ICSA-21-070-01
·
Published 2021-03-11
·
View on CISA ICS-CERT ↗
Schneider Electric IGSS SCADA Software
CVSS 7.8
HIGH
Risk Summary
Successful exploitation of these vulnerabilities could result in remote code execution.
Remediations
- Schneider Electric has provided Version 15.0.0.21042 of the IGSS Definition module: Def.exe to address these vulnerabilities. The update is available for download through IGSS Master > Update IGSS Software or from the Schneider Electric support page.
- Avoid importing CGF files from untrusted sources.
- For more information, see the Schneider Electric security notification.
Affected Vendors
Schneider Electric Software, LLC
Affected Products (1)
Schneider Electric Software, LLC
·
IGSS Definition (Def.exe)
<= 15.0.0.21041
Affected Sectors
Commercial Facilities, Critical Manufacturing, Energy
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more