Schneider Electric Update
2442Warning Date
Severity Level
Warning Number
Target Sector
8 August, 2021
● Critical
2021-3319
All
Description:
Schneider Electric has released a security update to address several vulnerabilities in the following product:
- NicheStack TCP/IP
- Lexium ILE ILA ILS firmware version V01.103 and prior
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Denial of service attack (DoS)
Best practice and Recommendations:
The CERT team encourages users to review Schneider Electric security advisory and apply the necessary updates:
The CERT team encourages users to apply best practice:
- Minimizing network exposure for all control system devices and/or systems
- Locating control system networks and devices behind firewalls and isolating them from the enterprise/business network
- When remote access is required, use secure methods such as virtual private networks (VPNs)