← Back to home
ICSA-24-011-05  ·  Published 2024-01-11  ·  View on CISA ICS-CERT ↗

Schneider Electric Easergy Studio

CVSS 7.8 HIGH

Risk Summary

Successful exploitation of this vulnerability could allow an attacker to gain full control of a workstation.

CVEs (1)

Remediations

  • Schneider Electric has released the following mitigations/fixes for the following products:
  • Easergy Studio: Version 9.3.6 of Easergy Studio includes a fix for this vulnerability and is available via SESU (Schneider Electric Software Update).
  • Customers of Schneider Electric should use appropriate patching methodologies when applying these patches to their systems. Schneider Electric strongly recommend the use of back-ups and evaluating the impact of these patches in a Test and Development environment or on an offline infrastructure. Contact Schneider Electric's Customer Care Center if assistance is needed in removing a patch.
  • If customers choose not to apply the remediation provided above, they should immediatelyapply Schneider Electric's General Security Recommendations to reduce the risk of exploit. For more information, see Schneider Electric SEVD-2024-009-02.

Affected Vendors

Schneider Electric

Affected Products (1)

Schneider Electric · Easergy Studio <v9.3.5

Affected Sectors

Energy

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more