Your review has been sent successfully

Schneider Electric Alert

2776
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

8 February, 2022

● Critical

2022-4343

All

Description:

Schneider Electric has released security alerts to address several vulnerabilities in the following products:

  • Harmony/Magelis iPC Series
  • Vijeo Designer
  • Vijeo Designer Basic
  • ClearSCADA all versions
  • EcoStruxure Geo SCADA Expert 2019
  • EcoStruxure Geo SCADA Expert 2020
  • spaceLYnk
  • Wiser for KNX (formerly homeLYnk)
  • fellerLYnk
  • Easergy P40 Series model numbers with Ethernet option bit as Q, R, S
  • EcoStruxure EV Charging Expert (formerly known as EVlink Load Management System):
  • HMIBSCEA53D1EDB
  • HMIBSCEA53D1EDS
  • HMIBSCEA53D1EDM
  • HMIBSCEA53D1EDL
  • HMIBSCEA53D1ESS
  • HMIBSCEA53D1ESM
  • HMIBSCEA53D1EML
  • IGSS Data Server
Threats:

Attacker could exploit these vulnerabilities by doing the following:

  • Cross-site request forgery (CSRF)
  • Escalation of privilege
  • Cross-site scripting (XSS)
  • Unauthorized disclosure of information
Best practice and Recommendations:
Last updated at 9 February, 2022

Rate the content

rate-icon
up icon