← Back to home
ICSA-25-107-03  ·  Published 2025-04-08  ·  View on CISA ICS-CERT ↗

Schneider Electric ConneXium Network Manager Software

CVSS 7.8 HIGH

Remediations

  • Please note that the ConneXium Network Manager product has reached the end of its life and is no longer supported. Customers should immediately apply the following mitigations to reduce the risk of exploit: • Disable the webserver (disabled by default) • Follow workstation, network and site-hardening guidelines in the Recommended Cybersecurity Best Practices available for download here: https://www.se.com/ww/en/download/document/7EN52-0390/
  • Please note that the ConneXium Network Manager product has reached the end of its life and is no longer supported. Customers should immediately apply the following mitigations to reduce the risk of exploit: • Only open project files received from a trusted source. • Compute a hash of the project files and regularly check the consistency of this hash to verify the integrity before usage. • Encrypt project file when stored and restrict the access to only trusted users. • When exchanging files over the network, use secure communication protocols. • Follow workstation, network and site-hardening guidelines in the Recommended Cybersecurity Best Practices available for download here: https://www.se.com/ww/en/download/document/7EN52-0390/

Affected Vendors

Schneider Electric

Affected Products (2)

Schneider Electric · ConneXium Network Manager 2.0.01
Schneider Electric · ConneXium Network Manager vers:all/*

Affected Sectors

Commercial Facilities, Critical Manufacturing, Energy

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more