevated privileges
Patch: Vulnerabilities fixed on central cloud service between 2021-12-10 (CVE-2021-44228) and 2021-12-21 (C
Vulnerabilities fixed on central cloud service between 2021-12-10 (CVE-2021-44228) and 2021-12-21 (CVE-2021-45105); no user actions necessary
Mitigation: Note: EnergyIP V8.5 and V8.6 applications are not directly affected, but CAS is.
Note: EnergyIP V8.5 and V8.6 applications are not directly affected, but CAS is.
Patch: Vulnerabilities fixed for Command installations on a project basis; no user actions necessary
Vulnerabilities fixed for Command installations on a project basis; no user actions necessary
Mitigation: Note: Earlier versions of the product contained a vulnerable version of log4j, but no risk for explo
Note: Earlier versions of the product contained a vulnerable version of log4j, but no risk for exploitation could be identified.
Patch: Vulnerabilities fixed on central cloud service starting 2021-12-13; no user actions necessary
Vulnerabilities fixed on central cloud service starting 2021-12-13; no user actions necessary
Mitigation: Stop and disable autostart for maxView Storage Manager WebServer. Note: This software is not require
Stop and disable autostart for maxView Storage Manager WebServer. Note: This software is not required for the underlying RAID to work
Mitigation: Find detailed mitigation steps for both server and client installations at: https://support.sw.sieme
Find detailed mitigation steps for both server and client installations at: https://support.sw.siemens.com/en-US/knowledge- base/PL8602538
Mitigation: If, for a particular product listed in the table above, no remediation or specific mitigation is giv
If, for a particular product listed in the table above, no remediation or specific mitigation is given: Block both incoming and outgoing connections between the system and the Internet.
Mitigation: Find detailed mitigation steps at: https://support.sw.siemens.com/en- US/knowledge-base/MG618363
Find detailed mitigation steps at: https://support.sw.siemens.com/en- US/knowledge-base/MG618363
Patch: Update to V1.4.0-42 or later version
Update to V1.4.0-42 or later version
Patch: Although the Mendix runtime itself is not vulnerable to this exploit, we nevertheless recommend to u
Although the Mendix runtime itself is not vulnerable to this exploit, we nevertheless recommend to upgrade log4j-core to the latest available version if log4j-core is part of your project. This advice is regardless of the JRE/JDK version the app runs on.
Mitigation: Additional information is available at https://support.sw.siemens.com/en-US/product/1644094854/knowl
Additional information is available at https://support.sw.siemens.com/en-US/product/1644094854/knowledge- base/MG618343
Patch: Update to V1.4.11 or later version
Update to V1.4.11 or later version
Patch: Update to V4.4.1 or later version
Update to V4.4.1 or later version
Mitigation: Find detailed remediation and mitigation information at: https://support.sw.siemens.com/knowledge-ba
Find detailed remediation and mitigation information at: https://support.sw.siemens.com/knowledge-base/MG618362
Patch: Vulnerabilities fixed for Vantage installations on a project basis; no user actions necessary
Vulnerabilities fixed for Vantage installations on a project basis; no user actions necessary
Mitigation: Find detailed remediation and mitigation information at: https://support.sw.siemens.com/en-US/knowle
Find detailed remediation and mitigation information at: https://support.sw.siemens.com/en-US/knowledge-base/PL8601468
Mitigation: For Comfy and Enlighted, see also chapter Additional Information below
For Comfy and Enlighted, see also chapter Additional Information below
Mitigation: Disable ports 8080/tcp and 8443/tcp in the firewall configuration of the IPC
Disable ports 8080/tcp and 8443/tcp in the firewall configuration of the IPC
Mitigation: Find detailed remediation and mitigation information at: https://support.sw.siemens.com/en-US/knowle
Find detailed remediation and mitigation information at: https://support.sw.siemens.com/en-US/knowledge-base/PL8600700
Patch: Vulnerability CVE-2021-44228 fixed on central cloud service starting 2021-12-13; no user actions nec
Vulnerability CVE-2021-44228 fixed on central cloud service starting 2021-12-13; no user actions necessary
Mitigation: Find detailed remediation and mitigation information at: https://support.sw.siemens.com/en-US/knowle
Find detailed remediation and mitigation information at: https://support.sw.siemens.com/en-US/knowledge-base/PL8601203
Patch: Vulnerabilities fixed on central cloud service starting 2021-12-11; no user actions necessary
Vulnerabilities fixed on central cloud service starting 2021-12-11; no user actions necessary
Patch: Update to V3.0.29 or later version
Update to V3.0.29 or later version
Patch: Update to V4.70 SP9 Security Patch 1 or later version. Please contact your local Siemens representa
Update to V4.70 SP9 Security Patch 1 or later version. Please contact your local Siemens representative.
