Zeros312
ot | ICSA-26-174-07 | CVE-2026-1840 | Hubbell Aclara Metrum Cellular Web Interface | 2026-06-23 09:00:00+03:00 | 2026-06-23 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-07.json | 5bac4f9d904f2356409be534b23b55822c80c51f833b430a01b3c3366f4cbac4 | 2026-06-24 07:37:39.992137+03:00 | 2026-06-24 07:37:39.992137+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of this vulnerability could allow attackers to manipulate critical device settings and repeatedly disrupt operations, potentially causing a loss of communications to the device.', 'title': 'Advisory Summary', 'category': 'summary'}, {'text': 'Energy', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'United States', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Hubbell Aclara Metrum Cellular Web Interface', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-174-07', 'status': 'final', 'version': '1', 'generator': {'date': '2026-06-22T21:14:03.666009Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-06-23T06:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}], 'current_release_date': '2026-06-23T06:00:00.000000Z', 'initial_release_date': '2026-06-23T06:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-07.json', 'summary': 'ICS Advisory ICSA-26-174-07 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-07', 'summary': 'ICSA Advisory ICSA-26-174-07 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Abhirup Konwar'], 'summary': 'reported this vulnerability to CISA'}]}, 'product_tree': {'branches': [{'name': 'Hubbell', 'branches': [{'name': 'Aclara Metrum Cellular Web Interface', 'branches': [{'name': '<v2.1.0.105', 'product': {'name': 'Hubbell Aclara Metrum Cellular Web Interface: <v2.1.0.105', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-1840', 'cwe': {'id': 'CWE-306', 'name': 'Missing Authentication for Critical Function'}, 'notes': [{'text': 'The Aclara Metrum Cellular Web Interface is vulnerable to unauthorized access due to the absence of authentication controls on critical system functions. This weakness exposes essential configuration settings, allowing attackers to alter operational parameters and trigger system restarts without restriction. Such unauthorized changes can disrupt normal functionality and, if performed repeatedly, may lead to a loss of communications to the device.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-06-22T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/306.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-1840', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://aclara.my.site.com/AclaraConnect/s/', 'details': 'Hubbell encourages users to update their firmware to v2.1.0.105 in order to minimize network exposure and ensure that devices are not accessible from the Internet. Users can download version 2.1.0.105 from AclaraConnect https://aclara.my.site.com/AclaraConnect/s/.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-174-06 | CVE-2026-31431 | Impact of Linux Kernel vulnerabilities on B&R products | 2026-06-11 03:30:00+03:00 | 2026-06-23 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-06.json | 4339fb2d3ab3f0174027050fe7fda568f20686d5460ef310f31646d9f80c0cfb | 2026-06-24 07:37:39.992137+03:00 | 2026-06-24 07:37:39.992137+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'B&R is aware of publicly reported vulnerabilities affecting the Linux kernel versions shipped with the products listed as affected in the advisory.\n\nSuccessful local exploitation of these vulnerabilities could allow an attacker to escalate privileges on the affected system. Public proof-of-concept exploits are available for the vulnerabilities described herein. At the time of publication of this advisory, B&R had no evidence of active exploitation targeting B&R products.', 'title': 'Summary', 'category': 'summary'}, {'text': 'For additional instructions and support please contact your local B&R service organization. For contact information, see https://www.br-automation.com/en/about-us/locations/.\n\nInformation about ABB’s cyber security program and capabilities can be found at www.abb.com/cybersecurity.\n\n\n', 'title': 'Support', 'category': 'other'}, {'text': 'The information in this document is subject to change without notice, and should not be construed as a commitment by B&R.\n\nB&R provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall B&R or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if B&R or its suppliers have been advised of the possibility of such damages.\n\nThis document and parts hereof must not be reproduced or copied without written permission from B&R, and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose.\n\nAll rights to registrations and trademarks reside with their respective owners.', 'title': 'Notice', 'category': 'legal_disclaimer'}, {'text': 'For any installation of software related ABB products we strongly recommend the following (non-exhaustive) list of cyber security practices:\n\n- Isolate special purpose networks (e.g. for automation systems) and remote devices behind firewalls and separate them from any general purpose network (e.g. office or home networks).\n\n- Install physical controls so no unauthorized personnel can access your devices, components, peripheral equipment, and networks.\n\n- Never connect programming software or computers containing programing software to any network other than the network for the devices that it is intended for.\n\n- Scan all data imported into your environment before use to detect potential malware infections.\n\n- Minimize network exposure for all applications and endpoints to ensure that they are not accessible from the Internet unless they are designed for such exposure and the intended use requires such.\n\n- Ensure all nodes are always up to date in terms of installed software, operating system, and firmware patches as well as anti-virus and firewall.\n\n- When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.\n\nFor more information on recommended practices, please refer to the following documents listed in the reference section:\n\n- Defense in Depth for B&R products\n', 'title': 'General security recommendations', 'category': 'other'}, {'text': 'B&R has a rigorous internal cyber security continuous improvement process which involves regular testing with industry leading tools and periodic assessments to identify potential product issues. Occasionally an issue is determined to be a design or coding flaw with implications that may impact product cyber security.\n\nWhen a potential product vulnerability is identified or reported, B&R immediately initiates our vulnerability handling process. This entails validating if the issue is in fact a product issue, identifying root causes, determining what related products may be impacted, developing a remediation, and notifying end users and governmental organizations.\n\nThe resulting Cyber Security Advisory intends to notify customers of the vulnerability and provide details on which products are impacted, how to mitigate the vulnerability or explain workarounds that minimize the potential risk as much as possible. The release of a Cyber Security Advisory should not be misconstrued as an affirmation or indication of an active threat or ongoing campaign targeting the products mentioned here. If B&R is aware of any specific threats, it will be clearly mentioned in the communication.\n\nThe publication of this Cyber Security Advisory is an example of B&R’s commitment to the user community in support of this critical topic. Responsible disclosure is an important element in the chain of trust we work to maintain with our many customers. The release of an Advisory provides timely information which is essential to help ensure our customers are fully informed.', 'title': 'Purpose', 'category': 'other'}, {'text': 'What causes the vulnerabilities?\n- The vulnerabilities are caused by a vulnerable Linux Kernel component.\n\nWhat might an attacker use the vulnerability to do?\n- An authenticated attacker with low privileges may elevate privileges to root.\n\nCould the vulnerabilities be exploited remotely? \n- Yes, an attacker with privileges to login in a vulnerable system node could exploit these vulnerabilities. Recommended practices include that process control systems are physically protected, have no direct connections to the Internet, and are separated from other networks by means of a firewall system that has a minimal number of ports exposed. \n\nWhen this security advisory was issued, had B&R received any reports that these vulnerabilities were being exploited?\n- B&R is aware of reports indicating that these vulnerabilities had been exploited at the time this security advisory was originally issued; however, no exploitation has been observed in B&R products.', 'title': 'Frequently asked questions', 'category': 'faq'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of ABB PSIRT SA26P010 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact ABB PSIRT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Switzerland', 'title': 'Company headquarters location', 'category': 'other'}], 'title': 'Impact of Linux Kernel vulnerabilities on B&R products', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-174-06', 'status': 'final', 'version': '3', 'generator': {'date': '2026-06-18T13:26:13.151541Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2026-06-11T00:30:00.000000Z', 'number': '1', 'summary': 'Initial version.', 'legacy_version': 'Initial'}, {'date': '2026-06-18T00:30:00.000000Z', 'number': '2', 'summary': 'Updating the CWE classification for CVE-2026-43494.', 'legacy_version': 'Additional Release 1'}, {'date': '2026-06-23T06:00:00.000000Z', 'number': '3', 'summary': 'Initial CISA Republication of ABB PSIRT SA26P010 advisory', 'legacy_version': 'CISA Republication'}], 'current_release_date': '2026-06-23T06:00:00.000000Z', 'initial_release_date': '2026-06-11T00:30:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://psirt.abb.com/csaf/2026/sa26p010.json', 'summary': 'B&R CYBERSECURITY ADVISORY - CSAF Version ', 'category': 'self'}, {'url': 'https://br-cws-assets.de-fra-1.linodeobjects.com/SA26P010-0ea64434.pdf', 'summary': 'B&R CYBERSECURITY ADVISORY - PDF Version ', 'category': 'self'}, {'url': 'https://www.br-automation.com/fileadmin/Cyber_Security_-_Defense_in_Depth_for_BR_Products-bdd37e82.pdf', 'summary': 'Defense in Depth for B&R products'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-06.json', 'summary': 'ICS Advisory ICSA-26-174-06 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-06', 'summary': 'ICS Advisory ICSA-26-174-06 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to CISA.', 'organization': 'ABB PSIRT'}]}, 'product_tree': {'branches': [{'name': 'B&R Industrial Automation GmbH', 'branches': [{'name': 'Linux for B&R', 'branches': [{'name': '<=12', 'product': {'name': 'B&R Industrial Automation GmbH Linux for B&R <=12', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'APROL', 'branches': [{'name': '<APROL-AutoYaST-DVD-_V4.4-010.10.260602', 'product': {'name': 'B&R Industrial Automation GmbH APROL <APROL-AutoYaST-DVD- V4.4-010.10.260602', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}, {'name': 'APROL-AutoYaST-DVD-_V4.4-010.10.260602', 'product': {'name': 'B&R Industrial Automation GmbH APROL APROL-AutoYaST-DVD- V4.4-010.10.260602', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'X20EDS410', 'branches': [{'name': '/all', 'product': {'name': 'B&R Industrial Automation GmbH X20EDS410 /all', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-31431', 'cwe': {'id': 'CWE-669', 'name': 'Incorrect Resource Transfer Between Spheres'}, 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2026-31431', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:H/RC:C', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'reportConfidence': 'CONFIRMED', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'LOW', 'exploitCodeMaturity': 'HIGH', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31431', 'summary': 'NVD - CVE-2026-31431', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-31431', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/669.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:H/RC:C', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'For affected products, software updates should be installed upon availability.\n\n Product\t Patch version\n- APROL\t : APROL-AutoYaST-DVD- V4.4-010.10.260602\n\nUntil remediated software versions are available, customers are required to conduct a risk assessment of their affected systems and to implement the mitigation measures and workarounds specified in this advisory.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Successful exploitation of the vulnerabilities described in this advisory requires local access to the affected system with low-privileged user credentials. Customers are strongly advised to enforce strict access control policies on all Linux-based systems, ensuring that interactive access is exclusively granted to authorized and trusted personnel. This includes reviewing and hardening user account permissions and disabling unused accounts.\n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.\n', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}, {'details': 'Security researchers have identified and validated the following workarounds to reduce exposure to the vulnerabilities described in this advisory. These measures do not remediate the underlying vulnerabilities but effectively block known attack vectors until patched software versions are deployed.\n\nImportant: Customers are advised to thoroughly test their systems after applying any of the listed workarounds. B&R has no visibility into customer-specific applications running on the underlying Linux system. It is the customer\'s responsibility to assess whether the applied workarounds interfere with existing application workloads prior to deployment in production environments.\n\nFor Debian-based systems within an active support lifecycle, kernel patches addressing CVE-2026-31431 are already available via the official package repositories. Customers are strongly encouraged to apply these updates immediately by executing the following command:\nsudo apt update && sudo apt upgrade\nA system reboot is required after the upgrade for the updated kernel to take effect.\n\nTemporary Mitigation: If an immediate system update is not feasible, the affected kernel module (algif_aead) can be disabled persistently. Security researchers have confirmed this measure effectively prevents exploitation of CVE-2026-31431.\nExecute the following commands as root:\n\necho "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf\nrmmod algif_aead 2>/dev/null || true\n\nImpact assessment: Disabling the algif_aead module removes the AEAD socket interface from the kernel cryp-to API. This does not affect dm-crypt/LUKS, kTLS, IPsec/XFRM, OpenSSL, GnuTLS, NSS, or SSH. Applications explicitly configured to use the afalg engine or that directly bind aead, skcipher, or hash sockets via AF_ALG may be affected. To assess exposure prior to applying this workaround, run:\n\nlsof | grep AF_ALG', 'category': 'workaround', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}], 'product_status': {'fixed': ['CSAFPID-0003'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}}, {'cve': 'CVE-2026-43284', 'cwe': {'id': 'CWE-123', 'name': 'Write-what-where Condition'}, 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths that may modify packet data can first make a private copy. The IPv4/IPv6 datagram append paths did not set this flag when splicing pages into UDP skbs. That leaves an ESP-in-UDP packet made from shared pipe pages looking like an ordinary uncloned nonlinear skb. ESP input then takes the no-COW fast path for uncloned skbs without a frag_list and decrypts in place over data that is not owned privately by the skb. Mark IPv4/IPv6 datagram splice frags with SKBFL_SHARED_FRAG, matching TCP. Also make ESP input fall back to skb_cow_data() when the flag is present, so ESP does not decrypt external-ly backed frags in place. Private nonlinear skb frags still use the existing fast path. This intentionally does not change ESP output. In esp_output_head(), the path that appends the ESP trailer to existing skb tailroom without calling skb_cow_data() is not reachable for nonlinear skbs: skb_tailroom() returns zero when skb->data_len is nonzero, while ESP tailen is positive. Thus ESP output will either use the separate destination-frag path or fall back to skb_cow_data().', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2026-43284', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.9, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43284', 'summary': 'NVD - CVE-2026-43284', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-43284', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/123.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'For affected products, software updates should be installed upon availability.\n\n Product\t Patch version\n- APROL\t : APROL-AutoYaST-DVD- V4.4-010.10.260602\n\nUntil remediated software versions are available, customers are required to conduct a risk assessment of their affected systems and to implement the mitigation measures and workarounds specified in this advisory.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Successful exploitation of the vulnerabilities described in this advisory requires local access to the affected system with low-privileged user credentials. Customers are strongly advised to enforce strict access control policies on all Linux-based systems, ensuring that interactive access is exclusively granted to authorized and trusted personnel. This includes reviewing and hardening user account permissions and disabling unused accounts.\n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.\n', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}, {'details': 'Security researchers have identified and validated the following workarounds to reduce exposure to the vulnerabilities described in this advisory. These measures do not remediate the underlying vulnerabilities but effectively block known attack vectors until patched software versions are deployed.\n\nImportant: Customers are advised to thoroughly test their systems after applying any of the listed workarounds. B&R has no visibility into customer-specific applications running on the underlying Linux system. It is the customer\'s responsibility to assess whether the applied workarounds interfere with existing application workloads prior to deployment in production environments.\n\nFor Debian-based systems within an active support lifecycle, kernel patches addressing CVE-2026-31431 are already available via the official package repositories. Customers are strongly encouraged to apply these updates immediately by executing the following command:\nsudo apt update && sudo apt upgrade\nA system reboot is required after the upgrade for the updated kernel to take effect.\n\nTemporary Mitigation: If an immediate system update is not feasible, the affected kernel module (algif_aead) can be disabled persistently. Security researchers have confirmed this measure effectively prevents exploitation of CVE-2026-31431.\nExecute the following commands as root:\n\necho "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf\nrmmod algif_aead 2>/dev/null || true\n\nImpact assessment: Disabling the algif_aead module removes the AEAD socket interface from the kernel cryp-to API. This does not affect dm-crypt/LUKS, kTLS, IPsec/XFRM, OpenSSL, GnuTLS, NSS, or SSH. Applications explicitly configured to use the afalg engine or that directly bind aead, skcipher, or hash sockets via AF_ALG may be affected. To assess exposure prior to applying this workaround, run:\n\nlsof | grep AF_ALG', 'category': 'workaround', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}], 'product_status': {'fixed': ['CSAFPID-0003'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}}, {'cve': 'CVE-2026-46333', 'cwe': {'id': 'CWE-269', 'name': 'Improper Privilege Management'}, 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner \'get_dumpable()\' logic The \'dumpability\' of a task is fundamentally about the memory image of the task - the concept comes from whether it can core dump or not - and makes no sense when you don\'t have an associated mm. And almost all users do in fact use it only for the case where the task has a mm pointer. But we have one odd special case: ptrace_may_access() uses \'dumpable\' to check various other things entirely independently of the MM (typically explicitly using flags like PTRACE_MODE_READ_FSCREDS). Including for threads that no longer have a VM (and maybe never did, like most kernel threads). It\'s not what this flag was designed for, but it is what it is. The ptrace code does check that the uid/gid matches, so you do have to be uid-0 to see kernel thread details, but this means that the traditional "drop capabilities" model doesn\'t make any difference for this all. Make it all make a *bit* more sense by saying that if you don\'t have a MM pointer, we\'ll use a cached "last dumpability" flag if the thread ever had a MM (it will be zero for kernel threads since it is never set), and require a proper CAP_SYS_PTRACE capability to override.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2026-46333', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.1, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N', 'temporalScore': 7.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.1, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46333', 'summary': 'NVD - CVE-2026-46333', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-46333', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/269.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'For affected products, software updates should be installed upon availability.\n\n Product\t Patch version\n- APROL\t : APROL-AutoYaST-DVD- V4.4-010.10.260602\n\nUntil remediated software versions are available, customers are required to conduct a risk assessment of their affected systems and to implement the mitigation measures and workarounds specified in this advisory.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Successful exploitation of the vulnerabilities described in this advisory requires local access to the affected system with low-privileged user credentials. Customers are strongly advised to enforce strict access control policies on all Linux-based systems, ensuring that interactive access is exclusively granted to authorized and trusted personnel. This includes reviewing and hardening user account permissions and disabling unused accounts.\n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.\n', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}, {'details': 'Security researchers have identified and validated the following workarounds to reduce exposure to the vulnerabilities described in this advisory. These measures do not remediate the underlying vulnerabilities but effectively block known attack vectors until patched software versions are deployed.\n\nImportant: Customers are advised to thoroughly test their systems after applying any of the listed workarounds. B&R has no visibility into customer-specific applications running on the underlying Linux system. It is the customer\'s responsibility to assess whether the applied workarounds interfere with existing application workloads prior to deployment in production environments.\n\nFor Debian-based systems within an active support lifecycle, kernel patches addressing CVE-2026-31431 are already available via the official package repositories. Customers are strongly encouraged to apply these updates immediately by executing the following command:\nsudo apt update && sudo apt upgrade\nA system reboot is required after the upgrade for the updated kernel to take effect.\n\nTemporary Mitigation: If an immediate system update is not feasible, the affected kernel module (algif_aead) can be disabled persistently. Security researchers have confirmed this measure effectively prevents exploitation of CVE-2026-31431.\nExecute the following commands as root:\n\necho "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf\nrmmod algif_aead 2>/dev/null || true\n\nImpact assessment: Disabling the algif_aead module removes the AEAD socket interface from the kernel cryp-to API. This does not affect dm-crypt/LUKS, kTLS, IPsec/XFRM, OpenSSL, GnuTLS, NSS, or SSH. Applications explicitly configured to use the afalg engine or that directly bind aead, skcipher, or hash sockets via AF_ALG may be affected. To assess exposure prior to applying this workaround, run:\n\nlsof | grep AF_ALG', 'category': 'workaround', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}], 'product_status': {'fixed': ['CSAFPID-0003'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}}, {'cve': 'CVE-2026-46300', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() can attach paged frags from @from to @to. If @from has SKBFL_SHARED_FRAG set, the resulting @to skb can contain the same externally-owned or page-cache-backed frags, but the shared-frag marker is currently lost. That breaks the invariant relied on by later in-place writers. In particular, ESP input checks skb_has_shared_frag() before deciding whether an uncloned nonlinear skb can skip skb_cow_data(). If TCP receive coalescing has moved shared frags into an unmarked skb, ESP can see skb_has_shared_frag() as false and decrypt in place over page-cache backed frags. Propagate SKBFL_SHARED_FRAG when skb_try_coalesce() transfers paged frags. The tailroom copy path does not need the marker because it copies bytes into @to's linear data rather than transferring frag descriptors..", 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2026-46300', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46300', 'summary': 'NVD - CVE-2026-46300 ', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-46300', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'For affected products, software updates should be installed upon availability.\n\n Product\t Patch version\n- APROL\t : APROL-AutoYaST-DVD- V4.4-010.10.260602\n\nUntil remediated software versions are available, customers are required to conduct a risk assessment of their affected systems and to implement the mitigation measures and workarounds specified in this advisory.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Successful exploitation of the vulnerabilities described in this advisory requires local access to the affected system with low-privileged user credentials. Customers are strongly advised to enforce strict access control policies on all Linux-based systems, ensuring that interactive access is exclusively granted to authorized and trusted personnel. This includes reviewing and hardening user account permissions and disabling unused accounts.\n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.\n', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}, {'details': 'Security researchers have identified and validated the following workarounds to reduce exposure to the vulnerabilities described in this advisory. These measures do not remediate the underlying vulnerabilities but effectively block known attack vectors until patched software versions are deployed.\n\nImportant: Customers are advised to thoroughly test their systems after applying any of the listed workarounds. B&R has no visibility into customer-specific applications running on the underlying Linux system. It is the customer\'s responsibility to assess whether the applied workarounds interfere with existing application workloads prior to deployment in production environments.\n\nFor Debian-based systems within an active support lifecycle, kernel patches addressing CVE-2026-31431 are already available via the official package repositories. Customers are strongly encouraged to apply these updates immediately by executing the following command:\nsudo apt update && sudo apt upgrade\nA system reboot is required after the upgrade for the updated kernel to take effect.\n\nTemporary Mitigation: If an immediate system update is not feasible, the affected kernel module (algif_aead) can be disabled persistently. Security researchers have confirmed this measure effectively prevents exploitation of CVE-2026-31431.\nExecute the following commands as root:\n\necho "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf\nrmmod algif_aead 2>/dev/null || true\n\nImpact assessment: Disabling the algif_aead module removes the AEAD socket interface from the kernel cryp-to API. This does not affect dm-crypt/LUKS, kTLS, IPsec/XFRM, OpenSSL, GnuTLS, NSS, or SSH. Applications explicitly configured to use the afalg engine or that directly bind aead, skcipher, or hash sockets via AF_ALG may be affected. To assess exposure prior to applying this workaround, run:\n\nlsof | grep AF_ALG', 'category': 'workaround', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}], 'product_status': {'fixed': ['CSAFPID-0003'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}}, {'cve': 'CVE-2026-43494', 'cwe': {'id': 'CWE-1341', 'name': 'Multiple Releases of Same Resource or Handle'}, 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved: net/rds: reset op_nents when zerocopy page pin fails When iov_iter_get_pages2() fails in rds_message_zcopy_from_user(), the pinned pages are released with put_page(), and rm->data.op_mmp_znotifier is cleared. But we fail to properly clear rm->data.op_nents. Later when rds_message_purge() is called from rds_sendmsg() the cleanup loop iterates over the incorrectly non zero number of op_nents and frees them again. Fix this by properly resetting op_nents when it should be in rds_message_zcopy_from_user().', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2026-43494', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43494', 'summary': 'NVD - CVE-2026-43494', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-43494', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/1341.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'For affected products, software updates should be installed upon availability.\n\n Product\t Patch version\n- APROL\t : APROL-AutoYaST-DVD- V4.4-010.10.260602\n\nUntil remediated software versions are available, customers are required to conduct a risk assessment of their affected systems and to implement the mitigation measures and workarounds specified in this advisory.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Successful exploitation of the vulnerabilities described in this advisory requires local access to the affected system with low-privileged user credentials. Customers are strongly advised to enforce strict access control policies on all Linux-based systems, ensuring that interactive access is exclusively granted to authorized and trusted personnel. This includes reviewing and hardening user account permissions and disabling unused accounts.\n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.\n', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}, {'details': 'Security researchers have identified and validated the following workarounds to reduce exposure to the vulnerabilities described in this advisory. These measures do not remediate the underlying vulnerabilities but effectively block known attack vectors until patched software versions are deployed.\n\nImportant: Customers are advised to thoroughly test their systems after applying any of the listed workarounds. B&R has no visibility into customer-specific applications running on the underlying Linux system. It is the customer\'s responsibility to assess whether the applied workarounds interfere with existing application workloads prior to deployment in production environments.\n\nFor Debian-based systems within an active support lifecycle, kernel patches addressing CVE-2026-31431 are already available via the official package repositories. Customers are strongly encouraged to apply these updates immediately by executing the following command:\nsudo apt update && sudo apt upgrade\nA system reboot is required after the upgrade for the updated kernel to take effect.\n\nTemporary Mitigation: If an immediate system update is not feasible, the affected kernel module (algif_aead) can be disabled persistently. Security researchers have confirmed this measure effectively prevents exploitation of CVE-2026-31431.\nExecute the following commands as root:\n\necho "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf\nrmmod algif_aead 2>/dev/null || true\n\nImpact assessment: Disabling the algif_aead module removes the AEAD socket interface from the kernel cryp-to API. This does not affect dm-crypt/LUKS, kTLS, IPsec/XFRM, OpenSSL, GnuTLS, NSS, or SSH. Applications explicitly configured to use the afalg engine or that directly bind aead, skcipher, or hash sockets via AF_ALG may be affected. To assess exposure prior to applying this workaround, run:\n\nlsof | grep AF_ALG', 'category': 'workaround', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}], 'product_status': {'fixed': ['CSAFPID-0003'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}}]} | |
ot | ICSA-26-174-06 | CVE-2026-43284 | Impact of Linux Kernel vulnerabilities on B&R products | 2026-06-11 03:30:00+03:00 | 2026-06-23 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-06.json | 63c643c705b5c66633353aa398a8b8813d9670b9d8cd3ea9c953a2102cb99091 | 2026-06-24 07:37:39.992137+03:00 | 2026-06-24 07:37:39.992137+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'B&R is aware of publicly reported vulnerabilities affecting the Linux kernel versions shipped with the products listed as affected in the advisory.\n\nSuccessful local exploitation of these vulnerabilities could allow an attacker to escalate privileges on the affected system. Public proof-of-concept exploits are available for the vulnerabilities described herein. At the time of publication of this advisory, B&R had no evidence of active exploitation targeting B&R products.', 'title': 'Summary', 'category': 'summary'}, {'text': 'For additional instructions and support please contact your local B&R service organization. For contact information, see https://www.br-automation.com/en/about-us/locations/.\n\nInformation about ABB’s cyber security program and capabilities can be found at www.abb.com/cybersecurity.\n\n\n', 'title': 'Support', 'category': 'other'}, {'text': 'The information in this document is subject to change without notice, and should not be construed as a commitment by B&R.\n\nB&R provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall B&R or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if B&R or its suppliers have been advised of the possibility of such damages.\n\nThis document and parts hereof must not be reproduced or copied without written permission from B&R, and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose.\n\nAll rights to registrations and trademarks reside with their respective owners.', 'title': 'Notice', 'category': 'legal_disclaimer'}, {'text': 'For any installation of software related ABB products we strongly recommend the following (non-exhaustive) list of cyber security practices:\n\n- Isolate special purpose networks (e.g. for automation systems) and remote devices behind firewalls and separate them from any general purpose network (e.g. office or home networks).\n\n- Install physical controls so no unauthorized personnel can access your devices, components, peripheral equipment, and networks.\n\n- Never connect programming software or computers containing programing software to any network other than the network for the devices that it is intended for.\n\n- Scan all data imported into your environment before use to detect potential malware infections.\n\n- Minimize network exposure for all applications and endpoints to ensure that they are not accessible from the Internet unless they are designed for such exposure and the intended use requires such.\n\n- Ensure all nodes are always up to date in terms of installed software, operating system, and firmware patches as well as anti-virus and firewall.\n\n- When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.\n\nFor more information on recommended practices, please refer to the following documents listed in the reference section:\n\n- Defense in Depth for B&R products\n', 'title': 'General security recommendations', 'category': 'other'}, {'text': 'B&R has a rigorous internal cyber security continuous improvement process which involves regular testing with industry leading tools and periodic assessments to identify potential product issues. Occasionally an issue is determined to be a design or coding flaw with implications that may impact product cyber security.\n\nWhen a potential product vulnerability is identified or reported, B&R immediately initiates our vulnerability handling process. This entails validating if the issue is in fact a product issue, identifying root causes, determining what related products may be impacted, developing a remediation, and notifying end users and governmental organizations.\n\nThe resulting Cyber Security Advisory intends to notify customers of the vulnerability and provide details on which products are impacted, how to mitigate the vulnerability or explain workarounds that minimize the potential risk as much as possible. The release of a Cyber Security Advisory should not be misconstrued as an affirmation or indication of an active threat or ongoing campaign targeting the products mentioned here. If B&R is aware of any specific threats, it will be clearly mentioned in the communication.\n\nThe publication of this Cyber Security Advisory is an example of B&R’s commitment to the user community in support of this critical topic. Responsible disclosure is an important element in the chain of trust we work to maintain with our many customers. The release of an Advisory provides timely information which is essential to help ensure our customers are fully informed.', 'title': 'Purpose', 'category': 'other'}, {'text': 'What causes the vulnerabilities?\n- The vulnerabilities are caused by a vulnerable Linux Kernel component.\n\nWhat might an attacker use the vulnerability to do?\n- An authenticated attacker with low privileges may elevate privileges to root.\n\nCould the vulnerabilities be exploited remotely? \n- Yes, an attacker with privileges to login in a vulnerable system node could exploit these vulnerabilities. Recommended practices include that process control systems are physically protected, have no direct connections to the Internet, and are separated from other networks by means of a firewall system that has a minimal number of ports exposed. \n\nWhen this security advisory was issued, had B&R received any reports that these vulnerabilities were being exploited?