← Back to home
ICSA-14-350-01  ·  Published 2025-06-06  ·  View on CISA ICS-CERT ↗

Schneider Electric ProClima Command Injection Vulnerabilities

CVSS 10.0 CRITICAL

Remediations

  • Schneider Electric has released an updated version of the ProClima software, Version 6.1.7, which mitigates these vulnerabilities. Customers are encouraged to download the new version and update their installations. It is important that customers first uninstall the current version. The new version can be downloaded from Schneider Electric’s web site at the following location: (http://www.schneider-electric.com/ww/en/download/document/ProClima_software)
  • For further information on these vulnerabilities, please see Schneider Electric’s security notification (SEVD 2014-344-01) at Schneider Electric’s cybersecurity web page: (http://www2.schneider-electric.com/sites/corporate/en/support/cybersecurity/cyber-security-vulnerabilities-sorted.page)

Affected Vendors

Schneider Electric

Affected Products (1)

Schneider Electric · ProClima <=6.0.1

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more