Patch: Apply the patch. Please contact your local Siemens representative.
Apply the patch. Please contact your local Siemens representative.
Patch: Update to V12.1.0.14 or later version
Update to V12.1.0.14 or later version
Patch: Vulnerabilities fixed with update on 2021-12-21; no user actions necessary
Vulnerabilities fixed with update on 2021-12-21; no user actions necessary
Patch: Update to V3.0.30 or later version
Update to V3.0.30 or later version
Patch: Update to V13.17.2 was deployed on all cRSP services on 2021-12-21; no user actions necessary
Update to V13.17.2 was deployed on all cRSP services on 2021-12-21; no user actions necessary
Patch: Follow the remediation steps documented at: https://support.sw.siemens.com/en-US/knowledge-base/PL86
Follow the remediation steps documented at: https://support.sw.siemens.com/en-US/knowledge-base/PL8602466
Patch: Vulnerabilities fixed on remote VPL server; no user actions necessary
Vulnerabilities fixed on remote VPL server; no user actions necessary
Patch: Update to V4.2.3 or later version
Update to V4.2.3 or later version
Patch: Update to V2021.1 SP2202 or later version
Update to V2021.1 SP2202 or later version
Patch: Update to VX.2.8 Update 13 or later version
Update to VX.2.8 Update 13 or later version
Patch: Update to V5.2.4 or later version
Update to V5.2.4 or later version
Mitigation: For customers requiring the use of Uni-Telway driver, Schneider Electric recommends using following
For customers requiring the use of Uni-Telway driver, Schneider Electric recommends using following mitigations to reduce the risk of exploit:• McAfee Application and Change Control software for application control. Refer to the Cybersecurity Application Note available https://www.se.com/ww/en/download/document/EIO0000004778/ • Follow workstation, network and site-hardening guidelines in the Schneider Electric [Recommended Cybersecurity Best Practices](https://www.se.com/ww/en/download/document/7EN52-0390/) document. For customers not requiring the use of Uni-Telway driver, Schneider Electric recommends uninstalling the driver. Version 16.2 of EcoStruxureTM Control Expert, version 2025 of EcoStruxureTM Process Expert, version 2025 of EcoStruxureTM Process Expert for AVEVA System Platform, and version 3.63SP3 of OPC Factory Server do not include Uni-Telway driver by default anymore. This vulnerability is only affecting customers who have installed Uni-Telway driver.
Mitigation: Schneider Electric is establishing a remediation plan for all future versions of Security Administra
Schneider Electric is establishing a remediation plan for all future versions of Security Administrator configuration software that will include a fix for this vulnerability. We will update this document when the remediation is available. Until then, customers should immediately apply the following mitigations to reduce the risk of exploit:• Only open project files received from a trusted source. • Compute a hash of the project files and regularly check the consistency of this hash to verify the integrity before usage.• Encrypt project file when stored and restrict the access to only trusted users. • When exchanging files over the network, use secure communication protocols. • Follow the SCADAPack™ Security Guidelines
Patch: Version R3.4.2 RemoteConnect configuration software includes a fix for this vulnerability and is ava
Version R3.4.2 RemoteConnect configuration software includes a fix for this vulnerability and is available for download here:https://www.se.com/ww/en/download/document/RemoteConnect/
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: Schneider Electric is establishing a remediation plan for all future versions of Security Administrator configuration software that will include a fix for this vulnerability. We will update this document when the remediation is available. Until then, customers should immediately apply the following mitigations to reduce the risk of exploit:• Only open project files received from a trusted source. • Compute a hash of the project files and regularly check the consistency of this hash to verify the integrity before usage.• Encrypt project file when stored and restrict the access to only trusted users. • When exchanging files over the network, use secure communication protocols. • Follow the SCADAPack™ Security Guidelines
Patch: Modicon M580 CPU (part numbers BMEP* and BMEH*): Firmware SV4.10 includes a fix for this vulnerabili
Modicon M580 CPU (part numbers BMEP* and BMEH*): Firmware SV4.10 includes a fix for this vulnerability and is available for download.