\n- B&R is aware of reports indicating that these vulnerabilities had been exploited at the time this security advisory was originally issued; however, no exploitation has been observed in B&R products.', 'title': 'Frequently asked questions', 'category': 'faq'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of ABB PSIRT SA26P010 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact ABB PSIRT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Switzerland', 'title': 'Company headquarters location', 'category': 'other'}], 'title': 'Impact of Linux Kernel vulnerabilities on B&R products', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-174-06', 'status': 'final', 'version': '3', 'generator': {'date': '2026-06-18T13:26:13.151541Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2026-06-11T00:30:00.000000Z', 'number': '1', 'summary': 'Initial version.', 'legacy_version': 'Initial'}, {'date': '2026-06-18T00:30:00.000000Z', 'number': '2', 'summary': 'Updating the CWE classification for CVE-2026-43494.', 'legacy_version': 'Additional Release 1'}, {'date': '2026-06-23T06:00:00.000000Z', 'number': '3', 'summary': 'Initial CISA Republication of ABB PSIRT SA26P010 advisory', 'legacy_version': 'CISA Republication'}], 'current_release_date': '2026-06-23T06:00:00.000000Z', 'initial_release_date': '2026-06-11T00:30:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://psirt.abb.com/csaf/2026/sa26p010.json', 'summary': 'B&R CYBERSECURITY ADVISORY - CSAF Version ', 'category': 'self'}, {'url': 'https://br-cws-assets.de-fra-1.linodeobjects.com/SA26P010-0ea64434.pdf', 'summary': 'B&R CYBERSECURITY ADVISORY - PDF Version ', 'category': 'self'}, {'url': 'https://www.br-automation.com/fileadmin/Cyber_Security_-_Defense_in_Depth_for_BR_Products-bdd37e82.pdf', 'summary': 'Defense in Depth for B&R products'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-06.json', 'summary': 'ICS Advisory ICSA-26-174-06 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-06', 'summary': 'ICS Advisory ICSA-26-174-06 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to CISA.', 'organization': 'ABB PSIRT'}]}, 'product_tree': {'branches': [{'name': 'B&R Industrial Automation GmbH', 'branches': [{'name': 'Linux for B&R', 'branches': [{'name': '<=12', 'product': {'name': 'B&R Industrial Automation GmbH Linux for B&R <=12', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'APROL', 'branches': [{'name': '<APROL-AutoYaST-DVD-_V4.4-010.10.260602', 'product': {'name': 'B&R Industrial Automation GmbH APROL <APROL-AutoYaST-DVD- V4.4-010.10.260602', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}, {'name': 'APROL-AutoYaST-DVD-_V4.4-010.10.260602', 'product': {'name': 'B&R Industrial Automation GmbH APROL APROL-AutoYaST-DVD- V4.4-010.10.260602', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'X20EDS410', 'branches': [{'name': '/all', 'product': {'name': 'B&R Industrial Automation GmbH X20EDS410 /all', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-31431', 'cwe': {'id': 'CWE-669', 'name': 'Incorrect Resource Transfer Between Spheres'}, 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2026-31431', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:H/RC:C', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'reportConfidence': 'CONFIRMED', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'LOW', 'exploitCodeMaturity': 'HIGH', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31431', 'summary': 'NVD - CVE-2026-31431', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-31431', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/669.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:H/RC:C', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'For affected products, software updates should be installed upon availability.\n\n Product\t Patch version\n- APROL\t : APROL-AutoYaST-DVD- V4.4-010.10.260602\n\nUntil remediated software versions are available, customers are required to conduct a risk assessment of their affected systems and to implement the mitigation measures and workarounds specified in this advisory.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Successful exploitation of the vulnerabilities described in this advisory requires local access to the affected system with low-privileged user credentials. Customers are strongly advised to enforce strict access control policies on all Linux-based systems, ensuring that interactive access is exclusively granted to authorized and trusted personnel. This includes reviewing and hardening user account permissions and disabling unused accounts.\n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.\n', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}, {'details': 'Security researchers have identified and validated the following workarounds to reduce exposure to the vulnerabilities described in this advisory. These measures do not remediate the underlying vulnerabilities but effectively block known attack vectors until patched software versions are deployed.\n\nImportant: Customers are advised to thoroughly test their systems after applying any of the listed workarounds. B&R has no visibility into customer-specific applications running on the underlying Linux system. It is the customer\'s responsibility to assess whether the applied workarounds interfere with existing application workloads prior to deployment in production environments.\n\nFor Debian-based systems within an active support lifecycle, kernel patches addressing CVE-2026-31431 are already available via the official package repositories. Customers are strongly encouraged to apply these updates immediately by executing the following command:\nsudo apt update && sudo apt upgrade\nA system reboot is required after the upgrade for the updated kernel to take effect.\n\nTemporary Mitigation: If an immediate system update is not feasible, the affected kernel module (algif_aead) can be disabled persistently. Security researchers have confirmed this measure effectively prevents exploitation of CVE-2026-31431.\nExecute the following commands as root:\n\necho "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf\nrmmod algif_aead 2>/dev/null || true\n\nImpact assessment: Disabling the algif_aead module removes the AEAD socket interface from the kernel cryp-to API. This does not affect dm-crypt/LUKS, kTLS, IPsec/XFRM, OpenSSL, GnuTLS, NSS, or SSH. Applications explicitly configured to use the afalg engine or that directly bind aead, skcipher, or hash sockets via AF_ALG may be affected. To assess exposure prior to applying this workaround, run:\n\nlsof | grep AF_ALG', 'category': 'workaround', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}], 'product_status': {'fixed': ['CSAFPID-0003'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}}, {'cve': 'CVE-2026-43284', 'cwe': {'id': 'CWE-123', 'name': 'Write-what-where Condition'}, 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths that may modify packet data can first make a private copy. The IPv4/IPv6 datagram append paths did not set this flag when splicing pages into UDP skbs. That leaves an ESP-in-UDP packet made from shared pipe pages looking like an ordinary uncloned nonlinear skb. ESP input then takes the no-COW fast path for uncloned skbs without a frag_list and decrypts in place over data that is not owned privately by the skb. Mark IPv4/IPv6 datagram splice frags with SKBFL_SHARED_FRAG, matching TCP. Also make ESP input fall back to skb_cow_data() when the flag is present, so ESP does not decrypt external-ly backed frags in place. Private nonlinear skb frags still use the existing fast path. This intentionally does not change ESP output. In esp_output_head(), the path that appends the ESP trailer to existing skb tailroom without calling skb_cow_data() is not reachable for nonlinear skbs: skb_tailroom() returns zero when skb->data_len is nonzero, while ESP tailen is positive. Thus ESP output will either use the separate destination-frag path or fall back to skb_cow_data().', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2026-43284', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.9, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43284', 'summary': 'NVD - CVE-2026-43284', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-43284', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/123.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'For affected products, software updates should be installed upon availability.\n\n Product\t Patch version\n- APROL\t : APROL-AutoYaST-DVD- V4.4-010.10.260602\n\nUntil remediated software versions are available, customers are required to conduct a risk assessment of their affected systems and to implement the mitigation measures and workarounds specified in this advisory.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Successful exploitation of the vulnerabilities described in this advisory requires local access to the affected system with low-privileged user credentials. Customers are strongly advised to enforce strict access control policies on all Linux-based systems, ensuring that interactive access is exclusively granted to authorized and trusted personnel. This includes reviewing and hardening user account permissions and disabling unused accounts.\n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.\n', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}, {'details': 'Security researchers have identified and validated the following workarounds to reduce exposure to the vulnerabilities described in this advisory. These measures do not remediate the underlying vulnerabilities but effectively block known attack vectors until patched software versions are deployed.\n\nImportant: Customers are advised to thoroughly test their systems after applying any of the listed workarounds. B&R has no visibility into customer-specific applications running on the underlying Linux system. It is the customer\'s responsibility to assess whether the applied workarounds interfere with existing application workloads prior to deployment in production environments.\n\nFor Debian-based systems within an active support lifecycle, kernel patches addressing CVE-2026-31431 are already available via the official package repositories. Customers are strongly encouraged to apply these updates immediately by executing the following command:\nsudo apt update && sudo apt upgrade\nA system reboot is required after the upgrade for the updated kernel to take effect.\n\nTemporary Mitigation: If an immediate system update is not feasible, the affected kernel module (algif_aead) can be disabled persistently. Security researchers have confirmed this measure effectively prevents exploitation of CVE-2026-31431.\nExecute the following commands as root:\n\necho "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf\nrmmod algif_aead 2>/dev/null || true\n\nImpact assessment: Disabling the algif_aead module removes the AEAD socket interface from the kernel cryp-to API. This does not affect dm-crypt/LUKS, kTLS, IPsec/XFRM, OpenSSL, GnuTLS, NSS, or SSH. Applications explicitly configured to use the afalg engine or that directly bind aead, skcipher, or hash sockets via AF_ALG may be affected. To assess exposure prior to applying this workaround, run:\n\nlsof | grep AF_ALG', 'category': 'workaround', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}], 'product_status': {'fixed': ['CSAFPID-0003'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}}, {'cve': 'CVE-2026-46333', 'cwe': {'id': 'CWE-269', 'name': 'Improper Privilege Management'}, 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner \'get_dumpable()\' logic The \'dumpability\' of a task is fundamentally about the memory image of the task - the concept comes from whether it can core dump or not - and makes no sense when you don\'t have an associated mm. And almost all users do in fact use it only for the case where the task has a mm pointer. But we have one odd special case: ptrace_may_access() uses \'dumpable\' to check various other things entirely independently of the MM (typically explicitly using flags like PTRACE_MODE_READ_FSCREDS). Including for threads that no longer have a VM (and maybe never did, like most kernel threads). It\'s not what this flag was designed for, but it is what it is. The ptrace code does check that the uid/gid matches, so you do have to be uid-0 to see kernel thread details, but this means that the traditional "drop capabilities" model doesn\'t make any difference for this all. Make it all make a *bit* more sense by saying that if you don\'t have a MM pointer, we\'ll use a cached "last dumpability" flag if the thread ever had a MM (it will be zero for kernel threads since it is never set), and require a proper CAP_SYS_PTRACE capability to override.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2026-46333', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.1, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N', 'temporalScore': 7.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.1, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46333', 'summary': 'NVD - CVE-2026-46333', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-46333', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/269.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'For affected products, software updates should be installed upon availability.\n\n Product\t Patch version\n- APROL\t : APROL-AutoYaST-DVD- V4.4-010.10.260602\n\nUntil remediated software versions are available, customers are required to conduct a risk assessment of their affected systems and to implement the mitigation measures and workarounds specified in this advisory.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Successful exploitation of the vulnerabilities described in this advisory requires local access to the affected system with low-privileged user credentials. Customers are strongly advised to enforce strict access control policies on all Linux-based systems, ensuring that interactive access is exclusively granted to authorized and trusted personnel. This includes reviewing and hardening user account permissions and disabling unused accounts.\n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.\n', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}, {'details': 'Security researchers have identified and validated the following workarounds to reduce exposure to the vulnerabilities described in this advisory. These measures do not remediate the underlying vulnerabilities but effectively block known attack vectors until patched software versions are deployed.\n\nImportant: Customers are advised to thoroughly test their systems after applying any of the listed workarounds. B&R has no visibility into customer-specific applications running on the underlying Linux system. It is the customer\'s responsibility to assess whether the applied workarounds interfere with existing application workloads prior to deployment in production environments.\n\nFor Debian-based systems within an active support lifecycle, kernel patches addressing CVE-2026-31431 are already available via the official package repositories. Customers are strongly encouraged to apply these updates immediately by executing the following command:\nsudo apt update && sudo apt upgrade\nA system reboot is required after the upgrade for the updated kernel to take effect.\n\nTemporary Mitigation: If an immediate system update is not feasible, the affected kernel module (algif_aead) can be disabled persistently. Security researchers have confirmed this measure effectively prevents exploitation of CVE-2026-31431.\nExecute the following commands as root:\n\necho "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf\nrmmod algif_aead 2>/dev/null || true\n\nImpact assessment: Disabling the algif_aead module removes the AEAD socket interface from the kernel cryp-to API. This does not affect dm-crypt/LUKS, kTLS, IPsec/XFRM, OpenSSL, GnuTLS, NSS, or SSH. Applications explicitly configured to use the afalg engine or that directly bind aead, skcipher, or hash sockets via AF_ALG may be affected. To assess exposure prior to applying this workaround, run:\n\nlsof | grep AF_ALG', 'category': 'workaround', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}], 'product_status': {'fixed': ['CSAFPID-0003'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}}, {'cve': 'CVE-2026-46300', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() can attach paged frags from @from to @to. If @from has SKBFL_SHARED_FRAG set, the resulting @to skb can contain the same externally-owned or page-cache-backed frags, but the shared-frag marker is currently lost. That breaks the invariant relied on by later in-place writers. In particular, ESP input checks skb_has_shared_frag() before deciding whether an uncloned nonlinear skb can skip skb_cow_data(). If TCP receive coalescing has moved shared frags into an unmarked skb, ESP can see skb_has_shared_frag() as false and decrypt in place over page-cache backed frags. Propagate SKBFL_SHARED_FRAG when skb_try_coalesce() transfers paged frags. The tailroom copy path does not need the marker because it copies bytes into @to's linear data rather than transferring frag descriptors..", 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2026-46300', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46300', 'summary': 'NVD - CVE-2026-46300 ', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-46300', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'For affected products, software updates should be installed upon availability.\n\n Product\t Patch version\n- APROL\t : APROL-AutoYaST-DVD- V4.4-010.10.260602\n\nUntil remediated software versions are available, customers are required to conduct a risk assessment of their affected systems and to implement the mitigation measures and workarounds specified in this advisory.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Successful exploitation of the vulnerabilities described in this advisory requires local access to the affected system with low-privileged user credentials. Customers are strongly advised to enforce strict access control policies on all Linux-based systems, ensuring that interactive access is exclusively granted to authorized and trusted personnel. This includes reviewing and hardening user account permissions and disabling unused accounts.\n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.\n', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}, {'details': 'Security researchers have identified and validated the following workarounds to reduce exposure to the vulnerabilities described in this advisory. These measures do not remediate the underlying vulnerabilities but effectively block known attack vectors until patched software versions are deployed.\n\nImportant: Customers are advised to thoroughly test their systems after applying any of the listed workarounds. B&R has no visibility into customer-specific applications running on the underlying Linux system. It is the customer\'s responsibility to assess whether the applied workarounds interfere with existing application workloads prior to deployment in production environments.\n\nFor Debian-based systems within an active support lifecycle, kernel patches addressing CVE-2026-31431 are already available via the official package repositories. Customers are strongly encouraged to apply these updates immediately by executing the following command:\nsudo apt update && sudo apt upgrade\nA system reboot is required after the upgrade for the updated kernel to take effect.\n\nTemporary Mitigation: If an immediate system update is not feasible, the affected kernel module (algif_aead) can be disabled persistently. Security researchers have confirmed this measure effectively prevents exploitation of CVE-2026-31431.\nExecute the following commands as root:\n\necho "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf\nrmmod algif_aead 2>/dev/null || true\n\nImpact assessment: Disabling the algif_aead module removes the AEAD socket interface from the kernel cryp-to API. This does not affect dm-crypt/LUKS, kTLS, IPsec/XFRM, OpenSSL, GnuTLS, NSS, or SSH. Applications explicitly configured to use the afalg engine or that directly bind aead, skcipher, or hash sockets via AF_ALG may be affected. To assess exposure prior to applying this workaround, run:\n\nlsof | grep AF_ALG', 'category': 'workaround', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}], 'product_status': {'fixed': ['CSAFPID-0003'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}}, {'cve': 'CVE-2026-43494', 'cwe': {'id': 'CWE-1341', 'name': 'Multiple Releases of Same Resource or Handle'}, 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved: net/rds: reset op_nents when zerocopy page pin fails When iov_iter_get_pages2() fails in rds_message_zcopy_from_user(), the pinned pages are released with put_page(), and rm->data.op_mmp_znotifier is cleared. But we fail to properly clear rm->data.op_nents. Later when rds_message_purge() is called from rds_sendmsg() the cleanup loop iterates over the incorrectly non zero number of op_nents and frees them again. Fix this by properly resetting op_nents when it should be in rds_message_zcopy_from_user().', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2026-43494', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43494', 'summary': 'NVD - CVE-2026-43494', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-43494', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/1341.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'For affected products, software updates should be installed upon availability.\n\n Product\t Patch version\n- APROL\t : APROL-AutoYaST-DVD- V4.4-010.10.260602\n\nUntil remediated software versions are available, customers are required to conduct a risk assessment of their affected systems and to implement the mitigation measures and workarounds specified in this advisory.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Successful exploitation of the vulnerabilities described in this advisory requires local access to the affected system with low-privileged user credentials. Customers are strongly advised to enforce strict access control policies on all Linux-based systems, ensuring that interactive access is exclusively granted to authorized and trusted personnel. This includes reviewing and hardening user account permissions and disabling unused accounts.\n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.\n', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}, {'details': 'Security researchers have identified and validated the following workarounds to reduce exposure to the vulnerabilities described in this advisory. These measures do not remediate the underlying vulnerabilities but effectively block known attack vectors until patched software versions are deployed.\n\nImportant: Customers are advised to thoroughly test their systems after applying any of the listed workarounds. B&R has no visibility into customer-specific applications running on the underlying Linux system. It is the customer\'s responsibility to assess whether the applied workarounds interfere with existing application workloads prior to deployment in production environments.\n\nFor Debian-based systems within an active support lifecycle, kernel patches addressing CVE-2026-31431 are already available via the official package repositories. Customers are strongly encouraged to apply these updates immediately by executing the following command:\nsudo apt update && sudo apt upgrade\nA system reboot is required after the upgrade for the updated kernel to take effect.\n\nTemporary Mitigation: If an immediate system update is not feasible, the affected kernel module (algif_aead) can be disabled persistently. Security researchers have confirmed this measure effectively prevents exploitation of CVE-2026-31431.\nExecute the following commands as root:\n\necho "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf\nrmmod algif_aead 2>/dev/null || true\n\nImpact assessment: Disabling the algif_aead module removes the AEAD socket interface from the kernel cryp-to API. This does not affect dm-crypt/LUKS, kTLS, IPsec/XFRM, OpenSSL, GnuTLS, NSS, or SSH. Applications explicitly configured to use the afalg engine or that directly bind aead, skcipher, or hash sockets via AF_ALG may be affected. To assess exposure prior to applying this workaround, run:\n\nlsof | grep AF_ALG', 'category': 'workaround', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}], 'product_status': {'fixed': ['CSAFPID-0003'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}}]} | |
ot | ICSA-26-174-06 | CVE-2026-46333 | Impact of Linux Kernel vulnerabilities on B&R products | 2026-06-11 03:30:00+03:00 | 2026-06-23 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-06.json | 678474eea136d3df536da6b2ce8f0939208ca17dc1dd76da4b32b618cf82dc7d | 2026-06-24 07:37:39.992137+03:00 | 2026-06-24 07:37:39.992137+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'B&R is aware of publicly reported vulnerabilities affecting the Linux kernel versions shipped with the products listed as affected in the advisory.\n\nSuccessful local exploitation of these vulnerabilities could allow an attacker to escalate privileges on the affected system. Public proof-of-concept exploits are available for the vulnerabilities described herein. At the time of publication of this advisory, B&R had no evidence of active exploitation targeting B&R products.', 'title': 'Summary', 'category': 'summary'}, {'text': 'For additional instructions and support please contact your local B&R service organization. For contact information, see https://www.br-automation.com/en/about-us/locations/.\n\nInformation about ABB’s cyber security program and capabilities can be found at www.abb.com/cybersecurity.\n\n\n', 'title': 'Support', 'category': 'other'}, {'text': 'The information in this document is subject to change without notice, and should not be construed as a commitment by B&R.\n\nB&R provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall B&R or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if B&R or its suppliers have been advised of the possibility of such damages.\n\nThis document and parts hereof must not be reproduced or copied without written permission from B&R, and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose.\n\nAll rights to registrations and trademarks reside with their respective owners.', 'title': 'Notice', 'category': 'legal_disclaimer'}, {'text': 'For any installation of software related ABB products we strongly recommend the following (non-exhaustive) list of cyber security practices:\n\n- Isolate special purpose networks (e.g. for automation systems) and remote devices behind firewalls and separate them from any general purpose network (e.g. office or home networks).\n\n- Install physical controls so no unauthorized personnel can access your devices, components, peripheral equipment, and networks.\n\n- Never connect programming software or computers containing programing software to any network other than the network for the devices that it is intended for.\n\n- Scan all data imported into your environment before use to detect potential malware infections.\n\n- Minimize network exposure for all applications and endpoints to ensure that they are not accessible from the Internet unless they are designed for such exposure and the intended use requires such.\n\n- Ensure all nodes are always up to date in terms of installed software, operating system, and firmware patches as well as anti-virus and firewall.\n\n- When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.\n\nFor more information on recommended practices, please refer to the following documents listed in the reference section:\n\n- Defense in Depth for B&R products\n', 'title': 'General security recommendations', 'category': 'other'}, {'text': 'B&R has a rigorous internal cyber security continuous improvement process which involves regular testing with industry leading tools and periodic assessments to identify potential product issues. Occasionally an issue is determined to be a design or coding flaw with implications that may impact product cyber security.\n\nWhen a potential product vulnerability is identified or reported, B&R immediately initiates our vulnerability handling process. This entails validating if the issue is in fact a product issue, identifying root causes, determining what related products may be impacted, developing a remediation, and notifying end users and governmental organizations.\n\nThe resulting Cyber Security Advisory intends to notify customers of the vulnerability and provide details on which products are impacted, how to mitigate the vulnerability or explain workarounds that minimize the potential risk as much as possible. The release of a Cyber Security Advisory should not be misconstrued as an affirmation or indication of an active threat or ongoing campaign targeting the products mentioned here. If B&R is aware of any specific threats, it will be clearly mentioned in the communication.\n\nThe publication of this Cyber Security Advisory is an example of B&R’s commitment to the user community in support of this critical topic. Responsible disclosure is an important element in the chain of trust we work to maintain with our many customers. The release of an Advisory provides timely information which is essential to help ensure our customers are fully informed.', 'title': 'Purpose', 'category': 'other'}, {'text': 'What causes the vulnerabilities?\n- The vulnerabilities are caused by a vulnerable Linux Kernel component.\n\nWhat might an attacker use the vulnerability to do?\n- An authenticated attacker with low privileges may elevate privileges to root.\n\nCould the vulnerabilities be exploited remotely? \n- Yes, an attacker with privileges to login in a vulnerable system node could exploit these vulnerabilities. Recommended practices include that process control systems are physically protected, have no direct connections to the Internet, and are separated from other networks by means of a firewall system that has a minimal number of ports exposed. \n\nWhen this security advisory was issued, had B&R received any reports that these vulnerabilities were being exploited?\n- B&R is aware of reports indicating that these vulnerabilities had been exploited at the time this security advisory was originally issued; however, no exploitation has been observed in B&R products.', 'title': 'Frequently asked questions', 'category': 'faq'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of ABB PSIRT SA26P010 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact ABB PSIRT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Switzerland', 'title': 'Company headquarters location', 'category': 'other'}], 'title': 'Impact of Linux Kernel vulnerabilities on B&R products', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-174-06', 'status': 'final', 'version': '3', 'generator': {'date': '2026-06-18T13:26:13.151541Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2026-06-11T00:30:00.000000Z', 'number': '1', 'summary': 'Initial version.', 'legacy_version': 'Initial'}, {'date': '2026-06-18T00:30:00.000000Z', 'number': '2', 'summary': 'Updating the CWE classification for CVE-2026-43494.', 'legacy_version': 'Additional Release 1'}, {'date': '2026-06-23T06:00:00.000000Z', 'number': '3', 'summary': 'Initial CISA Republication of ABB PSIRT SA26P010 advisory', 'legacy_version': 'CISA Republication'}], 'current_release_date': '2026-06-23T06:00:00.000000Z', 'initial_release_date': '2026-06-11T00:30:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://psirt.abb.com/csaf/2026/sa26p010.json', 'summary': 'B&R CYBERSECURITY ADVISORY - CSAF Version ', 'category': 'self'}, {'url': 'https://br-cws-assets.de-fra-1.linodeobjects.com/SA26P010-0ea64434.pdf', 'summary': 'B&R CYBERSECURITY ADVISORY - PDF Version ', 'category': 'self'}, {'url': 'https://www.br-automation.com/fileadmin/Cyber_Security_-_Defense_in_Depth_for_BR_Products-bdd37e82.pdf', 'summary': 'Defense in Depth for B&R products'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-06.json', 'summary': 'ICS Advisory ICSA-26-174-06 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-06', 'summary': 'ICS Advisory ICSA-26-174-06 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to CISA.', 'organization': 'ABB PSIRT'}]}, 'product_tree': {'branches': [{'name': 'B&R Industrial Automation GmbH', 'branches': [{'name': 'Linux for B&R', 'branches': [{'name': '<=12', 'product': {'name': 'B&R Industrial Automation GmbH Linux for B&R <=12', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'APROL', 'branches': [{'name': '<APROL-AutoYaST-DVD-_V4.4-010.10.260602', 'product': {'name': 'B&R Industrial Automation GmbH APROL <APROL-AutoYaST-DVD- V4.4-010.10.260602', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}, {'name': 'APROL-AutoYaST-DVD-_V4.4-010.10.260602', 'product': {'name': 'B&R Industrial Automation GmbH APROL APROL-AutoYaST-DVD- V4.4-010.10.260602', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'X20EDS410', 'branches': [{'name': '/all', 'product': {'name': 'B&R Industrial Automation GmbH X20EDS410 /all', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-31431', 'cwe': {'id': 'CWE-669', 'name': 'Incorrect Resource Transfer Between Spheres'}, 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2026-31431', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:H/RC:C', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'reportConfidence': 'CONFIRMED', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'LOW', 'exploitCodeMaturity': 'HIGH', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31431', 'summary': 'NVD - CVE-2026-31431', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-31431', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/669.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:H/RC:C', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'For affected products, software updates should be installed upon availability.\n\n Product\t Patch version\n- APROL\t : APROL-AutoYaST-DVD- V4.4-010.10.260602\n\nUntil remediated software versions are available, customers are required to conduct a risk assessment of their affected systems and to implement the mitigation measures and workarounds specified in this advisory.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Successful exploitation of the vulnerabilities described in this advisory requires local access to the affected system with low-privileged user credentials. Customers are strongly advised to enforce strict access control policies on all Linux-based systems, ensuring that interactive access is exclusively granted to authorized and trusted personnel. This includes reviewing and hardening user account permissions and disabling unused accounts.\n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.\n', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}, {'details': 'Security researchers have identified and validated the following workarounds to reduce exposure to the vulnerabilities described in this advisory. These measures do not remediate the underlying vulnerabilities but effectively block known attack vectors until patched software versions are deployed.\n\nImportant: Customers are advised to thoroughly test their systems after applying any of the listed workarounds. B&R has no visibility into customer-specific applications running on the underlying Linux system. It is the customer\'s responsibility to assess whether the applied workarounds interfere with existing application workloads prior to deployment in production environments.\n\nFor Debian-based systems within an active support lifecycle, kernel patches addressing CVE-2026-31431 are already available via the official package repositories. Customers are strongly encouraged to apply these updates immediately by executing the following command:\nsudo apt update && sudo apt upgrade\nA system reboot is required after the upgrade for the updated kernel to take effect.\n\nTemporary Mitigation: If an immediate system update is not feasible, the affected kernel module (algif_aead) can be disabled persistently. Security researchers have confirmed this measure effectively prevents exploitation of CVE-2026-31431.\nExecute the following commands as root:\n\necho "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf\nrmmod algif_aead 2>/dev/null || true\n\nImpact assessment: Disabling the algif_aead module removes the AEAD socket interface from the kernel cryp-to API. This does not affect dm-crypt/LUKS, kTLS, IPsec/XFRM, OpenSSL, GnuTLS, NSS, or SSH. Applications explicitly configured to use the afalg engine or that directly bind aead, skcipher, or hash sockets via AF_ALG may be affected. To assess exposure prior to applying this workaround, run:\n\nlsof | grep AF_ALG', 'category': 'workaround', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}], 'product_status': {'fixed': ['CSAFPID-0003'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}}, {'cve': 'CVE-2026-43284', 'cwe': {'id': 'CWE-123', 'name': 'Write-what-where Condition'}, 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths that may modify packet data can first make a private copy. The IPv4/IPv6 datagram append paths did not set this flag when splicing pages into UDP skbs. That leaves an ESP-in-UDP packet made from shared pipe pages looking like an ordinary uncloned nonlinear skb. ESP input then takes the no-COW fast path for uncloned skbs without a frag_list and decrypts in place over data that is not owned privately by the skb. Mark IPv4/IPv6 datagram splice frags with SKBFL_SHARED_FRAG, matching TCP. Also make ESP input fall back to skb_cow_data() when the flag is present, so ESP does not decrypt external-ly backed frags in place. Private nonlinear skb frags still use the existing fast path. This intentionally does not change ESP output. In esp_output_head(), the path that appends the ESP trailer to existing skb tailroom without calling skb_cow_data() is not reachable for nonlinear skbs: skb_tailroom() returns zero when skb->data_len is nonzero, while ESP tailen is positive. Thus ESP output will either use the separate destination-frag path or fall back to skb_cow_data().', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2026-43284', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.9, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43284', 'summary': 'NVD - CVE-2026-43284', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-43284', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/123.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'For affected products, software updates should be installed upon availability.\n\n Product\t Patch version\n- APROL\t : APROL-AutoYaST-DVD- V4.4-010.10.260602\n\nUntil remediated software versions are available, customers are required to conduct a risk assessment of their affected systems and to implement the mitigation measures and workarounds specified in this advisory.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Successful exploitation of the vulnerabilities described in this advisory requires local access to the affected system with low-privileged user credentials. Customers are strongly advised to enforce strict access control policies on all Linux-based systems, ensuring that interactive access is exclusively granted to authorized and trusted personnel. This includes reviewing and hardening user account permissions and disabling unused accounts.\n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.\n', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}, {'details': 'Security researchers have identified and validated the following workarounds to reduce exposure to the vulnerabilities described in this advisory. These measures do not remediate the underlying vulnerabilities but effectively block known attack vectors until patched software versions are deployed.\n\nImportant: Customers are advised to thoroughly test their systems after applying any of the listed workarounds. B&R has no visibility into customer-specific applications running on the underlying Linux system. It is the customer\'s responsibility to assess whether the applied workarounds interfere with existing application workloads prior to deployment in production environments.