ICSA-23-180-02
·
Published 2023-06-29
·
View on CISA ICS-CERT ↗
Schneider Electric EcoStruxure Operator Terminal Expert
CVSS 7.8
HIGH
Risk Summary
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code and gain access to sensitive information on the machine.
CVEs (1)
Remediations
- Schneider Electric has released EcoStruxure Operation Terminal Expert v3.4 for users to download.
- Customers should use appropriate patching methodologies when applying these patches to their systems. We strongly recommend the use of back-ups and evaluating the impact of these patches in a Test and Development environment or on an offline infrastructure. Contact Schneider Electric's Customer Care Center if you need assistance removing a patch.
- For more information, see Schneider Electric's Advisory.
Affected Vendors
Schneider Electric
Affected Products (1)
Schneider Electric
·
EcoStruxure Operator Terminal Expert
<= 3.3 SP1
Affected Sectors
Commercial Facilities, Critical Manufacturing, Energy
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more