Mitigation: For more information, see Schneider Electric's security advisory SEVD-2023-010-05.
For more information, see Schneider Electric's security advisory SEVD-2023-010-05.
Mitigation: Users should contact Schneider Electric for assistance in removing a patch.
Users should contact Schneider Electric for assistance in removing a patch.
Patch: EcoStruxure Process Expert: Version V2021 available for download and is not impacted by this vulnera
EcoStruxure Process Expert: Version V2021 available for download and is not impacted by this vulnerability as the affected component has been removed from this version.
Patch: Modicon M340 CPU (part numbers BMXP34*): Firmware SV3.51 includes a fix for this vulnerability and i
Modicon M340 CPU (part numbers BMXP34*): Firmware SV3.51 includes a fix for this vulnerability and is available for download.
Mitigation: Users should apply the best practices for network hardening as documented in the product user guide
Users should apply the best practices for network hardening as documented in the product user guide and the Schneider Electric Recommended Cybersecurity Best Practices.
Mitigation: Users should use appropriate patching methodologies when applying these patches to their systems. Sc
Users should use appropriate patching methodologies when applying these patches to their systems. Schneider Electric recommends using backups and evaluating the impact of these patches in a "testing and development environment" or on an offline infrastructure.
Patch: Modicon Momentum Unity M1E Processor (part numbers 171CBU*): Firmware VS2.6 includes a fix for this
Modicon Momentum Unity M1E Processor (part numbers 171CBU*): Firmware VS2.6 includes a fix for this vulnerability and is available for download.
Mitigation: Schneider Electric has released the following remediations for users to implement:
Schneider Electric has released the following remediations for users to implement:
Patch: EcoStruxure Control Expert: Software V15.3 includes a fix for this vulnerability and is available fo
EcoStruxure Control Expert: Software V15.3 includes a fix for this vulnerability and is available for download.
Patch: Modicon MC80 CPU (part numbers BMKC80*): Firmware SV1.90 includes a fix for this vulnerability and i
Modicon MC80 CPU (part numbers BMKC80*): Firmware SV1.90 includes a fix for this vulnerability and is available for download.
Patch: Hotfix_75031_PME2022 available for EcoStruxure™ Power Monitoring Expert (PME) that includes a fix
Hotfix_75031_PME2022 available for EcoStruxure™ Power Monitoring Expert (PME) that includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center https://www.se.com/us/en/work/support/ to download this hotfix.
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit. EcoStruxure™ Power Monitoring Expert 2021 and prior have reached end-of-life support. Customers should consider upgrading to the latest version offering of PME to resolve this issue. Please contact Schneider Electric Customer Care Center https://www.se.com/us/en/work/support/ for more details.
Mitigation: 3S-Smart Software Solutions GmbH continued investigating the issue after Version 3.5.15.0 was releas
3S-Smart Software Solutions GmbH continued investigating the issue after Version 3.5.15.0 was released as an initial mitigation. They have released version 3.5.16.0 as a more complete resolution for this vulnerability in all affected CODESYS products.
Mitigation: Use controllers and devices only in a protected environment to minimize network exposure and ensure
Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.
Mitigation: Use firewalls to protect and separate the control system network from other networks.
Use firewalls to protect and separate the control system network from other networks.
Mitigation: Limit the access to both development and control system by physical means, operating system features
Limit the access to both development and control system by physical means, operating system features, etc.
Mitigation: Protect both development and control system by using up to date virus detecting solutions. For more
Protect both development and control system by using up to date virus detecting solutions. For more information and general recommendations for protecting machines and plants, see also the CODESYS security whitepaper.
Mitigation: For more information, 3S-Smart Software Solutions GmbH has released a security report.
For more information, 3S-Smart Software Solutions GmbH has released a security report.
Mitigation: Use VPN (virtual private networks) tunnels if remote access is required.
Use VPN (virtual private networks) tunnels if remote access is required.
Mitigation: Please visit the CODESYS update page for more information on how to obtain the software update: http
Please visit the CODESYS update page for more information on how to obtain the software update: https://www.codesys.com/download/
Mitigation: Activate and apply user management and password features.
Activate and apply user management and password features.
Mitigation: Place all controllers in locked cabinets and never leave them in the "Program" mode.
Place all controllers in locked cabinets and never leave them in the "Program" mode.
