ICSA-26-078-04
·
Published 2026-03-19
·
View on CISA ICS-CERT ↗
Schneider Electric EcoStruxure PME and EPO
CVSS 7.8
HIGH
CVEs (1)
Remediations
- Hotfix_279338_Release_2024R2 is available for EcoStruxure Power Monitoring Expert (PME) that includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center to download this hotfix. No reboot required.
- Customers should upgrade to EcoStruxure Power Monitoring Expert (PME) 2024 R3. Contact Schneider Electric’s Customer Care Center for assistance.
- Hotfix_282807 - for 2023R2 is available for EcoStruxure Power Monitoring Expert (PME) that includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center to download this hotfix. No reboot required.
- Customers should upgrade to EcoStruxure Power Monitoring Expert (PME) 2023 R2. Once upgraded, Hotfix_282807 - for 2023R2 is available for EcoStruxure Power Monitoring Expert (PME) that includes a fix for this vulnerability. Contact Schneider Electric’s Customer Care Center for assistance.
- EcoStruxure Power Monitoring Expert (PME) 2022 version has reached its end of life and is no longer supported. • Ensure your deployment of PME has followed the cybersecurity hardening guidelines provided with the product. https://product-help.schneider-electric.com/EcoStruxure/Power-Monitoring-Expert-2024/content/2_planning/cybersecurity/cyber-planningrecactions.htm • Ensure PME is running in an isolated network • Deploy and configure the Windows firewall to limit access to appropriate network segments• Enforce complex password policies.o Review Server Access Permissions o Conduct an audit of all Windows-authenticated users who currently have access to PME. Repeat this audit of your system periodically. o Identify all accounts with access rights, especially those with elevated privileges or remote access. o Limit access to essential users only.o Revoke access for any user accounts that are not critical for system functionality or daily operations.o Apply the principle of least privilege to ensure users have only the access necessary for their role(s). Customers should also consider upgrading to the latest product offering EcoStruxure Power Monitoring Expert (PME) 2024 R3 to resolve this issue.
- EcoStruxure Power Operation (EPO) 2022 version and EcoStruxure Power Monitoring Expert (PME) 2022 has reached its end of life and is no longer supported. • Ensure your deployment of PME has followed the cybersecurity hardening guidelines provided with the product. https://product-help.schneider-electric.com/EcoStruxure/Power-Monitoring-Expert-2024/content/2_planning/cybersecurity/cyber-planningrecactions.htm • Ensure PME is running in an isolated network • Deploy and configure the Windows firewall to limit access to appropriate network segments• Enforce complex password policies.o Review Server Access Permissions o Conduct an audit of all Windows-authenticated users who currently have access to PME. Repeat this audit of your system periodically. o Identify all accounts with access rights, especially those with elevated privileges or remote access. o Limit access to essential users only.o Revoke access for any user accounts that are not critical for system functionality or daily operations.o Apply the principle of least privilege to ensure users have only the access necessary for their role(s). Customers should also consider upgrading to the latest product offering EcoStruxure Power Monitoring Expert (PME) 2024 R3 to resolve this issue.
Affected Vendors
Schneider Electric
Affected Products (9)
Schneider Electric
·
EcoStruxure Power Monitoring Expert (PME) 2022
<=2022
Schneider Electric
·
EcoStruxure Power Monitoring Expert (PME)
2023
Schneider Electric
·
EcoStruxure Power Monitoring Expert (PME)
2023_R2
Schneider Electric
·
EcoStruxure Power Monitoring Expert (PME)
2024
Schneider Electric
·
EcoStruxure Power Monitoring Expert (PME)
2024_R2
Schneider Electric
·
EcoStruxure Power Operation (EPO) 2022 Advanced Reporting and Dashboards Module
<=2022
Schneider Electric
·
EcoStruxure Power Operation (EPO) Advanced Reporting and Dashboards Module
2024
Schneider Electric
·
EcoStruxure Power Monitoring Expert (PME)
2023_R2_Hotfix_282807
Schneider Electric
·
EcoStruxure Power Monitoring Expert (PME)
2024_R2_Hotfix_279338__2024R2
Affected Sectors
Healthcare and Public Health, Information Technology, Critical Manufacturing, Commercial Facilities, Energy, Transportation Systems, Government Services and Facilities, Water and Wastewater
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more