تحديثات Schneider Electric
3089تاريخ التحذير
مستوى الخطورة
رقم التحذير
القطاع المستهدف
10 نوفمبر, 2021
● عالٍ جدًا
2021-3835
الطاقة - الصناعة
الوصف:
أصدرت Schneider Electric عدى تحديثات لمعالجة عدد من الثغرات في المنتجات التالية:
- GUIcon
- Versions 2.0 (Build 683.003) and prior
- Uninterruptible Power Supply (UPS) Products
- 1-Phase Uninterruptible Power Supply (UPS) using NMC2, including Smart-UPS, Symmetra, and Galaxy 3500 with Network Management Card 2 (NMC2): NMC2 AOS v6.9.8 and prior
- 3-Phase Uninterruptible Power Supply (UPS) using NMC2, including Symmetra PX 250/500 (SYPX) Network Management Card 2 (NMC2): NMC2 AOS v6.9.6 and prior
- 3-Phase Uninterruptible Power Supply (UPS) using NMC2 including Symmetra PX 48/96/100/160 kW UPS (PX2), Symmetra PX 20/40 kW UPS (SY3P), Gutor (SXW, GVX), and Galaxy (GVMTS, GVMSA, GVXTS, GVXSA, G7K, GFC, G9KCHU): NMC2 AOS v6.9.6 and prior
- 1-Phase Uninterruptible Power Supply (UPS) using NMC3 including Smart-UPS, Symmetra, and Galaxy 3500 with Network Management Card 3 (NMC3): NMC3 AOS v1.4.2.1 and prior
- APC Power Distribution Products
- APC Rack Power Distribution Units (PDU) using NMC2: NMC2 AOS v6.9.6 and prior
- APC Rack Power Distribution Units (PDU) using NMC3: NMC3 AOS v1.4.0 and prior
- APC 3-Phase Power Distribution Products using NMC2: NMC2 AOS v6.9.6 and prior
- Network Management Card 2 (NMC2) for InfraStruxure 150 kVA PDU with 84 Poles (X84P): NMC2 AOS v6.9.6 and prior
- Network Management Card 2 for InfraStruxure 40/60kVA PDU (XPDU): NMC2 AOS v6.9.6 and prior
- Network Management Card 2 for Modular 150/175kVA PDU (XRDP): NMC2 AOS v6.9.6 and prior
- Network Management Card 2 for 400 and 500 kVA (PMM): NMC2 AOS v6.9.6 and prior
- Network Management Card 2 for Modular PDU (XRDP2G): NMC2 AOS v6.9.6 and prior
- Rack Automatic Transfer Switches (ATS): NMC2 AOS v6.9.6 and prior
- Environmental Monitoring
- Environmental Monitoring Unit with embedded NMC2 (NB250) NetBotz NBRK0250: NMC2 AOS v6.9.6 and prior
- Cooling Products
- Network Management Card 2 (NMC2) Cooling Products: NMC2 AOS v6.9.6 and prior
- Battery Management Products
- Network Management Card 2 (NMC2) AP9922 Battery Management System (BM4): NMC2 AOS v6.9.6 and prior
التهديدات:
يمكن للمهاجم استغلال الثغرات وتنفيذ ما يلي:
- هجمة البرمجة عبر المواقع Cross-site scripting (XSS)
- الكشف والإفصاح عن معلومات حساسة
- تعديل غير مصرح به
الإجراءات الوقائية:
يوصي المركز بتحديث النسخ المتأثرة حيث أصدرت Schneider Electricتوضيحًا لهذه التحديثات:
- https://download.schneider-electric.com/files?p_File_Name=990-3403Z-EN.pdf&p_Doc_Ref=SPD_ARAJ-9TN74X_EN&p_enDocType=User+guide
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-313-03
- https://download.schneider-electric.com/files?p_Doc_Ref=SPD_CCON-SURELNOTE_EN&p_enDocType=User+guide&p_File_Name=990-6322E-EN.pdf
- https://www.apc.com/us/en/support/contact-us/
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-313-07
أداة GUIcon متوقفة الدعم من قبل الشركة منذ يونيو 2020.