\n\nFor Debian-based systems within an active support lifecycle, kernel patches addressing CVE-2026-31431 are already available via the official package repositories. Customers are strongly encouraged to apply these updates immediately by executing the following command:\nsudo apt update && sudo apt upgrade\nA system reboot is required after the upgrade for the updated kernel to take effect.\n\nTemporary Mitigation: If an immediate system update is not feasible, the affected kernel module (algif_aead) can be disabled persistently. Security researchers have confirmed this measure effectively prevents exploitation of CVE-2026-31431.\nExecute the following commands as root:\n\necho "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf\nrmmod algif_aead 2>/dev/null || true\n\nImpact assessment: Disabling the algif_aead module removes the AEAD socket interface from the kernel cryp-to API. This does not affect dm-crypt/LUKS, kTLS, IPsec/XFRM, OpenSSL, GnuTLS, NSS, or SSH. Applications explicitly configured to use the afalg engine or that directly bind aead, skcipher, or hash sockets via AF_ALG may be affected. To assess exposure prior to applying this workaround, run:\n\nlsof | grep AF_ALG', 'category': 'workaround', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}], 'product_status': {'fixed': ['CSAFPID-0003'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}}, {'cve': 'CVE-2026-46333', 'cwe': {'id': 'CWE-269', 'name': 'Improper Privilege Management'}, 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner \'get_dumpable()\' logic The \'dumpability\' of a task is fundamentally about the memory image of the task - the concept comes from whether it can core dump or not - and makes no sense when you don\'t have an associated mm. And almost all users do in fact use it only for the case where the task has a mm pointer. But we have one odd special case: ptrace_may_access() uses \'dumpable\' to check various other things entirely independently of the MM (typically explicitly using flags like PTRACE_MODE_READ_FSCREDS). Including for threads that no longer have a VM (and maybe never did, like most kernel threads). It\'s not what this flag was designed for, but it is what it is. The ptrace code does check that the uid/gid matches, so you do have to be uid-0 to see kernel thread details, but this means that the traditional "drop capabilities" model doesn\'t make any difference for this all. Make it all make a *bit* more sense by saying that if you don\'t have a MM pointer, we\'ll use a cached "last dumpability" flag if the thread ever had a MM (it will be zero for kernel threads since it is never set), and require a proper CAP_SYS_PTRACE capability to override.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2026-46333', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.1, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N', 'temporalScore': 7.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.1, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46333', 'summary': 'NVD - CVE-2026-46333', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-46333', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/269.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'For affected products, software updates should be installed upon availability.\n\n Product\t Patch version\n- APROL\t : APROL-AutoYaST-DVD- V4.4-010.10.260602\n\nUntil remediated software versions are available, customers are required to conduct a risk assessment of their affected systems and to implement the mitigation measures and workarounds specified in this advisory.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Successful exploitation of the vulnerabilities described in this advisory requires local access to the affected system with low-privileged user credentials. Customers are strongly advised to enforce strict access control policies on all Linux-based systems, ensuring that interactive access is exclusively granted to authorized and trusted personnel. This includes reviewing and hardening user account permissions and disabling unused accounts.\n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.\n', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}, {'details': 'Security researchers have identified and validated the following workarounds to reduce exposure to the vulnerabilities described in this advisory. These measures do not remediate the underlying vulnerabilities but effectively block known attack vectors until patched software versions are deployed.\n\nImportant: Customers are advised to thoroughly test their systems after applying any of the listed workarounds. B&R has no visibility into customer-specific applications running on the underlying Linux system. It is the customer\'s responsibility to assess whether the applied workarounds interfere with existing application workloads prior to deployment in production environments.\n\nFor Debian-based systems within an active support lifecycle, kernel patches addressing CVE-2026-31431 are already available via the official package repositories. Customers are strongly encouraged to apply these updates immediately by executing the following command:\nsudo apt update && sudo apt upgrade\nA system reboot is required after the upgrade for the updated kernel to take effect.\n\nTemporary Mitigation: If an immediate system update is not feasible, the affected kernel module (algif_aead) can be disabled persistently. Security researchers have confirmed this measure effectively prevents exploitation of CVE-2026-31431.\nExecute the following commands as root:\n\necho "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf\nrmmod algif_aead 2>/dev/null || true\n\nImpact assessment: Disabling the algif_aead module removes the AEAD socket interface from the kernel cryp-to API. This does not affect dm-crypt/LUKS, kTLS, IPsec/XFRM, OpenSSL, GnuTLS, NSS, or SSH. Applications explicitly configured to use the afalg engine or that directly bind aead, skcipher, or hash sockets via AF_ALG may be affected. To assess exposure prior to applying this workaround, run:\n\nlsof | grep AF_ALG', 'category': 'workaround', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}], 'product_status': {'fixed': ['CSAFPID-0003'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}}, {'cve': 'CVE-2026-46300', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() can attach paged frags from @from to @to. If @from has SKBFL_SHARED_FRAG set, the resulting @to skb can contain the same externally-owned or page-cache-backed frags, but the shared-frag marker is currently lost. That breaks the invariant relied on by later in-place writers. In particular, ESP input checks skb_has_shared_frag() before deciding whether an uncloned nonlinear skb can skip skb_cow_data(). If TCP receive coalescing has moved shared frags into an unmarked skb, ESP can see skb_has_shared_frag() as false and decrypt in place over page-cache backed frags. Propagate SKBFL_SHARED_FRAG when skb_try_coalesce() transfers paged frags. The tailroom copy path does not need the marker because it copies bytes into @to's linear data rather than transferring frag descriptors..", 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2026-46300', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46300', 'summary': 'NVD - CVE-2026-46300 ', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-46300', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'For affected products, software updates should be installed upon availability.\n\n Product\t Patch version\n- APROL\t : APROL-AutoYaST-DVD- V4.4-010.10.260602\n\nUntil remediated software versions are available, customers are required to conduct a risk assessment of their affected systems and to implement the mitigation measures and workarounds specified in this advisory.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Successful exploitation of the vulnerabilities described in this advisory requires local access to the affected system with low-privileged user credentials. Customers are strongly advised to enforce strict access control policies on all Linux-based systems, ensuring that interactive access is exclusively granted to authorized and trusted personnel. This includes reviewing and hardening user account permissions and disabling unused accounts.\n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.\n', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}, {'details': 'Security researchers have identified and validated the following workarounds to reduce exposure to the vulnerabilities described in this advisory. These measures do not remediate the underlying vulnerabilities but effectively block known attack vectors until patched software versions are deployed.\n\nImportant: Customers are advised to thoroughly test their systems after applying any of the listed workarounds. B&R has no visibility into customer-specific applications running on the underlying Linux system. It is the customer\'s responsibility to assess whether the applied workarounds interfere with existing application workloads prior to deployment in production environments.\n\nFor Debian-based systems within an active support lifecycle, kernel patches addressing CVE-2026-31431 are already available via the official package repositories. Customers are strongly encouraged to apply these updates immediately by executing the following command:\nsudo apt update && sudo apt upgrade\nA system reboot is required after the upgrade for the updated kernel to take effect.\n\nTemporary Mitigation: If an immediate system update is not feasible, the affected kernel module (algif_aead) can be disabled persistently. Security researchers have confirmed this measure effectively prevents exploitation of CVE-2026-31431.\nExecute the following commands as root:\n\necho "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf\nrmmod algif_aead 2>/dev/null || true\n\nImpact assessment: Disabling the algif_aead module removes the AEAD socket interface from the kernel cryp-to API. This does not affect dm-crypt/LUKS, kTLS, IPsec/XFRM, OpenSSL, GnuTLS, NSS, or SSH. Applications explicitly configured to use the afalg engine or that directly bind aead, skcipher, or hash sockets via AF_ALG may be affected. To assess exposure prior to applying this workaround, run:\n\nlsof | grep AF_ALG', 'category': 'workaround', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}], 'product_status': {'fixed': ['CSAFPID-0003'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}}, {'cve': 'CVE-2026-43494', 'cwe': {'id': 'CWE-1341', 'name': 'Multiple Releases of Same Resource or Handle'}, 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved: net/rds: reset op_nents when zerocopy page pin fails When iov_iter_get_pages2() fails in rds_message_zcopy_from_user(), the pinned pages are released with put_page(), and rm->data.op_mmp_znotifier is cleared. But we fail to properly clear rm->data.op_nents. Later when rds_message_purge() is called from rds_sendmsg() the cleanup loop iterates over the incorrectly non zero number of op_nents and frees them again. Fix this by properly resetting op_nents when it should be in rds_message_zcopy_from_user().', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2026-43494', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43494', 'summary': 'NVD - CVE-2026-43494', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-43494', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/1341.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'For affected products, software updates should be installed upon availability.\n\n Product\t Patch version\n- APROL\t : APROL-AutoYaST-DVD- V4.4-010.10.260602\n\nUntil remediated software versions are available, customers are required to conduct a risk assessment of their affected systems and to implement the mitigation measures and workarounds specified in this advisory.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Successful exploitation of the vulnerabilities described in this advisory requires local access to the affected system with low-privileged user credentials. Customers are strongly advised to enforce strict access control policies on all Linux-based systems, ensuring that interactive access is exclusively granted to authorized and trusted personnel. This includes reviewing and hardening user account permissions and disabling unused accounts.\n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.\n', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}, {'details': 'Security researchers have identified and validated the following workarounds to reduce exposure to the vulnerabilities described in this advisory. These measures do not remediate the underlying vulnerabilities but effectively block known attack vectors until patched software versions are deployed.\n\nImportant: Customers are advised to thoroughly test their systems after applying any of the listed workarounds. B&R has no visibility into customer-specific applications running on the underlying Linux system. It is the customer\'s responsibility to assess whether the applied workarounds interfere with existing application workloads prior to deployment in production environments.\n\nFor Debian-based systems within an active support lifecycle, kernel patches addressing CVE-2026-31431 are already available via the official package repositories. Customers are strongly encouraged to apply these updates immediately by executing the following command:\nsudo apt update && sudo apt upgrade\nA system reboot is required after the upgrade for the updated kernel to take effect.\n\nTemporary Mitigation: If an immediate system update is not feasible, the affected kernel module (algif_aead) can be disabled persistently. Security researchers have confirmed this measure effectively prevents exploitation of CVE-2026-31431.\nExecute the following commands as root:\n\necho "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf\nrmmod algif_aead 2>/dev/null || true\n\nImpact assessment: Disabling the algif_aead module removes the AEAD socket interface from the kernel cryp-to API. This does not affect dm-crypt/LUKS, kTLS, IPsec/XFRM, OpenSSL, GnuTLS, NSS, or SSH. Applications explicitly configured to use the afalg engine or that directly bind aead, skcipher, or hash sockets via AF_ALG may be affected. To assess exposure prior to applying this workaround, run:\n\nlsof | grep AF_ALG', 'category': 'workaround', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}], 'product_status': {'fixed': ['CSAFPID-0003'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}}]} | |
ot | ICSA-26-174-06 | CVE-2026-46300 | Impact of Linux Kernel vulnerabilities on B&R products | 2026-06-11 03:30:00+03:00 | 2026-06-23 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-06.json | 5c20fb10ed4e4f1d697114896ac65bf050103bcc91817c483e29255a58e6cff5 | 2026-06-24 07:37:39.992137+03:00 | 2026-06-24 07:37:39.992137+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'B&R is aware of publicly reported vulnerabilities affecting the Linux kernel versions shipped with the products listed as affected in the advisory.\n\nSuccessful local exploitation of these vulnerabilities could allow an attacker to escalate privileges on the affected system. Public proof-of-concept exploits are available for the vulnerabilities described herein. At the time of publication of this advisory, B&R had no evidence of active exploitation targeting B&R products.', 'title': 'Summary', 'category': 'summary'}, {'text': 'For additional instructions and support please contact your local B&R service organization. For contact information, see https://www.br-automation.com/en/about-us/locations/.\n\nInformation about ABB’s cyber security program and capabilities can be found at www.abb.com/cybersecurity.\n\n\n', 'title': 'Support', 'category': 'other'}, {'text': 'The information in this document is subject to change without notice, and should not be construed as a commitment by B&R.\n\nB&R provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall B&R or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if B&R or its suppliers have been advised of the possibility of such damages.\n\nThis document and parts hereof must not be reproduced or copied without written permission from B&R, and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose.\n\nAll rights to registrations and trademarks reside with their respective owners.', 'title': 'Notice', 'category': 'legal_disclaimer'}, {'text': 'For any installation of software related ABB products we strongly recommend the following (non-exhaustive) list of cyber security practices:\n\n- Isolate special purpose networks (e.g. for automation systems) and remote devices behind firewalls and separate them from any general purpose network (e.g. office or home networks).\n\n- Install physical controls so no unauthorized personnel can access your devices, components, peripheral equipment, and networks.\n\n- Never connect programming software or computers containing programing software to any network other than the network for the devices that it is intended for.\n\n- Scan all data imported into your environment before use to detect potential malware infections.\n\n- Minimize network exposure for all applications and endpoints to ensure that they are not accessible from the Internet unless they are designed for such exposure and the intended use requires such.\n\n- Ensure all nodes are always up to date in terms of installed software, operating system, and firmware patches as well as anti-virus and firewall.\n\n- When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.\n\nFor more information on recommended practices, please refer to the following documents listed in the reference section:\n\n- Defense in Depth for B&R products\n', 'title': 'General security recommendations', 'category': 'other'}, {'text': 'B&R has a rigorous internal cyber security continuous improvement process which involves regular testing with industry leading tools and periodic assessments to identify potential product issues. Occasionally an issue is determined to be a design or coding flaw with implications that may impact product cyber security.\n\nWhen a potential product vulnerability is identified or reported, B&R immediately initiates our vulnerability handling process. This entails validating if the issue is in fact a product issue, identifying root causes, determining what related products may be impacted, developing a remediation, and notifying end users and governmental organizations.\n\nThe resulting Cyber Security Advisory intends to notify customers of the vulnerability and provide details on which products are impacted, how to mitigate the vulnerability or explain workarounds that minimize the potential risk as much as possible. The release of a Cyber Security Advisory should not be misconstrued as an affirmation or indication of an active threat or ongoing campaign targeting the products mentioned here. If B&R is aware of any specific threats, it will be clearly mentioned in the communication.\n\nThe publication of this Cyber Security Advisory is an example of B&R’s commitment to the user community in support of this critical topic. Responsible disclosure is an important element in the chain of trust we work to maintain with our many customers. The release of an Advisory provides timely information which is essential to help ensure our customers are fully informed.', 'title': 'Purpose', 'category': 'other'}, {'text': 'What causes the vulnerabilities?\n- The vulnerabilities are caused by a vulnerable Linux Kernel component.\n\nWhat might an attacker use the vulnerability to do?\n- An authenticated attacker with low privileges may elevate privileges to root.\n\nCould the vulnerabilities be exploited remotely? \n- Yes, an attacker with privileges to login in a vulnerable system node could exploit these vulnerabilities. Recommended practices include that process control systems are physically protected, have no direct connections to the Internet, and are separated from other networks by means of a firewall system that has a minimal number of ports exposed. \n\nWhen this security advisory was issued, had B&R received any reports that these vulnerabilities were being exploited?\n- B&R is aware of reports indicating that these vulnerabilities had been exploited at the time this security advisory was originally issued; however, no exploitation has been observed in B&R products.', 'title': 'Frequently asked questions', 'category': 'faq'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of ABB PSIRT SA26P010 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact ABB PSIRT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Switzerland', 'title': 'Company headquarters location', 'category': 'other'}], 'title': 'Impact of Linux Kernel vulnerabilities on B&R products', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-174-06', 'status': 'final', 'version': '3', 'generator': {'date': '2026-06-18T13:26:13.151541Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2026-06-11T00:30:00.000000Z', 'number': '1', 'summary': 'Initial version.', 'legacy_version': 'Initial'}, {'date': '2026-06-18T00:30:00.000000Z', 'number': '2', 'summary': 'Updating the CWE classification for CVE-2026-43494.', 'legacy_version': 'Additional Release 1'}, {'date': '2026-06-23T06:00:00.000000Z', 'number': '3', 'summary': 'Initial CISA Republication of ABB PSIRT SA26P010 advisory', 'legacy_version': 'CISA Republication'}], 'current_release_date': '2026-06-23T06:00:00.000000Z', 'initial_release_date': '2026-06-11T00:30:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://psirt.abb.com/csaf/2026/sa26p010.json', 'summary': 'B&R CYBERSECURITY ADVISORY - CSAF Version ', 'category': 'self'}, {'url': 'https://br-cws-assets.de-fra-1.linodeobjects.com/SA26P010-0ea64434.pdf', 'summary': 'B&R CYBERSECURITY ADVISORY - PDF Version ', 'category': 'self'}, {'url': 'https://www.br-automation.com/fileadmin/Cyber_Security_-_Defense_in_Depth_for_BR_Products-bdd37e82.pdf', 'summary': 'Defense in Depth for B&R products'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-06.json', 'summary': 'ICS Advisory ICSA-26-174-06 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-06', 'summary': 'ICS Advisory ICSA-26-174-06 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to CISA.', 'organization': 'ABB PSIRT'}]}, 'product_tree': {'branches': [{'name': 'B&R Industrial Automation GmbH', 'branches': [{'name': 'Linux for B&R', 'branches': [{'name': '<=12', 'product': {'name': 'B&R Industrial Automation GmbH Linux for B&R <=12', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'APROL', 'branches': [{'name': '<APROL-AutoYaST-DVD-_V4.4-010.10.260602', 'product': {'name': 'B&R Industrial Automation GmbH APROL <APROL-AutoYaST-DVD- V4.4-010.10.260602', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}, {'name': 'APROL-AutoYaST-DVD-_V4.4-010.10.260602', 'product': {'name': 'B&R Industrial Automation GmbH APROL APROL-AutoYaST-DVD- V4.4-010.10.260602', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'X20EDS410', 'branches': [{'name': '/all', 'product': {'name': 'B&R Industrial Automation GmbH X20EDS410 /all', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-31431', 'cwe': {'id': 'CWE-669', 'name': 'Incorrect Resource Transfer Between Spheres'}, 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2026-31431', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:H/RC:C', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'reportConfidence': 'CONFIRMED', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'LOW', 'exploitCodeMaturity': 'HIGH', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31431', 'summary': 'NVD - CVE-2026-31431', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-31431', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/669.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:H/RC:C', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'For affected products, software updates should be installed upon availability.\n\n Product\t Patch version\n- APROL\t : APROL-AutoYaST-DVD- V4.4-010.10.260602\n\nUntil remediated software versions are available, customers are required to conduct a risk assessment of their affected systems and to implement the mitigation measures and workarounds specified in this advisory.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Successful exploitation of the vulnerabilities described in this advisory requires local access to the affected system with low-privileged user credentials. Customers are strongly advised to enforce strict access control policies on all Linux-based systems, ensuring that interactive access is exclusively granted to authorized and trusted personnel. This includes reviewing and hardening user account permissions and disabling unused accounts.\n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.\n', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}, {'details': 'Security researchers have identified and validated the following workarounds to reduce exposure to the vulnerabilities described in this advisory. These measures do not remediate the underlying vulnerabilities but effectively block known attack vectors until patched software versions are deployed.\n\nImportant: Customers are advised to thoroughly test their systems after applying any of the listed workarounds. B&R has no visibility into customer-specific applications running on the underlying Linux system. It is the customer\'s responsibility to assess whether the applied workarounds interfere with existing application workloads prior to deployment in production environments.\n\nFor Debian-based systems within an active support lifecycle, kernel patches addressing CVE-2026-31431 are already available via the official package repositories. Customers are strongly encouraged to apply these updates immediately by executing the following command:\nsudo apt update && sudo apt upgrade\nA system reboot is required after the upgrade for the updated kernel to take effect.\n\nTemporary Mitigation: If an immediate system update is not feasible, the affected kernel module (algif_aead) can be disabled persistently. Security researchers have confirmed this measure effectively prevents exploitation of CVE-2026-31431.\nExecute the following commands as root:\n\necho "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf\nrmmod algif_aead 2>/dev/null || true\n\nImpact assessment: Disabling the algif_aead module removes the AEAD socket interface from the kernel cryp-to API. This does not affect dm-crypt/LUKS, kTLS, IPsec/XFRM, OpenSSL, GnuTLS, NSS, or SSH. Applications explicitly configured to use the afalg engine or that directly bind aead, skcipher, or hash sockets via AF_ALG may be affected. To assess exposure prior to applying this workaround, run:\n\nlsof | grep AF_ALG', 'category': 'workaround', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}], 'product_status': {'fixed': ['CSAFPID-0003'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}}, {'cve': 'CVE-2026-43284', 'cwe': {'id': 'CWE-123', 'name': 'Write-what-where Condition'}, 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths that may modify packet data can first make a private copy. The IPv4/IPv6 datagram append paths did not set this flag when splicing pages into UDP skbs. That leaves an ESP-in-UDP packet made from shared pipe pages looking like an ordinary uncloned nonlinear skb. ESP input then takes the no-COW fast path for uncloned skbs without a frag_list and decrypts in place over data that is not owned privately by the skb. Mark IPv4/IPv6 datagram splice frags with SKBFL_SHARED_FRAG, matching TCP. Also make ESP input fall back to skb_cow_data() when the flag is present, so ESP does not decrypt external-ly backed frags in place. Private nonlinear skb frags still use the existing fast path. This intentionally does not change ESP output. In esp_output_head(), the path that appends the ESP trailer to existing skb tailroom without calling skb_cow_data() is not reachable for nonlinear skbs: skb_tailroom() returns zero when skb->data_len is nonzero, while ESP tailen is positive. Thus ESP output will either use the separate destination-frag path or fall back to skb_cow_data().', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2026-43284', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.9, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43284', 'summary': 'NVD - CVE-2026-43284', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-43284', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/123.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'For affected products, software updates should be installed upon availability.\n\n Product\t Patch version\n- APROL\t : APROL-AutoYaST-DVD- V4.4-010.10.260602\n\nUntil remediated software versions are available, customers are required to conduct a risk assessment of their affected systems and to implement the mitigation measures and workarounds specified in this advisory.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Successful exploitation of the vulnerabilities described in this advisory requires local access to the affected system with low-privileged user credentials. Customers are strongly advised to enforce strict access control policies on all Linux-based systems, ensuring that interactive access is exclusively granted to authorized and trusted personnel. This includes reviewing and hardening user account permissions and disabling unused accounts.\n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.\n', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}, {'details': 'Security researchers have identified and validated the following workarounds to reduce exposure to the vulnerabilities described in this advisory. These measures do not remediate the underlying vulnerabilities but effectively block known attack vectors until patched software versions are deployed.\n\nImportant: Customers are advised to thoroughly test their systems after applying any of the listed workarounds. B&R has no visibility into customer-specific applications running on the underlying Linux system. It is the customer\'s responsibility to assess whether the applied workarounds interfere with existing application workloads prior to deployment in production environments.\n\nFor Debian-based systems within an active support lifecycle, kernel patches addressing CVE-2026-31431 are already available via the official package repositories. Customers are strongly encouraged to apply these updates immediately by executing the following command:\nsudo apt update && sudo apt upgrade\nA system reboot is required after the upgrade for the updated kernel to take effect.\n\nTemporary Mitigation: If an immediate system update is not feasible, the affected kernel module (algif_aead) can be disabled persistently. Security researchers have confirmed this measure effectively prevents exploitation of CVE-2026-31431.\nExecute the following commands as root:\n\necho "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf\nrmmod algif_aead 2>/dev/null || true\n\nImpact assessment: Disabling the algif_aead module removes the AEAD socket interface from the kernel cryp-to API. This does not affect dm-crypt/LUKS, kTLS, IPsec/XFRM, OpenSSL, GnuTLS, NSS, or SSH. Applications explicitly configured to use the afalg engine or that directly bind aead, skcipher, or hash sockets via AF_ALG may be affected. To assess exposure prior to applying this workaround, run:\n\nlsof | grep AF_ALG', 'category': 'workaround', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}], 'product_status': {'fixed': ['CSAFPID-0003'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}}, {'cve': 'CVE-2026-46333', 'cwe': {'id': 'CWE-269', 'name': 'Improper Privilege Management'}, 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner \'get_dumpable()\' logic The \'dumpability\' of a task is fundamentally about the memory image of the task - the concept comes from whether it can core dump or not - and makes no sense when you don\'t have an associated mm. And almost all users do in fact use it only for the case where the task has a mm pointer. But we have one odd special case: ptrace_may_access() uses \'dumpable\' to check various other things entirely independently of the MM (typically explicitly using flags like PTRACE_MODE_READ_FSCREDS). Including for threads that no longer have a VM (and maybe never did, like most kernel threads). It\'s not what this flag was designed for, but it is what it is. The ptrace code does check that the uid/gid matches, so you do have to be uid-0 to see kernel thread details, but this means that the traditional "drop capabilities" model doesn\'t make any difference for this all. Make it all make a *bit* more sense by saying that if you don\'t have a MM pointer, we\'ll use a cached "last dumpability" flag if the thread ever had a MM (it will be zero for kernel threads since it is never set), and require a proper CAP_SYS_PTRACE capability to override.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2026-46333', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.1, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N', 'temporalScore': 7.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.1, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46333', 'summary': 'NVD - CVE-2026-46333', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-46333', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/269.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'For affected products, software updates should be installed upon availability.\n\n Product\t Patch version\n- APROL\t : APROL-AutoYaST-DVD- V4.4-010.10.260602\n\nUntil remediated software versions are available, customers are required to conduct a risk assessment of their affected systems and to implement the mitigation measures and workarounds specified in this advisory.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Successful exploitation of the vulnerabilities described in this advisory requires local access to the affected system with low-privileged user credentials. Customers are strongly advised to enforce strict access control policies on all Linux-based systems, ensuring that interactive access is exclusively granted to authorized and trusted personnel. This includes reviewing and hardening user account permissions and disabling unused accounts.\n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.\n', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}, {'details': 'Security researchers have identified and validated the following workarounds to reduce exposure to the vulnerabilities described in this advisory. These measures do not remediate the underlying vulnerabilities but effectively block known attack vectors until patched software versions are deployed.\n\nImportant: Customers are advised to thoroughly test their systems after applying any of the listed workarounds. B&R has no visibility into customer-specific applications running on the underlying Linux system. It is the customer\'s responsibility to assess whether the applied workarounds interfere with existing application workloads prior to deployment in production environments.\n\nFor Debian-based systems within an active support lifecycle, kernel patches addressing CVE-2026-31431 are already available via the official package repositories. Customers are strongly encouraged to apply these updates immediately by executing the following command:\nsudo apt update && sudo apt upgrade\nA system reboot is required after the upgrade for the updated kernel to take effect.\n\nTemporary Mitigation: If an immediate system update is not feasible, the affected kernel module (algif_aead) can be disabled persistently. Security researchers have confirmed this measure effectively prevents exploitation of CVE-2026-31431.\nExecute the following commands as root:\n\necho "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf\nrmmod algif_aead 2>/dev/null || true\n\nImpact assessment: Disabling the algif_aead module removes the AEAD socket interface from the kernel cryp-to API. This does not affect dm-crypt/LUKS, kTLS, IPsec/XFRM, OpenSSL, GnuTLS, NSS, or SSH. Applications explicitly configured to use the afalg engine or that directly bind aead, skcipher, or hash sockets via AF_ALG may be affected. To assess exposure prior to applying this workaround, run:\n\nlsof | grep AF_ALG', 'category': 'workaround', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}], 'product_status': {'fixed': ['CSAFPID-0003'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}}, {'cve': 'CVE-2026-46300', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() can attach paged frags from @from to @to. If @from has SKBFL_SHARED_FRAG set, the resulting @to skb can contain the same externally-owned or page-cache-backed frags, but the shared-frag marker is currently lost. That breaks the invariant relied on by later in-place writers. In particular, ESP input checks skb_has_shared_frag() before deciding whether an uncloned nonlinear skb can skip skb_cow_data(). If TCP receive coalescing has moved shared frags into an unmarked skb, ESP can see skb_has_shared_frag() as false and decrypt in place over page-cache backed frags. Propagate SKBFL_SHARED_FRAG when skb_try_coalesce() transfers paged frags. The tailroom copy path does not need the marker because it copies bytes into @to's linear data rather than transferring frag descriptors..", 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2026-46300', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46300', 'summary': 'NVD - CVE-2026-46300 ', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-46300', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'For affected products, software updates should be installed upon availability.\n\n Product\t Patch version\n- APROL\t : APROL-AutoYaST-DVD- V4.4-010.10.260602\n\nUntil remediated software versions are available, customers are required to conduct a risk assessment of their affected systems and to implement the mitigation measures and workarounds specified in this advisory.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Successful exploitation of the vulnerabilities described in this advisory requires local access to the affected system with low-privileged user credentials. Customers are strongly advised to enforce strict access control policies on all Linux-based systems, ensuring that interactive access is exclusively granted to authorized and trusted personnel. This includes reviewing and hardening user account permissions and disabling unused accounts.\n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.\n', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}, {'details': 'Security researchers have identified and validated the following workarounds to reduce exposure to the vulnerabilities described in this advisory. These measures do not remediate the underlying vulnerabilities but effectively block known attack vectors until patched software versions are deployed.\n\nImportant: Customers are advised to thoroughly test their systems after applying any of the listed workarounds. B&R has no visibility into customer-specific applications running on the underlying Linux system. It is the customer\'s responsibility to assess whether the applied workarounds interfere with existing application workloads prior to deployment in production environments.\n\nFor Debian-based systems within an active support lifecycle, kernel patches addressing CVE-2026-31431 are already available via the official package repositories. Customers are strongly encouraged to apply these updates immediately by executing the following command:\nsudo apt update && sudo apt upgrade\nA system reboot is required after the upgrade for the updated kernel to take effect.\n\nTemporary Mitigation: If an immediate system update is not feasible, the affected kernel module (algif_aead) can be disabled persistently. Security researchers have confirmed this measure effectively prevents exploitation of CVE-2026-31431.\nExecute the following commands as root:\n\necho "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf\nrmmod algif_aead 2>/dev/null || true\n\nImpact assessment: Disabling the algif_aead module removes the AEAD socket interface from the kernel cryp-to API. This does not affect dm-crypt/LUKS, kTLS, IPsec/XFRM, OpenSSL, GnuTLS, NSS, or SSH. Applications explicitly configured to use the afalg engine or that directly bind aead, skcipher, or hash sockets via AF_ALG may be affected. To assess exposure prior to applying this workaround, run:\n\nlsof | grep AF_ALG', 'category': 'workaround', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}], 'product_status': {'fixed': ['CSAFPID-0003'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}}, {'cve': 'CVE-2026-43494', 'cwe': {'id': 'CWE-1341', 'name': 'Multiple Releases of Same Resource or Handle'}, 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved: net/rds: reset op_nents when zerocopy page pin fails When iov_iter_get_pages2() fails in rds_message_zcopy_from_user(), the pinned pages are released with put_page(), and rm->data.op_mmp_znotifier is cleared. But we fail to properly clear rm->data.op_nents. Later when rds_message_purge() is called from rds_sendmsg() the cleanup loop iterates over the incorrectly non zero number of op_nents and frees them again. Fix this by properly resetting op_nents when it should be in rds_message_zcopy_from_user().', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2026-43494', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43494', 'summary': 'NVD - CVE-2026-43494', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-43494', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/1341.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'For affected products, software updates should be installed upon availability.\n\n Product\t Patch version\n- APROL\t : APROL-AutoYaST-DVD- V4.4-010.10.260602\n\nUntil remediated software versions are available, customers are required to conduct a risk assessment of their affected systems and to implement the mitigation measures and workarounds specified in this advisory.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Successful exploitation of the vulnerabilities described in this advisory requires local access to the affected system with low-privileged user credentials. Customers are strongly advised to enforce strict access control policies on all Linux-based systems, ensuring that interactive access is exclusively granted to authorized and trusted personnel. This includes reviewing and hardening user account permissions and disabling unused accounts.\n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.\n', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}, {'details': 'Security researchers have identified and validated the following workarounds to reduce exposure to the vulnerabilities described in this advisory. These measures do not remediate the underlying vulnerabilities but effectively block known attack vectors until patched software versions are deployed.\n\nImportant: Customers are advised to thoroughly test their systems after applying any of the listed workarounds. B&R has no visibility into customer-specific applications running on the underlying Linux system. It is the customer\'s responsibility to assess whether the applied workarounds interfere with existing application workloads prior to deployment in production environments.\n\nFor Debian-based systems within an active support lifecycle, kernel patches addressing CVE-2026-31431 are already available via the official package repositories. Customers are strongly encouraged to apply these updates immediately by executing the following command:\nsudo apt update && sudo apt upgrade\nA system reboot is required after the upgrade for the updated kernel to take effect.\n\nTemporary Mitigation: If an immediate system update is not feasible, the affected kernel module (algif_aead) can be disabled persistently. Security researchers have confirmed this measure effectively prevents exploitation of CVE-2026-31431.\nExecute the following commands as root:\n\necho "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf\nrmmod algif_aead 2>/dev/null || true\n\nImpact assessment: Disabling the algif_aead module removes the AEAD socket interface from the kernel cryp-to API. This does not affect dm-crypt/LUKS, kTLS, IPsec/XFRM, OpenSSL, GnuTLS, NSS, or SSH. Applications explicitly configured to use the afalg engine or that directly bind aead, skcipher, or hash sockets via AF_ALG may be affected. To assess exposure prior to applying this workaround, run:\n\nlsof | grep AF_ALG', 'category': 'workaround', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}], 'product_status': {'fixed': ['CSAFPID-0003'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}}]} | |