Mitigation: Schneider Electric has released the following mitigations/fixes for the following products:
Schneider Electric has released the following mitigations/fixes for the following products:
Mitigation: Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. bef
Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.
Mitigation: Minimize network exposure for all control system devices and systems and ensure that they are not ac
Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.
Mitigation: Schneider Electric also recommends the following cybersecurity best practices:
Schneider Electric also recommends the following cybersecurity best practices:
Mitigation: For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices docume
For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document.
Mitigation: Install physical controls so no unauthorized personnel can access your industrial control and safety
Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.
Mitigation: Never connect programming software to any network other than the network intended for that device.
Never connect programming software to any network other than the network intended for that device.
Mitigation: For further information, see Schnieder Electric's Security Advisory.
For further information, see Schnieder Electric's Security Advisory.
Mitigation: When remote access is required, use secure methods, such as virtual private networks (VPNs). Recogni
When remote access is required, use secure methods, such as virtual private networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.
Mitigation: Locate control and safety system networks and remote devices behind firewalls and isolate them from
Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.
Mitigation: Never allow mobile devices that have connected to any other network besides the intended network to
Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.
Patch: The table will be updated in case vulnerable products become known.
The table will be updated in case vulnerable products become known.
Mitigation: For more information on this vulnerability, including security updates, please see security bulletin
For more information on this vulnerability, including security updates, please see security bulletin AVEVA-2022-001
Mitigation: Utilize OS group policy objects (GPOs) to further restrict what those unique user accounts are allow
Utilize OS group policy objects (GPOs) to further restrict what those unique user accounts are allowed to do.
Mitigation: Create unique user accounts with minimal privileges dedicated only to remote access of InTouch Acces
Create unique user accounts with minimal privileges dedicated only to remote access of InTouch Access Anywhere and Plant SCADA Access Anywhere applications.
Mitigation: Restrict access based on Microsoft's recommended block list.
Restrict access based on Microsoft's recommended block list.
Mitigation: Disable the Windows language bar on the server machine hosting InTouch Access Anywhere and Plant SCA
Disable the Windows language bar on the server machine hosting InTouch Access Anywhere and Plant SCADA Access Anywhere applications unless it is required.
Mitigation: When remote access is required, use secure methods, such as virtual private networks (VPNs). Recogni
When remote access is required, use secure methods, such as virtual private networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.
Mitigation: Never allow mobile devices that have connected to any other network besides the intended network to
Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.
Mitigation: https://www.apc.com/pcss
https://www.apc.com/pcss
Mitigation: Version 2.6-GA-01-23248 of Easy UPS Online Monitoring Software includes a fix for the vulnerabilitie
Version 2.6-GA-01-23248 of Easy UPS Online Monitoring Software includes a fix for the vulnerabilities for Microsoft supported versions of Windows 10, 11, Windows Server 2016, 2019 & 2022 and is available for download.
Mitigation: Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. bef
Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.
Mitigation: Install physical controls so no unauthorized personnel can access your industrial control and safety
Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.
Mitigation: Place all controllers in locked cabinets and never leave them in the "Program" mode.
Place all controllers in locked cabinets and never leave them in the "Program" mode.
Mitigation: For more information on this vulnerability and the associated mitigations, see Schneider Electric vu
For more information on this vulnerability and the associated mitigations, see Schneider Electric vulnerability disclosure SEVD-2023-346-03.
Mitigation: https://www.apc.com/pcns
https://www.apc.com/pcns
Mitigation: Minimize network exposure for all control system devices and systems and ensure that they are not ac
Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.
Mitigation: Never connect programming software to any network other than the network intended for that device.
Never connect programming software to any network other than the network intended for that device.
Mitigation: For more information on cybersecurity industry best practices, refer to the Schneider Electric recom
For more information on cybersecurity industry best practices, refer to the Schneider Electric recommended cybersecurity best practices document.
Mitigation: Locate control and safety system networks and remote devices behind firewalls and isolate them from
Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.
Mitigation: The Easy UPS Online Monitoring Software has been discontinued coinciding with the discontinuation of
The Easy UPS Online Monitoring Software has been discontinued coinciding with the discontinuation of the Easy UPS Online SNMP Cards (APV9601, APVS9601) managed by this software.
