← Back to home
ICSA-17-012-03  ·  Published 2017-01-12  ·  View on CISA ICS-CERT ↗

Carlo Gavazzi VMU-C EM and VMU-C PV

CVSS 10.0 CRITICAL

Risk Summary

ATTENTION: Remotely exploitable/low skill level to exploit.

Remediations

  • Carlo Gavazzi has created firmware updates that mitigate these vulnerabilities. Carlo Gavazzi recommends upgrading to the following firmware versions: VMU-C EM A11_U05 for VMUC EM, and VMU-C PV A17 for VMUC PV.
  • The relevant firmware versions are available either by means of the firmware update function embedded in the VMU-C or by downloading them from Carlo Gavazzi's web site. Please open the link:
  • Then:Click on “Select the Product.;Choose “Web-Server” from the “FUNCTION” column.;A list including both VMU-C EM and VMU-C PV will appear; select the target VMU-C model from the list.;From the “downloads” section on the right click on the “Software” icon to start downloading the updated firmware package.

Affected Vendors

Carlo Gavazzi

Affected Products (2)

Carlo Gavazzi · VMU-C PV < A17
Carlo Gavazzi · VMU-C EM < A11_U05

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more