ot | ICSA-26-174-06 | CVE-2026-43494 | Impact of Linux Kernel vulnerabilities on B&R products | 2026-06-11 03:30:00+03:00 | 2026-06-23 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-06.json | d19b4b5700c37a4ee69bc33d3695fb7cfb79a99f5aed18c00b2849fdb4c75ea1 | 2026-06-24 07:37:39.992137+03:00 | 2026-06-24 07:37:39.992137+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'B&R is aware of publicly reported vulnerabilities affecting the Linux kernel versions shipped with the products listed as affected in the advisory.\n\nSuccessful local exploitation of these vulnerabilities could allow an attacker to escalate privileges on the affected system. Public proof-of-concept exploits are available for the vulnerabilities described herein. At the time of publication of this advisory, B&R had no evidence of active exploitation targeting B&R products.', 'title': 'Summary', 'category': 'summary'}, {'text': 'For additional instructions and support please contact your local B&R service organization. For contact information, see https://www.br-automation.com/en/about-us/locations/.\n\nInformation about ABB’s cyber security program and capabilities can be found at www.abb.com/cybersecurity.\n\n\n', 'title': 'Support', 'category': 'other'}, {'text': 'The information in this document is subject to change without notice, and should not be construed as a commitment by B&R.\n\nB&R provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall B&R or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if B&R or its suppliers have been advised of the possibility of such damages.\n\nThis document and parts hereof must not be reproduced or copied without written permission from B&R, and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose.\n\nAll rights to registrations and trademarks reside with their respective owners.', 'title': 'Notice', 'category': 'legal_disclaimer'}, {'text': 'For any installation of software related ABB products we strongly recommend the following (non-exhaustive) list of cyber security practices:\n\n- Isolate special purpose networks (e.g. for automation systems) and remote devices behind firewalls and separate them from any general purpose network (e.g. office or home networks).\n\n- Install physical controls so no unauthorized personnel can access your devices, components, peripheral equipment, and networks.\n\n- Never connect programming software or computers containing programing software to any network other than the network for the devices that it is intended for.\n\n- Scan all data imported into your environment before use to detect potential malware infections.\n\n- Minimize network exposure for all applications and endpoints to ensure that they are not accessible from the Internet unless they are designed for such exposure and the intended use requires such.\n\n- Ensure all nodes are always up to date in terms of installed software, operating system, and firmware patches as well as anti-virus and firewall.\n\n- When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.\n\nFor more information on recommended practices, please refer to the following documents listed in the reference section:\n\n- Defense in Depth for B&R products\n', 'title': 'General security recommendations', 'category': 'other'}, {'text': 'B&R has a rigorous internal cyber security continuous improvement process which involves regular testing with industry leading tools and periodic assessments to identify potential product issues. Occasionally an issue is determined to be a design or coding flaw with implications that may impact product cyber security.\n\nWhen a potential product vulnerability is identified or reported, B&R immediately initiates our vulnerability handling process. This entails validating if the issue is in fact a product issue, identifying root causes, determining what related products may be impacted, developing a remediation, and notifying end users and governmental organizations.\n\nThe resulting Cyber Security Advisory intends to notify customers of the vulnerability and provide details on which products are impacted, how to mitigate the vulnerability or explain workarounds that minimize the potential risk as much as possible. The release of a Cyber Security Advisory should not be misconstrued as an affirmation or indication of an active threat or ongoing campaign targeting the products mentioned here. If B&R is aware of any specific threats, it will be clearly mentioned in the communication.\n\nThe publication of this Cyber Security Advisory is an example of B&R’s commitment to the user community in support of this critical topic. Responsible disclosure is an important element in the chain of trust we work to maintain with our many customers. The release of an Advisory provides timely information which is essential to help ensure our customers are fully informed.', 'title': 'Purpose', 'category': 'other'}, {'text': 'What causes the vulnerabilities?\n- The vulnerabilities are caused by a vulnerable Linux Kernel component.\n\nWhat might an attacker use the vulnerability to do?\n- An authenticated attacker with low privileges may elevate privileges to root.\n\nCould the vulnerabilities be exploited remotely? \n- Yes, an attacker with privileges to login in a vulnerable system node could exploit these vulnerabilities. Recommended practices include that process control systems are physically protected, have no direct connections to the Internet, and are separated from other networks by means of a firewall system that has a minimal number of ports exposed. \n\nWhen this security advisory was issued, had B&R received any reports that these vulnerabilities were being exploited?\n- B&R is aware of reports indicating that these vulnerabilities had been exploited at the time this security advisory was originally issued; however, no exploitation has been observed in B&R products.', 'title': 'Frequently asked questions', 'category': 'faq'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of ABB PSIRT SA26P010 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact ABB PSIRT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Switzerland', 'title': 'Company headquarters location', 'category': 'other'}], 'title': 'Impact of Linux Kernel vulnerabilities on B&R products', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-174-06', 'status': 'final', 'version': '3', 'generator': {'date': '2026-06-18T13:26:13.151541Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2026-06-11T00:30:00.000000Z', 'number': '1', 'summary': 'Initial version.', 'legacy_version': 'Initial'}, {'date': '2026-06-18T00:30:00.000000Z', 'number': '2', 'summary': 'Updating the CWE classification for CVE-2026-43494.', 'legacy_version': 'Additional Release 1'}, {'date': '2026-06-23T06:00:00.000000Z', 'number': '3', 'summary': 'Initial CISA Republication of ABB PSIRT SA26P010 advisory', 'legacy_version': 'CISA Republication'}], 'current_release_date': '2026-06-23T06:00:00.000000Z', 'initial_release_date': '2026-06-11T00:30:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://psirt.abb.com/csaf/2026/sa26p010.json', 'summary': 'B&R CYBERSECURITY ADVISORY - CSAF Version ', 'category': 'self'}, {'url': 'https://br-cws-assets.de-fra-1.linodeobjects.com/SA26P010-0ea64434.pdf', 'summary': 'B&R CYBERSECURITY ADVISORY - PDF Version ', 'category': 'self'}, {'url': 'https://www.br-automation.com/fileadmin/Cyber_Security_-_Defense_in_Depth_for_BR_Products-bdd37e82.pdf', 'summary': 'Defense in Depth for B&R products'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-06.json', 'summary': 'ICS Advisory ICSA-26-174-06 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-06', 'summary': 'ICS Advisory ICSA-26-174-06 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to CISA.', 'organization': 'ABB PSIRT'}]}, 'product_tree': {'branches': [{'name': 'B&R Industrial Automation GmbH', 'branches': [{'name': 'Linux for B&R', 'branches': [{'name': '<=12', 'product': {'name': 'B&R Industrial Automation GmbH Linux for B&R <=12', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'APROL', 'branches': [{'name': '<APROL-AutoYaST-DVD-_V4.4-010.10.260602', 'product': {'name': 'B&R Industrial Automation GmbH APROL <APROL-AutoYaST-DVD- V4.4-010.10.260602', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}, {'name': 'APROL-AutoYaST-DVD-_V4.4-010.10.260602', 'product': {'name': 'B&R Industrial Automation GmbH APROL APROL-AutoYaST-DVD- V4.4-010.10.260602', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'X20EDS410', 'branches': [{'name': '/all', 'product': {'name': 'B&R Industrial Automation GmbH X20EDS410 /all', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-31431', 'cwe': {'id': 'CWE-669', 'name': 'Incorrect Resource Transfer Between Spheres'}, 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2026-31431', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:H/RC:C', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'reportConfidence': 'CONFIRMED', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'LOW', 'exploitCodeMaturity': 'HIGH', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-31431', 'summary': 'NVD - CVE-2026-31431', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-31431', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/669.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:H/RC:C', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'For affected products, software updates should be installed upon availability.\n\n Product\t Patch version\n- APROL\t : APROL-AutoYaST-DVD- V4.4-010.10.260602\n\nUntil remediated software versions are available, customers are required to conduct a risk assessment of their affected systems and to implement the mitigation measures and workarounds specified in this advisory.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Successful exploitation of the vulnerabilities described in this advisory requires local access to the affected system with low-privileged user credentials. Customers are strongly advised to enforce strict access control policies on all Linux-based systems, ensuring that interactive access is exclusively granted to authorized and trusted personnel. This includes reviewing and hardening user account permissions and disabling unused accounts.\n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.\n', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}, {'details': 'Security researchers have identified and validated the following workarounds to reduce exposure to the vulnerabilities described in this advisory. These measures do not remediate the underlying vulnerabilities but effectively block known attack vectors until patched software versions are deployed.\n\nImportant: Customers are advised to thoroughly test their systems after applying any of the listed workarounds. B&R has no visibility into customer-specific applications running on the underlying Linux system. It is the customer\'s responsibility to assess whether the applied workarounds interfere with existing application workloads prior to deployment in production environments.\n\nFor Debian-based systems within an active support lifecycle, kernel patches addressing CVE-2026-31431 are already available via the official package repositories. Customers are strongly encouraged to apply these updates immediately by executing the following command:\nsudo apt update && sudo apt upgrade\nA system reboot is required after the upgrade for the updated kernel to take effect.\n\nTemporary Mitigation: If an immediate system update is not feasible, the affected kernel module (algif_aead) can be disabled persistently. Security researchers have confirmed this measure effectively prevents exploitation of CVE-2026-31431.\nExecute the following commands as root:\n\necho "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf\nrmmod algif_aead 2>/dev/null || true\n\nImpact assessment: Disabling the algif_aead module removes the AEAD socket interface from the kernel cryp-to API. This does not affect dm-crypt/LUKS, kTLS, IPsec/XFRM, OpenSSL, GnuTLS, NSS, or SSH. Applications explicitly configured to use the afalg engine or that directly bind aead, skcipher, or hash sockets via AF_ALG may be affected. To assess exposure prior to applying this workaround, run:\n\nlsof | grep AF_ALG', 'category': 'workaround', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}], 'product_status': {'fixed': ['CSAFPID-0003'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}}, {'cve': 'CVE-2026-43284', 'cwe': {'id': 'CWE-123', 'name': 'Write-what-where Condition'}, 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths that may modify packet data can first make a private copy. The IPv4/IPv6 datagram append paths did not set this flag when splicing pages into UDP skbs. That leaves an ESP-in-UDP packet made from shared pipe pages looking like an ordinary uncloned nonlinear skb. ESP input then takes the no-COW fast path for uncloned skbs without a frag_list and decrypts in place over data that is not owned privately by the skb. Mark IPv4/IPv6 datagram splice frags with SKBFL_SHARED_FRAG, matching TCP. Also make ESP input fall back to skb_cow_data() when the flag is present, so ESP does not decrypt external-ly backed frags in place. Private nonlinear skb frags still use the existing fast path. This intentionally does not change ESP output. In esp_output_head(), the path that appends the ESP trailer to existing skb tailroom without calling skb_cow_data() is not reachable for nonlinear skbs: skb_tailroom() returns zero when skb->data_len is nonzero, while ESP tailen is positive. Thus ESP output will either use the separate destination-frag path or fall back to skb_cow_data().', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2026-43284', 'scores': [{'cvss_v3': {'scope': 'CHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.9, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43284', 'summary': 'NVD - CVE-2026-43284', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-43284', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/123.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'For affected products, software updates should be installed upon availability.\n\n Product\t Patch version\n- APROL\t : APROL-AutoYaST-DVD- V4.4-010.10.260602\n\nUntil remediated software versions are available, customers are required to conduct a risk assessment of their affected systems and to implement the mitigation measures and workarounds specified in this advisory.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Successful exploitation of the vulnerabilities described in this advisory requires local access to the affected system with low-privileged user credentials. Customers are strongly advised to enforce strict access control policies on all Linux-based systems, ensuring that interactive access is exclusively granted to authorized and trusted personnel. This includes reviewing and hardening user account permissions and disabling unused accounts.\n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.\n', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}, {'details': 'Security researchers have identified and validated the following workarounds to reduce exposure to the vulnerabilities described in this advisory. These measures do not remediate the underlying vulnerabilities but effectively block known attack vectors until patched software versions are deployed.\n\nImportant: Customers are advised to thoroughly test their systems after applying any of the listed workarounds. B&R has no visibility into customer-specific applications running on the underlying Linux system. It is the customer\'s responsibility to assess whether the applied workarounds interfere with existing application workloads prior to deployment in production environments.\n\nFor Debian-based systems within an active support lifecycle, kernel patches addressing CVE-2026-31431 are already available via the official package repositories. Customers are strongly encouraged to apply these updates immediately by executing the following command:\nsudo apt update && sudo apt upgrade\nA system reboot is required after the upgrade for the updated kernel to take effect.\n\nTemporary Mitigation: If an immediate system update is not feasible, the affected kernel module (algif_aead) can be disabled persistently. Security researchers have confirmed this measure effectively prevents exploitation of CVE-2026-31431.\nExecute the following commands as root:\n\necho "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf\nrmmod algif_aead 2>/dev/null || true\n\nImpact assessment: Disabling the algif_aead module removes the AEAD socket interface from the kernel cryp-to API. This does not affect dm-crypt/LUKS, kTLS, IPsec/XFRM, OpenSSL, GnuTLS, NSS, or SSH. Applications explicitly configured to use the afalg engine or that directly bind aead, skcipher, or hash sockets via AF_ALG may be affected. To assess exposure prior to applying this workaround, run:\n\nlsof | grep AF_ALG', 'category': 'workaround', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}], 'product_status': {'fixed': ['CSAFPID-0003'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}}, {'cve': 'CVE-2026-46333', 'cwe': {'id': 'CWE-269', 'name': 'Improper Privilege Management'}, 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner \'get_dumpable()\' logic The \'dumpability\' of a task is fundamentally about the memory image of the task - the concept comes from whether it can core dump or not - and makes no sense when you don\'t have an associated mm. And almost all users do in fact use it only for the case where the task has a mm pointer. But we have one odd special case: ptrace_may_access() uses \'dumpable\' to check various other things entirely independently of the MM (typically explicitly using flags like PTRACE_MODE_READ_FSCREDS). Including for threads that no longer have a VM (and maybe never did, like most kernel threads). It\'s not what this flag was designed for, but it is what it is. The ptrace code does check that the uid/gid matches, so you do have to be uid-0 to see kernel thread details, but this means that the traditional "drop capabilities" model doesn\'t make any difference for this all. Make it all make a *bit* more sense by saying that if you don\'t have a MM pointer, we\'ll use a cached "last dumpability" flag if the thread ever had a MM (it will be zero for kernel threads since it is never set), and require a proper CAP_SYS_PTRACE capability to override.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2026-46333', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.1, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N', 'temporalScore': 7.1, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'NONE', 'environmentalScore': 7.1, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46333', 'summary': 'NVD - CVE-2026-46333', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-46333', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/269.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'For affected products, software updates should be installed upon availability.\n\n Product\t Patch version\n- APROL\t : APROL-AutoYaST-DVD- V4.4-010.10.260602\n\nUntil remediated software versions are available, customers are required to conduct a risk assessment of their affected systems and to implement the mitigation measures and workarounds specified in this advisory.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Successful exploitation of the vulnerabilities described in this advisory requires local access to the affected system with low-privileged user credentials. Customers are strongly advised to enforce strict access control policies on all Linux-based systems, ensuring that interactive access is exclusively granted to authorized and trusted personnel. This includes reviewing and hardening user account permissions and disabling unused accounts.\n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.\n', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}, {'details': 'Security researchers have identified and validated the following workarounds to reduce exposure to the vulnerabilities described in this advisory. These measures do not remediate the underlying vulnerabilities but effectively block known attack vectors until patched software versions are deployed.\n\nImportant: Customers are advised to thoroughly test their systems after applying any of the listed workarounds. B&R has no visibility into customer-specific applications running on the underlying Linux system. It is the customer\'s responsibility to assess whether the applied workarounds interfere with existing application workloads prior to deployment in production environments.\n\nFor Debian-based systems within an active support lifecycle, kernel patches addressing CVE-2026-31431 are already available via the official package repositories. Customers are strongly encouraged to apply these updates immediately by executing the following command:\nsudo apt update && sudo apt upgrade\nA system reboot is required after the upgrade for the updated kernel to take effect.\n\nTemporary Mitigation: If an immediate system update is not feasible, the affected kernel module (algif_aead) can be disabled persistently. Security researchers have confirmed this measure effectively prevents exploitation of CVE-2026-31431.\nExecute the following commands as root:\n\necho "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf\nrmmod algif_aead 2>/dev/null || true\n\nImpact assessment: Disabling the algif_aead module removes the AEAD socket interface from the kernel cryp-to API. This does not affect dm-crypt/LUKS, kTLS, IPsec/XFRM, OpenSSL, GnuTLS, NSS, or SSH. Applications explicitly configured to use the afalg engine or that directly bind aead, skcipher, or hash sockets via AF_ALG may be affected. To assess exposure prior to applying this workaround, run:\n\nlsof | grep AF_ALG', 'category': 'workaround', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}], 'product_status': {'fixed': ['CSAFPID-0003'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}}, {'cve': 'CVE-2026-46300', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': "In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() can attach paged frags from @from to @to. If @from has SKBFL_SHARED_FRAG set, the resulting @to skb can contain the same externally-owned or page-cache-backed frags, but the shared-frag marker is currently lost. That breaks the invariant relied on by later in-place writers. In particular, ESP input checks skb_has_shared_frag() before deciding whether an uncloned nonlinear skb can skip skb_cow_data(). If TCP receive coalescing has moved shared frags into an unmarked skb, ESP can see skb_has_shared_frag() as false and decrypt in place over page-cache backed frags. Propagate SKBFL_SHARED_FRAG when skb_try_coalesce() transfers paged frags. The tailroom copy path does not need the marker because it copies bytes into @to's linear data rather than transferring frag descriptors..", 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2026-46300', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-46300', 'summary': 'NVD - CVE-2026-46300 ', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-46300', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'For affected products, software updates should be installed upon availability.\n\n Product\t Patch version\n- APROL\t : APROL-AutoYaST-DVD- V4.4-010.10.260602\n\nUntil remediated software versions are available, customers are required to conduct a risk assessment of their affected systems and to implement the mitigation measures and workarounds specified in this advisory.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Successful exploitation of the vulnerabilities described in this advisory requires local access to the affected system with low-privileged user credentials. Customers are strongly advised to enforce strict access control policies on all Linux-based systems, ensuring that interactive access is exclusively granted to authorized and trusted personnel. This includes reviewing and hardening user account permissions and disabling unused accounts.\n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.\n', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}, {'details': 'Security researchers have identified and validated the following workarounds to reduce exposure to the vulnerabilities described in this advisory. These measures do not remediate the underlying vulnerabilities but effectively block known attack vectors until patched software versions are deployed.\n\nImportant: Customers are advised to thoroughly test their systems after applying any of the listed workarounds. B&R has no visibility into customer-specific applications running on the underlying Linux system. It is the customer\'s responsibility to assess whether the applied workarounds interfere with existing application workloads prior to deployment in production environments.\n\nFor Debian-based systems within an active support lifecycle, kernel patches addressing CVE-2026-31431 are already available via the official package repositories. Customers are strongly encouraged to apply these updates immediately by executing the following command:\nsudo apt update && sudo apt upgrade\nA system reboot is required after the upgrade for the updated kernel to take effect.\n\nTemporary Mitigation: If an immediate system update is not feasible, the affected kernel module (algif_aead) can be disabled persistently. Security researchers have confirmed this measure effectively prevents exploitation of CVE-2026-31431.\nExecute the following commands as root:\n\necho "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf\nrmmod algif_aead 2>/dev/null || true\n\nImpact assessment: Disabling the algif_aead module removes the AEAD socket interface from the kernel cryp-to API. This does not affect dm-crypt/LUKS, kTLS, IPsec/XFRM, OpenSSL, GnuTLS, NSS, or SSH. Applications explicitly configured to use the afalg engine or that directly bind aead, skcipher, or hash sockets via AF_ALG may be affected. To assess exposure prior to applying this workaround, run:\n\nlsof | grep AF_ALG', 'category': 'workaround', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}], 'product_status': {'fixed': ['CSAFPID-0003'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}}, {'cve': 'CVE-2026-43494', 'cwe': {'id': 'CWE-1341', 'name': 'Multiple Releases of Same Resource or Handle'}, 'notes': [{'text': 'In the Linux kernel, the following vulnerability has been resolved: net/rds: reset op_nents when zerocopy page pin fails When iov_iter_get_pages2() fails in rds_message_zcopy_from_user(), the pinned pages are released with put_page(), and rm->data.op_mmp_znotifier is cleared. But we fail to properly clear rm->data.op_nents. Later when rds_message_purge() is called from rds_sendmsg() the cleanup loop iterates over the incorrectly non zero number of op_nents and frees them again. Fix this by properly resetting op_nents when it should be in rds_message_zcopy_from_user().', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2026-43494', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'temporalScore': 7.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.8, 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2026-43494', 'summary': 'NVD - CVE-2026-43494', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-43494', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/1341.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'For affected products, software updates should be installed upon availability.\n\n Product\t Patch version\n- APROL\t : APROL-AutoYaST-DVD- V4.4-010.10.260602\n\nUntil remediated software versions are available, customers are required to conduct a risk assessment of their affected systems and to implement the mitigation measures and workarounds specified in this advisory.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Successful exploitation of the vulnerabilities described in this advisory requires local access to the affected system with low-privileged user credentials. Customers are strongly advised to enforce strict access control policies on all Linux-based systems, ensuring that interactive access is exclusively granted to authorized and trusted personnel. This includes reviewing and hardening user account permissions and disabling unused accounts.\n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.\n', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}, {'details': 'Security researchers have identified and validated the following workarounds to reduce exposure to the vulnerabilities described in this advisory. These measures do not remediate the underlying vulnerabilities but effectively block known attack vectors until patched software versions are deployed.\n\nImportant: Customers are advised to thoroughly test their systems after applying any of the listed workarounds. B&R has no visibility into customer-specific applications running on the underlying Linux system. It is the customer\'s responsibility to assess whether the applied workarounds interfere with existing application workloads prior to deployment in production environments.\n\nFor Debian-based systems within an active support lifecycle, kernel patches addressing CVE-2026-31431 are already available via the official package repositories. Customers are strongly encouraged to apply these updates immediately by executing the following command:\nsudo apt update && sudo apt upgrade\nA system reboot is required after the upgrade for the updated kernel to take effect.\n\nTemporary Mitigation: If an immediate system update is not feasible, the affected kernel module (algif_aead) can be disabled persistently. Security researchers have confirmed this measure effectively prevents exploitation of CVE-2026-31431.\nExecute the following commands as root:\n\necho "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf\nrmmod algif_aead 2>/dev/null || true\n\nImpact assessment: Disabling the algif_aead module removes the AEAD socket interface from the kernel cryp-to API. This does not affect dm-crypt/LUKS, kTLS, IPsec/XFRM, OpenSSL, GnuTLS, NSS, or SSH. Applications explicitly configured to use the afalg engine or that directly bind aead, skcipher, or hash sockets via AF_ALG may be affected. To assess exposure prior to applying this workaround, run:\n\nlsof | grep AF_ALG', 'category': 'workaround', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004']}], 'product_status': {'fixed': ['CSAFPID-0003'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0004']}}]} | |
