Schneider Electric Alert
2820Warning Date
Severity Level
Warning Number
Target Sector
14 March, 2023
● Critical
2023-5499
All
Schneider Electric has released security update to address several vulnerabilities in the following products:
- PowerLogic™ HDPM6000
- Version 0.58.6 and prior
- IGSS Data Server (IGSSdataServer.exe)
- V16.0.0.23040 and prior
- IGSS Dashboard (DashBoard.exe)
- V16.0.0.23040 and prior
- Custom Reports (RMS16.dll)
- V16.0.0.23040 and prior
An attacker could exploit these vulnerabilities by doing the following:
- Remote Code Execution
- Denial of Service (DoS)
The CERT team encourages users to review Schneider Electric security advisory and update the affected products:
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-073-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-073-02.pdf&_ga=2.45981476.1852790863.1678782548-7968118.1669104653
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-073-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-073-04.pdf&_ga=2.45981476.1852790863.1678782548-7968118.1669104653