ICSA-21-313-01
·
Published 2021-11-09
·
View on CISA ICS-CERT ↗
Schneider Electric NMC cards and Embedded Devices
CVSS 6.8
MEDIUM
Risk Summary
Successful exploitation of these vulnerabilities may allow data disclosure or cross-site scripting, which could result in an execution of malicious web code or a loss of device functionality.
Remediations
- 1-Phase Uninterruptible Power Supply (UPS) using NMC2: Update to v7.04 or later.
- SUMX (SmartUPS & Galaxy 3500)
- SY (Single Phase Symmetra)
- SUMX & SY Release notes
- 3-Phase Uninterruptible Power Supply (UPS) using NMC2 including Symmetra PX 250/500 (SYPX) Network Management Card 2 (NMC2) (See SEVD-2021-313-03 on what specific models are mitigated): Update to v7.0.4 or later of the NMC2 SYPX application. Contact a Schneider Electric support team for SYPX application upgrade.
- Update to v7.0.4 or later of the NMC2 SYPX application. Contact a Schneider Electric support team for SYPX application upgrade.
- 1-Phase Uninterruptible Power Supply (UPS) using NMC3: Update to v1.5 or later of the NMC3 SU and SY applications
- Release notes
- APC Rack Power Distribution Units (PDU) using NMC2: Update to v7.0.6 or later of the NMC2 RPDU2G application.
- RPDU2G (direct download)
- APC 3-Phase Power Distribution Products using NMC2: Update to v7.0.4 or later of the NMC2 RPP application.
- Galaxy RPP
- Network Management Card 2 (NMC2) Cooling Products (See SEVD-2021-313-03 on what specific series are mitigated): Update to v7.0.4 or later of the NMC2 of the cooling applications. Contact a Schneider Electric support team for upgrades.
- For the products not listed above, Schneider Electric is in the process of establishing a remediation plan for affected NMC2 and NMC3 offers.
- NMC users should not trust links provided from sources that have not been verified as authentic.
- Ensure the workstation where the browser is being used is secured.
- If a debug.tar file is generated via Web or CLI, ensure it is deleted after retrieval.
- Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.
- Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.
- Never connect programming software to any network other than the network for the devices that it is intended for.
- Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.
- Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.
- Minimize network exposure for all control system devices and systems and ensure they are not accessible from the Internet.
- When remote access is required, use secure methods, such as virtual private networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.
Affected Vendors
Schneider Electric Software, LLC
Affected Products (16)
Schneider Electric Software, LLC
·
APC 3-Phase Power Distribution Products using NMC2
NMC2 <= 6.9.6
Schneider Electric Software, LLC
·
Network Management Card 2 (NMC2) for InfraStruxure 150 kVA PDU with 84 Poles (X84P)
NMC2 <= 6.9.6
Schneider Electric Software, LLC
·
Network Management Card 2 for Modular 150/175kVA PDU (XRDP)
NMC2 <= 6.9.6
Schneider Electric Software, LLC
·
3-Phase Uninterruptible Power Supply (UPS) using NMC2 including Symmetra PX 48/96/100/160 kW UPS (PX2) Symmetra PX 20/40 kW UPS (SY3P) Gutor (SXW GVX) and Galaxy (GVMTS GVMSA GVXTS GVXSA G7K GFC G9KCHU)
NMC2 <= 6.9.6
Schneider Electric Software, LLC
·
1-Phase Uninterruptible Power Supply (UPS) using NMC3 including Smart-UPS Symmetra and Galaxy 3500 with Network Management Card 3 (NMC3)
NMC3 <= 1.4.2.1
Schneider Electric Software, LLC
·
3-Phase Uninterruptible Power Supply (UPS) using NMC2 including Symmetra PX 250/500 (SYPX) Network Management Card 2 (NMC2)
NMC2 <= 6.9.6
Schneider Electric Software, LLC
·
Network Management Card 2 (NMC2) AP9922 Battery Management System (BM4)
NMC2 <= 6.9.6
Schneider Electric Software, LLC
·
1-Phase Uninterruptible Power Supply (UPS) using NMC2 including Smart-UPS Symmetra and Galaxy 3500 with Network Management Card 2 (NMC2)
NMC2 <= 6.9.8
Schneider Electric Software, LLC
·
Rack Automatic Transfer Switches (ATS)
NMC2 <= 6.9.6
Schneider Electric Software, LLC
·
Network Management Card 2 for Modular PDU (XRDP2G)
NMC2 <= 6.9.6
Schneider Electric Software, LLC
·
Network Management Card 2 (NMC2) Cooling Products
NMC2 <= 6.9.6
Schneider Electric Software, LLC
·
APC Rack Power Distribution Units (PDU) using NMC3
NMC3 <= 1.4.0
Schneider Electric Software, LLC
·
Environmental Monitoring Unit with embedded NMC2 (NB250) NetBotz NBRK0250
NMC2 <= 6.9.6
Schneider Electric Software, LLC
·
APC Rack Power Distribution Units (PDU) using NMC2
NMC2 <= 6.9.6
Schneider Electric Software, LLC
·
Network Management Card 2 for 400 and 500 kVA (PMM)
NMC2 <= 6.9.6
Schneider Electric Software, LLC
·
Network Management Card 2 for InfraStruxure 40/60kVA PDU (XPDU)
NMC2 <= 6.9.6
Affected Sectors
Energy
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more