ot | ICSA-26-174-05 | CVE-2025-7064 | ABB Freelance Security Lock | 2026-06-10 03:30:00+03:00 | 2026-06-23 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-05.json | 0519786215d9a946796d5a019a2092fab98c83fcc8f260bdcb2beddbb66c315b | 2026-06-24 07:37:39.992137+03:00 | 2026-06-24 07:37:39.992137+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'ABB is aware of a vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the product to stop or make the product inaccessible.', 'title': 'Summary', 'category': 'summary'}, {'text': 'For any installation of software-related ABB products we strongly recommend the following (non-exhaustive) list of cyber security practices:\n- Isolate special purpose networks (e.g. for automation systems) and remote devices behind firewalls and separate them from any general-purpose network (e.g. office or home networks).\n- Install physical controls so no unauthorized personnel can access your devices, components, peripheral equipment, and networks.\n- Never connect programming software or computers containing programming software to any net-work other than the network for the devices that it is intended for.\n- Scan all data imported into your environment before use to detect potential malware infections.\n- Minimize network exposure for all applications and endpoints to ensure that they are not accessible from the Internet unless they are designed for such exposure and the intended use requires such.\n- Ensure all nodes are always up to date in terms of installed software, operating system, and firmware patches as well as anti-virus and firewall.\n- When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.\n\nFor more information on recommended practices, please refer to the following documents listed in the reference section:\n\n- 2PAA112641-121\tFreelance Hardening Manual \n\n- 3BSE032547\tSecurity for Industrial Automation and Control Systems \n\n- 2PAA122516\tABB Ability™ System 800xA, Symphony® Plus and Freelance System Hardening\n\n', 'title': 'General security recommendations', 'category': 'other'}, {'text': 'For additional instructions and support please contact your local ABB service organization. For contact information, see www.abb.com/contactcenters.\n\nInformation about ABB’s cyber security program and capabilities can be found at www.abb.com/cybersecurity\n', 'title': 'Support', 'category': 'other'}, {'text': 'The information in this document is subject to change without notice, and should not be construed as a commitment by ABB.\n\nABB provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall ABB or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if ABB or its suppliers have been advised of the possibility of such damages.\n\nThis document and parts hereof must not be reproduced or copied without written permission from ABB, and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose.\n\nAll rights to registrations and trademarks reside with their respective owners.\n', 'title': 'Notice', 'category': 'legal_disclaimer'}, {'text': 'What causes the vulnerability?\n- The vulnerability is caused by not blocking non-admin user modify Security Lock data files.\n\nWhat is Freelance Security Lock?\n- Security Lock is an auxiliary program for the control system Freelance. It provides access control for configuration with Freelance Engineering and for operation and observation with Freelance Operations. The access control system can be implemented for an entire Freelance system with a single Security lock configuration.\n\nWhat might an attacker use the vulnerability to do?\n- An attacker who successfully exploited this vulnerability could manipulate the access control of the complete Freelance system and cause the affected system node to stop or become inaccessible and /or allow the attacker to take control of the system node.\n\nHow could an attacker exploit the vulnerability?\n- An attacker could try to exploit the vulnerability if he is able to access the actual node where Freelance Security Lock is installed. By using specific key combinations on modern keyboards, he may bypass Freelance Operations and gain access to the Windows OS, enabling manipulation of Security Lock data files.\n\nCould the vulnerability be exploited remotely? \n- Yes, an attacker who has network access to an affected system node could exploit this vulnerability. Recommended practices include that process control systems are physically protected, have no direct connections to the Internet, and are separated from other networks by means of a firewall system that has a minimal number of ports exposed.\n\nCan functional safety be affected by an exploit of this vulnerability?\n- No, because Freelance does not support functional safety.\n\nWhat does the workaround do?\n- The workaround will use another tool which does not have the vulnerability. The future update will remove the vulnerability.\n\nWhen this security advisory was issued, had this vulnerability been publicly disclosed?\n- No, ABB received information about this vulnerability through responsible disclosure.\n\nWhen this security advisory was issued, had ABB received any reports that this vulnerability was being exploited?\n- No, ABB had not received any information indicating that this vulnerability had been exploited when this security advisory was originally issued.', 'title': 'Frequently asked questions', 'category': 'faq'}, {'text': 'ABB has a rigorous internal cyber security continuous improvement process which involves regular testing with industry leading tools and periodic assessments to identify potential product issues. Occasionally an issue is determined to be a design or coding flaw with implications that may impact product cyber security.\n\nWhen a potential product vulnerability is identified or reported, ABB immediately initiates our vulnerability handling process. This entails validating if the issue is in fact a product issue, identifying root causes, determining what related products may be impacted, developing a remediation, and notifying end users and governmental organizations.\n\nThe resulting Cyber Security Advisory intends to notify customers of the vulnerability and provide details on which products are impacted, how to mitigate the vulnerability or explain workarounds that minimize the potential risk as much as possible. The release of a Cyber Security Advisory should not be misconstrued as an affirmation or indication of an active threat or ongoing campaign targeting the products mentioned here. If ABB is aware of any specific threats, it will be clearly mentioned in the communication.\n\nThe publication of this Cyber Security Advisory is an example of ABB’s commitment to the user community in support of this critical topic. Responsible disclosure is an important element in the chain of trust we work to maintain with our many customers. The release of an Advisory provides timely information which is essential to help ensure our customers are fully informed.', 'title': 'Purpose', 'category': 'other'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of ABB PSIRT 7PAA020361 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact ABB PSIRT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Switzerland', 'title': 'Company headquarters location', 'category': 'other'}], 'title': 'ABB Freelance Security Lock', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-174-05', 'status': 'final', 'version': '2', 'generator': {'date': '2026-06-18T13:26:12.423576Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2026-06-10T00:30:00.000000Z', 'number': '1', 'summary': 'Initial version.', 'legacy_version': 'Initial'}, {'date': '2026-06-23T06:00:00.000000Z', 'number': '2', 'summary': 'Initial CISA Republication of ABB PSIRT 7PAA020361 advisory', 'legacy_version': 'CISA Republication'}], 'current_release_date': '2026-06-23T06:00:00.000000Z', 'initial_release_date': '2026-06-10T00:30:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://psirt.abb.com/csaf/2026/7paa020361.json', 'summary': 'ABB CYBERSECURITY ADVISORY - CSAF Version ', 'category': 'self'}, {'url': 'https://search.abb.com/library/Download.aspx?DocumentID=7PAA020361&LanguageCode=en&DocumentPartId=&Action=Launch', 'summary': 'ABB CYBERSECURITY ADVISORY - PDF Version ', 'category': 'self'}, {'url': 'https://search.abb.com/library/Download.aspx?DocumentID=3BDD012560-121&LanguageCode=en&DocumentPartId=&Action=Launch', 'summary': '3BDD012560-121 : Getting started '}, {'url': 'https://search.abb.com/library/Download.aspx?DocumentID=7PAA000403-121&LanguageCode=en&DocumentPartId=&Action=Launch', 'summary': '7PAA000403-121 : Release Notes for Freelance 2024 system release '}, {'url': 'https://search.abb.com/library/Download.aspx?DocumentID=2PAA112641-121&LanguageCode=en&DocumentPartId=&Action=Launch', 'summary': '2PAA112641-121 - Freelance Hardening Manual '}, {'url': 'https://search.abb.com/library/Download.aspx?DocumentID=3BSE032547&LanguageCode=en&DocumentPartId=&Action=Launch', 'summary': '3BSE032547 - Security for Industrial Automation and Control Systems \n'}, {'url': 'https://search.abb.com/library/Download.aspx?DocumentID=2PAA122516&LanguageCode=en&DocumentPartId=&Action=Launch', 'summary': '2PAA122516 - ABB Ability™ System 800xA, Symphony® Plus and Freelance System Hardening \n'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-05.json', 'summary': 'ICS Advisory ICSA-26-174-05 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-05', 'summary': 'ICS Advisory ICSA-26-174-05 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Gergely Regweld Szini'], 'summary': 'reported this vulnerability to ABB.'}]}, 'product_tree': {'branches': [{'name': 'ABB', 'branches': [{'name': 'System Version', 'branches': [{'name': '<=Freelance_2013', 'product': {'name': 'ABB System Version <=Freelance 2013', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}, {'name': 'Freelance_2013_SP1', 'product': {'name': 'ABB System Version Freelance 2013 SP1', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version'}, {'name': 'Freelance_2016', 'product': {'name': 'ABB System Version Freelance 2016', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version'}, {'name': 'Freelance_2016_SP1', 'product': {'name': 'ABB System Version Freelance 2016 SP1', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version'}, {'name': 'Freelance_2019', 'product': {'name': 'ABB System Version Freelance 2019', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version'}, {'name': 'Freelance_2019_SP1', 'product': {'name': 'ABB System Version Freelance 2019 SP1', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version'}, {'name': 'Freelance_2019_SP1_FP1', 'product': {'name': 'ABB System Version Freelance 2019 SP1 FP1', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version'}, {'name': 'Freelance_2024', 'product': {'name': 'ABB System Version Freelance 2024', 'product_id': 'CSAFPID-0008'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Freelance Security Lock', 'product': {'name': 'ABB Freelance Security Lock', 'product_id': 'CSAFPID-0009'}, 'category': 'product_name'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'ABB System Version <=Freelance 2013 installed on ABB Freelance Security Lock', 'product_id': 'CSAFPID-0010'}, 'product_reference': 'CSAFPID-0001', 'relates_to_product_reference': 'CSAFPID-0009'}, {'category': 'installed_on', 'full_product_name': {'name': 'ABB System Version Freelance 2013 SP1 installed on ABB Freelance Security Lock', 'product_id': 'CSAFPID-0011'}, 'product_reference': 'CSAFPID-0002', 'relates_to_product_reference': 'CSAFPID-0009'}, {'category': 'installed_on', 'full_product_name': {'name': 'ABB System Version Freelance 2016 installed on ABB Freelance Security Lock', 'product_id': 'CSAFPID-0012'}, 'product_reference': 'CSAFPID-0003', 'relates_to_product_reference': 'CSAFPID-0009'}, {'category': 'installed_on', 'full_product_name': {'name': 'ABB System Version Freelance 2016 SP1 installed on ABB Freelance Security Lock', 'product_id': 'CSAFPID-0013'}, 'product_reference': 'CSAFPID-0004', 'relates_to_product_reference': 'CSAFPID-0009'}, {'category': 'installed_on', 'full_product_name': {'name': 'ABB System Version Freelance 2019 installed on ABB Freelance Security Lock', 'product_id': 'CSAFPID-0014'}, 'product_reference': 'CSAFPID-0005', 'relates_to_product_reference': 'CSAFPID-0009'}, {'category': 'installed_on', 'full_product_name': {'name': 'ABB System Version Freelance 2019 SP1 installed on ABB Freelance Security Lock', 'product_id': 'CSAFPID-0015'}, 'product_reference': 'CSAFPID-0006', 'relates_to_product_reference': 'CSAFPID-0009'}, {'category': 'installed_on', 'full_product_name': {'name': 'ABB System Version Freelance 2019 SP1 FP1 installed on ABB Freelance Security Lock', 'product_id': 'CSAFPID-0016'}, 'product_reference': 'CSAFPID-0007', 'relates_to_product_reference': 'CSAFPID-0009'}, {'category': 'installed_on', 'full_product_name': {'name': 'ABB System Version Freelance 2024 installed on ABB Freelance Security Lock', 'product_id': 'CSAFPID-0017'}, 'product_reference': 'CSAFPID-0008', 'relates_to_product_reference': 'CSAFPID-0009'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-7064', 'cwe': {'id': 'CWE-305', 'name': 'Authentication Bypass by Primary Weakness'}, 'notes': [{'text': 'An attacker is able to attack Freelance user management when Security Lock is enabled. The precondition is that the attacker bypasses Freelance Operations which blocks access to the Windows operating system. This bypass can be achieved via undocumented or special key combinations available on modern keyboards. \n\nThese combinations may allow access to underlying OS functions even when Freelance Operations is active, depending on system configuration and user permissions.\n', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2025-7064', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.6, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L/E:P/RL:W/RC:R/CR:L/IR:L/AR:L', 'temporalScore': 5.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'WORKAROUND', 'reportConfidence': 'REASONABLE', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'LOW', 'environmentalScore': 4.1, 'privilegesRequired': 'LOW', 'exploitCodeMaturity': 'PROOF_OF_CONCEPT', 'integrityRequirement': 'LOW', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'MEDIUM', 'availabilityRequirement': 'LOW', 'confidentialityRequirement': 'LOW'}, 'products': ['CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-7064', 'summary': 'NVD - CVE-2025-7064', 'category': 'self'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-7064', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/305.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L/E:P/RL:W/RC:R/CR:L/IR:L/AR:L', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'ABB recommends using Freelance Extended User Management instead of Security Lock. Freelance Extended User Management is based on Windows user accounts and is available for Freelance 2019 or higher. For Freelance 2016 and earlier, please refer to chapter “General Security Information”.\n\nA fix for Freelance Security Lock is in preparation and will be announced in this updated document.\n\nRefer to section “General security recommendations” for further advise on how to keep your system secure. To reduce the likelihood of exploitation via keyboard shortcuts:\n- disable unnecessary accessibility features\n- use hardened OS configurations that suppress system-level shortcuts\n- implement BIOS/UEFI-level restrictions on keyboard input during runtime.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017']}, {'details': 'Workarounds are specific measures that a user can take to help block an attack, for example, temporarily disabling the vulnerable feature may remove the exposure with well-known impact on functionality. ABB has tested the following workaround. Although this workaround will not correct the underlying vulnerability, it can help block known attack vectors. When a workaround reduces functionality, this is identified below as “Impact of workaround”.\n\nFor Freelance 2019 and higher, ABB recommends using Freelance Extended User Management instead of Security Lock. For Freelance 2016 SP1 and older, no workaround is available. ', 'category': 'workaround', 'product_ids': ['CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017']}], 'product_status': {'known_affected': ['CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017']}}]} | |
ot | ICSA-26-174-04 | CVE-2026-46746 | Siemens SINEC INS | 2026-06-09 03:00:00+03:00 | 2026-06-23 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-04.json | 332e5edfc6efe7447298d4c2396a6c8723a2f4cbd3187bf044dedb7143626df7 | 2026-06-24 07:37:39.992137+03:00 | 2026-06-24 07:37:39.992137+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'SINEC INS before V1.0 SP2 Update 6 is affected by multiple vulnerabilities.\n\nSiemens has released a new version for SINEC INS and recommends to update to the latest version.', 'title': 'Summary', 'category': 'summary'}, {'text': "As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals.\nAdditional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity", 'title': 'General Recommendations', 'category': 'general'}, {'text': 'For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.', 'title': 'Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of Siemens ProductCERT SSA-860189 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Critical Manufacturing, Transportation Systems, Energy, Healthcare and Public Health, Financial Services, Government Services and Facilities', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Germany', 'title': 'Company headquarters location', 'category': 'other'}], 'title': 'Siemens SINEC INS', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-174-04', 'status': 'final', 'version': '2', 'generator': {'date': '2026-06-17T15:49:49.601568Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2026-06-09T00:00:00.000000Z', 'number': '1', 'summary': 'Publication Date', 'legacy_version': 'Initial'}, {'date': '2026-06-23T06:00:00.000000Z', 'number': '2', 'summary': 'Initial CISA Republication of Siemens ProductCERT SSA-860189 advisory', 'legacy_version': 'CISA Republication'}], 'current_release_date': '2026-06-23T06:00:00.000000Z', 'initial_release_date': '2026-06-09T00:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://cert-portal.siemens.com/productcert/csaf/ssa-860189.json', 'summary': 'SSA-860189: Multiple Vulnerabilities in SINEC INS Before V1.0 SP2 Update 6 - CSAF Version', 'category': 'self'}, {'url': 'https://cert-portal.siemens.com/productcert/html/ssa-860189.html', 'summary': 'SSA-860189: Multiple Vulnerabilities in SINEC INS Before V1.0 SP2 Update 6 - HTML Version', 'category': 'self'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-04.json', 'summary': 'ICS Advisory ICSA-26-174-04 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-04', 'summary': 'ICS Advisory ICSA-26-174-04 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to CISA.', 'organization': 'Siemens ProductCERT'}]}, 'product_tree': {'branches': [{'name': 'Siemens', 'branches': [{'name': 'SINEC INS', 'branches': [{'name': 'vers:intdot/<1.0.2.6', 'product': {'name': 'SINEC INS', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-46746', 'cwe': {'id': 'CWE-78', 'name': "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}, 'notes': [{'text': 'The application does not properly sanitize user input in the /api/sftp/uploadFiles endpoint, allowing the injection of shell command payloads via crafted directory names. These payloads are stored and executed when directory listings are retrieved. This could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system with the privileges of the affected service user (sinecins).', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-46746', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-46746', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/78.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://support.industry.siemens.com/cs/ww/en/view/110002283/', 'details': 'Update to V1.0 SP2 Update 6 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-46747', 'cwe': {'id': 'CWE-26', 'name': "Path Traversal: '/dir/../filename'"}, 'notes': [{'text': 'The affected application does not properly sanitize path input in the `GET /api/sftp/uploadFiles` endpoint used for directory listing. This allows path traversal through crafted input, enabling access to unintended file system locations.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-46747', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-46747', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/26.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://support.industry.siemens.com/cs/ww/en/view/110002283/', 'details': 'Update to V1.0 SP2 Update 6 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-46748', 'cwe': {'id': 'CWE-250', 'name': 'Execution with Unnecessary Privileges'}, 'notes': [{'text': 'The affected system includes a binary that is configured with the cap_dac_override capability. This capability allows the process to bypass file system permission checks, resulting in unrestricted file system access. This could allow a local attacker to escalate privileges leading to arbitrary file modification and gaining root privileges on the system.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-46748', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-46748', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/250.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://support.industry.siemens.com/cs/ww/en/view/110002283/', 'details': 'Update to V1.0 SP2 Update 6 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-46749', 'cwe': {'id': 'CWE-760', 'name': 'Use of a One-Way Hash with a Predictable Salt'}, 'notes': [{'text': 'The affected application uses a password hashing implementation with a static, hardcoded salt shared across all users and installations, and is configured with an insufficient number of iterations. This could allow an attacker to efficiently recover user passwords using brute-force or precomputed attacks, potentially resulting in unauthorized access.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-46749', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-46749', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/760.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://support.industry.siemens.com/cs/ww/en/view/110002283/', 'details': 'Update to V1.0 SP2 Update 6 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-174-04 | CVE-2026-46747 | Siemens SINEC INS | 2026-06-09 03:00:00+03:00 | 2026-06-23 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-04.json | 2ed44d581b72ce5f9e8a06c9a1fd2e09e7fc01e77daca4bb3bd3befea4960030 | 2026-06-24 07:37:39.992137+03:00 | 2026-06-24 07:37:39.992137+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'SINEC INS before V1.0 SP2 Update 6 is affected by multiple vulnerabilities.\n\nSiemens has released a new version for SINEC INS and recommends to update to the latest version.', 'title': 'Summary', 'category': 'summary'}, {'text': "As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals.\nAdditional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity", 'title': 'General Recommendations', 'category': 'general'}, {'text': 'For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.', 'title': 'Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of Siemens ProductCERT SSA-860189 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Critical Manufacturing, Transportation Systems, Energy, Healthcare and Public Health, Financial Services, Government Services and Facilities', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Germany', 'title': 'Company headquarters location', 'category': 'other'}], 'title': 'Siemens SINEC INS', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-174-04', 'status': 'final', 'version': '2', 'generator': {'date': '2026-06-17T15:49:49.601568Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2026-06-09T00:00:00.000000Z', 'number': '1', 'summary': 'Publication Date', 'legacy_version': 'Initial'}, {'date': '2026-06-23T06:00:00.000000Z', 'number': '2', 'summary': 'Initial CISA Republication of Siemens ProductCERT SSA-860189 advisory', 'legacy_version': 'CISA Republication'}], 'current_release_date': '2026-06-23T06:00:00.000000Z', 'initial_release_date': '2026-06-09T00:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://cert-portal.siemens.com/productcert/csaf/ssa-860189.json', 'summary': 'SSA-860189: Multiple Vulnerabilities in SINEC INS Before V1.0 SP2 Update 6 - CSAF Version', 'category': 'self'}, {'url': 'https://cert-portal.siemens.com/productcert/html/ssa-860189.html', 'summary': 'SSA-860189: Multiple Vulnerabilities in SINEC INS Before V1.0 SP2 Update 6 - HTML Version', 'category': 'self'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-04.json', 'summary': 'ICS Advisory ICSA-26-174-04 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-04', 'summary': 'ICS Advisory ICSA-26-174-04 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to CISA.', 'organization': 'Siemens ProductCERT'}]}, 'product_tree': {'branches': [{'name': 'Siemens', 'branches': [{'name': 'SINEC INS', 'branches': [{'name': 'vers:intdot/<1.0.2.6', 'product': {'name': 'SINEC INS', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-46746', 'cwe': {'id': 'CWE-78', 'name': "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}, 'notes': [{'text': 'The application does not properly sanitize user input in the /api/sftp/uploadFiles endpoint, allowing the injection of shell command payloads via crafted directory names. These payloads are stored and executed when directory listings are retrieved. This could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system with the privileges of the affected service user (sinecins).', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-46746', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-46746', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/78.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://support.industry.siemens.com/cs/ww/en/view/110002283/', 'details': 'Update to V1.0 SP2 Update 6 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-46747', 'cwe': {'id': 'CWE-26', 'name': "Path Traversal: '/dir/../filename'"}, 'notes': [{'text': 'The affected application does not properly sanitize path input in the `GET /api/sftp/uploadFiles` endpoint used for directory listing. This allows path traversal through crafted input, enabling access to unintended file system locations.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-46747', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-46747', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/26.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://support.industry.siemens.com/cs/ww/en/view/110002283/', 'details': 'Update to V1.0 SP2 Update 6 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-46748', 'cwe': {'id': 'CWE-250', 'name': 'Execution with Unnecessary Privileges'}, 'notes': [{'text': 'The affected system includes a binary that is configured with the cap_dac_override capability. This capability allows the process to bypass file system permission checks, resulting in unrestricted file system access. This could allow a local attacker to escalate privileges leading to arbitrary file modification and gaining root privileges on the system.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-46748', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-46748', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/250.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://support.industry.siemens.com/cs/ww/en/view/110002283/', 'details': 'Update to V1.0 SP2 Update 6 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-46749', 'cwe': {'id': 'CWE-760', 'name': 'Use of a One-Way Hash with a Predictable Salt'}, 'notes': [{'text': 'The affected application uses a password hashing implementation with a static, hardcoded salt shared across all users and installations, and is configured with an insufficient number of iterations. This could allow an attacker to efficiently recover user passwords using brute-force or precomputed attacks, potentially resulting in unauthorized access.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-46749', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-46749', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/760.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://support.industry.siemens.com/cs/ww/en/view/110002283/', 'details': 'Update to V1.0 SP2 Update 6 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-174-04 | CVE-2026-46748 | Siemens SINEC INS | 2026-06-09 03:00:00+03:00 | 2026-06-23 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-04.json | ae9bc7eb153cb0c302506f3274d8c2e034ead18fc666d453d555e9cec6e89532 | 2026-06-24 07:37:39.992137+03:00 | 2026-06-24 07:37:39.992137+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'SINEC INS before V1.0 SP2 Update 6 is affected by multiple vulnerabilities.\n\nSiemens has released a new version for SINEC INS and recommends to update to the latest version.', 'title': 'Summary', 'category': 'summary'}, {'text': "As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals.\nAdditional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity", 'title': 'General Recommendations', 'category': 'general'}, {'text': 'For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.', 'title': 'Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of Siemens ProductCERT SSA-860189 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Critical Manufacturing, Transportation Systems, Energy, Healthcare and Public Health, Financial Services, Government Services and Facilities', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Germany', 'title': 'Company headquarters location', 'category': 'other'}], 'title': 'Siemens SINEC INS', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-174-04', 'status': 'final', 'version': '2', 'generator': {'date': '2026-06-17T15:49:49.601568Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2026-06-09T00:00:00.000000Z', 'number': '1', 'summary': 'Publication Date', 'legacy_version': 'Initial'}, {'date': '2026-06-23T06:00:00.000000Z', 'number': '2', 'summary': 'Initial CISA Republication of Siemens ProductCERT SSA-860189 advisory', 'legacy_version': 'CISA Republication'}], 'current_release_date': '2026-06-23T06:00:00.000000Z', 'initial_release_date': '2026-06-09T00:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://cert-portal.siemens.com/productcert/csaf/ssa-860189.json', 'summary': 'SSA-860189: Multiple Vulnerabilities in SINEC INS Before V1.0 SP2 Update 6 - CSAF Version', 'category': 'self'}, {'url': 'https://cert-portal.siemens.com/productcert/html/ssa-860189.html', 'summary': 'SSA-860189: Multiple Vulnerabilities in SINEC INS Before V1.0 SP2 Update 6 - HTML Version', 'category': 'self'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-04.json', 'summary': 'ICS Advisory ICSA-26-174-04 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-04', 'summary': 'ICS Advisory ICSA-26-174-04 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to CISA.', 'organization': 'Siemens ProductCERT'}]}, 'product_tree': {'branches': [{'name': 'Siemens', 'branches': [{'name': 'SINEC INS', 'branches': [{'name': 'vers:intdot/<1.0.2.6', 'product': {'name': 'SINEC INS', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-46746', 'cwe': {'id': 'CWE-78', 'name': "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}, 'notes': [{'text': 'The application does not properly sanitize user input in the /api/sftp/uploadFiles endpoint, allowing the injection of shell command payloads via crafted directory names. These payloads are stored and executed when directory listings are retrieved. This could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system with the privileges of the affected service user (sinecins).', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-46746', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-46746', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/78.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://support.industry.siemens.com/cs/ww/en/view/110002283/', 'details': 'Update to V1.0 SP2 Update 6 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-46747', 'cwe': {'id': 'CWE-26', 'name': "Path Traversal: '/dir/../filename'"}, 'notes': [{'text': 'The affected application does not properly sanitize path input in the `GET /api/sftp/uploadFiles` endpoint used for directory listing. This allows path traversal through crafted input, enabling access to unintended file system locations.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-46747', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-46747', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/26.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://support.industry.siemens.com/cs/ww/en/view/110002283/', 'details': 'Update to V1.0 SP2 Update 6 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-46748', 'cwe': {'id': 'CWE-250', 'name': 'Execution with Unnecessary Privileges'}, 'notes': [{'text': 'The affected system includes a binary that is configured with the cap_dac_override capability. This capability allows the process to bypass file system permission checks, resulting in unrestricted file system access. This could allow a local attacker to escalate privileges leading to arbitrary file modification and gaining root privileges on the system.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-46748', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-46748', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/250.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://support.industry.siemens.com/cs/ww/en/view/110002283/', 'details': 'Update to V1.0 SP2 Update 6 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-46749', 'cwe': {'id': 'CWE-760', 'name': 'Use of a One-Way Hash with a Predictable Salt'}, 'notes': [{'text': 'The affected application uses a password hashing implementation with a static, hardcoded salt shared across all users and installations, and is configured with an insufficient number of iterations. This could allow an attacker to efficiently recover user passwords using brute-force or precomputed attacks, potentially resulting in unauthorized access.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-46749', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-46749', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/760.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://support.industry.siemens.com/cs/ww/en/view/110002283/', 'details': 'Update to V1.0 SP2 Update 6 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-174-04 | CVE-2026-46749 | Siemens SINEC INS | 2026-06-09 03:00:00+03:00 | 2026-06-23 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-04.json | 708eed5af22b0cd4877970deff171a634cc0f1c1c13fb5d53497188020cecb3e | 2026-06-24 07:37:39.992137+03:00 | 2026-06-24 07:37:39.992137+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'SINEC INS before V1.0 SP2 Update 6 is affected by multiple vulnerabilities.\n\nSiemens has released a new version for SINEC INS and recommends to update to the latest version.', 'title': 'Summary', 'category': 'summary'}, {'text': "As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals.\nAdditional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity", 'title': 'General Recommendations', 'category': 'general'}, {'text': 'For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.', 'title': 'Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of Siemens ProductCERT SSA-860189 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Critical Manufacturing, Transportation Systems, Energy, Healthcare and Public Health, Financial Services, Government Services and Facilities', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Germany', 'title': 'Company headquarters location', 'category': 'other'}], 'title': 'Siemens SINEC INS', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-174-04', 'status': 'final', 'version': '2', 'generator': {'date': '2026-06-17T15:49:49.601568Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2026-06-09T00:00:00.000000Z', 'number': '1', 'summary': 'Publication Date', 'legacy_version': 'Initial'}, {'date': '2026-06-23T06:00:00.000000Z', 'number': '2', 'summary': 'Initial CISA Republication of Siemens ProductCERT SSA-860189 advisory', 'legacy_version': 'CISA Republication'}], 'current_release_date': '2026-06-23T06:00:00.000000Z', 'initial_release_date': '2026-06-09T00:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://cert-portal.siemens.com/productcert/csaf/ssa-860189.json', 'summary': 'SSA-860189: Multiple Vulnerabilities in SINEC INS Before V1.0 SP2 Update 6 - CSAF Version', 'category': 'self'}, {'url': 'https://cert-portal.siemens.com/productcert/html/ssa-860189.html', 'summary': 'SSA-860189: Multiple Vulnerabilities in SINEC INS Before V1.0 SP2 Update 6 - HTML Version', 'category': 'self'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-04.json', 'summary': 'ICS Advisory ICSA-26-174-04 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-04', 'summary': 'ICS Advisory ICSA-26-174-04 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to CISA.', 'organization': 'Siemens ProductCERT'}]}, 'product_tree': {'branches': [{'name': 'Siemens', 'branches': [{'name': 'SINEC INS', 'branches': [{'name': 'vers:intdot/<1.0.2.6', 'product': {'name': 'SINEC INS', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-46746', 'cwe': {'id': 'CWE-78', 'name': "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}, 'notes': [{'text': 'The application does not properly sanitize user input in the /api/sftp/uploadFiles endpoint, allowing the injection of shell command payloads via crafted directory names. These payloads are stored and executed when directory listings are retrieved. This could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system with the privileges of the affected service user (sinecins).', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-46746', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-46746', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/78.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://support.industry.siemens.com/cs/ww/en/view/110002283/', 'details': 'Update to V1.0 SP2 Update 6 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-46747', 'cwe': {'id': 'CWE-26', 'name': "Path Traversal: '/dir/../filename'"}, 'notes': [{'text': 'The affected application does not properly sanitize path input in the `GET /api/sftp/uploadFiles` endpoint used for directory listing. This allows path traversal through crafted input, enabling access to unintended file system locations.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-46747', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-46747', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/26.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://support.industry.siemens.com/cs/ww/en/view/110002283/', 'details': 'Update to V1.0 SP2 Update 6 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-46748', 'cwe': {'id': 'CWE-250', 'name': 'Execution with Unnecessary Privileges'}, 'notes': [{'text': 'The affected system includes a binary that is configured with the cap_dac_override capability. This capability allows the process to bypass file system permission checks, resulting in unrestricted file system access. This could allow a local attacker to escalate privileges leading to arbitrary file modification and gaining root privileges on the system.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-46748', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-46748', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/250.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://support.industry.siemens.com/cs/ww/en/view/110002283/', 'details': 'Update to V1.0 SP2 Update 6 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-46749', 'cwe': {'id': 'CWE-760', 'name': 'Use of a One-Way Hash with a Predictable Salt'}, 'notes': [{'text': 'The affected application uses a password hashing implementation with a static, hardcoded salt shared across all users and installations, and is configured with an insufficient number of iterations. This could allow an attacker to efficiently recover user passwords using brute-force or precomputed attacks, potentially resulting in unauthorized access.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-46749', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-46749', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/760.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://support.industry.siemens.com/cs/ww/en/view/110002283/', 'details': 'Update to V1.0 SP2 Update 6 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-174-03 | CVE-2025-15467 | Siemens Products using OpenSSL | 2026-06-09 03:00:00+03:00 | 2026-06-23 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-03.json | fd13967cbba96403588ddf6c4562bb91093d37ab754558a3de8083623bd4ac47 | 2026-06-24 07:37:39.992137+03:00 | 2026-06-24 07:37:39.992137+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution.\n\nSiemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.', 'title': 'Summary', 'category': 'summary'}, {'text': "As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals.