ICSA-14-086-01A
·
Published 2025-06-25
·
View on CISA ICS-CERT ↗
Schneider Electric Serial Modbus Driver Buffer Overflow (Update A)
CVSS 9.3
CRITICAL
CVEs (1)
Remediations
- Schneider Electric has released a security notification with further information on this vulnerability and how to mitigate it: (http://download.schneider-electric.com/files?p_Doc_Ref=SEVD 2013-070-01).
- Schneider Electric recommends that products that use this driver be updated with the latest version of software.
- New versions of OFS V3.5 and Unity Pro V8 include the updated ModbusDriverSuite.
- For the other products listed above, the updated ModbusDriverSuite will be implemented with each new version of those software products. Asset owners concerned about the Modbus Serial Driver used for those applications, please contact Schneider Electric Technical Support at: (http://www2.schneider-electric.com/sites/corporate/en/products-services/services/field-services/services-by-business-activity/automation/lifecycle/technical-support.page).
- Until this software can be updated in the vulnerable devices, Schneider Electric recommends a defense-in-depth strategy, which includes locating the PLCs and devices running the vulnerable software behind firewalls configured to limit access to authorized personnel and protocols.
Affected Vendors
Schneider Electric
Affected Products (16)
Schneider Electric
·
TwidoSuite
<=2.31.04
Schneider Electric
·
PowerSuite
<=2.6
Schneider Electric
·
SoMove
<=1.7
Schneider Electric
·
SoMachine
2.0|3.0|3.1|3.0
Schneider Electric
·
Unity Pro
<=7.0
Schneider Electric
·
UnityLoader
<=2.3
Schneider Electric
·
Concept
<=2.6_SR7
Schneider Electric
·
ModbusCommDTM sl
<=2.1.2
Schneider Electric
·
PL7
<=4.5_SP5
Schneider Electric
·
SFT2841
14
Schneider Electric
·
SFT2841
<=13.1
Schneider Electric
·
OPC Factory Server (OFS)
<=3.40
Schneider Electric
·
Modbus Serial Driver Windows XP 32 bit
V1.10_IE_v37
Schneider Electric
·
Modbus Serial Driver Windows Vista 32 bit
V2.2_IE12
Schneider Electric
·
Modbus Serial Driver Windows 7 32 bit
V2.2_IE12
Schneider Electric
·
Modbus Serial Driver Windows 7 64 bit
V3.2_IE12
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more