← Back to home
ICSA-21-070-01  ·  Published 2021-03-11  ·  View on CISA ICS-CERT ↗

Schneider Electric IGSS SCADA Software

CVSS 7.8 HIGH

Risk Summary

Successful exploitation of these vulnerabilities could result in remote code execution.

Remediations

  • Schneider Electric has provided Version 15.0.0.21042 of the IGSS Definition module: Def.exe to address these vulnerabilities. The update is available for download through IGSS Master > Update IGSS Software or from the Schneider Electric support page.
  • Avoid importing CGF files from untrusted sources.
  • For more information, see the Schneider Electric security notification.

Affected Vendors

Schneider Electric Software, LLC

Affected Products (1)

Schneider Electric Software, LLC · IGSS Definition (Def.exe) <= 15.0.0.21041

Affected Sectors

Commercial Facilities, Critical Manufacturing, Energy

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more