Mitigation: Schneider Electric strongly recommends users follow cybersecurity industry best practices, including
Schneider Electric strongly recommends users follow cybersecurity industry best practices, including:
Mitigation: Schneider Electric recommends that users currently using Easy UPS Online Monitoring Software to mana
Schneider Electric recommends that users currently using Easy UPS Online Monitoring Software to manage Easy UPS Online (SRV/SRVS) should transition to PowerChute Serial Shutdown for serial/USB shutdown and monitoring; and to PowerChute Network Shutdown for network shutdown and monitoring. For more information about PowerChute software please see the following:
Mitigation: Only build and run applications from trusted sources.
Only build and run applications from trusted sources.
Patch: Update to V3.1.5 or later version
Update to V3.1.5 or later version
Patch: Update to V2.0 SP1 or later version
Update to V2.0 SP1 or later version
Mitigation: Please see Schneider Electric's publication SEVD-2021-159-05 for more information.
Please see Schneider Electric's publication SEVD-2021-159-05 for more information.
Mitigation: Web access service is disabled by default. Because the web server is only necessary for specific mai
Web access service is disabled by default. Because the web server is only necessary for specific maintenance and configuration activities, it is advised users disable the web (HTTP) service when it is not needed through the Ecostruxure Control Expert application.
Mitigation: Set up network segmentation and implement a firewall to block all unauthorized access to HTTP Port 8
Set up network segmentation and implement a firewall to block all unauthorized access to HTTP Port 80/TCP on the controllers.
Patch: Change the default password used to access the device web server. Update username and password for H
Change the default password used to access the device web server. Update username and password for HTTP access rights with the “Security” link on the Setup page. See the Modicon X80 BMXNOR0200H RTU Module User Manual.
Mitigation: When used in an architecture including a BMXNOC module, configure the Access Control Lists following
When used in an architecture including a BMXNOC module, configure the Access Control Lists following the recommendation in the Modicon Controllers Platform Cyber Security Reference Manual.
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • Limit authenticated user access to the workstation and implement existing User Account Control practices. • Follow workstation, network and site-hardening guidelines in the Recommended Cybersecurity Best Practices guide available for download here.
Mitigation: Locate control and safety system networks and remote devices behind firewalls and isolate them from
Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.
Patch: Version V6.3SP1 HF1 of Vijeo Designer includes a fix for this vulnerability. Please contact your S
Version V6.3SP1 HF1 of Vijeo Designer includes a fix for this vulnerability. Please contact your Schneider Electric Customer Support https://www.se.com/ww/en/work/support/country-selector/contact-us.jsp to get Vijeo Designer version V6.3SP1 HF1 software.
Patch: EcoStruxure Machine Expert Twin: All versions
EcoStruxure Machine Expert Twin: All versions
Patch: Version 4.0 of Pro-face BLUE includes a fix for this vulnerability and is available for download h
Version 4.0 of Pro-face BLUE includes a fix for this vulnerability and is available for download here: https://www.proface.com/en/hmi_design_studio/blue/page/installer
Mitigation: When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recogni
When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.
Mitigation: Never connect programming software to any network other than the network intended for that device.
Never connect programming software to any network other than the network intended for that device.
Mitigation: Limit authenticated user access to the workstation and implement existing User Account Control pract
Limit authenticated user access to the workstation and implement existing User Account Control practices.
Patch: Version v2.3 of EcoStruxure™ Machine Expert Twin includes a fix for this vulnerability and can be in
Version v2.3 of EcoStruxure™ Machine Expert Twin includes a fix for this vulnerability and can be installed through Schneider Electric Software Installer available here: https://www.se.com/ww/en/download/document/ESEMACS10_INSTALLER/
Patch: Version 2023 (v4.8.0.5715) of EcoStruxure™ Process Expert includes a fix for this vulnerability an
Version 2023 (v4.8.0.5715) of EcoStruxure™ Process Expert includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-country-selector/?pageType=product-range&sourceId=65406
Mitigation: EcoStruxure Machine SCADA Expert - Asset Link: All versions
EcoStruxure Machine SCADA Expert - Asset Link: All versions
Mitigation: For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices docume
For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document.
Patch: EcoStruxure Machine Expert including EcoStruxure Machine Expert Safety: All versions
EcoStruxure Machine Expert including EcoStruxure Machine Expert Safety: All versions
Mitigation: Follow workstation, network and site-hardening guidelines in the Recommended Cybersecurity Best Prac
Follow workstation, network and site-hardening guidelines in the Recommended Cybersecurity Best Practices guide available for download here.
