← Back to home
ICSA-21-012-01  ·  Published 2021-02-18  ·  View on CISA ICS-CERT ↗

Schneider Electric EcoStruxure Power Build-Rapsody (Update A)

CVSS 7.8 HIGH

Risk Summary

Successful exploitation of this vulnerability could allow a local attacker to upload a malicious SSD file, resulting in a use-after-free condition or a stack-based buffer overflow.

Remediations

  • Schneider Electric reports fixes will be available in the first half of 2021. Until then, Schneider recommends affected users immediately apply the following mitigations to reduce the risk of exploit:
  • Apply the principle of least privilege to limit access to the computer running the Rapsody software.
  • Install application whitelisting software on the computer to block the execution of malicious code.
  • Install antivirus on the computer and keep it up to date.
  • All updates, including details on affected products and remediation plans, can be found by subscribing to Schneider Electric's security notification service.
  • For more information see the Schneider Electric advisory.

Affected Vendors

Schneider Electric Software, LLC

Affected Products (1)

Schneider Electric Software, LLC · EcoStruxure Power Build-Rapsody software <= 2.1.13

Affected Sectors

Commercial Facilities, Energy, Food and Agriculture, Government Facilities, Transportation Systems, Water and Wastewater Systems

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more