ICSA-21-012-01
·
Published 2021-02-18
·
View on CISA ICS-CERT ↗
Schneider Electric EcoStruxure Power Build-Rapsody (Update A)
CVSS 7.8
HIGH
Risk Summary
Successful exploitation of this vulnerability could allow a local attacker to upload a malicious SSD file, resulting in a use-after-free condition or a stack-based buffer overflow.
CVEs (2)
Remediations
- Schneider Electric reports fixes will be available in the first half of 2021. Until then, Schneider recommends affected users immediately apply the following mitigations to reduce the risk of exploit:
- Apply the principle of least privilege to limit access to the computer running the Rapsody software.
- Install application whitelisting software on the computer to block the execution of malicious code.
- Install antivirus on the computer and keep it up to date.
- All updates, including details on affected products and remediation plans, can be found by subscribing to Schneider Electric's security notification service.
- For more information see the Schneider Electric advisory.
Affected Vendors
Schneider Electric Software, LLC
Affected Products (1)
Schneider Electric Software, LLC
·
EcoStruxure Power Build-Rapsody software
<= 2.1.13
Affected Sectors
Commercial Facilities, Energy, Food and Agriculture, Government Facilities, Transportation Systems, Water and Wastewater Systems
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more