← Back to home
ICSA-23-180-02  ·  Published 2023-06-29  ·  View on CISA ICS-CERT ↗

Schneider Electric EcoStruxure Operator Terminal Expert

CVSS 7.8 HIGH

Risk Summary

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code and gain access to sensitive information on the machine.

CVEs (1)

Remediations

  • Schneider Electric has released EcoStruxure Operation Terminal Expert v3.4 for users to download.
  • Customers should use appropriate patching methodologies when applying these patches to their systems. We strongly recommend the use of back-ups and evaluating the impact of these patches in a Test and Development environment or on an offline infrastructure. Contact Schneider Electric's Customer Care Center if you need assistance removing a patch.
  • For more information, see Schneider Electric's Advisory.

Affected Vendors

Schneider Electric

Affected Products (1)

Schneider Electric · EcoStruxure Operator Terminal Expert <= 3.3 SP1

Affected Sectors

Commercial Facilities, Critical Manufacturing, Energy

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more