\nAdditional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity", 'title': 'General Recommendations', 'category': 'general'}, {'text': 'For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.', 'title': 'Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of Siemens ProductCERT SSA-434797 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Critical Manufacturing, Transportation Systems, Energy, Healthcare and Public Health, Financial Services, Government Services and Facilities', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Germany', 'title': 'Company headquarters location', 'category': 'other'}], 'title': 'Siemens Products using OpenSSL', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-174-03', 'status': 'final', 'version': '2', 'generator': {'date': '2026-06-17T15:49:48.211610Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2026-06-09T00:00:00.000000Z', 'number': '1', 'summary': 'Publication Date', 'legacy_version': 'Initial'}, {'date': '2026-06-23T06:00:00.000000Z', 'number': '2', 'summary': 'Initial CISA Republication of Siemens ProductCERT SSA-434797 advisory', 'legacy_version': 'CISA Republication'}], 'current_release_date': '2026-06-23T06:00:00.000000Z', 'initial_release_date': '2026-06-09T00:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://cert-portal.siemens.com/productcert/csaf/ssa-434797.json', 'summary': 'SSA-434797: Buffer Overflow Vulnerability in OpenSSL affecting Siemens Products - CSAF Version', 'category': 'self'}, {'url': 'https://cert-portal.siemens.com/productcert/html/ssa-434797.html', 'summary': 'SSA-434797: Buffer Overflow Vulnerability in OpenSSL affecting Siemens Products - HTML Version', 'category': 'self'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-03.json', 'summary': 'ICS Advisory ICSA-26-174-03 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-03', 'summary': 'ICS Advisory ICSA-26-174-03 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported this vulnerability to CISA.', 'organization': 'Siemens ProductCERT'}]}, 'product_tree': {'branches': [{'name': 'Siemens', 'branches': [{'name': 'AI Lightweight Inference Server', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'AI Lightweight Inference Server', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Connector for Azure', 'branches': [{'name': 'vers:intdot/<1.8.0', 'product': {'name': 'Connector for Azure', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Databus', 'branches': [{'name': 'vers:intdot/<3.3.2', 'product': {'name': 'Databus', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'HiMed Cockpit', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'HiMed Cockpit', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2)', 'product_id': 'CSAFPID-0005', 'product_identification_helper': {'model_numbers': ['6GK6108-4AM00-2BA2']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2)', 'product_id': 'CSAFPID-0006', 'product_identification_helper': {'model_numbers': ['6GK6108-4AM00-2DA2']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE LPE9403 (6GK5998-3GS00-2AC2)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE LPE9403 (6GK5998-3GS00-2AC2)', 'product_id': 'CSAFPID-0007', 'product_identification_helper': {'model_numbers': ['6GK5998-3GS00-2AC2']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE LPE9413 (6GK5998-3GS01-2AC2)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE LPE9413 (6GK5998-3GS01-2AC2)', 'product_id': 'CSAFPID-0008', 'product_identification_helper': {'model_numbers': ['6GK5998-3GS01-2AC2']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE LPE9433 (6GK5998-3GS11-2AC2)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE LPE9433 (6GK5998-3GS11-2AC2)', 'product_id': 'CSAFPID-0009', 'product_identification_helper': {'model_numbers': ['6GK5998-3GS11-2AC2']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE M804PB (6GK5804-0AP00-2AA2)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE M804PB (6GK5804-0AP00-2AA2)', 'product_id': 'CSAFPID-0010', 'product_identification_helper': {'model_numbers': ['6GK5804-0AP00-2AA2']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE M812-1 ADSL-Router family', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE M812-1 ADSL-Router family', 'product_id': 'CSAFPID-0011'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE M816-1 ADSL-Router family', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE M816-1 ADSL-Router family', 'product_id': 'CSAFPID-0012'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE M826-2 SHDSL-Router (6GK5826-2AB00-2AB2)', 'product_id': 'CSAFPID-0013', 'product_identification_helper': {'model_numbers': ['6GK5826-2AB00-2AB2']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE M874-2 (6GK5874-2AA00-2AA2)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE M874-2 (6GK5874-2AA00-2AA2)', 'product_id': 'CSAFPID-0014', 'product_identification_helper': {'model_numbers': ['6GK5874-2AA00-2AA2']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE M874-3 (6GK5874-3AA00-2AA2)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE M874-3 (6GK5874-3AA00-2AA2)', 'product_id': 'CSAFPID-0015', 'product_identification_helper': {'model_numbers': ['6GK5874-3AA00-2AA2']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE M874-3 3G-Router (CN) (6GK5874-3AA00-2FA2)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE M874-3 3G-Router (CN) (6GK5874-3AA00-2FA2)', 'product_id': 'CSAFPID-0016', 'product_identification_helper': {'model_numbers': ['6GK5874-3AA00-2FA2']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE M876-3 (6GK5876-3AA02-2BA2)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE M876-3 (6GK5876-3AA02-2BA2)', 'product_id': 'CSAFPID-0017', 'product_identification_helper': {'model_numbers': ['6GK5876-3AA02-2BA2']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE M876-3 (ROK) (6GK5876-3AA02-2EA2)', 'product_id': 'CSAFPID-0018', 'product_identification_helper': {'model_numbers': ['6GK5876-3AA02-2EA2']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE M876-4 (6GK5876-4AA10-2BA2)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE M876-4 (6GK5876-4AA10-2BA2)', 'product_id': 'CSAFPID-0019', 'product_identification_helper': {'model_numbers': ['6GK5876-4AA10-2BA2']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE M876-4 (EU) (6GK5876-4AA00-2BA2)', 'product_id': 'CSAFPID-0020', 'product_identification_helper': {'model_numbers': ['6GK5876-4AA00-2BA2']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE M876-4 (NAM) (6GK5876-4AA00-2DA2)', 'product_id': 'CSAFPID-0021', 'product_identification_helper': {'model_numbers': ['6GK5876-4AA00-2DA2']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE MUB852-1 (A1) (6GK5852-1EA10-1AA1)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE MUB852-1 (A1) (6GK5852-1EA10-1AA1)', 'product_id': 'CSAFPID-0022', 'product_identification_helper': {'model_numbers': ['6GK5852-1EA10-1AA1']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE MUB852-1 (B1) (6GK5852-1EA10-1BA1)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE MUB852-1 (B1) (6GK5852-1EA10-1BA1)', 'product_id': 'CSAFPID-0023', 'product_identification_helper': {'model_numbers': ['6GK5852-1EA10-1BA1']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE MUM853-1 (A1) (6GK5853-2EA10-2AA1)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE MUM853-1 (A1) (6GK5853-2EA10-2AA1)', 'product_id': 'CSAFPID-0024', 'product_identification_helper': {'model_numbers': ['6GK5853-2EA10-2AA1']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE MUM853-1 (B1) (6GK5853-2EA10-2BA1)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE MUM853-1 (B1) (6GK5853-2EA10-2BA1)', 'product_id': 'CSAFPID-0025', 'product_identification_helper': {'model_numbers': ['6GK5853-2EA10-2BA1']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE MUM853-1 (EU) (6GK5853-2EA00-2DA1)', 'product_id': 'CSAFPID-0026', 'product_identification_helper': {'model_numbers': ['6GK5853-2EA00-2DA1']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE MUM856-1 (A1) (6GK5856-2EA10-3AA1)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE MUM856-1 (A1) (6GK5856-2EA10-3AA1)', 'product_id': 'CSAFPID-0027', 'product_identification_helper': {'model_numbers': ['6GK5856-2EA10-3AA1']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE MUM856-1 (B1) (6GK5856-2EA10-3BA1)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE MUM856-1 (B1) (6GK5856-2EA10-3BA1)', 'product_id': 'CSAFPID-0028', 'product_identification_helper': {'model_numbers': ['6GK5856-2EA10-3BA1']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE MUM856-1 (CN) (6GK5856-2EA00-3FA1)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE MUM856-1 (CN) (6GK5856-2EA00-3FA1)', 'product_id': 'CSAFPID-0029', 'product_identification_helper': {'model_numbers': ['6GK5856-2EA00-3FA1']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE MUM856-1 (EU) (6GK5856-2EA00-3DA1)', 'product_id': 'CSAFPID-0030', 'product_identification_helper': {'model_numbers': ['6GK5856-2EA00-3DA1']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE MUM856-1 (RoW) (6GK5856-2EA00-3AA1)', 'product_id': 'CSAFPID-0031', 'product_identification_helper': {'model_numbers': ['6GK5856-2EA00-3AA1']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE S615 EEC LAN-Router (6GK5615-0AA01-2AA2)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE S615 EEC LAN-Router (6GK5615-0AA01-2AA2)', 'product_id': 'CSAFPID-0032', 'product_identification_helper': {'model_numbers': ['6GK5615-0AA01-2AA2']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE S615 LAN-Router (6GK5615-0AA00-2AA2)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE S615 LAN-Router (6GK5615-0AA00-2AA2)', 'product_id': 'CSAFPID-0033', 'product_identification_helper': {'model_numbers': ['6GK5615-0AA00-2AA2']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE SC622-2C (6GK5622-2GS00-2AC2)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE SC622-2C (6GK5622-2GS00-2AC2)', 'product_id': 'CSAFPID-0034', 'product_identification_helper': {'model_numbers': ['6GK5622-2GS00-2AC2']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE SC626-2C (6GK5626-2GS00-2AC2)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE SC626-2C (6GK5626-2GS00-2AC2)', 'product_id': 'CSAFPID-0035', 'product_identification_helper': {'model_numbers': ['6GK5626-2GS00-2AC2']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE SC632-2C (6GK5632-2GS00-2AC2)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE SC632-2C (6GK5632-2GS00-2AC2)', 'product_id': 'CSAFPID-0036', 'product_identification_helper': {'model_numbers': ['6GK5632-2GS00-2AC2']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE SC636-2C (6GK5636-2GS00-2AC2)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE SC636-2C (6GK5636-2GS00-2AC2)', 'product_id': 'CSAFPID-0037', 'product_identification_helper': {'model_numbers': ['6GK5636-2GS00-2AC2']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE SC642-2C (6GK5642-2GS00-2AC2)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE SC642-2C (6GK5642-2GS00-2AC2)', 'product_id': 'CSAFPID-0038', 'product_identification_helper': {'model_numbers': ['6GK5642-2GS00-2AC2']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE SC646-2C (6GK5646-2GS00-2AC2)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE SC646-2C (6GK5646-2GS00-2AC2)', 'product_id': 'CSAFPID-0039', 'product_identification_helper': {'model_numbers': ['6GK5646-2GS00-2AC2']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0)', 'product_id': 'CSAFPID-0040', 'product_identification_helper': {'model_numbers': ['6GK5762-1AJ00-6AA0']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE WAM763-1 (6GK5763-1AL00-7DA0)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE WAM763-1 (6GK5763-1AL00-7DA0)', 'product_id': 'CSAFPID-0041', 'product_identification_helper': {'model_numbers': ['6GK5763-1AL00-7DA0']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE WAM763-1 (ME) (6GK5763-1AL00-7DC0)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE WAM763-1 (ME) (6GK5763-1AL00-7DC0)', 'product_id': 'CSAFPID-0042', 'product_identification_helper': {'model_numbers': ['6GK5763-1AL00-7DC0']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE WAM763-1 (US) (6GK5763-1AL00-7DB0)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE WAM763-1 (US) (6GK5763-1AL00-7DB0)', 'product_id': 'CSAFPID-0043', 'product_identification_helper': {'model_numbers': ['6GK5763-1AL00-7DB0']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE WAM766-1 (6GK5766-1GE00-7DA0)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE WAM766-1 (6GK5766-1GE00-7DA0)', 'product_id': 'CSAFPID-0044', 'product_identification_helper': {'model_numbers': ['6GK5766-1GE00-7DA0']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE WAM766-1 (ME) (6GK5766-1GE00-7DC0)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE WAM766-1 (ME) (6GK5766-1GE00-7DC0)', 'product_id': 'CSAFPID-0045', 'product_identification_helper': {'model_numbers': ['6GK5766-1GE00-7DC0']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE WAM766-1 (US) (6GK5766-1GE00-7DB0)', 'product_id': 'CSAFPID-0046', 'product_identification_helper': {'model_numbers': ['6GK5766-1GE00-7DB0']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TA0)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE WAM766-1 EEC (6GK5766-1GE00-7TA0)', 'product_id': 'CSAFPID-0047', 'product_identification_helper': {'model_numbers': ['6GK5766-1GE00-7TA0']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE WAM766-1 EEC (ME) (6GK5766-1GE00-7TC0)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE WAM766-1 EEC (ME) (6GK5766-1GE00-7TC0)', 'product_id': 'CSAFPID-0048', 'product_identification_helper': {'model_numbers': ['6GK5766-1GE00-7TC0']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE WAM766-1 EEC (US) (6GK5766-1GE00-7TB0)', 'product_id': 'CSAFPID-0049', 'product_identification_helper': {'model_numbers': ['6GK5766-1GE00-7TB0']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE WUB762-1 (6GK5762-1AJ00-1AA0)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE WUB762-1 (6GK5762-1AJ00-1AA0)', 'product_id': 'CSAFPID-0050', 'product_identification_helper': {'model_numbers': ['6GK5762-1AJ00-1AA0']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE WUB762-1 iFeatures (6GK5762-1AJ00-2AA0)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE WUB762-1 iFeatures (6GK5762-1AJ00-2AA0)', 'product_id': 'CSAFPID-0051', 'product_identification_helper': {'model_numbers': ['6GK5762-1AJ00-2AA0']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE WUM763-1 (6GK5763-1AL00-3AA0)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE WUM763-1 (6GK5763-1AL00-3AA0)', 'product_id': 'CSAFPID-0052', 'product_identification_helper': {'model_numbers': ['6GK5763-1AL00-3AA0']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE WUM763-1 (6GK5763-1AL00-3DA0)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE WUM763-1 (6GK5763-1AL00-3DA0)', 'product_id': 'CSAFPID-0053', 'product_identification_helper': {'model_numbers': ['6GK5763-1AL00-3DA0']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE WUM763-1 (US) (6GK5763-1AL00-3AB0)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE WUM763-1 (US) (6GK5763-1AL00-3AB0)', 'product_id': 'CSAFPID-0054', 'product_identification_helper': {'model_numbers': ['6GK5763-1AL00-3AB0']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE WUM763-1 (US) (6GK5763-1AL00-3DB0)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE WUM763-1 (US) (6GK5763-1AL00-3DB0)', 'product_id': 'CSAFPID-0055', 'product_identification_helper': {'model_numbers': ['6GK5763-1AL00-3DB0']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE WUM766-1 (6GK5766-1GE00-3DA0)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE WUM766-1 (6GK5766-1GE00-3DA0)', 'product_id': 'CSAFPID-0056', 'product_identification_helper': {'model_numbers': ['6GK5766-1GE00-3DA0']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE WUM766-1 (ME) (6GK5766-1GE00-3DC0)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE WUM766-1 (ME) (6GK5766-1GE00-3DC0)', 'product_id': 'CSAFPID-0057', 'product_identification_helper': {'model_numbers': ['6GK5766-1GE00-3DC0']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE WUM766-1 (USA) (6GK5766-1GE00-3DB0)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE WUM766-1 (USA) (6GK5766-1GE00-3DB0)', 'product_id': 'CSAFPID-0058', 'product_identification_helper': {'model_numbers': ['6GK5766-1GE00-3DB0']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE XC316-8 (6GK5324-8TS00-2AC2)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE XC316-8 (6GK5324-8TS00-2AC2)', 'product_id': 'CSAFPID-0059', 'product_identification_helper': {'model_numbers': ['6GK5324-8TS00-2AC2']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE XC324-4 (6GK5328-4TS00-2AC2)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE XC324-4 (6GK5328-4TS00-2AC2)', 'product_id': 'CSAFPID-0060', 'product_identification_helper': {'model_numbers': ['6GK5328-4TS00-2AC2']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE XC324-4 EEC (6GK5328-4TS00-2EC2)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE XC324-4 EEC (6GK5328-4TS00-2EC2)', 'product_id': 'CSAFPID-0061', 'product_identification_helper': {'model_numbers': ['6GK5328-4TS00-2EC2']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE XC332 (6GK5332-0GA00-2AC2)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE XC332 (6GK5332-0GA00-2AC2)', 'product_id': 'CSAFPID-0062', 'product_identification_helper': {'model_numbers': ['6GK5332-0GA00-2AC2']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE XC416-8 (6GK5424-8TR00-2AC2)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE XC416-8 (6GK5424-8TR00-2AC2)', 'product_id': 'CSAFPID-0063', 'product_identification_helper': {'model_numbers': ['6GK5424-8TR00-2AC2']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE XC424-4 (6GK5428-4TR00-2AC2)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE XC424-4 (6GK5428-4TR00-2AC2)', 'product_id': 'CSAFPID-0064', 'product_identification_helper': {'model_numbers': ['6GK5428-4TR00-2AC2']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE XC432 (6GK5432-0GR00-2AC2)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE XC432 (6GK5432-0GR00-2AC2)', 'product_id': 'CSAFPID-0065', 'product_identification_helper': {'model_numbers': ['6GK5432-0GR00-2AC2']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE XR302-32 (6GK5334-5TS00-2AR3)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE XR302-32 (6GK5334-5TS00-2AR3)', 'product_id': 'CSAFPID-0066', 'product_identification_helper': {'model_numbers': ['6GK5334-5TS00-2AR3']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE XR302-32 (6GK5334-5TS00-3AR3)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE XR302-32 (6GK5334-5TS00-3AR3)', 'product_id': 'CSAFPID-0067', 'product_identification_helper': {'model_numbers': ['6GK5334-5TS00-3AR3']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE XR302-32 (6GK5334-5TS00-4AR3)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE XR302-32 (6GK5334-5TS00-4AR3)', 'product_id': 'CSAFPID-0068', 'product_identification_helper': {'model_numbers': ['6GK5334-5TS00-4AR3']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE XR322-12 (6GK5334-3TS00-2AR3)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE XR322-12 (6GK5334-3TS00-2AR3)', 'product_id': 'CSAFPID-0069', 'product_identification_helper': {'model_numbers': ['6GK5334-3TS00-2AR3']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE XR322-12 (6GK5334-3TS00-3AR3)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE XR322-12 (6GK5334-3TS00-3AR3)', 'product_id': 'CSAFPID-0070', 'product_identification_helper': {'model_numbers': ['6GK5334-3TS00-3AR3']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE XR322-12 (6GK5334-3TS00-4AR3)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE XR322-12 (6GK5334-3TS00-4AR3)', 'product_id': 'CSAFPID-0071', 'product_identification_helper': {'model_numbers': ['6GK5334-3TS00-4AR3']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE XR326-8 (6GK5334-2TS00-2AR3)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE XR326-8 (6GK5334-2TS00-2AR3)', 'product_id': 'CSAFPID-0072', 'product_identification_helper': {'model_numbers': ['6GK5334-2TS00-2AR3']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE XR326-8 (6GK5334-2TS00-3AR3)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE XR326-8 (6GK5334-2TS00-3AR3)', 'product_id': 'CSAFPID-0073', 'product_identification_helper': {'model_numbers': ['6GK5334-2TS00-3AR3']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE XR326-8 (6GK5334-2TS00-4AR3)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE XR326-8 (6GK5334-2TS00-4AR3)', 'product_id': 'CSAFPID-0074', 'product_identification_helper': {'model_numbers': ['6GK5334-2TS00-4AR3']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE XR326-8 EEC (6GK5334-2TS00-2ER3)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE XR326-8 EEC (6GK5334-2TS00-2ER3)', 'product_id': 'CSAFPID-0075', 'product_identification_helper': {'model_numbers': ['6GK5334-2TS00-2ER3']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE XR502-32 (6GK5534-5TR00-2AR3)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE XR502-32 (6GK5534-5TR00-2AR3)', 'product_id': 'CSAFPID-0076', 'product_identification_helper': {'model_numbers': ['6GK5534-5TR00-2AR3']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE XR502-32 (6GK5534-5TR00-3AR3)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE XR502-32 (6GK5534-5TR00-3AR3)', 'product_id': 'CSAFPID-0077', 'product_identification_helper': {'model_numbers': ['6GK5534-5TR00-3AR3']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE XR502-32 (6GK5534-5TR00-4AR3)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE XR502-32 (6GK5534-5TR00-4AR3)', 'product_id': 'CSAFPID-0078', 'product_identification_helper': {'model_numbers': ['6GK5534-5TR00-4AR3']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE XR522-12 (6GK5534-3TR00-2AR3)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE XR522-12 (6GK5534-3TR00-2AR3)', 'product_id': 'CSAFPID-0079', 'product_identification_helper': {'model_numbers': ['6GK5534-3TR00-2AR3']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE XR522-12 (6GK5534-3TR00-3AR3)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE XR522-12 (6GK5534-3TR00-3AR3)', 'product_id': 'CSAFPID-0080', 'product_identification_helper': {'model_numbers': ['6GK5534-3TR00-3AR3']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE XR522-12 (6GK5534-3TR00-4AR3)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE XR522-12 (6GK5534-3TR00-4AR3)', 'product_id': 'CSAFPID-0081', 'product_identification_helper': {'model_numbers': ['6GK5534-3TR00-4AR3']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE XR524-8WG (6GK5532-2SR00-2AR3)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE XR524-8WG (6GK5532-2SR00-2AR3)', 'product_id': 'CSAFPID-0082', 'product_identification_helper': {'model_numbers': ['6GK5532-2SR00-2AR3']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE XR524-8WG (6GK5532-2SR00-2RR3)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE XR524-8WG (6GK5532-2SR00-2RR3)', 'product_id': 'CSAFPID-0083', 'product_identification_helper': {'model_numbers': ['6GK5532-2SR00-2RR3']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE XR524-8WG (6GK5532-2SR00-3AR3)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE XR524-8WG (6GK5532-2SR00-3AR3)', 'product_id': 'CSAFPID-0084', 'product_identification_helper': {'model_numbers': ['6GK5532-2SR00-3AR3']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE XR524-8WG (6GK5532-2SR00-3RR3)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE XR524-8WG (6GK5532-2SR00-3RR3)', 'product_id': 'CSAFPID-0085', 'product_identification_helper': {'model_numbers': ['6GK5532-2SR00-3RR3']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE XR526-8 (6GK5534-2TR00-2AR3)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE XR526-8 (6GK5534-2TR00-2AR3)', 'product_id': 'CSAFPID-0086', 'product_identification_helper': {'model_numbers': ['6GK5534-2TR00-2AR3']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE XR526-8 (6GK5534-2TR00-3AR3)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE XR526-8 (6GK5534-2TR00-3AR3)', 'product_id': 'CSAFPID-0087', 'product_identification_helper': {'model_numbers': ['6GK5534-2TR00-3AR3']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCALANCE XR526-8 (6GK5534-2TR00-4AR3)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SCALANCE XR526-8 (6GK5534-2TR00-4AR3)', 'product_id': 'CSAFPID-0088', 'product_identification_helper': {'model_numbers': ['6GK5534-2TR00-4AR3']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Shopfloor IT Suite', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Shopfloor IT Suite', 'product_id': 'CSAFPID-0089'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIDIS Prime', 'branches': [{'name': 'vers:intdot/>=4.0.700', 'product': {'name': 'SIDIS Prime', 'product_id': 'CSAFPID-0090'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Siemens OPC UA Modelling Editor (SiOME)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Siemens OPC UA Modelling Editor (SiOME)', 'product_id': 'CSAFPID-0091'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC Comfort/Mobile RT', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIMATIC Comfort/Mobile RT', 'product_id': 'CSAFPID-0092'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC eaSie Core Package (6DL5424-0AX00-0AV8)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIMATIC eaSie Core Package (6DL5424-0AX00-0AV8)', 'product_id': 'CSAFPID-0093', 'product_identification_helper': {'model_numbers': ['6DL5424-0AX00-0AV8']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC eaSie PCS 7 Skill Package (6DL5424-0BX00-0AV8)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIMATIC eaSie PCS 7 Skill Package (6DL5424-0BX00-0AV8)', 'product_id': 'CSAFPID-0094', 'product_identification_helper': {'model_numbers': ['6DL5424-0BX00-0AV8']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC HMI Basic Panels', 'branches': [{'name': 'vers:intdot/<17.0.9', 'product': {'name': 'SIMATIC HMI Basic Panels', 'product_id': 'CSAFPID-0095'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC HMI Comfort Panels', 'branches': [{'name': 'vers:intdot/<17.0.9', 'product': {'name': 'SIMATIC HMI Comfort Panels', 'product_id': 'CSAFPID-0096'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC HMI Mobile Panels', 'branches': [{'name': 'vers:intdot/<17.0.9', 'product': {'name': 'SIMATIC HMI Mobile Panels', 'product_id': 'CSAFPID-0097'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC IOT2050 (6ES7647-0BA00-1YA2)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIMATIC IOT2050 (6ES7647-0BA00-1YA2)', 'product_id': 'CSAFPID-0098', 'product_identification_helper': {'model_numbers': ['6ES7647-0BA00-1YA2']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC IPC BX-21A', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIMATIC IPC BX-21A', 'product_id': 'CSAFPID-0099'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC IPC MD-57A', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIMATIC IPC MD-57A', 'product_id': 'CSAFPID-0100'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC IPC ORCLA', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIMATIC IPC ORCLA', 'product_id': 'CSAFPID-0101'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC PDM V9.3', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIMATIC PDM V9.3', 'product_id': 'CSAFPID-0102'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC RTLS Locating Manager (6GT2780-0DA00)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIMATIC RTLS Locating Manager (6GT2780-0DA00)', 'product_id': 'CSAFPID-0103', 'product_identification_helper': {'model_numbers': ['6GT2780-0DA00']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC RTLS Locating Manager (6GT2780-0DA10)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIMATIC RTLS Locating Manager (6GT2780-0DA10)', 'product_id': 'CSAFPID-0104', 'product_identification_helper': {'model_numbers': ['6GT2780-0DA10']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC RTLS Locating Manager (6GT2780-0DA20)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIMATIC RTLS Locating Manager (6GT2780-0DA20)', 'product_id': 'CSAFPID-0105', 'product_identification_helper': {'model_numbers': ['6GT2780-0DA20']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC RTLS Locating Manager (6GT2780-0DA30)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIMATIC RTLS Locating Manager (6GT2780-0DA30)', 'product_id': 'CSAFPID-0106', 'product_identification_helper': {'model_numbers': ['6GT2780-0DA30']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC RTLS Locating Manager (6GT2780-1EA10)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIMATIC RTLS Locating Manager (6GT2780-1EA10)', 'product_id': 'CSAFPID-0107', 'product_identification_helper': {'model_numbers': ['6GT2780-1EA10']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC RTLS Locating Manager (6GT2780-1EA20)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIMATIC RTLS Locating Manager (6GT2780-1EA20)', 'product_id': 'CSAFPID-0108', 'product_identification_helper': {'model_numbers': ['6GT2780-1EA20']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC RTLS Locating Manager (6GT2780-1EA30)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIMATIC RTLS Locating Manager (6GT2780-1EA30)', 'product_id': 'CSAFPID-0109', 'product_identification_helper': {'model_numbers': ['6GT2780-1EA30']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC STEP 7 V5', 'branches': [{'name': 'vers:intdot/<5.7.4', 'product': {'name': 'SIMATIC STEP 7 V5', 'product_id': 'CSAFPID-0110'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC Target', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIMATIC Target', 'product_id': 'CSAFPID-0111'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC WinCC OA V3.19', 'branches': [{'name': 'vers:intdot/<3.19.024', 'product': {'name': 'SIMATIC WinCC OA V3.19', 'product_id': 'CSAFPID-0112'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC WinCC OA V3.20', 'branches': [{'name': 'vers:intdot/<3.20.012', 'product': {'name': 'SIMATIC WinCC OA V3.20', 'product_id': 'CSAFPID-0113'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC WinCC OA V3.21', 'branches': [{'name': 'vers:intdot/<3.21.02', 'product': {'name': 'SIMATIC WinCC OA V3.21', 'product_id': 'CSAFPID-0114'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC WinCC Runtime Advanced V17', 'branches': [{'name': 'vers:intdot/<17.0.9', 'product': {'name': 'SIMATIC WinCC Runtime Advanced V17', 'product_id': 'CSAFPID-0115'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC WinCC Unified Sequence', 'branches': [{'name': 'vers:intdot/<21', 'product': {'name': 'SIMATIC WinCC Unified Sequence', 'product_id': 'CSAFPID-0116'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC WinCC V7.5', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIMATIC WinCC V7.5', 'product_id': 'CSAFPID-0117'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC WinCC V8.0', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIMATIC WinCC V8.0', 'product_id': 'CSAFPID-0118'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC WinCC V8.1', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIMATIC WinCC V8.1', 'product_id': 'CSAFPID-0119'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMOTION OACAMGEN (6AU1820-3EA20-0AB0)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIMOTION OACAMGEN (6AU1820-3EA20-0AB0)', 'product_id': 'CSAFPID-0120', 'product_identification_helper': {'model_numbers': ['6AU1820-3EA20-0AB0']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMOVE Fleetmanager V3.1', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIMOVE Fleetmanager V3.1', 'product_id': 'CSAFPID-0121'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMOVE Fleetmanager V3.2', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIMOVE Fleetmanager V3.2', 'product_id': 'CSAFPID-0122'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMOVE Fleetmanager V3.3', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIMOVE Fleetmanager V3.3', 'product_id': 'CSAFPID-0123'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SINAMICS G200', 'branches': [{'name': 'vers:intdot/>=6.3', 'product': {'name': 'SINAMICS G200', 'product_id': 'CSAFPID-0124'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SINAMICS G220', 'branches': [{'name': 'vers:intdot/>=6.3', 'product': {'name': 'SINAMICS G220', 'product_id': 'CSAFPID-0125'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SINAMICS S200', 'branches': [{'name': 'vers:intdot/>=6.3', 'product': {'name': 'SINAMICS S200', 'product_id': 'CSAFPID-0126'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SINAMICS S210', 'branches': [{'name': 'vers:intdot/>=6.3', 'product': {'name': 'SINAMICS S210', 'product_id': 'CSAFPID-0127'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SINAMICS S220', 'branches': [{'name': 'vers:intdot/>=6.3', 'product': {'name': 'SINAMICS S220', 'product_id': 'CSAFPID-0128'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SINEC INS', 'branches': [{'name': 'vers:intdot/<1.0.2.5', 'product': {'name': 'SINEC INS', 'product_id': 'CSAFPID-0129'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SINEC NMS', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SINEC NMS', 'product_id': 'CSAFPID-0130'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SINEC Security Monitor', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SINEC Security Monitor', 'product_id': 'CSAFPID-0131'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SINUMERIK Access MyMachine /OPC UA', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SINUMERIK Access MyMachine /OPC UA', 'product_id': 'CSAFPID-0132'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPLANT', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPLANT', 'product_id': 'CSAFPID-0133'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SITRANS ASM IQ', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SITRANS ASM IQ', 'product_id': 'CSAFPID-0134'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SITRANS Soft Sensor Engine IQ (SITRANS SSE IQ)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SITRANS Soft Sensor Engine IQ (SITRANS SSE IQ)', 'product_id': 'CSAFPID-0135'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'User Management Component (UMC)', 'branches': [{'name': 'vers:intdot/<2.15.3.0', 'product': {'name': 'User Management Component (UMC)', 'product_id': 'CSAFPID-0136'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Visual Inspection Cockpit', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Visual Inspection Cockpit', 'product_id': 'CSAFPID-0137'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-15467', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'Issue summary: Parsing CMS AuthEnvelopedData message with maliciously\r\ncrafted AEAD parameters can trigger a stack buffer overflow.\r\nImpact summary: A stack buffer overflow may lead to a crash, causing Denial\r\nof Service, or potentially remote code execution.\r\n\r\nWhen parsing CMS AuthEnvelopedData structures that use AEAD ciphers such as\r\nAES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is\r\ncopied into a fixed-size stack buffer without verifying that its length fits\r\nthe destination. An attacker can supply a crafted CMS message with an\r\noversized IV, causing a stack-based out-of-bounds write before any\r\nauthentication or tag verification occurs.\r\n\r\nApplications and services that parse untrusted CMS or PKCS#7 content using\r\nAEAD ciphers (e.g., S/MIME AuthEnvelopedData with AES-GCM) are vulnerable.\r\nBecause the overflow occurs prior to authentication, no valid key material\r\nis required to trigger it. While exploitability to remote code execution\r\ndepends on platform and toolchain mitigations, the stack-based write\r\nprimitive represents a severe risk.\r\n\r\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\r\nissue, as the CMS implementation is outside the OpenSSL FIPS module\r\nboundary.\r\n\r\nOpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.\r\n\r\nOpenSSL 1.1.1 and 1.0.2 are not affected by this issue.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2025-15467', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0028', 'CSAFPID-0029', 'CSAFPID-0030', 'CSAFPID-0031', 'CSAFPID-0032', 'CSAFPID-0033', 'CSAFPID-0034', 'CSAFPID-0035', 'CSAFPID-0036', 'CSAFPID-0037', 'CSAFPID-0038', 'CSAFPID-0039', 'CSAFPID-0040', 'CSAFPID-0041', 'CSAFPID-0042', 'CSAFPID-0043', 'CSAFPID-0044', 'CSAFPID-0045', 'CSAFPID-0046', 'CSAFPID-0047', 'CSAFPID-0048', 'CSAFPID-0049', 'CSAFPID-0050', 'CSAFPID-0051', 'CSAFPID-0052', 'CSAFPID-0053', 'CSAFPID-0054', 'CSAFPID-0055', 'CSAFPID-0056', 'CSAFPID-0057', 'CSAFPID-0058', 'CSAFPID-0059', 'CSAFPID-0060', 'CSAFPID-0061', 'CSAFPID-0062', 'CSAFPID-0063', 'CSAFPID-0064', 'CSAFPID-0065', 'CSAFPID-0066', 'CSAFPID-0067', 'CSAFPID-0068', 'CSAFPID-0069', 'CSAFPID-0070', 'CSAFPID-0071', 'CSAFPID-0072', 'CSAFPID-0073', 'CSAFPID-0074', 'CSAFPID-0075', 'CSAFPID-0076', 'CSAFPID-0077', 'CSAFPID-0078', 'CSAFPID-0079', 'CSAFPID-0080', 'CSAFPID-0081', 'CSAFPID-0082', 'CSAFPID-0083', 'CSAFPID-0084', 'CSAFPID-0085', 'CSAFPID-0086', 'CSAFPID-0087', 'CSAFPID-0088', 'CSAFPID-0089', 'CSAFPID-0090', 'CSAFPID-0091', 'CSAFPID-0092', 'CSAFPID-0093', 'CSAFPID-0094', 'CSAFPID-0095', 'CSAFPID-0096', 'CSAFPID-0097', 'CSAFPID-0098', 'CSAFPID-0099', 'CSAFPID-0100', 'CSAFPID-0101', 'CSAFPID-0102', 'CSAFPID-0103', 'CSAFPID-0104', 'CSAFPID-0105', 'CSAFPID-0106', 'CSAFPID-0107', 'CSAFPID-0108', 'CSAFPID-0109', 'CSAFPID-0110', 'CSAFPID-0111', 'CSAFPID-0112', 'CSAFPID-0113', 'CSAFPID-0114', 'CSAFPID-0115', 'CSAFPID-0116', 'CSAFPID-0117', 'CSAFPID-0118', 'CSAFPID-0119', 'CSAFPID-0120', 'CSAFPID-0121', 'CSAFPID-0122', 'CSAFPID-0123', 'CSAFPID-0124', 'CSAFPID-0125', 'CSAFPID-0126', 'CSAFPID-0127', 'CSAFPID-0128', 'CSAFPID-0129', 'CSAFPID-0130', 'CSAFPID-0131', 'CSAFPID-0132', 'CSAFPID-0133', 'CSAFPID-0134', 'CSAFPID-0135', 'CSAFPID-0136', 'CSAFPID-0137']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-15467', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'As a defense-in-depth measure, organizations may review whether affected systems are exposed to untrusted CMS/PKCS#7 content from external sources.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0028', 'CSAFPID-0029', 'CSAFPID-0030', 'CSAFPID-0031', 'CSAFPID-0032', 'CSAFPID-0033', 'CSAFPID-0034', 'CSAFPID-0035', 'CSAFPID-0036', 'CSAFPID-0037', 'CSAFPID-0038', 'CSAFPID-0039', 'CSAFPID-0040', 'CSAFPID-0041', 'CSAFPID-0042', 'CSAFPID-0043', 'CSAFPID-0044', 'CSAFPID-0045', 'CSAFPID-0046', 'CSAFPID-0047', 'CSAFPID-0048', 'CSAFPID-0049', 'CSAFPID-0050', 'CSAFPID-0051', 'CSAFPID-0052', 'CSAFPID-0053', 'CSAFPID-0054', 'CSAFPID-0055', 'CSAFPID-0056', 'CSAFPID-0057', 'CSAFPID-0058', 'CSAFPID-0059', 'CSAFPID-0060', 'CSAFPID-0061', 'CSAFPID-0062', 'CSAFPID-0063', 'CSAFPID-0064', 'CSAFPID-0065', 'CSAFPID-0066', 'CSAFPID-0067', 'CSAFPID-0068', 'CSAFPID-0069', 'CSAFPID-0070', 'CSAFPID-0071', 'CSAFPID-0072', 'CSAFPID-0073', 'CSAFPID-0074', 'CSAFPID-0075', 'CSAFPID-0076', 'CSAFPID-0077', 'CSAFPID-0078', 'CSAFPID-0079', 'CSAFPID-0080', 'CSAFPID-0081', 'CSAFPID-0082', 'CSAFPID-0083', 'CSAFPID-0084', 'CSAFPID-0085', 'CSAFPID-0086', 'CSAFPID-0087', 'CSAFPID-0088', 'CSAFPID-0089', 'CSAFPID-0090', 'CSAFPID-0091', 'CSAFPID-0092', 'CSAFPID-0093', 'CSAFPID-0094', 'CSAFPID-0095', 'CSAFPID-0096', 'CSAFPID-0097', 'CSAFPID-0098', 'CSAFPID-0099', 'CSAFPID-0100', 'CSAFPID-0101', 'CSAFPID-0102', 'CSAFPID-0103', 'CSAFPID-0104', 'CSAFPID-0105', 'CSAFPID-0106', 'CSAFPID-0107', 'CSAFPID-0108', 'CSAFPID-0109', 'CSAFPID-0110', 'CSAFPID-0111', 'CSAFPID-0112', 'CSAFPID-0113', 'CSAFPID-0114', 'CSAFPID-0115', 'CSAFPID-0116', 'CSAFPID-0117', 'CSAFPID-0118', 'CSAFPID-0119', 'CSAFPID-0120', 'CSAFPID-0121', 'CSAFPID-0122', 'CSAFPID-0123', 'CSAFPID-0124', 'CSAFPID-0125', 'CSAFPID-0126', 'CSAFPID-0127', 'CSAFPID-0128', 'CSAFPID-0129', 'CSAFPID-0130', 'CSAFPID-0131', 'CSAFPID-0132', 'CSAFPID-0133', 'CSAFPID-0134', 'CSAFPID-0135', 'CSAFPID-0136', 'CSAFPID-0137']}, {'details': 'Do not accept files from untrusted and unvalidated sources in the affected applications', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0028', 'CSAFPID-0029', 'CSAFPID-0030', 'CSAFPID-0031', 'CSAFPID-0032', 'CSAFPID-0033', 'CSAFPID-0034', 'CSAFPID-0035', 'CSAFPID-0036', 'CSAFPID-0037', 'CSAFPID-0038', 'CSAFPID-0039', 'CSAFPID-0040', 'CSAFPID-0041', 'CSAFPID-0042', 'CSAFPID-0043', 'CSAFPID-0044', 'CSAFPID-0045', 'CSAFPID-0046', 'CSAFPID-0047', 'CSAFPID-0048', 'CSAFPID-0049', 'CSAFPID-0050', 'CSAFPID-0051', 'CSAFPID-0052', 'CSAFPID-0053', 'CSAFPID-0054', 'CSAFPID-0055', 'CSAFPID-0056', 'CSAFPID-0057', 'CSAFPID-0058', 'CSAFPID-0059', 'CSAFPID-0060', 'CSAFPID-0061', 'CSAFPID-0062', 'CSAFPID-0063', 'CSAFPID-0064', 'CSAFPID-0065', 'CSAFPID-0066', 'CSAFPID-0067', 'CSAFPID-0068', 'CSAFPID-0069', 'CSAFPID-0070', 'CSAFPID-0071', 'CSAFPID-0072', 'CSAFPID-0073', 'CSAFPID-0074', 'CSAFPID-0075', 'CSAFPID-0076', 'CSAFPID-0077', 'CSAFPID-0078', 'CSAFPID-0079', 'CSAFPID-0080', 'CSAFPID-0081', 'CSAFPID-0082', 'CSAFPID-0083', 'CSAFPID-0084', 'CSAFPID-0085', 'CSAFPID-0086', 'CSAFPID-0087', 'CSAFPID-0088', 'CSAFPID-0089', 'CSAFPID-0090', 'CSAFPID-0091', 'CSAFPID-0092', 'CSAFPID-0093', 'CSAFPID-0094', 'CSAFPID-0095', 'CSAFPID-0096', 'CSAFPID-0097', 'CSAFPID-0098', 'CSAFPID-0099', 'CSAFPID-0100', 'CSAFPID-0101', 'CSAFPID-0102', 'CSAFPID-0103', 'CSAFPID-0104', 'CSAFPID-0105', 'CSAFPID-0106', 'CSAFPID-0107', 'CSAFPID-0108', 'CSAFPID-0109', 'CSAFPID-0110', 'CSAFPID-0111', 'CSAFPID-0112', 'CSAFPID-0113', 'CSAFPID-0114', 'CSAFPID-0115', 'CSAFPID-0116', 'CSAFPID-0117', 'CSAFPID-0118', 'CSAFPID-0119', 'CSAFPID-0120', 'CSAFPID-0121', 'CSAFPID-0122', 'CSAFPID-0123', 'CSAFPID-0124', 'CSAFPID-0125', 'CSAFPID-0126', 'CSAFPID-0127', 'CSAFPID-0128', 'CSAFPID-0129', 'CSAFPID-0130', 'CSAFPID-0131', 'CSAFPID-0132', 'CSAFPID-0133', 'CSAFPID-0134', 'CSAFPID-0135', 'CSAFPID-0136', 'CSAFPID-0137']}, {'details': 'Restrict the port at the host with the DeviceConnectionProxy to secure destinations', 'category': 'mitigation', 'product_ids': ['CSAFPID-0103', 'CSAFPID-0104', 'CSAFPID-0105', 'CSAFPID-0106', 'CSAFPID-0107', 'CSAFPID-0108', 'CSAFPID-0109']}, {'details': 'Securing the connected email server as follows:\n\n• Configure the email server to enforce encrypted communication (TLS/SSL) for all SMTP connections.