← Back to home
ICSA-25-259-01  ·  Published 2026-05-26  ·  View on CISA ICS-CERT ↗

Schneider Electric Altivar Products, ATVdPAC Module, ILC992 InterLink Converter (Update B)

CVSS 6.1 MEDIUM

Risk Summary

Schneider Electric is aware of a vulnerability in its [ATVdPAC module](http://www.se.com/ww/en/product/VW3A3530D/atv-dpac-module/) / [ATV6000 Medium Voltage Altivar Process Drives](http://www.se.com/ww/en/product-range/65607-altivar-process-atv6000) / [ATV630/650/660/680/6A0/6B0/6L0 Altivar Process Drives](http://www.se.com/ww/en/product-range/62317-altivar-process-atv600) / [ATV930/950/955/960/980/9A0/9B0/9L0 Altivar Process Drives](http://www.se.com/ww/en/product-range/63124-altivar-process-atv900) / [ATV340E Altivar Machine Drives](http://www.se.com/ww/en/product-range/63441-altivar-machine-atv340#products) /[ATS490 Altivar Soft Starter](http://www.se.com/ww/en/product-range/213421154-altivar-soft-starter-ats490) / [Altivar Process Communication Modules](http://www.se.com/ww/en/product-range/62317-altivar-process-atv600/117623851529-modular-drives-apm) product(s). Failure to apply remediation mitigations provided below may risk Cross-Site Scripting, which could result in partial loss of confidentiality and integrity of the workstation running a Web browser.

CVEs (1)

Remediations

  • Version 25.0 of VW3A3530D: ATVdPAC module includes a fix for this vulnerability and is available upon request from Schneider Electric's [Customer Care Center](https://www.se.com/us/en/work/support/contacts.jsp).
  • The version 4.5 of ATV6xx drives includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/62317-altivar-process-atv600/#software-and-firmware
  • The version 4.5 of ATV9xx drives includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/63124-altivar-process-atv900/#software-and-firmware
  • The version 4.5 of ATV340 drives includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/product-range/63441-altivar-machine-atv340/#software-and-firmware
  • The version 1.2ie05 of ATS490 drives includes a fix for this vulnerability and is available for download here: https://www.se.com/ww/en/download/document/ATS490-Firmware/
  • If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • End user cybersecurity awareness and workstation protections • Deactivate the Webserver after use when not needed. • Setup network segmentation and implement a firewall to block all unauthorized access to port 80/HTTP • Use VPN (Virtual Private Networks) tunnels if remote access is required.
  • Schneider Electric is establishing a remediation plan for all future versions of • ILC992 InterLink Converter • VW3A3720 & VW3A3721 Altivar Process Communication Modules that will include a fix for this vulnerability. We will update this document when the remediation is available. Until then, customers should immediately apply the following mitigations to reduce the risk of exploit: • End user cybersecurity awareness and workstation protections • Deactivate the Webserver after use when not needed. • Setup network segmentation and implement a firewall to block all unauthorized access to port 80/HTTP • Use VPN (Virtual Private Networks) tunnels if remote access is required.
  • Version 2.2 of ATV6000 drives includes a fix for this vulnerability and is available upon request from Schneider Electric's [Customer Care Center](https://www.se.com/us/en/work/support/contacts.jsp).

Affected Vendors

Schneider Electric

Affected Products (47)

Schneider Electric · ATVdPAC module vers:intdot/<25.0
Schneider Electric · ATVdPAC module 25.0
Schneider Electric · ATV630 vers:intdot/<4.5
Schneider Electric · ATV630 4.5
Schneider Electric · ATV650 vers:intdot/<4.5
Schneider Electric · ATV650 4.5
Schneider Electric · ATV660 vers:intdot/<4.5
Schneider Electric · ATV660 4.5
Schneider Electric · ATV680 vers:intdot/<4.5
Schneider Electric · ATV680 4.5
Schneider Electric · ATV6A0 vers:intdot/<4.5
Schneider Electric · ATV6A0 4.5
Schneider Electric · ATV6B0 vers:intdot/<4.5
Schneider Electric · ATV6B0 4.5
Schneider Electric · ATV6L0 vers:intdot/<4.5
Schneider Electric · ATV6L0 4.5
Schneider Electric · ATV930 vers:intdot/<4.5
Schneider Electric · ATV930 4.5
Schneider Electric · ATV950 vers:intdot/<4.5
Schneider Electric · ATV950 4.5
Schneider Electric · ATV955 vers:intdot/<4.5
Schneider Electric · ATV955 4.5
Schneider Electric · ATV960 vers:intdot/<4.5
Schneider Electric · ATV960 4.5
Schneider Electric · ATV980 vers:intdot/<4.5
Schneider Electric · ATV980 4.5
Schneider Electric · ATV9A0 vers:intdot/<4.5
Schneider Electric · ATV9A0 4.5
Schneider Electric · ATV9B0 vers:intdot/<4.5
Schneider Electric · ATV9B0 4.5
Schneider Electric · ATV9L0 vers:intdot/<4.5
Schneider Electric · ATV9L0 4.5
Schneider Electric · ATV991 vers:intdot/<4.5
Schneider Electric · ATV991 4.5
Schneider Electric · ATV992 vers:intdot/<4.5
Schneider Electric · ATV992 4.5
Schneider Electric · ATV993 vers:intdot/<4.5
Schneider Electric · ATV993 4.5
Schneider Electric · ATV6000 Medium Voltage vers:intdot/<2.2
Schneider Electric · ATV6000 Medium Voltage 2.2
Schneider Electric · ILC992 InterLink Converter vers:all/*
Schneider Electric · ATV340E vers:intdot/<4.5
Schneider Electric · ATV340 4.5
Schneider Electric · ATS490 vers:generic/<1.2ie05
Schneider Electric · ATS490 1.2ie05
Schneider Electric · Altivar Process Communication Modules vers:all/*
Schneider Electric · Altivar Process Communication Modules vers:all/*

Affected Sectors

Critical Manufacturing

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more