Mitigation: Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. bef
Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.
Mitigation: The document will be updated when the remediation is available. Until then, customers should immedia
The document will be updated when the remediation is available. Until then, customers should immediately apply the following mitigations to reduce the risk of exploit:
Patch: EcoStruxure Process Expert for AVEVA System Platform: All versions
EcoStruxure Process Expert for AVEVA System Platform: All versions
Mitigation: To ensure you are informed of all updates, including details on affected products and remediation pl
To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric's security notification service here.
Mitigation: Place all controllers in locked cabinets and never leave them in the "Program" mode.
Place all controllers in locked cabinets and never leave them in the "Program" mode.
Patch: Version 5.4.3 of Zelio Soft 2 includes a fix for this vulnerability and is available for download he
Version 5.4.3 of Zelio Soft 2 includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/542-zelio-soft/#software-and-firmware
Patch: Version v2.5.0.1 of EcoStruxure™ Machine Expert includes a fix for this vulnerability and can be ins
Version v2.5.0.1 of EcoStruxure™ Machine Expert includes a fix for this vulnerability and can be installed through Schneider Electric Software Installer available here: https://www.se.com/ww/en/download/document/ESEMACS10_INSTALLER/
Mitigation: Never allow mobile devices that have connected to any other network besides the intended network to
Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.
Patch: Version V7.0.18 of EcoStruxure™ Architecture Builder includes a fix for this vulnerability and is a
Version V7.0.18 of EcoStruxure™ Architecture Builder includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/195445393-ecostruxure-architecture-builder/ - software-and-firmware
Mitigation: Install physical controls so no unauthorized personnel can access your industrial control and safety
Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.
Mitigation: General Security Recommendations
General Security Recommendations
Patch: Version SV2.01SP3 of EcoStruxure™ OPC UA Server Expert includes a fix for this vulnerability and is
Version SV2.01SP3 of EcoStruxure™ OPC UA Server Expert includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/66388-ecostruxure-opc-ua-server-expert/#software-and-firmware
Mitigation: Schneider Electric is establishing a remediation plan for all future versions of the following tha
Schneider Electric is establishing a remediation plan for all future versions of the following that will include a fix for this vulnerability: • EcoStruxure™ Process Expert • EcoStruxure™ OPC UA Server Expert • EcoStruxure™ Machine SCADA Expert - Asset Link • EcoStruxure™ Operator Terminal Expert • EcoStruxure™ Machine Expert including EcoStruxure™ Machine Expert Safety • EcoStruxure™ Machine Expert Twin • Zelio Soft 2 We will update this document when the remediation is available. Until then, customers should immediately apply the following mitigations to reduce the risk of exploit: • Limit authenticated user access to the workstation and implement existing User Account Control practices. • Follow workstation, network and site-hardening guidelines in the Recommended Cybersecurity Best Practices guide available for download here https://www.se.com/ww/en/download/document/7EN52-0390/?ssr=true .
Mitigation: Minimize network exposure for all control system devices and systems and ensure that they are not ac
Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.
Patch: Version 2023 (v4.8.0.5715) of EcoStruxure™ Process Expert includes a fix for this vulnerability an
Version 2023 (v4.8.0.5715) of EcoStruxure™ Process Expert includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-country-selector/?pageType=productrange& sourceId=65406 Uninstall previous version 2023 (v4.8.0.5115) before installing Version 2023 (v4.8.0.5715). Version string can be found on engineering server console.
Patch: Version 4.0 of EcoStruxure™ Operator Terminal Expert includes a fix for this vulnerability and is
Version 4.0 of EcoStruxure™ Operator Terminal Expert includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/62621-ecostruxure-operator-terminal-expert/#software-and-firmware
Mitigation: Schneider Electric strongly recommends the following industry cybersecurity best practices:
Schneider Electric strongly recommends the following industry cybersecurity best practices:
Patch: Version V4.0SP1 of EcoStruxure™ Control Expert Asset Link includes a fix for this vulnerability an
Version V4.0SP1 of EcoStruxure™ Control Expert Asset Link includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/download/document/ECALV40SP1/
Patch: Version 16.2 of EcoStruxure™ Control Expert includes a fix for this vulnerability and is available
Version 16.2 of EcoStruxure™ Control Expert includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/548-ecostruxure-control-expert-unity-pro/ Reboot the computer after installation is completed.
