ICSA-25-107-03
·
Published 2025-04-08
·
View on CISA ICS-CERT ↗
Schneider Electric ConneXium Network Manager Software
CVSS 7.8
HIGH
CVEs (2)
Remediations
- Please note that the ConneXium Network Manager product has reached the end of its life and is no longer supported. Customers should immediately apply the following mitigations to reduce the risk of exploit: • Disable the webserver (disabled by default) • Follow workstation, network and site-hardening guidelines in the Recommended Cybersecurity Best Practices available for download here: https://www.se.com/ww/en/download/document/7EN52-0390/
- Please note that the ConneXium Network Manager product has reached the end of its life and is no longer supported. Customers should immediately apply the following mitigations to reduce the risk of exploit: • Only open project files received from a trusted source. • Compute a hash of the project files and regularly check the consistency of this hash to verify the integrity before usage. • Encrypt project file when stored and restrict the access to only trusted users. • When exchanging files over the network, use secure communication protocols. • Follow workstation, network and site-hardening guidelines in the Recommended Cybersecurity Best Practices available for download here: https://www.se.com/ww/en/download/document/7EN52-0390/
Affected Vendors
Schneider Electric
Affected Products (2)
Schneider Electric
·
ConneXium Network Manager
2.0.01
Schneider Electric
·
ConneXium Network Manager
vers:all/*
Affected Sectors
Commercial Facilities, Critical Manufacturing, Energy
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more