← Back to home
ICSA-14-014-01  ·  Published 2025-06-06  ·  View on CISA ICS-CERT ↗

Schneider Electric ClearSCADA Uncontrolled Resource Consumption Vulnerability

CVSS 4.3 MEDIUM

CVEs (1)

Remediations

  • Schneider Electric has fixed this issue in the latest released software version of SCADA Expert ClearSCADA 2013 R2.
  • ClearSCADA users should contact the local Schneider Electric office to obtain the latest software version for ClearSCADA
  • alternatively this new version is available for direct download from the Schneider Electric Web site. To upgrade, customers are required to complete and submit an online form available here: (http://telemetry.schneider-electric.com/id2/form/CMIform.html)
  • General instructions on how to upgrade the ClearSCADA license are available here: (http://resourcecenter.controlmicrosystems.com/display/CS/Updating+Your+ClearSCADA+License)
  • Detailed instructions on how to upgrade a ClearSCADA installation are available here: (http://resourcecenter.controlmicrosystems.com/display/public/CS/SCADA+Expert+ClearSCADA+2013+R2+Upgrade+Strategy)
  • Schneider Electric advises all ClearSCADA users to take steps to secure the interfaces to the ClearSCADA system. The following guidelines should be taken as a starting point only in establishing an appropriate level of system security: Monitor DNP3 traffic and system Event Journal to detect excessive amounts of traffic/logging that may be representative of a fuzzing attack. Upgrade the ClearSCADA server to SCADA Expert ClearSCADA 2013 R2 or newer, or Service Packs released later than November 2013.
  • Schneider Electric has also published security notification SEVD-2013-339-01.
  • The researchers suggest blocking DNP3 traffic from traversing onto business or corporate networks through the use of an intrusion prevention system or firewall with DNP3-specific rule sets to add an additional layer of protection.

Affected Vendors

Schneider Electric

Affected Products (7)

Schneider Electric · ClearSCADA 2010 R2 Build_71.4165
Schneider Electric · ClearSCADA 2010 R2.1 Build_71.4325
Schneider Electric · ClearSCADA 2010 R3 Build_72.4560
Schneider Electric · ClearSCADA 2010 R3.1 Build_72.4644
Schneider Electric · SCADA Expert ClearSCADA 2013 R1 Build_73.4729
Schneider Electric · SCADA Expert ClearSCADA 2013 R1.1 Build_73.4832
Schneider Electric · SCADA Expert ClearSCADA 2013 R1.1a 73.4903|2013|R1.2|73.4955

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more