← Back to home
ICSA-20-105-01  ·  Published 2020-04-14  ·  View on CISA ICS-CERT ↗

Eaton HMiSoft VU3

CVSS 7.8 HIGH

Risk Summary

Successful exploitation of these vulnerabilities could crash the device being accessed and may allow remote code execution or information disclosure.

Remediations

  • Eaton ceased manufacturing the HMiVU on December 31, 2018, and marked the HMiVU software as end of life. As a result, Eaton no longer provides technical support, security fixes, or other fixes for the HMiVU software. To better serve users and provide ongoing replacement solutions, HMiVU was replaced with the XV100 and XV300 lines of operator interface products. It is strongly recommended HMiVU users contact Eaton for technical support and migration assistance to the XV solution.
  • NOTE: Eaton has discontinued the HMiVU product and has asked users to upgrade.
  • For assistance with transitioning to XV, please work directly with the following contacts:
  • An Eaton sales contact
  • Eaton's Technical Resource Center at 1-877-ETN-CARE (386-2273), Option 2, then Option 5
  • Information regarding the XV Product offering can be found via the following: www.eaton.com/OI Eaton Catalog—Volume 7 Tab 05

Affected Vendors

Eaton

Affected Products (1)

Eaton · HMiSoft VU3 <= 3.00.23

Affected Sectors

Energy

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more