\n\n• Restrict access to the email server to trusted systems only (e.g., by using firewall rules or IP allowlists).\n\n• Ensure strong authentication to access the email server.\n\n• Keep the email server software and underlying operating system up to date with the latest security patches.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0103']}, {'details': 'Securing the connected email server as follows:\n\n• Configure the email server to enforce encrypted communication (TLS/SSL) for all SMTP connections.\n\n• Restrict access to the email server to trusted systems only (e.g., by using firewall rules or IP allowlists).\n\n• Ensure strong authentication to access the email server.\n\n• Keep the email server software and underlying operating system up to date with the latest security patches.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0104', 'CSAFPID-0105', 'CSAFPID-0106', 'CSAFPID-0107', 'CSAFPID-0108', 'CSAFPID-0109']}, {'details': 'The hardening instructions mentioned in the products security concept should be followed', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0028', 'CSAFPID-0029', 'CSAFPID-0030', 'CSAFPID-0031', 'CSAFPID-0032', 'CSAFPID-0033', 'CSAFPID-0034', 'CSAFPID-0035', 'CSAFPID-0036', 'CSAFPID-0037', 'CSAFPID-0038', 'CSAFPID-0039', 'CSAFPID-0040', 'CSAFPID-0041', 'CSAFPID-0042', 'CSAFPID-0043', 'CSAFPID-0044', 'CSAFPID-0045', 'CSAFPID-0046', 'CSAFPID-0047', 'CSAFPID-0048', 'CSAFPID-0049', 'CSAFPID-0050', 'CSAFPID-0051', 'CSAFPID-0052', 'CSAFPID-0053', 'CSAFPID-0054', 'CSAFPID-0055', 'CSAFPID-0056', 'CSAFPID-0057', 'CSAFPID-0058', 'CSAFPID-0059', 'CSAFPID-0060', 'CSAFPID-0061', 'CSAFPID-0062', 'CSAFPID-0063', 'CSAFPID-0064', 'CSAFPID-0065', 'CSAFPID-0066', 'CSAFPID-0067', 'CSAFPID-0068', 'CSAFPID-0069', 'CSAFPID-0070', 'CSAFPID-0071', 'CSAFPID-0072', 'CSAFPID-0073', 'CSAFPID-0074', 'CSAFPID-0075', 'CSAFPID-0076', 'CSAFPID-0077', 'CSAFPID-0078', 'CSAFPID-0079', 'CSAFPID-0080', 'CSAFPID-0081', 'CSAFPID-0082', 'CSAFPID-0083', 'CSAFPID-0084', 'CSAFPID-0085', 'CSAFPID-0086', 'CSAFPID-0087', 'CSAFPID-0088', 'CSAFPID-0089', 'CSAFPID-0090', 'CSAFPID-0091', 'CSAFPID-0092', 'CSAFPID-0093', 'CSAFPID-0094', 'CSAFPID-0095', 'CSAFPID-0096', 'CSAFPID-0097', 'CSAFPID-0098', 'CSAFPID-0099', 'CSAFPID-0100', 'CSAFPID-0101', 'CSAFPID-0102', 'CSAFPID-0103', 'CSAFPID-0104', 'CSAFPID-0105', 'CSAFPID-0106', 'CSAFPID-0107', 'CSAFPID-0108', 'CSAFPID-0109', 'CSAFPID-0110', 'CSAFPID-0111', 'CSAFPID-0112', 'CSAFPID-0113', 'CSAFPID-0114', 'CSAFPID-0115', 'CSAFPID-0116', 'CSAFPID-0117', 'CSAFPID-0118', 'CSAFPID-0119', 'CSAFPID-0120', 'CSAFPID-0121', 'CSAFPID-0122', 'CSAFPID-0123', 'CSAFPID-0124', 'CSAFPID-0125', 'CSAFPID-0126', 'CSAFPID-0127', 'CSAFPID-0128', 'CSAFPID-0129', 'CSAFPID-0130', 'CSAFPID-0131', 'CSAFPID-0132', 'CSAFPID-0133', 'CSAFPID-0134', 'CSAFPID-0135', 'CSAFPID-0136', 'CSAFPID-0137']}, {'details': 'Currently no fix is planned', 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0117', 'CSAFPID-0118', 'CSAFPID-0119']}, {'details': 'Currently no fix is available', 'category': 'none_available', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0028', 'CSAFPID-0029', 'CSAFPID-0030', 'CSAFPID-0031', 'CSAFPID-0032', 'CSAFPID-0033', 'CSAFPID-0034', 'CSAFPID-0035', 'CSAFPID-0036', 'CSAFPID-0037', 'CSAFPID-0038', 'CSAFPID-0039', 'CSAFPID-0040', 'CSAFPID-0041', 'CSAFPID-0042', 'CSAFPID-0043', 'CSAFPID-0044', 'CSAFPID-0045', 'CSAFPID-0046', 'CSAFPID-0047', 'CSAFPID-0048', 'CSAFPID-0049', 'CSAFPID-0050', 'CSAFPID-0051', 'CSAFPID-0052', 'CSAFPID-0053', 'CSAFPID-0054', 'CSAFPID-0055', 'CSAFPID-0056', 'CSAFPID-0057', 'CSAFPID-0058', 'CSAFPID-0059', 'CSAFPID-0060', 'CSAFPID-0061', 'CSAFPID-0062', 'CSAFPID-0063', 'CSAFPID-0064', 'CSAFPID-0065', 'CSAFPID-0066', 'CSAFPID-0067', 'CSAFPID-0068', 'CSAFPID-0069', 'CSAFPID-0070', 'CSAFPID-0071', 'CSAFPID-0072', 'CSAFPID-0073', 'CSAFPID-0074', 'CSAFPID-0075', 'CSAFPID-0076', 'CSAFPID-0077', 'CSAFPID-0078', 'CSAFPID-0079', 'CSAFPID-0080', 'CSAFPID-0081', 'CSAFPID-0082', 'CSAFPID-0083', 'CSAFPID-0084', 'CSAFPID-0085', 'CSAFPID-0086', 'CSAFPID-0087', 'CSAFPID-0088', 'CSAFPID-0089', 'CSAFPID-0091', 'CSAFPID-0092', 'CSAFPID-0093', 'CSAFPID-0094', 'CSAFPID-0098', 'CSAFPID-0099', 'CSAFPID-0100', 'CSAFPID-0101', 'CSAFPID-0102', 'CSAFPID-0103', 'CSAFPID-0104', 'CSAFPID-0105', 'CSAFPID-0106', 'CSAFPID-0107', 'CSAFPID-0108', 'CSAFPID-0109', 'CSAFPID-0111', 'CSAFPID-0120', 'CSAFPID-0121', 'CSAFPID-0122', 'CSAFPID-0123', 'CSAFPID-0124', 'CSAFPID-0125', 'CSAFPID-0126', 'CSAFPID-0127', 'CSAFPID-0128', 'CSAFPID-0130', 'CSAFPID-0131', 'CSAFPID-0132', 'CSAFPID-0134', 'CSAFPID-0135', 'CSAFPID-0137']}, {'url': 'https://support.industry.siemens.com/cs/ww/en/view/109999722/', 'details': 'Update to V1.0 SP2 Update 5 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0129']}, {'url': 'https://docs.eu1.edge.siemens.cloud/release_notes/scope_of_delivery/scope_of_delivery.html', 'details': 'Update to V1.8.0 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://support.industry.siemens.com/cs/ww/en/view/109800912/', 'details': 'Update to V17 Update 9 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0115']}, {'url': 'https://support.industry.siemens.com/cs/ww/en/view/109825750/', 'details': 'Update to V17.9 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0095', 'CSAFPID-0096']}, {'url': 'https://support.industry.siemens.com/cs/ww/en/view/109825750/', 'details': 'Update to V17 Update 9 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0097']}, {'url': 'https://support.industry.siemens.com/cs/ww/en/view/110000730/', 'details': 'Update to V2.15.3.0 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0136']}, {'url': 'https://support.industry.siemens.com/cs/ww/en/view/109996963/', 'details': 'Update to V21 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0116']}, {'url': 'https://support.industry.siemens.com/cs/ww/en/view/110000400/', 'details': 'Update to V3.19 P024 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0112']}, {'url': 'https://support.industry.siemens.com/cs/ww/en/view/110000657/', 'details': 'Update to V3.20 P012 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0113']}, {'url': 'https://support.industry.siemens.com/cs/ww/en/view/110000985/', 'details': 'Update to V3.21 P02 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0114']}, {'url': 'https://docs.eu1.edge.siemens.cloud/release_notes/scope_of_delivery/scope_of_delivery.html', 'details': 'Update to V3.3.2 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://support.industry.siemens.com/cs/ww/en/view/109991080/', 'details': 'Update to V5.7 SP4 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0110']}, {'details': 'Contact customer support siplant-support.de@siemens.com', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0133']}, {'details': 'Contact customer support', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0090']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0028', 'CSAFPID-0029', 'CSAFPID-0030', 'CSAFPID-0031', 'CSAFPID-0032', 'CSAFPID-0033', 'CSAFPID-0034', 'CSAFPID-0035', 'CSAFPID-0036', 'CSAFPID-0037', 'CSAFPID-0038', 'CSAFPID-0039', 'CSAFPID-0040', 'CSAFPID-0041', 'CSAFPID-0042', 'CSAFPID-0043', 'CSAFPID-0044', 'CSAFPID-0045', 'CSAFPID-0046', 'CSAFPID-0047', 'CSAFPID-0048', 'CSAFPID-0049', 'CSAFPID-0050', 'CSAFPID-0051', 'CSAFPID-0052', 'CSAFPID-0053', 'CSAFPID-0054', 'CSAFPID-0055', 'CSAFPID-0056', 'CSAFPID-0057', 'CSAFPID-0058', 'CSAFPID-0059', 'CSAFPID-0060', 'CSAFPID-0061', 'CSAFPID-0062', 'CSAFPID-0063', 'CSAFPID-0064', 'CSAFPID-0065', 'CSAFPID-0066', 'CSAFPID-0067', 'CSAFPID-0068', 'CSAFPID-0069', 'CSAFPID-0070', 'CSAFPID-0071', 'CSAFPID-0072', 'CSAFPID-0073', 'CSAFPID-0074', 'CSAFPID-0075', 'CSAFPID-0076', 'CSAFPID-0077', 'CSAFPID-0078', 'CSAFPID-0079', 'CSAFPID-0080', 'CSAFPID-0081', 'CSAFPID-0082', 'CSAFPID-0083', 'CSAFPID-0084', 'CSAFPID-0085', 'CSAFPID-0086', 'CSAFPID-0087', 'CSAFPID-0088', 'CSAFPID-0089', 'CSAFPID-0090', 'CSAFPID-0091', 'CSAFPID-0092', 'CSAFPID-0093', 'CSAFPID-0094', 'CSAFPID-0095', 'CSAFPID-0096', 'CSAFPID-0097', 'CSAFPID-0098', 'CSAFPID-0099', 'CSAFPID-0100', 'CSAFPID-0101', 'CSAFPID-0102', 'CSAFPID-0103', 'CSAFPID-0104', 'CSAFPID-0105', 'CSAFPID-0106', 'CSAFPID-0107', 'CSAFPID-0108', 'CSAFPID-0109', 'CSAFPID-0110', 'CSAFPID-0111', 'CSAFPID-0112', 'CSAFPID-0113', 'CSAFPID-0114', 'CSAFPID-0115', 'CSAFPID-0116', 'CSAFPID-0117', 'CSAFPID-0118', 'CSAFPID-0119', 'CSAFPID-0120', 'CSAFPID-0121', 'CSAFPID-0122', 'CSAFPID-0123', 'CSAFPID-0124', 'CSAFPID-0125', 'CSAFPID-0126', 'CSAFPID-0127', 'CSAFPID-0128', 'CSAFPID-0129', 'CSAFPID-0130', 'CSAFPID-0131', 'CSAFPID-0132', 'CSAFPID-0133', 'CSAFPID-0134', 'CSAFPID-0135', 'CSAFPID-0136', 'CSAFPID-0137']}}]} | |
ot | ICSA-26-174-02 | CVE-2025-40808 | Siemens SIPROTEC 5 Using DIGSI5 Protocol | 2026-06-09 03:00:00+03:00 | 2026-06-23 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-02.json | 2e64e09f0bfc6f00a1a56dcfdab78a846010dd10b5ca6443c451d16e69b253ed | 2026-06-24 07:37:39.992137+03:00 | 2026-06-24 07:37:39.992137+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'SIPROTEC 5 is vulnerable to arbitrary file uploads by authenticated users using the DIGSI 5 protocol.\nThis could allow an attacker to upload malicious configuration files, potentially causing a permanent denial of service condition.\n\nAs a mitigation measure, users of the CP050 and CP150 device models are advised to upgrade to version 9.90 or later. For CP300 device models, devices 7ST85 and 7ST86 are advised to upgrade to version 10.00 or later, while the remaining models should upgrade to version 9.90 or later. These versions introduce an allow-list feature that restricts arbitrary file uploads and reduces the risk associated with this vulnerability.\n\nSiemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.', 'title': 'Summary', 'category': 'summary'}, {'text': "Operators of critical power systems (e.g. TSOs or DSOs) worldwide are usually required by regulations to build resilience into the power grids by applying multi-level redundant secondary protection schemes. It is therefore recommended that the operators check whether appropriate resilient protection measures are in place. The risk of cyber incidents impacting the grid's reliability can thus be minimized by virtue of the grid design.\nSiemens strongly recommends applying the provided security updates using the corresponding tooling and documented procedures made available with the product. If supported by the product, an automated means to apply the security updates across multiple product instances may be used. Siemens strongly recommends prior validation of any security update before being applied, and supervision by trained staff of the update process in the target environment. \nAs a general security measure Siemens strongly recommends to protect network access with appropriate mechanisms (e.g. firewalls, segmentation, VPN). It is advised to configure the environment according to our operational guidelines in order to run the devices in a protected IT environment.\n\nRecommended security guidelines can be found at:\nhttps://www.siemens.com/gridsecurity", 'title': 'General Recommendations', 'category': 'general'}, {'text': 'For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.', 'title': 'Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of Siemens ProductCERT SSA-139483 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Critical Manufacturing, Transportation Systems, Energy, Healthcare and Public Health, Financial Services, Government Services and Facilities', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Germany', 'title': 'Company headquarters location', 'category': 'other'}], 'title': 'Siemens SIPROTEC 5 Using DIGSI5 Protocol', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-174-02', 'status': 'final', 'version': '2', 'generator': {'date': '2026-06-17T15:49:48.904844Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2026-06-09T00:00:00.000000Z', 'number': '1', 'summary': 'Publication Date', 'legacy_version': 'Initial'}, {'date': '2026-06-23T06:00:00.000000Z', 'number': '2', 'summary': 'Initial CISA Republication of Siemens ProductCERT SSA-139483 advisory', 'legacy_version': 'CISA Republication'}], 'current_release_date': '2026-06-23T06:00:00.000000Z', 'initial_release_date': '2026-06-09T00:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://cert-portal.siemens.com/productcert/csaf/ssa-139483.json', 'summary': 'SSA-139483: File Upload Vulnerability in SIPROTEC 5 Using DIGSI5 Protocol - CSAF Version', 'category': 'self'}, {'url': 'https://cert-portal.siemens.com/productcert/html/ssa-139483.html', 'summary': 'SSA-139483: File Upload Vulnerability in SIPROTEC 5 Using DIGSI5 Protocol - HTML Version', 'category': 'self'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-02.json', 'summary': 'ICS Advisory ICSA-26-174-02 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-02', 'summary': 'ICS Advisory ICSA-26-174-02 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported this vulnerability to CISA.', 'organization': 'Siemens ProductCERT'}]}, 'product_tree': {'branches': [{'name': 'Siemens', 'branches': [{'name': 'SIPROTEC 5 6MD84 (CP300)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 6MD84 (CP300)', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 6MD85 (CP200)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 6MD85 (CP200)', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 6MD85 (CP300)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 6MD85 (CP300)', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 6MD86 (CP200)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 6MD86 (CP200)', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 6MD86 (CP300)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 6MD86 (CP300)', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 6MD89 (CP300)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 6MD89 (CP300)', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 6MU85 (CP300)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 6MU85 (CP300)', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7KE85 (CP200)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7KE85 (CP200)', 'product_id': 'CSAFPID-0008'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7KE85 (CP300)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7KE85 (CP300)', 'product_id': 'CSAFPID-0009'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SA82 (CP100)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SA82 (CP100)', 'product_id': 'CSAFPID-0010'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SA82 (CP150)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SA82 (CP150)', 'product_id': 'CSAFPID-0011'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SA86 (CP200)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SA86 (CP200)', 'product_id': 'CSAFPID-0012'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SA86 (CP300)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SA86 (CP300)', 'product_id': 'CSAFPID-0013'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SA87 (CP200)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SA87 (CP200)', 'product_id': 'CSAFPID-0014'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SA87 (CP300)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SA87 (CP300)', 'product_id': 'CSAFPID-0015'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SD82 (CP100)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SD82 (CP100)', 'product_id': 'CSAFPID-0016'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SD82 (CP150)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SD82 (CP150)', 'product_id': 'CSAFPID-0017'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SD86 (CP200)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SD86 (CP200)', 'product_id': 'CSAFPID-0018'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SD86 (CP300)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SD86 (CP300)', 'product_id': 'CSAFPID-0019'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SD87 (CP200)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SD87 (CP200)', 'product_id': 'CSAFPID-0020'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SD87 (CP300)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SD87 (CP300)', 'product_id': 'CSAFPID-0021'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SJ81 (CP100)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SJ81 (CP100)', 'product_id': 'CSAFPID-0022'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SJ81 (CP150)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SJ81 (CP150)', 'product_id': 'CSAFPID-0023'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SJ82 (CP100)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SJ82 (CP100)', 'product_id': 'CSAFPID-0024'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SJ82 (CP150)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SJ82 (CP150)', 'product_id': 'CSAFPID-0025'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SJ85 (CP200)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SJ85 (CP200)', 'product_id': 'CSAFPID-0026'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SJ85 (CP300)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SJ85 (CP300)', 'product_id': 'CSAFPID-0027'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SJ86 (CP200)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SJ86 (CP200)', 'product_id': 'CSAFPID-0028'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SJ86 (CP300)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SJ86 (CP300)', 'product_id': 'CSAFPID-0029'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SK82 (CP100)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SK82 (CP100)', 'product_id': 'CSAFPID-0030'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SK82 (CP150)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SK82 (CP150)', 'product_id': 'CSAFPID-0031'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SK85 (CP200)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SK85 (CP200)', 'product_id': 'CSAFPID-0032'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SK85 (CP300)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SK85 (CP300)', 'product_id': 'CSAFPID-0033'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SL82 (CP100)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SL82 (CP100)', 'product_id': 'CSAFPID-0034'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SL82 (CP150)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SL82 (CP150)', 'product_id': 'CSAFPID-0035'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SL86 (CP200)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SL86 (CP200)', 'product_id': 'CSAFPID-0036'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SL86 (CP300)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SL86 (CP300)', 'product_id': 'CSAFPID-0037'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SL87 (CP200)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SL87 (CP200)', 'product_id': 'CSAFPID-0038'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SL87 (CP300)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SL87 (CP300)', 'product_id': 'CSAFPID-0039'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SS85 (CP200)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SS85 (CP200)', 'product_id': 'CSAFPID-0040'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SS85 (CP300)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SS85 (CP300)', 'product_id': 'CSAFPID-0041'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7ST85 (CP200)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7ST85 (CP200)', 'product_id': 'CSAFPID-0042'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7ST85 (CP300)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7ST85 (CP300)', 'product_id': 'CSAFPID-0043'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7ST86 (CP300)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7ST86 (CP300)', 'product_id': 'CSAFPID-0044'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SX82 (CP150)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SX82 (CP150)', 'product_id': 'CSAFPID-0045'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SX85 (CP300)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SX85 (CP300)', 'product_id': 'CSAFPID-0046'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7SY82 (CP150)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7SY82 (CP150)', 'product_id': 'CSAFPID-0047'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7UM85 (CP300)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7UM85 (CP300)', 'product_id': 'CSAFPID-0048'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7UT82 (CP100)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7UT82 (CP100)', 'product_id': 'CSAFPID-0049'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7UT82 (CP150)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7UT82 (CP150)', 'product_id': 'CSAFPID-0050'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7UT85 (CP200)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7UT85 (CP200)', 'product_id': 'CSAFPID-0051'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7UT85 (CP300)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7UT85 (CP300)', 'product_id': 'CSAFPID-0052'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7UT86 (CP200)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7UT86 (CP200)', 'product_id': 'CSAFPID-0053'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7UT86 (CP300)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7UT86 (CP300)', 'product_id': 'CSAFPID-0054'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7UT87 (CP200)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7UT87 (CP200)', 'product_id': 'CSAFPID-0055'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7UT87 (CP300)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7UT87 (CP300)', 'product_id': 'CSAFPID-0056'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7VE85 (CP300)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7VE85 (CP300)', 'product_id': 'CSAFPID-0057'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7VK87 (CP200)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7VK87 (CP200)', 'product_id': 'CSAFPID-0058'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7VK87 (CP300)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7VK87 (CP300)', 'product_id': 'CSAFPID-0059'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 7VU85 (CP300)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 7VU85 (CP300)', 'product_id': 'CSAFPID-0060'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIPROTEC 5 Compact 7SX800 (CP050)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIPROTEC 5 Compact 7SX800 (CP050)', 'product_id': 'CSAFPID-0061'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-40808', 'cwe': {'id': 'CWE-434', 'name': 'Unrestricted Upload of File with Dangerous Type'}, 'notes': [{'text': 'The affected application allows authenticated users to upload arbitrary files using DIGSI 5 protocol. This could allow an attacker to upload malicious configuration files, that could cause denial of service condition and potentially lead to code execution.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2025-40808', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0028', 'CSAFPID-0029', 'CSAFPID-0030', 'CSAFPID-0031', 'CSAFPID-0032', 'CSAFPID-0033', 'CSAFPID-0034', 'CSAFPID-0035', 'CSAFPID-0036', 'CSAFPID-0037', 'CSAFPID-0038', 'CSAFPID-0039', 'CSAFPID-0040', 'CSAFPID-0041', 'CSAFPID-0042', 'CSAFPID-0043', 'CSAFPID-0044', 'CSAFPID-0045', 'CSAFPID-0046', 'CSAFPID-0047', 'CSAFPID-0048', 'CSAFPID-0049', 'CSAFPID-0050', 'CSAFPID-0051', 'CSAFPID-0052', 'CSAFPID-0053', 'CSAFPID-0054', 'CSAFPID-0055', 'CSAFPID-0056', 'CSAFPID-0057', 'CSAFPID-0058', 'CSAFPID-0059', 'CSAFPID-0060', 'CSAFPID-0061']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-40808', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/434.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': '<br>\nUsers are advised to upgrade to V9.90 or later, which introduces an allow-list feature that restricts arbitrary file uploads', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0011', 'CSAFPID-0013', 'CSAFPID-0015', 'CSAFPID-0017', 'CSAFPID-0019', 'CSAFPID-0021', 'CSAFPID-0023', 'CSAFPID-0025', 'CSAFPID-0027', 'CSAFPID-0029', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0035', 'CSAFPID-0037', 'CSAFPID-0039', 'CSAFPID-0041', 'CSAFPID-0045', 'CSAFPID-0046', 'CSAFPID-0047', 'CSAFPID-0048', 'CSAFPID-0050', 'CSAFPID-0052', 'CSAFPID-0054', 'CSAFPID-0056', 'CSAFPID-0057', 'CSAFPID-0059', 'CSAFPID-0060', 'CSAFPID-0061']}, {'details': 'Apply password protection to all DIGSI connections to ensure secure communication', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0028', 'CSAFPID-0029', 'CSAFPID-0030', 'CSAFPID-0031', 'CSAFPID-0032', 'CSAFPID-0033', 'CSAFPID-0034', 'CSAFPID-0035', 'CSAFPID-0036', 'CSAFPID-0037', 'CSAFPID-0038', 'CSAFPID-0039', 'CSAFPID-0040', 'CSAFPID-0041', 'CSAFPID-0042', 'CSAFPID-0043', 'CSAFPID-0044', 'CSAFPID-0045', 'CSAFPID-0046', 'CSAFPID-0047', 'CSAFPID-0048', 'CSAFPID-0049', 'CSAFPID-0050', 'CSAFPID-0051', 'CSAFPID-0052', 'CSAFPID-0053', 'CSAFPID-0054', 'CSAFPID-0055', 'CSAFPID-0056', 'CSAFPID-0057', 'CSAFPID-0058', 'CSAFPID-0059', 'CSAFPID-0060', 'CSAFPID-0061']}, {'details': 'For DIGSI access provision your own certificates signed by your customer PKI as described in https://support.industry.siemens.com/cs/document/109768375', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0028', 'CSAFPID-0029', 'CSAFPID-0030', 'CSAFPID-0031', 'CSAFPID-0032', 'CSAFPID-0033', 'CSAFPID-0034', 'CSAFPID-0035', 'CSAFPID-0036', 'CSAFPID-0037', 'CSAFPID-0038', 'CSAFPID-0039', 'CSAFPID-0040', 'CSAFPID-0041', 'CSAFPID-0042', 'CSAFPID-0043', 'CSAFPID-0044', 'CSAFPID-0045', 'CSAFPID-0046', 'CSAFPID-0047', 'CSAFPID-0048', 'CSAFPID-0049', 'CSAFPID-0050', 'CSAFPID-0051', 'CSAFPID-0052', 'CSAFPID-0053', 'CSAFPID-0054', 'CSAFPID-0055', 'CSAFPID-0056', 'CSAFPID-0057', 'CSAFPID-0058', 'CSAFPID-0059', 'CSAFPID-0060', 'CSAFPID-0061']}, {'details': 'For the available devices [CP050, CP100, CP150 and CP300] , activate role based access control (RBAC) in the device (supported in SIPROTEC 5 firmware versions V7.80 and higher)', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0028', 'CSAFPID-0029', 'CSAFPID-0030', 'CSAFPID-0031', 'CSAFPID-0032', 'CSAFPID-0033', 'CSAFPID-0034', 'CSAFPID-0035', 'CSAFPID-0036', 'CSAFPID-0037', 'CSAFPID-0038', 'CSAFPID-0039', 'CSAFPID-0040', 'CSAFPID-0041', 'CSAFPID-0042', 'CSAFPID-0043', 'CSAFPID-0044', 'CSAFPID-0045', 'CSAFPID-0046', 'CSAFPID-0047', 'CSAFPID-0048', 'CSAFPID-0049', 'CSAFPID-0050', 'CSAFPID-0051', 'CSAFPID-0052', 'CSAFPID-0053', 'CSAFPID-0054', 'CSAFPID-0055', 'CSAFPID-0056', 'CSAFPID-0057', 'CSAFPID-0058', 'CSAFPID-0059', 'CSAFPID-0060', 'CSAFPID-0061']}, {'details': 'Users are advised to upgrade to V10.00 or later, which introduces an allow-list feature that restricts arbitrary file uploads', 'category': 'mitigation', 'product_ids': ['CSAFPID-0043', 'CSAFPID-0044']}, {'details': 'Currently no fix is planned', 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0002', 'CSAFPID-0004', 'CSAFPID-0008', 'CSAFPID-0010', 'CSAFPID-0012', 'CSAFPID-0014', 'CSAFPID-0016', 'CSAFPID-0018', 'CSAFPID-0020', 'CSAFPID-0022', 'CSAFPID-0024', 'CSAFPID-0026', 'CSAFPID-0028', 'CSAFPID-0030', 'CSAFPID-0032', 'CSAFPID-0034', 'CSAFPID-0036', 'CSAFPID-0038', 'CSAFPID-0040', 'CSAFPID-0042', 'CSAFPID-0049', 'CSAFPID-0051', 'CSAFPID-0053', 'CSAFPID-0055', 'CSAFPID-0058']}, {'details': 'Currently no fix is available', 'category': 'none_available', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0011', 'CSAFPID-0013', 'CSAFPID-0015', 'CSAFPID-0017', 'CSAFPID-0019', 'CSAFPID-0021', 'CSAFPID-0023', 'CSAFPID-0025', 'CSAFPID-0027', 'CSAFPID-0029', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0035', 'CSAFPID-0037', 'CSAFPID-0039', 'CSAFPID-0041', 'CSAFPID-0043', 'CSAFPID-0044', 'CSAFPID-0045', 'CSAFPID-0046', 'CSAFPID-0047', 'CSAFPID-0048', 'CSAFPID-0050', 'CSAFPID-0052', 'CSAFPID-0054', 'CSAFPID-0056', 'CSAFPID-0057', 'CSAFPID-0059', 'CSAFPID-0060', 'CSAFPID-0061']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0028', 'CSAFPID-0029', 'CSAFPID-0030', 'CSAFPID-0031', 'CSAFPID-0032', 'CSAFPID-0033', 'CSAFPID-0034', 'CSAFPID-0035', 'CSAFPID-0036', 'CSAFPID-0037', 'CSAFPID-0038', 'CSAFPID-0039', 'CSAFPID-0040', 'CSAFPID-0041', 'CSAFPID-0042', 'CSAFPID-0043', 'CSAFPID-0044', 'CSAFPID-0045', 'CSAFPID-0046', 'CSAFPID-0047', 'CSAFPID-0048', 'CSAFPID-0049', 'CSAFPID-0050', 'CSAFPID-0051', 'CSAFPID-0052', 'CSAFPID-0053', 'CSAFPID-0054', 'CSAFPID-0055', 'CSAFPID-0056', 'CSAFPID-0057', 'CSAFPID-0058', 'CSAFPID-0059', 'CSAFPID-0060', 'CSAFPID-0061']}}]} | |
ot | ICSA-26-174-01 | CVE-2026-24349 | Siemens WinCC Certificate Manager | 2026-06-09 03:00:00+03:00 | 2026-06-23 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-01.json | 6014e239052790a46d0704c33715c23c181a2cfcda0f2c3b5f35081b3a7d6eec | 2026-06-24 07:37:39.992137+03:00 | 2026-06-24 07:37:39.992137+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'WinCC Certificate Manager insufficiently protects key material that could allow an attacker to extract sensitive information.\n\nSiemens has released a new version for SIMATIC WinCC Unified PC Runtime V21 and recommends to update to the latest version. Siemens recommends specific countermeasures for products where fixes are not, or not yet available.', 'title': 'Summary', 'category': 'summary'}, {'text': "As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals.\nAdditional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity", 'title': 'General Recommendations', 'category': 'general'}, {'text': 'For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.', 'title': 'Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of Siemens ProductCERT SSA-063511 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Critical Manufacturing, Transportation Systems, Energy, Healthcare and Public Health, Financial Services, Government Services and Facilities', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Germany', 'title': 'Company headquarters location', 'category': 'other'}], 'title': 'Siemens WinCC Certificate Manager', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-174-01', 'status': 'final', 'version': '2', 'generator': {'date': '2026-06-17T15:49:50.475600Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2026-06-09T00:00:00.000000Z', 'number': '1', 'summary': 'Publication Date', 'legacy_version': 'Initial'}, {'date': '2026-06-23T06:00:00.000000Z', 'number': '2', 'summary': 'Initial CISA Republication of Siemens ProductCERT SSA-063511 advisory', 'legacy_version': 'CISA Republication'}], 'current_release_date': '2026-06-23T06:00:00.000000Z', 'initial_release_date': '2026-06-09T00:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://cert-portal.siemens.com/productcert/csaf/ssa-063511.json', 'summary': 'SSA-063511: Insufficient protection of key material in WinCC Certificate Manager - CSAF Version', 'category': 'self'}, {'url': 'https://cert-portal.siemens.com/productcert/html/ssa-063511.html', 'summary': 'SSA-063511: Insufficient protection of key material in WinCC Certificate Manager - HTML Version', 'category': 'self'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-174-01.json', 'summary': 'ICS Advisory ICSA-26-174-01 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-174-01', 'summary': 'ICS Advisory ICSA-26-174-01 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported this vulnerability to CISA.', 'organization': 'Siemens ProductCERT'}]}, 'product_tree': {'branches': [{'name': 'Siemens', 'branches': [{'name': 'SIMATIC WinCC Unified PC Runtime V16', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIMATIC WinCC Unified PC Runtime V16', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC WinCC Unified PC Runtime V17', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIMATIC WinCC Unified PC Runtime V17', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC WinCC Unified PC Runtime V18', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIMATIC WinCC Unified PC Runtime V18', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC WinCC Unified PC Runtime V19', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIMATIC WinCC Unified PC Runtime V19', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC WinCC Unified PC Runtime V20', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'SIMATIC WinCC Unified PC Runtime V20', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SIMATIC WinCC Unified PC Runtime V21', 'branches': [{'name': 'vers:intdot/<21.0.2', 'product': {'name': 'SIMATIC WinCC Unified PC Runtime V21', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-24349', 'cwe': {'id': 'CWE-313', 'name': 'Cleartext Storage in a File or on Disk'}, 'notes': [{'text': 'Insufficient protection of key material in WinCC Certificate Manager that could allow an attacker to extract sensitive information.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-24349', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-24349', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/313.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'The affected product may be operated only by personnel qualified for the specific task in accordance with the relevant documentation, in particular its warning notices and safety instructions. Qualified personnel are those who, based on their training and experience, are capable of identifying risks and avoiding potential hazards when working with the affected product.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006']}, {'details': 'Currently no fix is planned', 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005']}, {'url': 'https://support.industry.siemens.com/cs/ww/en/view/109991140/', 'details': 'Update to V21 Update 2 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0006']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006']}}]} | |
