ICSA-26-020-02
·
Published 2026-01-20
·
View on CISA ICS-CERT ↗
Schneider Electric devices using CODESYS Runtime
CVSS 8.8
HIGH
CVEs (37)
CVE-2022-4046
CVE-2023-28355
CVE-2022-47378
CVE-2022-47379
CVE-2022-47380
CVE-2022-47381
CVE-2022-47382
CVE-2022-47383
CVE-2022-47384
CVE-2022-47386
CVE-2022-47387
CVE-2022-47388
CVE-2022-47389
CVE-2022-47390
CVE-2022-47385
CVE-2022-47392
CVE-2022-47393
CVE-2022-47391
CVE-2023-37545
CVE-2023-37546
CVE-2023-37547
CVE-2023-37548
CVE-2023-37549
CVE-2023-37550
CVE-2023-37551
CVE-2023-37552
CVE-2023-37553
CVE-2023-37554
CVE-2023-37555
CVE-2023-37556
CVE-2023-37557
CVE-2023-37558
CVE-2023-37559
CVE-2023-3662
CVE-2023-3663
CVE-2023-3669
CVE-2023-3670
Remediations
- Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.
- Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.
- Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.
- Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.
- Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.
- PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.
- Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.
- SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application.
- Schneider Electric´s Modicon LMC078 controllers have reached end of their life and are no longer commercially available. They have been replaced by the Modicon M262 controllers. We recommend our customers to migrate to the latest offer. Please contact your local Schneider Electric technical support for more information.
- Schneider Electric’s Modicon M218 controllers have reached their end of life and are no longer commercially available. They have been replaced by the Modicon Easy M200 and Modicon M241 controllers. We recommend our customers to migrate to the latest offer. Please contact your local Schneider Electric technical support for more information.
- • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.
- • Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp
- Version 6.3 HF3 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. As an alternative, please contact your Schneider Electric Customer Care Center to obtain the Hot Fix. For additional detail please refer to the supplied help file in Hot Fix. On the engineering workstation, update to v6.3 HF3 of Vijeo Designer.
- Vijeo Designer Basic v2.0 HotFix 2 includes a fix for this vulnerability. Please contact your Schneider Electric Customer Care Center to obtain the installer. To complete the update, connect to Harmony HMI and download the firmware using Vijeo Designer Basic.
- Version 6.3 SP2 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware As an alternative, please contact your Schneider Electric Customer Care Center to obtain the Fix. For additional details, please refer to the supplied help file in Hot Fix. On the engineering workstation, update to v6.3 SP2 of Vijeo Designer.
- Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.
- Version 3.1.5.82 includes a fix for this vulnerability and can be download here: https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 As an alternative, contact your Schneider Electric Customer Care Center to obtain the firmware. To complete the update, connect to M310 and download the firmware using EcoStruxureTM Motion Expert.
Affected Vendors
Schneider Electric
Affected Products (27)
Schneider Electric
·
HMISCU Controller
<6.3.1
Schneider Electric
·
Modicon Controller LMC078
vers:all/*
Schneider Electric
·
Modicon Controller M241
<5.2.11.18
Schneider Electric
·
Modicon Controller M251
<5.2.11.18
Schneider Electric
·
Modicon Controller M262
<5.2.8.12
Schneider Electric
·
Modicon Controller M258
vers:all/*
Schneider Electric
·
Modicon Controller LMC058
vers:all/*
Schneider Electric
·
Modicon Controller M218
vers:all/*
Schneider Electric
·
PacDrive 3 Controllers: LMC Eco/Pro/Pro2
<1.76.14.1
Schneider Electric
·
SoftSPS embedded in EcoStruxure Machine Expert
<2.2
Schneider Electric
·
Vijeo Designer embedded in EcoStruxure Machine Expert
<6.3.1
Schneider Electric
·
Harmony (Formerly Magelis) HMIGK/HMIGTO/HMIGTU/HMIGTUX/HMISTU series
<6.3_HF3
Schneider Electric
·
Easy Harmony HMIET6/HMIFT6 Magelis HMIGXU series
<2.0_HF2
Schneider Electric
·
HMISCU Controller
6.3.1
Schneider Electric
·
Modicon Controller M241
5.2.11.18
Schneider Electric
·
Modicon Controller M251
5.2.11.18
Schneider Electric
·
Modicon Controller M262
5.2.8.12
Schneider Electric
·
PacDrive 3 Controllers: LMC Eco/Pro/Pro2
1.76.14.1
Schneider Electric
·
SoftSPS embedded in EcoStruxure Machine Expert
2.2
Schneider Electric
·
Vijeo Designer embedded in EcoStruxure Machine Expert
6.3.1
Schneider Electric
·
Harmony (Formerly Magelis) HMIGK/HMIGTO/HMIGTU/HMIGTUX/HMISTU series iPC series with Vijeo Designer runtime
6.3_HF3
Schneider Electric
·
Vijeo Designer Basic
2.0_HotFix_2
Schneider Electric
·
Magelis XBT series
vers:all/*
Schneider Electric
·
Easy Modicon M310
<3.1.5.82
Schneider Electric
·
Vijeo Designer runtime
<6.3_SP2
Schneider Electric
·
Vijeo Designer runtime
6.3_SP2
Schneider Electric
·
Easy Modicon M310
3.1.5.82
Affected Sectors
Commercial Facilities, Critical Manufacturing, Energy
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more