Mitigation: Users of the affected software unable to upgrade to one of the corrected versions should follow Rock
Users of the affected software unable to upgrade to one of the corrected versions should follow Rockwell Automation's security best practices.
Mitigation: Version 1.007
Version 1.007
Mitigation: Rockwell Automation released a product update addressing this vulnerability:
Rockwell Automation released a product update addressing this vulnerability:
Patch: The table will be updated in case vulnerable products become known.
The table will be updated in case vulnerable products become known.
Patch: Update to V3.0.4 or later version
Update to V3.0.4 or later version
Mitigation: Schneider Electric recommends users to update to Version 1.15.9 or later. Note: A reboot will be nee
Schneider Electric recommends users to update to Version 1.15.9 or later. Note: A reboot will be needed after the update.
Mitigation: Use an allow list for this application
Use an allow list for this application
Mitigation: Use an antivirus program
Use an antivirus program
Mitigation: See Schneider Electric's security notification SEVD-2021-194-04 for more information.
See Schneider Electric's security notification SEVD-2021-194-04 for more information.
Mitigation: Secure the computer to prevent unauthorized personnel from accessing the computer
Secure the computer to prevent unauthorized personnel from accessing the computer
Mitigation: Turn on the computer's firewall
Turn on the computer's firewall
Patch: To further reduce the risk, apply v6.8.4 or later of the Enerlin'X Com'X 510 firmware.
To further reduce the risk, apply v6.8.4 or later of the Enerlin'X Com'X 510 firmware.
Mitigation: If the Guest account password on the device remains set to the default value, users should immediate
If the Guest account password on the device remains set to the default value, users should immediately change the account password to one that is unique and has a strong value.
Mitigation: Users who have configured their Com'X 510 device to access remote SMTP, FTP, or HTTPS services shoul
Users who have configured their Com'X 510 device to access remote SMTP, FTP, or HTTPS services should immediately change access passwords on the affected services and update the Com'X configuration.
Mitigation: For additional information on this vulnerability, see Schneider Electric's security notification SEV
For additional information on this vulnerability, see Schneider Electric's security notification SEVD-2021-159-06
Mitigation: Schneider Electric recommends that customers update to Version 5.4.2.2. It can be updated through th
Schneider Electric recommends that customers update to Version 5.4.2.2. It can be updated through the Schneider Electric Software Update (SESU) application and is also available for download here.
Patch: Version 1.23.1.10 of EcoStruxure™ IT Gateway includes a fix for this vulnerability and is availabl
Version 1.23.1.10 of EcoStruxure™ IT Gateway includes a fix for this vulnerability and is available for download here: • https://community.se.com/t5/What-s-new-inEcoStruxure-IT/Download-the-EcoStruxure-ITGateway/ta-p/455022 • Instructions provided in the link above. • We encourage customers to enable automatic updates to receive updates promptly. • Customers who have enabled automatic updates do not need to take any further action. Prior versions are not impacted by this vulnerability.
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: Customers should protect the Gateway from remote access by controlling access to the software over a network. The following actions could be taken: • Placing the Gateway software on protected access-controlled networks only • Implementing a local firewall to deny remote access to the web API. • Removing the Gateway software and installing a clean build of 1.23.1.10
Patch: Version ES v2.7.52 of EcoStruxure Power Build Rapsody includes a fix for this vulnerability and are
Version ES v2.7.52 of EcoStruxure Power Build Rapsody includes a fix for this vulnerability and are available for download here: https://www.se.com/es/es/product-range/2309-ecostruxure-power-build-rapsody/#software-and-firmwarePlease reboot after installing the new version.
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • Only open projects from trusted sources. • Ensure use of malware scans before opening any externally created project • Encrypt project file when stored and restrict the access to only trusted users. • When exchanging files over the network, use secure communication protocols. • Compute a hash of the project files and regularly check the consistency of this hash to verify the integrity before usage. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/security-notifications.jsp
Patch: Version FR v2.7.12 of EcoStruxure Power Build Rapsody includes a fix for this vulnerability and are
Version FR v2.7.12 of EcoStruxure Power Build Rapsody includes a fix for this vulnerability and are available for download here: https://www.se.com/fr/fr/product-range/2309-ecostruxure-power-build-rapsody/#software-and-firmwarePlease reboot after installing the new version.
