← Back to home
ICSA-14-086-01A  ·  Published 2025-06-25  ·  View on CISA ICS-CERT ↗

Schneider Electric Serial Modbus Driver Buffer Overflow (Update A)

CVSS 9.3 CRITICAL

CVEs (1)

Remediations

  • Schneider Electric has released a security notification with further information on this vulnerability and how to mitigate it: (http://download.schneider-electric.com/files?p_Doc_Ref=SEVD 2013-070-01).
  • Schneider Electric recommends that products that use this driver be updated with the latest version of software.
  • New versions of OFS V3.5 and Unity Pro V8 include the updated ModbusDriverSuite.
  • For the other products listed above, the updated ModbusDriverSuite will be implemented with each new version of those software products. Asset owners concerned about the Modbus Serial Driver used for those applications, please contact Schneider Electric Technical Support at: (http://www2.schneider-electric.com/sites/corporate/en/products-services/services/field-services/services-by-business-activity/automation/lifecycle/technical-support.page).
  • Until this software can be updated in the vulnerable devices, Schneider Electric recommends a defense-in-depth strategy, which includes locating the PLCs and devices running the vulnerable software behind firewalls configured to limit access to authorized personnel and protocols.

Affected Vendors

Schneider Electric

Affected Products (16)

Schneider Electric · TwidoSuite <=2.31.04
Schneider Electric · PowerSuite <=2.6
Schneider Electric · SoMove <=1.7
Schneider Electric · SoMachine 2.0|3.0|3.1|3.0
Schneider Electric · Unity Pro <=7.0
Schneider Electric · UnityLoader <=2.3
Schneider Electric · Concept <=2.6_SR7
Schneider Electric · ModbusCommDTM sl <=2.1.2
Schneider Electric · PL7 <=4.5_SP5
Schneider Electric · SFT2841 14
Schneider Electric · SFT2841 <=13.1
Schneider Electric · OPC Factory Server (OFS) <=3.40
Schneider Electric · Modbus Serial Driver Windows XP 32 bit V1.10_IE_v37
Schneider Electric · Modbus Serial Driver Windows Vista 32 bit V2.2_IE12
Schneider Electric · Modbus Serial Driver Windows 7 32 bit V2.2_IE12
Schneider Electric · Modbus Serial Driver Windows 7 64 bit V3.2_IE12

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more