← Back to home
ICSA-19-192-05  ·  Published 2019-07-11  ·  View on CISA ICS-CERT ↗

AVEVA Vijeo Citect and Citect SCADA Floating License Manager

CVSS 9.8 CRITICAL

Risk Summary

These vulnerabilities could allow an attacker to deny the acquisition of a valid license for legal use of the product.

Remediations

  • AVEVA states that users who have deployed Floating License Manager Version 2.3.0.0 and earlier to manage their Software Licensing for Vijeo Citect or Citect SCADA (Version 7.30 and later) could be impacted.
  • Impacted users should upgrade to Floating License Manager (FLM) Version 2.3.1.0 as soon as possible.
  • FLM Version 2.3.1.0 is already available via SESU (Schneider Electric Software Update tool).
  • Details are described in the Schneider Electric Security Notification SEVD-2019-134-04.

Affected Vendors

AVEVA Software, LLC

Affected Products (1)

AVEVA Software, LLC · Vijeo Citect and Citect SCADA Floating License Manager <= 2.3.0.0

Affected Sectors

Energy

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more