Patch: Version NL v2.7.2 of EcoStruxure Power Build Rapsody includes a fix for this vulnerability and are a
Version NL v2.7.2 of EcoStruxure Power Build Rapsody includes a fix for this vulnerability and are available for download here: https://www.se.com/nl/nl/product-range/2309-ecostruxure-power-build-rapsody/#software-and-firmware Please reboot after installing the new version.
Patch: Version v2.8.4 INT of EcoStruxure Power Build Rapsody includes a fix for this vulnerability and is a
Version v2.8.4 INT of EcoStruxure Power Build Rapsody includes a fix for this vulnerability and is available for download here:https://www.se.com/ww/en/product-range/2309-ecostruxure-power-build-rapsody/#overview Please reboot the system after installing the new version.
Patch: Upgrade PowerManage to Version 4.10
Upgrade PowerManage to Version 4.10
Patch: Remove the JndiLookup class from the classpath. Detailed instructions are available at https://suppo
Remove the JndiLookup class from the classpath. Detailed instructions are available at https://support.industry.siemens.com/cs/ww/en/view/109805562/
Patch: Update to V5.1 QU1 or later version
Update to V5.1 QU1 or later version
Patch: Update to V5.2.4 or later version
Update to V5.2.4 or later version
Mitigation: Note: EnergyIP V8.5 and V8.6 applications are not directly affected, but CAS is.
Note: EnergyIP V8.5 and V8.6 applications are not directly affected, but CAS is.
Mitigation: Johnson Controls recommends upgrading exacq Enterprise Manager to Version 21.12.1 or apply manual mi
Johnson Controls recommends upgrading exacq Enterprise Manager to Version 21.12.1 or apply manual mitigation steps (available upon request).
Mitigation: Further ICS security notices and product security guidance are located at Johnson Controls product s
Further ICS security notices and product security guidance are located at Johnson Controls product security website.
Mitigation: Refer to the exacq Hardening Guide for guidance on isolating exacqVision NVRs and Enterprise Manager
Refer to the exacq Hardening Guide for guidance on isolating exacqVision NVRs and Enterprise Manager from public facing networks to reduce network exposure to attacks.
Mitigation: For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI
For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2021-24 v1
Mitigation: For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI
For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2022-01 v1
Patch: Version 2.7.0 of PowerLogic PM5341 includes a fix for this vulnerability and is available for down
Version 2.7.0 of PowerLogic PM5341 includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product/METSEPM5341/pm5341-meter-ethernet-up-to31st-h-256k-2di-2do-35-alarms-mid/
Patch: Version 2.4.0 of PowerLogic PM5340 includes a fix for this vulnerability and is available for down
Version 2.4.0 of PowerLogic PM5340 includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product/METSEPM5340/power-meter-powerlogicpm5340-ethernet-up-to-31st-harmonic-256kb-2di-2do-35-alarms
Patch: Version 2.4.0 of PowerLogic PM5320 includes a fix for this vulnerability and is available for down
Version 2.4.0 of PowerLogic PM5320 includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product/METSEPM5340/power-meter-powerlogicpm5340-ethernet-up-to-31st-harmonic-256kb-2di-2do-35-alarms
Mitigation: If customers choose not to apply the remediation provided above, they should immediately apply the f
If customers choose not to apply the remediation provided above, they should immediately apply the following steps to reduce the risk of exploit: 1. Enable IGMP Snooping: o Ensure that IGMP Snooping is enabled on the switch. This feature allows the switch to intelligently forward multicast traffic only to the necessary ports where interested hosts reside. It prevents unnecessary flooding of multicast traffic across all ports, thereby enhancing network efficiency and minimizing unnecessary load on network resources. 2. Configure VLAN Interface Settings: o Set up VLAN interface settings on the switch. It's important to have distinct configurations for each VLAN to ensure proper IGMP operation. 3. Multicast Filtering: o Use IGMP filtering to control the propagation of IGMP traffic through the network. This involves configuring filters on a switch virtual interface (SVI), per-port, or per-port per-VLAN basis. Multicast filtering helps manage IGMP snooping and controls multicast traffic forwarding effectively.
Mitigation: Triangle Microworks recommends users update to Version 3.26.
Triangle Microworks recommends users update to Version 3.26.
Mitigation: Please contact Triangle MicroWorks support for additional details.
Please contact Triangle MicroWorks support for additional details.

// References