ICSA-25-140-06
·
Published 2025-05-13
·
View on CISA ICS-CERT ↗
Schneider Electric PrismaSeT Active - Wireless Panel Server
CVSS 9.8
CRITICAL
CVEs (1)
Remediations
- PrismaSeT Active - Wireless Panel Server product has reached its end of life and is no longer supported. Customers should immediately apply the following mitigations to reduce the risk of exploit: * Deactivate Bluetooth Low (BLE) communication of Wireless Panel Server when it is not in use. * Periodically review audit logs and/or EcoStruxure™ Facility Expert App security notifications to detect unexpected behaviors. * Regularly check the physical security of the Wireless Panel Server to protect against unauthorized Bluetooth pairing. * Use only Schneider Electric official EcoStruxure™ Power Commission App and EcoStruxure™ Facility Expert App available in Google Play Store and Apple App Store. * Do not use EcoStruxure Power Commission App and EcoStruxure™ Facility Expert App in rooted or jail-broken mobile devices. * Follow PrismaSeT Active - Wireless Panel Server Cybersecurity Recommendations https://www.productinfo.schneider-electric.com/wirelesspanelserverguide/viewer?docidentity=TPC_PanelServerCybersecurityRecomme-3453D816&lang=en&extension=xml&manualidentity=UserGuideWirelessPanelServerWHENPUB-5475323F
Affected Vendors
Schneider Electric
Affected Products (1)
Schneider Electric
·
PrismaSeT Active - Wireless Panel Server
vers:all/*
Affected Sectors
Commercial Facilities, Critical Manufacturing, Energy
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more