Schneider Electric Alert
2643Warning Date
Severity Level
Warning Number
Target Sector
9 August, 2022
● Critical
2022-5104
All
Schneider Electric has released security alerts to address several vulnerabilities in the following products:
- Modicon PAC Controllers
- EcoStruxureTM Control Expert, EcoStruxureTM Process Expert, and Modicon Controllers M580 and M340
Attacker could exploit these vulnerabilities by doing the following:
- Sensitive information disclosure
- Denial of service attack (DoS)
- Unauthorized access
The CERT team encourages users to review Schneider Electric security advisory and apply the necessary mitigations and updates when available:
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-221-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-221-04-Modicon_Controllers_Ethernet_Modules_Security_Notification.pdf&_ga=2.157067899.152402132.1660028873-1012372921.1658041905
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-221-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-221-02_Modicon_Controllers_Security_Notification.pdf&_ga=2.157067899.152402132.1660028873-1012372921.1658041905
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-221-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-221-01_EcoStruxure_Control_Expert_Modicon580_Security_Notification.pdf&_ga=2.199141999.152402132.1660028873-1012372921.1658041905