← Back to home
ICSA-26-078-04  ·  Published 2026-03-19  ·  View on CISA ICS-CERT ↗

Schneider Electric EcoStruxure PME and EPO

CVSS 7.8 HIGH

CVEs (1)

Remediations

  • Hotfix_279338_Release_2024R2 is available for EcoStruxure Power Monitoring Expert (PME) that includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center to download this hotfix. No reboot required.
  • Customers should upgrade to EcoStruxure Power Monitoring Expert (PME) 2024 R3. Contact Schneider Electric’s Customer Care Center for assistance.
  • Hotfix_282807 - for 2023R2 is available for EcoStruxure Power Monitoring Expert (PME) that includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center to download this hotfix. No reboot required.
  • Customers should upgrade to EcoStruxure Power Monitoring Expert (PME) 2023 R2. Once upgraded, Hotfix_282807 - for 2023R2 is available for EcoStruxure Power Monitoring Expert (PME) that includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for assistance.
  • EcoStruxure Power Monitoring Expert (PME) 2022 version has reached its end of life and is no longer supported. • Ensure your deployment of PME has followed the cybersecurity hardening guidelines provided with the product. https://product-help.schneider-electric.com/EcoStruxure/Power-Monitoring-Expert-2024/content/2_planning/cybersecurity/cyber-planningrecactions.htm • Ensure PME is running in an isolated network • Deploy and configure the Windows firewall to limit access to appropriate network segments• Enforce complex password policies.o Review Server Access Permissions o Conduct an audit of all Windows-authenticated users who currently have access to PME. Repeat this audit of your system periodically. o Identify all accounts with access rights, especially those with elevated privileges or remote access. o Limit access to essential users only.o Revoke access for any user accounts that are not critical for system functionality or daily operations.o Apply the principle of least privilege to ensure users have only the access necessary for their role(s). Customers should also consider upgrading to the latest product offering EcoStruxure Power Monitoring Expert (PME) 2024 R3 to resolve this issue.
  • EcoStruxure Power Operation (EPO) 2022 version and EcoStruxure Power Monitoring Expert (PME) 2022 has reached its end of life and is no longer supported. • Ensure your deployment of PME has followed the cybersecurity hardening guidelines provided with the product. https://product-help.schneider-electric.com/EcoStruxure/Power-Monitoring-Expert-2024/content/2_planning/cybersecurity/cyber-planningrecactions.htm • Ensure PME is running in an isolated network • Deploy and configure the Windows firewall to limit access to appropriate network segments• Enforce complex password policies.o Review Server Access Permissions o Conduct an audit of all Windows-authenticated users who currently have access to PME. Repeat this audit of your system periodically. o Identify all accounts with access rights, especially those with elevated privileges or remote access. o Limit access to essential users only.o Revoke access for any user accounts that are not critical for system functionality or daily operations.o Apply the principle of least privilege to ensure users have only the access necessary for their role(s). Customers should also consider upgrading to the latest product offering EcoStruxure Power Monitoring Expert (PME) 2024 R3 to resolve this issue.

Affected Vendors

Schneider Electric

Affected Products (9)

Schneider Electric · EcoStruxure Power Monitoring Expert (PME) 2022 <=2022
Schneider Electric · EcoStruxure Power Monitoring Expert (PME) 2023
Schneider Electric · EcoStruxure Power Monitoring Expert (PME) 2023_R2
Schneider Electric · EcoStruxure Power Monitoring Expert (PME) 2024
Schneider Electric · EcoStruxure Power Monitoring Expert (PME) 2024_R2
Schneider Electric · EcoStruxure Power Operation (EPO) 2022 Advanced Reporting and Dashboards Module <=2022
Schneider Electric · EcoStruxure Power Operation (EPO) Advanced Reporting and Dashboards Module 2024
Schneider Electric · EcoStruxure Power Monitoring Expert (PME) 2023_R2_Hotfix_282807
Schneider Electric · EcoStruxure Power Monitoring Expert (PME) 2024_R2_Hotfix_279338__2024R2

Affected Sectors

Healthcare and Public Health, Information Technology, Critical Manufacturing, Commercial Facilities, Energy, Transportation Systems, Government Services and Facilities, Water and Wastewater

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more