ICSA-21-159-05
·
Published 2021-06-08
·
View on CISA ICS-CERT ↗
Schneider Electric Modicon X80
CVSS 5.3
MEDIUM
Risk Summary
Successful exploitation of this vulnerability may result in information disclosure to an unauthenticated remote user, which could result in an understanding of the network architecture.
CVEs (1)
Remediations
- Web access service is disabled by default. Because the web server is only necessary for specific maintenance and configuration activities, it is advised users disable the web (HTTP) service when it is not needed through the Ecostruxure Control Expert application.
- Set up network segmentation and implement a firewall to block all unauthorized access to HTTP Port 80/TCP on the controllers.
- When used in an architecture including a BMXNOC module, configure the Access Control Lists following the recommendation in the Modicon Controllers Platform Cyber Security Reference Manual.
- Change the default password used to access the device web server. Update username and password for HTTP access rights with the “Security” link on the Setup page. See the Modicon X80 BMXNOR0200H RTU Module User Manual.
- Please see Schneider Electric's publication SEVD-2021-159-05 for more information.
Affected Vendors
Schneider Electric Software, LLC
Affected Products (1)
Schneider Electric Software, LLC
·
Modicon X80 BMXNOR0200H RTU
<= SV1.70 IR22
Affected Sectors
Commercial Facilities, Critical Manufacturing, Energy
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more