← Back to home
ICSA-13-016-01  ·  Published 2025-06-06  ·  View on CISA ICS-CERT ↗

Schneider Electric Authenticated Communication Risk Vulnerability

CVSS 9.3 CRITICAL

CVEs (1)

Remediations

  • Schneider Electric has produced a customer notificationSchneider Electric Customer Notification, (http://www2.schneider-electric.com/corporate/en/support/cybersecurity/viewer-news.page?c_filepath=/templatedata/Content/News/data/en/local/cybersecurity/general_information/2013/01/20130109_advisory_of_vulnerability_affecting_schneider_electric_s_software_upda.xml). that contains mitigations to resolve this vulnerability. According to Schneider Electric, in order to resolve the vulnerability with the software server, Schneider Electric has taken the following actions: The SESU server has been updated to the latest version. Currently, both HTTP and HTTPS are supported in parallel. HTTPS does ensure signed communication. The new SESU client has been updated as of January 2013 to use HTTPS instead of HTTP. The new version of the SESU Client will be made available to customers for distribution via the SESU mechanism in January 2013. Customers can also use an updated software product CD that will contain the updated SESU client, when the CD becomes available. Contact your local support desk for details. While both HTTP and HTTPS SESU client functionality is supported currently, several months after starting to update the SESU clients (May 2013) the HTTP port of the SESU server will be disabled. This means that only HTTPS will be supported during SESU client updates from that time forward, which mitigates this current vulnerability.

Affected Vendors

Schneider Electric

Affected Products (18)

Schneider Electric · Unity Pro V5.0_L_M_S_XL
Schneider Electric · Unity Pro V6.0_L_M_S_XL
Schneider Electric · Unity Pro V6.1_L_M_S_XL
Schneider Electric · Unity Pro V0_L_M_S_XL_XLS
Schneider Electric · Vijeo Designer 6.0.x|6.1.0.x|5.0.0.x|5.1.0.x
Schneider Electric · Vijeo Designer Opti 6.0.x|5.1.0.x|5.0.0.x
Schneider Electric · Web Gate Client Files V5.1.x
Schneider Electric · IDS 1.0|2.0
Schneider Electric · PowerSuite 2.5
Schneider Electric · Smart Widget Acti 9 V1.0.0.0
Schneider Electric · Smart Widget H8035 V1.0.0.0
Schneider Electric · Smart Widget H8036 V1.0.0.0
Schneider Electric · Smart Widget PM201 V1.0.0.0
Schneider Electric · Smart Widget PM710 V1.0.0.0
Schneider Electric · Smart Widget PM750 V1.0.0.0
Schneider Electric · SoMachine V1.2.1
Schneider Electric · Spacail.pro V1.0.0.x
Schneider Electric · SESU 1.0.x|1.1.x

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more