Schneider Electric Alert
2776Warning Date
Severity Level
Warning Number
Target Sector
8 February, 2022
● Critical
2022-4343
All
Schneider Electric has released security alerts to address several vulnerabilities in the following products:
- Harmony/Magelis iPC Series
- Vijeo Designer
- Vijeo Designer Basic
- ClearSCADA all versions
- EcoStruxure Geo SCADA Expert 2019
- EcoStruxure Geo SCADA Expert 2020
- spaceLYnk
- Wiser for KNX (formerly homeLYnk)
- fellerLYnk
- Easergy P40 Series model numbers with Ethernet option bit as Q, R, S
- EcoStruxure EV Charging Expert (formerly known as EVlink Load Management System):
- HMIBSCEA53D1EDB
- HMIBSCEA53D1EDS
- HMIBSCEA53D1EDM
- HMIBSCEA53D1EDL
- HMIBSCEA53D1ESS
- HMIBSCEA53D1ESM
- HMIBSCEA53D1EML
- IGSS Data Server
Attacker could exploit these vulnerabilities by doing the following:
- Cross-site request forgery (CSRF)
- Escalation of privilege
- Cross-site scripting (XSS)
- Unauthorized disclosure of information
The CERT team encourages users to review Schneider Electric security advisory and apply the necessary mitigations and updates when available:
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-039-01
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-039-02
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-039-03
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-039-04
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-039-05
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-039-06