ICSA-13-016-01
·
Published 2025-06-06
·
View on CISA ICS-CERT ↗
Schneider Electric Authenticated Communication Risk Vulnerability
CVSS 9.3
CRITICAL
CVEs (1)
Remediations
- Schneider Electric has produced a customer notificationSchneider Electric Customer Notification, (http://www2.schneider-electric.com/corporate/en/support/cybersecurity/viewer-news.page?c_filepath=/templatedata/Content/News/data/en/local/cybersecurity/general_information/2013/01/20130109_advisory_of_vulnerability_affecting_schneider_electric_s_software_upda.xml). that contains mitigations to resolve this vulnerability. According to Schneider Electric, in order to resolve the vulnerability with the software server, Schneider Electric has taken the following actions: The SESU server has been updated to the latest version. Currently, both HTTP and HTTPS are supported in parallel. HTTPS does ensure signed communication. The new SESU client has been updated as of January 2013 to use HTTPS instead of HTTP. The new version of the SESU Client will be made available to customers for distribution via the SESU mechanism in January 2013. Customers can also use an updated software product CD that will contain the updated SESU client, when the CD becomes available. Contact your local support desk for details. While both HTTP and HTTPS SESU client functionality is supported currently, several months after starting to update the SESU clients (May 2013) the HTTP port of the SESU server will be disabled. This means that only HTTPS will be supported during SESU client updates from that time forward, which mitigates this current vulnerability.
Affected Vendors
Schneider Electric
Affected Products (18)
Schneider Electric
·
Unity Pro
V5.0_L_M_S_XL
Schneider Electric
·
Unity Pro
V6.0_L_M_S_XL
Schneider Electric
·
Unity Pro
V6.1_L_M_S_XL
Schneider Electric
·
Unity Pro
V0_L_M_S_XL_XLS
Schneider Electric
·
Vijeo Designer
6.0.x|6.1.0.x|5.0.0.x|5.1.0.x
Schneider Electric
·
Vijeo Designer Opti
6.0.x|5.1.0.x|5.0.0.x
Schneider Electric
·
Web Gate Client Files
V5.1.x
Schneider Electric
·
IDS
1.0|2.0
Schneider Electric
·
PowerSuite
2.5
Schneider Electric
·
Smart Widget Acti 9
V1.0.0.0
Schneider Electric
·
Smart Widget H8035
V1.0.0.0
Schneider Electric
·
Smart Widget H8036
V1.0.0.0
Schneider Electric
·
Smart Widget PM201
V1.0.0.0
Schneider Electric
·
Smart Widget PM710
V1.0.0.0
Schneider Electric
·
Smart Widget PM750
V1.0.0.0
Schneider Electric
·
SoMachine
V1.2.1
Schneider Electric
·
Spacail.pro
V1.0.0.x
Schneider Electric
·
SESU
1.0.x|1.1.x
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more