Schneider Electric Alert
2819Warning Date
Severity Level
Warning Number
Target Sector
10 January, 2023
● High
2023-5413
All
Schneider Electric has released security updates to address several vulnerabilities in the following products:
- Modicon PAC Controllers
- EcoStruxure™ Control Expert, EcoStruxure™ Process Expert and Modicon M340, M580 and M580
- EcoStruxure™ Power Operation 2021
- EcoStruxure™ Power SCADA Operation 2020
- EcoStruxure™ Power SCADA Operation 2020 R2
- EcoStruxure™ Machine Expert – HVAC
- EcoStruxure™ Geo SCADA Expert
An attacker could exploit these vulnerabilities by doing the following:
- Arbitrary Code Execution
- Unauthorized Access
- Elevation of Privileges
- Denial of service attack (DoS)
The CERT team encourages users to review Schneider Electric security advisory and update the affected products:
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2019-134-11&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2019-134-11_Modicon_Controllers_Security_Notification.pdf&_ga=2.112085121.446819257.1673336040-701405032.1673336040
- https://download.schneider-electric.com/files?p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-011-06_CODESYSV3_Runtime_Development_System_and_Gateway_Security_Notification.pdf&_ga=2.121980046.446819257.1673336040-701405032.1673336040
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-010-06&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-010-06_Modicon_Controllers_Security_Notification.pdf&_ga=2.79580305.446819257.1673336040-701405032.1673336040
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-010-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-010-03_EcoStruxure_Power_Operation_Power_SCADA_Operation_Security_Notification.pdf&_ga=2.86919325.446819257.1673336040-701405032.1673336040
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-010-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-010-02_Geo_SCADA_Security_Notification.pdf&_ga=2.150907955.446819257.1673336040-701405032.1673336040