SEVD-2020-343-01
Schneider Electric is aware of a vulnerability in its EcoStruxure™ Control Expert product and EcoStruxure™ Process Expert. The EcoStruxure™ Control Expert product is a software to design, diagnose, maintain and update applications for Modicon M340, M580 and M580 Safety, Momentum, Premium, and Quantum PLCs. The EcoStruxure Process Expert DCS (formerly EcoStruxure Hybrid DCS) is a single automation system to engineer, operate, and maintain your entire infrastructure for a sustainable, productive and market-agile plant The RemoteConnect™ product is a Windows-based application based on EcoStruxure™ Control Expert (Unity Pro) software components that provides a programming and configuration environment for the SCADAPack x70 RTU series, which is comprised of the SCADAPack 470, 474, 570, 574 and 575 Smart RTUs. Failure to apply the mitigations provided below may risk opening a malicious file, which could result in crash of the software or unexpected code execution. July 2021 update: Added availability of fix in the version 15.0 SP1 of EcoStruxure Control Expert and added EcoStruxure™ Process Expert and RemoteConnect™ as impacted products.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider Electric EcoStruxure™ Process Expert all versions | ||
| Schneider Electric Unity Pro (former name of EcoStruxure™ Control Expert) all versions | ||
| Schneider Electric EcoStruxure™ Control Expert prior to v15.0 SP1 | ||
| Schneider Electric RemoteConnect™ all versions | ||
| Schneider Electric EcoStruxure Control Expert v15.0 SP1 |
Timeline
- Dec 8, 2020 CVE Published
- Jul 13, 2021 CVE Updated
References
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2020-343-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2020-343-01_EcoStruxure_Control_Expert_Process_Expert_RemoteConnect_Security_Notification_V2.0.pdf advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2020-343-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2020-343-01.json advisory
- https://www.se.com/us/en/download/document/7EN52-0390/ url
- https://www.se.com/ww/en/download/document/EcoStruxureControlExpert_15SP1 fix