ot | ICSA-26-111-06 | CVE-2026-1354 | Zero Motorcycles Firmware (Update A) | 2026-04-21 09:00:00+03:00 | 2026-06-23 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-111-06.json | e1456c657fc1a416a01492c8afcaca1ba0ef2290991e9fbd4b1f44bc1374f468 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-24 07:37:39.992137+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of this vulnerability could allow an attacker to pair via Bluetooth with a motorcycle, gaining unauthorized access to all Bluetooth functions, including changing the firmware.', 'title': 'Advisory Summary', 'category': 'summary'}, {'text': 'Transportation Systems', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability has a high attack complexity.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Zero Motorcycles Firmware (Update A)', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-111-06', 'status': 'final', 'version': '2', 'generator': {'date': '2026-06-16T21:48:47.189552Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-04-21T06:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}, {'date': '2026-06-23T06:00:00.000000Z', 'number': '2', 'summary': 'Update A - Firmware update now available.', 'legacy_version': 'Update A'}], 'current_release_date': '2026-06-23T06:00:00.000000Z', 'initial_release_date': '2026-04-21T06:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-111-06.json', 'summary': 'ICS Advisory ICSA-26-111-06 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-06', 'summary': 'ICSA Advisory ICSA-26-111-06 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Persephone Karnstein'], 'summary': 'reported this vulnerability to CISA', 'organization': 'Bureau Veritas Cybersecurity North America'}]}, 'product_tree': {'branches': [{'name': 'Zero Motorcycles', 'branches': [{'name': 'Zero Motorcycles firmware', 'branches': [{'name': '<=44', 'product': {'name': 'Zero Motorcycles Zero Motorcycles firmware: <=44', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-1354', 'cwe': {'id': 'CWE-322', 'name': 'Key Exchange without Entity Authentication'}, 'notes': [{'text': "Zero Motorcycles firmware versions 44 and prior enable an attacker to forcibly pair a device with the motorcycle via Bluetooth. Once paired, an attacker can utilize over-the-air firmware updating functionality to potentially upload malicious firmware to the motorcycle. The motorcycle must first be in Bluetooth pairing mode, and the attacker must be in proximity of the vehicle and understand the full pairing process, to be able to pair their device with the vehicle. The attacker's device must remain paired with and in proximity of the motorcycle for the entire duration of the firmware update.", 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-06-16T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/322.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-1354', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Zero Motorcycles has investigated this report and cautions users to pair their mobile device to their vehicle in a safe location where they can be sure no one else will try to pair at the same time. Once initiated, complete the full pairing process and confirm it is successful. Store physical keys in a secure location and do not leave the bike unattended with the key in the "ON" position. Zero Motorcycles has addressed this issue in a firmware update that is available on their FOTA platform and can be obtained by using the mobile app or by visiting an authorized Zero Motorcycles dealership. Zero Motorcycles recommends all users update the firmware to the latest available version.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-25-317-04 | CVE-2025-64307 | Brightpick Mission Control / Internal Logic Control (Update A) | 2025-11-13 10:00:00+03:00 | 2026-06-23 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-317-04.json | c8b1c9f6749fd0f59468954ace0d9a9605eee2a2fcec00ceb695525af921ddad | 2026-05-29 09:17:34.767089+03:00 | 2026-06-24 07:37:39.992137+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could result in the exposure of sensitive information and the manipulation of critical functions by an attacker.', 'title': 'Advisory Summary', 'category': 'summary'}, {'text': 'Commercial Facilities, Critical Manufacturing, Healthcare and Public Health', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Slovakia', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities are not exploitable remotely.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Brightpick Mission Control / Internal Logic Control (Update A)', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-25-317-04', 'status': 'final', 'version': '2', 'generator': {'date': '2026-06-22T15:10:22.909741Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2025-11-13T07:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}, {'date': '2026-06-23T06:00:00.000000Z', 'number': '2', 'summary': 'Update A - Updated vulnerability descriptions and mitigations', 'legacy_version': 'Update A'}], 'current_release_date': '2026-06-23T06:00:00.000000Z', 'initial_release_date': '2025-11-13T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-317-04.json', 'summary': 'ICS Advisory ICSA-25-317-04 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-25-317-04', 'summary': 'ICSA Advisory ICSA-25-317-04 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Souvik Kandar'], 'summary': 'reported these vulnerabilities to CISA'}]}, 'product_tree': {'branches': [{'name': 'Brightpick AI', 'branches': [{'name': 'Brightpick Mission Control / Internal Logic Control', 'branches': [{'name': '<1.67.0', 'product': {'name': 'Brightpick AI Brightpick Mission Control / Internal Logic Control: <1.67.0', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-64307', 'cwe': {'id': 'CWE-306', 'name': 'Missing Authentication for Critical Function'}, 'notes': [{'text': 'The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized user could exploit this interface to manipulate robot control functions, including initiating or halting runners, assigning jobs, clearing stations, and deploying storage totes.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-06-22T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/306.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-64307', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Brightpick AI has updated their backend in Mission Control to release 1.67.0 to mitigate these vulnerabilities as of February 04, 2026. Users running Mission Control 1.67.0 or later are mitigated.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'For CVE-2025-64307: Brightpick has introduced a reverse-proxy authentication layer inline between the public load balancer and the internal service. This vendor fix has been applied to all deployed instances.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://brightpick.ai/contact-us/', 'details': 'Users of the affected products are encouraged to contact Brightpick AI https://brightpick.ai/contact-us/ for additional information.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-64308', 'cwe': {'id': 'CWE-523', 'name': 'Unprotected Transport of Credentials'}, 'notes': [{'text': "The Brightpick Mission Control web application exposes hardcoded credentials in its client-side JavaScript bundle to Brightpick AI's documentation portal.", 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-06-22T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/523.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-64308', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Brightpick AI has updated their backend in Mission Control to release 1.67.0 to mitigate these vulnerabilities as of February 04, 2026. Users running Mission Control 1.67.0 or later are mitigated.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://brightpick.ai/contact-us/', 'details': 'Users of the affected products are encouraged to contact Brightpick AI https://brightpick.ai/contact-us/ for additional information.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-64309', 'cwe': {'id': 'CWE-523', 'name': 'Unprotected Transport of Credentials'}, 'notes': [{'text': 'The affected product discloses device telemetry, configuration, and sensitive information via WebSocket traffic to unauthenticated users when they connect to a specific URL. The unauthenticated URL can be discovered through basic network scanning techniques.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-06-22T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/523.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-64309', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Brightpick AI has updated their backend in Mission Control to release 1.67.0 to mitigate these vulnerabilities as of February 04, 2026. Users running Mission Control 1.67.0 or later are mitigated.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://brightpick.ai/contact-us/', 'details': 'Users of the affected products are encouraged to contact Brightpick AI https://brightpick.ai/contact-us/ for additional information.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-25-317-04 | CVE-2025-64308 | Brightpick Mission Control / Internal Logic Control (Update A) | 2025-11-13 10:00:00+03:00 | 2026-06-23 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-317-04.json | b1e5cd70adc7bb03de2c07fc8f51d639f8054fa392e580b4f7d6905ef2d55854 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-24 07:37:39.992137+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could result in the exposure of sensitive information and the manipulation of critical functions by an attacker.', 'title': 'Advisory Summary', 'category': 'summary'}, {'text': 'Commercial Facilities, Critical Manufacturing, Healthcare and Public Health', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Slovakia', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities are not exploitable remotely.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Brightpick Mission Control / Internal Logic Control (Update A)', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-25-317-04', 'status': 'final', 'version': '2', 'generator': {'date': '2026-06-22T15:10:22.909741Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2025-11-13T07:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}, {'date': '2026-06-23T06:00:00.000000Z', 'number': '2', 'summary': 'Update A - Updated vulnerability descriptions and mitigations', 'legacy_version': 'Update A'}], 'current_release_date': '2026-06-23T06:00:00.000000Z', 'initial_release_date': '2025-11-13T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-317-04.json', 'summary': 'ICS Advisory ICSA-25-317-04 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-25-317-04', 'summary': 'ICSA Advisory ICSA-25-317-04 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Souvik Kandar'], 'summary': 'reported these vulnerabilities to CISA'}]}, 'product_tree': {'branches': [{'name': 'Brightpick AI', 'branches': [{'name': 'Brightpick Mission Control / Internal Logic Control', 'branches': [{'name': '<1.67.0', 'product': {'name': 'Brightpick AI Brightpick Mission Control / Internal Logic Control: <1.67.0', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-64307', 'cwe': {'id': 'CWE-306', 'name': 'Missing Authentication for Critical Function'}, 'notes': [{'text': 'The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized user could exploit this interface to manipulate robot control functions, including initiating or halting runners, assigning jobs, clearing stations, and deploying storage totes.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-06-22T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/306.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-64307', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Brightpick AI has updated their backend in Mission Control to release 1.67.0 to mitigate these vulnerabilities as of February 04, 2026. Users running Mission Control 1.67.0 or later are mitigated.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'For CVE-2025-64307: Brightpick has introduced a reverse-proxy authentication layer inline between the public load balancer and the internal service. This vendor fix has been applied to all deployed instances.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://brightpick.ai/contact-us/', 'details': 'Users of the affected products are encouraged to contact Brightpick AI https://brightpick.ai/contact-us/ for additional information.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-64308', 'cwe': {'id': 'CWE-523', 'name': 'Unprotected Transport of Credentials'}, 'notes': [{'text': "The Brightpick Mission Control web application exposes hardcoded credentials in its client-side JavaScript bundle to Brightpick AI's documentation portal.", 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-06-22T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/523.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-64308', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Brightpick AI has updated their backend in Mission Control to release 1.67.0 to mitigate these vulnerabilities as of February 04, 2026. Users running Mission Control 1.67.0 or later are mitigated.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://brightpick.ai/contact-us/', 'details': 'Users of the affected products are encouraged to contact Brightpick AI https://brightpick.ai/contact-us/ for additional information.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-64309', 'cwe': {'id': 'CWE-523', 'name': 'Unprotected Transport of Credentials'}, 'notes': [{'text': 'The affected product discloses device telemetry, configuration, and sensitive information via WebSocket traffic to unauthenticated users when they connect to a specific URL. The unauthenticated URL can be discovered through basic network scanning techniques.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-06-22T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/523.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-64309', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Brightpick AI has updated their backend in Mission Control to release 1.67.0 to mitigate these vulnerabilities as of February 04, 2026. Users running Mission Control 1.67.0 or later are mitigated.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://brightpick.ai/contact-us/', 'details': 'Users of the affected products are encouraged to contact Brightpick AI https://brightpick.ai/contact-us/ for additional information.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-25-317-04 | CVE-2025-64309 | Brightpick Mission Control / Internal Logic Control (Update A) | 2025-11-13 10:00:00+03:00 | 2026-06-23 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-317-04.json | be4f3ef53708100df3783ab7a2b27f0aaf23b1af167def7949dae7c0d17a0c7e | 2026-05-29 09:17:34.767089+03:00 | 2026-06-24 07:37:39.992137+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could result in the exposure of sensitive information and the manipulation of critical functions by an attacker.', 'title': 'Advisory Summary', 'category': 'summary'}, {'text': 'Commercial Facilities, Critical Manufacturing, Healthcare and Public Health', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Slovakia', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities are not exploitable remotely.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Brightpick Mission Control / Internal Logic Control (Update A)', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-25-317-04', 'status': 'final', 'version': '2', 'generator': {'date': '2026-06-22T15:10:22.909741Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2025-11-13T07:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}, {'date': '2026-06-23T06:00:00.000000Z', 'number': '2', 'summary': 'Update A - Updated vulnerability descriptions and mitigations', 'legacy_version': 'Update A'}], 'current_release_date': '2026-06-23T06:00:00.000000Z', 'initial_release_date': '2025-11-13T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-317-04.json', 'summary': 'ICS Advisory ICSA-25-317-04 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-25-317-04', 'summary': 'ICSA Advisory ICSA-25-317-04 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Souvik Kandar'], 'summary': 'reported these vulnerabilities to CISA'}]}, 'product_tree': {'branches': [{'name': 'Brightpick AI', 'branches': [{'name': 'Brightpick Mission Control / Internal Logic Control', 'branches': [{'name': '<1.67.0', 'product': {'name': 'Brightpick AI Brightpick Mission Control / Internal Logic Control: <1.67.0', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-64307', 'cwe': {'id': 'CWE-306', 'name': 'Missing Authentication for Critical Function'}, 'notes': [{'text': 'The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized user could exploit this interface to manipulate robot control functions, including initiating or halting runners, assigning jobs, clearing stations, and deploying storage totes.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-06-22T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/306.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-64307', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Brightpick AI has updated their backend in Mission Control to release 1.67.0 to mitigate these vulnerabilities as of February 04, 2026. Users running Mission Control 1.67.0 or later are mitigated.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'For CVE-2025-64307: Brightpick has introduced a reverse-proxy authentication layer inline between the public load balancer and the internal service. This vendor fix has been applied to all deployed instances.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://brightpick.ai/contact-us/', 'details': 'Users of the affected products are encouraged to contact Brightpick AI https://brightpick.ai/contact-us/ for additional information.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-64308', 'cwe': {'id': 'CWE-523', 'name': 'Unprotected Transport of Credentials'}, 'notes': [{'text': "The Brightpick Mission Control web application exposes hardcoded credentials in its client-side JavaScript bundle to Brightpick AI's documentation portal.", 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-06-22T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/523.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-64308', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Brightpick AI has updated their backend in Mission Control to release 1.67.0 to mitigate these vulnerabilities as of February 04, 2026. Users running Mission Control 1.67.0 or later are mitigated.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://brightpick.ai/contact-us/', 'details': 'Users of the affected products are encouraged to contact Brightpick AI https://brightpick.ai/contact-us/ for additional information.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-64309', 'cwe': {'id': 'CWE-523', 'name': 'Unprotected Transport of Credentials'}, 'notes': [{'text': 'The affected product discloses device telemetry, configuration, and sensitive information via WebSocket traffic to unauthenticated users when they connect to a specific URL. The unauthenticated URL can be discovered through basic network scanning techniques.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-06-22T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/523.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-64309', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Brightpick AI has updated their backend in Mission Control to release 1.67.0 to mitigate these vulnerabilities as of February 04, 2026. Users running Mission Control 1.67.0 or later are mitigated.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://brightpick.ai/contact-us/', 'details': 'Users of the affected products are encouraged to contact Brightpick AI https://brightpick.ai/contact-us/ for additional information.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-24-345-06 | CVE-2024-11155 | Rockwell Automation Arena (Update C) | 2024-12-10 10:00:00+03:00 | 2026-06-23 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-345-06.json | cc56763771459393b980f0c4b58a7a5baa6264570352e6dfde6510a4bedf99d9 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-24 07:37:39.992137+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could result in execution of arbitrary code.', 'title': 'Advisory Summary', 'category': 'summary'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also recommends users take the following measures to protect themselves from social engineering attacks:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Do not click web links or open attachments in unsolicited email messages.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities are not exploitable remotely.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Rockwell Automation Arena (Update C)', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-24-345-06', 'status': 'final', 'version': '4', 'generator': {'date': '2026-06-22T21:23:33.184965Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2024-12-10T07:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}, {'date': '2025-01-09T07:00:00.000000Z', 'number': '2', 'summary': 'Update A - Added CVE-2024-11157, CVE-2024-12175, CVE-2024-12672, and CVE-2024-11364.', 'legacy_version': 'Update A'}, {'date': '2026-02-03T07:00:00.000000Z', 'number': '3', 'summary': 'Update B - Added CVE-2025-6376, CVE-2025-6377, updated affected products and mitigations.', 'legacy_version': 'Update B'}, {'date': '2026-06-23T06:00:00.000000Z', 'number': '4', 'summary': 'Update C - Added CVE-2026-6071', 'legacy_version': 'Update C'}], 'current_release_date': '2026-06-23T06:00:00.000000Z', 'initial_release_date': '2024-12-10T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-345-06.json', 'summary': 'ICS Advisory ICSA-24-345-06 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-24-345-06', 'summary': 'ICSA Advisory ICSA-24-345-06 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/ncas/tips/ST04-014', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Rocco Calvi'], 'summary': 'reported these vulnerabilities to Trend Micro Zero Day Initiative', 'organization': 'TecSecurity'}, {'names': ['Mat Powell'], 'summary': 'reported these vulnerabilities to Rockwell Automation', 'organization': 'Trend Micro Zero Day Initiative'}]}, 'product_tree': {'branches': [{'name': 'Rockwell Automation', 'branches': [{'name': 'Arena', 'branches': [{'name': '<=16.20.00', 'product': {'name': 'Rockwell Automation Arena: <=16.20.00', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.03', 'product': {'name': 'Rockwell Automation Arena: <=16.20.03', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.05', 'product': {'name': 'Rockwell Automation Arena: <=16.20.05', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.06', 'product': {'name': 'Rockwell Automation Arena: <=16.20.06', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.08', 'product': {'name': 'Rockwell Automation Arena: <=16.20.08', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena 32 bit', 'branches': [{'name': '<=16.20.07', 'product': {'name': 'Rockwell Automation Arena 32 bit: <=16.20.07', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena 32 bit', 'branches': [{'name': '<=16.20.06', 'product': {'name': 'Rockwell Automation Arena 32 bit: <=16.20.06', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2024-11155', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'A "use after free" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/416.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11155', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2024-11156', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'An "out of bounds write" code execution vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0002']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11156', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}], 'product_status': {'known_affected': ['CSAFPID-0002']}}, {'cve': 'CVE-2024-11158', 'cwe': {'id': 'CWE-665', 'name': 'Improper Initialization'}, 'notes': [{'text': 'An "uninitialized variable" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to access a variable before it is initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/665.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11158', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2024-12130', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'An "out of bounds read" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to read beyond the boundaries of an allocated memory. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0003']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/125.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12130', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}], 'product_status': {'known_affected': ['CSAFPID-0003']}}, {'cve': 'CVE-2024-11157', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A third-party vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0004']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11157', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}], 'product_status': {'known_affected': ['CSAFPID-0004']}}, {'cve': 'CVE-2024-12175', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Another "use after free" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0004']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/416.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12175', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}], 'product_status': {'known_affected': ['CSAFPID-0004']}}, {'cve': 'CVE-2024-12672', 'cwe': {'id': 'CWE-1395', 'name': 'Dependency on Vulnerable Third-Party Component'}, 'notes': [{'text': 'A third-party vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0006']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/1395.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12672', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}], 'product_status': {'known_affected': ['CSAFPID-0006']}}, {'cve': 'CVE-2024-11364', 'cwe': {'id': 'CWE-1395', 'name': 'Dependency on Vulnerable Third-Party Component'}, 'notes': [{'text': 'Another "uninitialized variable" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to access a variable prior to it being initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0007']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/1395.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11364', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}], 'product_status': {'known_affected': ['CSAFPID-0007']}}, {'cve': 'CVE-2025-6377', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-6377', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}, {'cve': 'CVE-2025-6376', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-6376', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}, {'cve': 'CVE-2026-6071', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products when parsing DOE files that could allow a remote attacker to write past the end of an allocated object and execute code within the context of the current process. To exploit this vulnerability, a legitimate user must visit a malicious page or open a malicious file.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-6071', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}]} | |
ot | ICSA-24-345-06 | CVE-2024-11156 | Rockwell Automation Arena (Update C) | 2024-12-10 10:00:00+03:00 | 2026-06-23 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-345-06.json | 1a3a25a401ac4d17f13f596fd3fbb478baa07b1c17966aa11f0c0f8492f180bf | 2026-05-29 09:17:34.767089+03:00 | 2026-06-24 07:37:39.992137+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could result in execution of arbitrary code.', 'title': 'Advisory Summary', 'category': 'summary'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also recommends users take the following measures to protect themselves from social engineering attacks:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Do not click web links or open attachments in unsolicited email messages.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities are not exploitable remotely.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Rockwell Automation Arena (Update C)', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-24-345-06', 'status': 'final', 'version': '4', 'generator': {'date': '2026-06-22T21:23:33.184965Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2024-12-10T07:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}, {'date': '2025-01-09T07:00:00.000000Z', 'number': '2', 'summary': 'Update A - Added CVE-2024-11157, CVE-2024-12175, CVE-2024-12672, and CVE-2024-11364.', 'legacy_version': 'Update A'}, {'date': '2026-02-03T07:00:00.000000Z', 'number': '3', 'summary': 'Update B - Added CVE-2025-6376, CVE-2025-6377, updated affected products and mitigations.', 'legacy_version': 'Update B'}, {'date': '2026-06-23T06:00:00.000000Z', 'number': '4', 'summary': 'Update C - Added CVE-2026-6071', 'legacy_version': 'Update C'}], 'current_release_date': '2026-06-23T06:00:00.000000Z', 'initial_release_date': '2024-12-10T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-345-06.json', 'summary': 'ICS Advisory ICSA-24-345-06 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-24-345-06', 'summary': 'ICSA Advisory ICSA-24-345-06 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/ncas/tips/ST04-014', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Rocco Calvi'], 'summary': 'reported these vulnerabilities to Trend Micro Zero Day Initiative', 'organization': 'TecSecurity'}, {'names': ['Mat Powell'], 'summary': 'reported these vulnerabilities to Rockwell Automation', 'organization': 'Trend Micro Zero Day Initiative'}]}, 'product_tree': {'branches': [{'name': 'Rockwell Automation', 'branches': [{'name': 'Arena', 'branches': [{'name': '<=16.20.00', 'product': {'name': 'Rockwell Automation Arena: <=16.20.00', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.03', 'product': {'name': 'Rockwell Automation Arena: <=16.20.03', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.05', 'product': {'name': 'Rockwell Automation Arena: <=16.20.05', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.06', 'product': {'name': 'Rockwell Automation Arena: <=16.20.06', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.08', 'product': {'name': 'Rockwell Automation Arena: <=16.20.08', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena 32 bit', 'branches': [{'name': '<=16.20.07', 'product': {'name': 'Rockwell Automation Arena 32 bit: <=16.20.07', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena 32 bit', 'branches': [{'name': '<=16.20.06', 'product': {'name': 'Rockwell Automation Arena 32 bit: <=16.20.06', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2024-11155', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'A "use after free" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/416.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11155', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2024-11156', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'An "out of bounds write" code execution vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0002']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11156', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}], 'product_status': {'known_affected': ['CSAFPID-0002']}}, {'cve': 'CVE-2024-11158', 'cwe': {'id': 'CWE-665', 'name': 'Improper Initialization'}, 'notes': [{'text': 'An "uninitialized variable" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to access a variable before it is initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/665.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11158', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2024-12130', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'An "out of bounds read" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to read beyond the boundaries of an allocated memory. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0003']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/125.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12130', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}], 'product_status': {'known_affected': ['CSAFPID-0003']}}, {'cve': 'CVE-2024-11157', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A third-party vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0004']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11157', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}], 'product_status': {'known_affected': ['CSAFPID-0004']}}, {'cve': 'CVE-2024-12175', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Another "use after free" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0004']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/416.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12175', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}], 'product_status': {'known_affected': ['CSAFPID-0004']}}, {'cve': 'CVE-2024-12672', 'cwe': {'id': 'CWE-1395', 'name': 'Dependency on Vulnerable Third-Party Component'}, 'notes': [{'text': 'A third-party vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0006']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/1395.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12672', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}], 'product_status': {'known_affected': ['CSAFPID-0006']}}, {'cve': 'CVE-2024-11364', 'cwe': {'id': 'CWE-1395', 'name': 'Dependency on Vulnerable Third-Party Component'}, 'notes': [{'text': 'Another "uninitialized variable" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to access a variable prior to it being initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0007']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/1395.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11364', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}], 'product_status': {'known_affected': ['CSAFPID-0007']}}, {'cve': 'CVE-2025-6377', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-6377', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}, {'cve': 'CVE-2025-6376', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-6376', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}, {'cve': 'CVE-2026-6071', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products when parsing DOE files that could allow a remote attacker to write past the end of an allocated object and execute code within the context of the current process. To exploit this vulnerability, a legitimate user must visit a malicious page or open a malicious file.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-6071', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}]} | |
ot | ICSA-24-345-06 | CVE-2024-11158 | Rockwell Automation Arena (Update C) | 2024-12-10 10:00:00+03:00 | 2026-06-23 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-345-06.json | cd7bc792314035db2974fc3ac38a26d1fc827257696785eeebf881c9b24de98d | 2026-05-29 09:17:34.767089+03:00 | 2026-06-24 07:37:39.992137+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could result in execution of arbitrary code.', 'title': 'Advisory Summary', 'category': 'summary'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also recommends users take the following measures to protect themselves from social engineering attacks:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Do not click web links or open attachments in unsolicited email messages.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities are not exploitable remotely.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Rockwell Automation Arena (Update C)', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-24-345-06', 'status': 'final', 'version': '4', 'generator': {'date': '2026-06-22T21:23:33.184965Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2024-12-10T07:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}, {'date': '2025-01-09T07:00:00.000000Z', 'number': '2', 'summary': 'Update A - Added CVE-2024-11157, CVE-2024-12175, CVE-2024-12672, and CVE-2024-11364.', 'legacy_version': 'Update A'}, {'date': '2026-02-03T07:00:00.000000Z', 'number': '3', 'summary': 'Update B - Added CVE-2025-6376, CVE-2025-6377, updated affected products and mitigations.', 'legacy_version': 'Update B'}, {'date': '2026-06-23T06:00:00.000000Z', 'number': '4', 'summary': 'Update C - Added CVE-2026-6071', 'legacy_version': 'Update C'}], 'current_release_date': '2026-06-23T06:00:00.000000Z', 'initial_release_date': '2024-12-10T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-345-06.json', 'summary': 'ICS Advisory ICSA-24-345-06 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-24-345-06', 'summary': 'ICSA Advisory ICSA-24-345-06 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/ncas/tips/ST04-014', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Rocco Calvi'], 'summary': 'reported these vulnerabilities to Trend Micro Zero Day Initiative', 'organization': 'TecSecurity'}, {'names': ['Mat Powell'], 'summary': 'reported these vulnerabilities to Rockwell Automation', 'organization': 'Trend Micro Zero Day Initiative'}]}, 'product_tree': {'branches': [{'name': 'Rockwell Automation', 'branches': [{'name': 'Arena', 'branches': [{'name': '<=16.20.00', 'product': {'name': 'Rockwell Automation Arena: <=16.20.00', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.03', 'product': {'name': 'Rockwell Automation Arena: <=16.20.03', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.05', 'product': {'name': 'Rockwell Automation Arena: <=16.20.05', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.06', 'product': {'name': 'Rockwell Automation Arena: <=16.20.06', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.08', 'product': {'name': 'Rockwell Automation Arena: <=16.20.08', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena 32 bit', 'branches': [{'name': '<=16.20.07', 'product': {'name': 'Rockwell Automation Arena 32 bit: <=16.20.07', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena 32 bit', 'branches': [{'name': '<=16.20.06', 'product': {'name': 'Rockwell Automation Arena 32 bit: <=16.20.06', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2024-11155', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'A "use after free" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/416.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11155', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2024-11156', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'An "out of bounds write" code execution vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0002']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11156', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}], 'product_status': {'known_affected': ['CSAFPID-0002']}}, {'cve': 'CVE-2024-11158', 'cwe': {'id': 'CWE-665', 'name': 'Improper Initialization'}, 'notes': [{'text': 'An "uninitialized variable" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to access a variable before it is initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/665.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11158', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2024-12130', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'An "out of bounds read" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to read beyond the boundaries of an allocated memory. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0003']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/125.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12130', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}], 'product_status': {'known_affected': ['CSAFPID-0003']}}, {'cve': 'CVE-2024-11157', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A third-party vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0004']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11157', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}], 'product_status': {'known_affected': ['CSAFPID-0004']}}, {'cve': 'CVE-2024-12175', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Another "use after free" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0004']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/416.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12175', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}], 'product_status': {'known_affected': ['CSAFPID-0004']}}, {'cve': 'CVE-2024-12672', 'cwe': {'id': 'CWE-1395', 'name': 'Dependency on Vulnerable Third-Party Component'}, 'notes': [{'text': 'A third-party vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0006']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/1395.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12672', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}], 'product_status': {'known_affected': ['CSAFPID-0006']}}, {'cve': 'CVE-2024-11364', 'cwe': {'id': 'CWE-1395', 'name': 'Dependency on Vulnerable Third-Party Component'}, 'notes': [{'text': 'Another "uninitialized variable" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to access a variable prior to it being initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0007']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/1395.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11364', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}], 'product_status': {'known_affected': ['CSAFPID-0007']}}, {'cve': 'CVE-2025-6377', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-6377', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}, {'cve': 'CVE-2025-6376', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-6376', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}, {'cve': 'CVE-2026-6071', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products when parsing DOE files that could allow a remote attacker to write past the end of an allocated object and execute code within the context of the current process. To exploit this vulnerability, a legitimate user must visit a malicious page or open a malicious file.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-6071', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}]} | |
ot | ICSA-24-345-06 | CVE-2024-12130 | Rockwell Automation Arena (Update C) | 2024-12-10 10:00:00+03:00 | 2026-06-23 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-345-06.json | 53e97360561079dd7dd18d649378eef7d605822b909032d97edeb6bf865af5d3 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-24 07:37:39.992137+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could result in execution of arbitrary code.', 'title': 'Advisory Summary', 'category': 'summary'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also recommends users take the following measures to protect themselves from social engineering attacks:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Do not click web links or open attachments in unsolicited email messages.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities are not exploitable remotely.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Rockwell Automation Arena (Update C)', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-24-345-06', 'status': 'final', 'version': '4', 'generator': {'date': '2026-06-22T21:23:33.184965Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2024-12-10T07:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}, {'date': '2025-01-09T07:00:00.000000Z', 'number': '2', 'summary': 'Update A - Added CVE-2024-11157, CVE-2024-12175, CVE-2024-12672, and CVE-2024-11364.', 'legacy_version': 'Update A'}, {'date': '2026-02-03T07:00:00.000000Z', 'number': '3', 'summary': 'Update B - Added CVE-2025-6376, CVE-2025-6377, updated affected products and mitigations.', 'legacy_version': 'Update B'}, {'date': '2026-06-23T06:00:00.000000Z', 'number': '4', 'summary': 'Update C - Added CVE-2026-6071', 'legacy_version': 'Update C'}], 'current_release_date': '2026-06-23T06:00:00.000000Z', 'initial_release_date': '2024-12-10T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-345-06.json', 'summary': 'ICS Advisory ICSA-24-345-06 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-24-345-06', 'summary': 'ICSA Advisory ICSA-24-345-06 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/ncas/tips/ST04-014', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Rocco Calvi'], 'summary': 'reported these vulnerabilities to Trend Micro Zero Day Initiative', 'organization': 'TecSecurity'}, {'names': ['Mat Powell'], 'summary': 'reported these vulnerabilities to Rockwell Automation', 'organization': 'Trend Micro Zero Day Initiative'}]}, 'product_tree': {'branches': [{'name': 'Rockwell Automation', 'branches': [{'name': 'Arena', 'branches': [{'name': '<=16.20.00', 'product': {'name': 'Rockwell Automation Arena: <=16.20.00', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.03', 'product': {'name': 'Rockwell Automation Arena: <=16.20.03', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.05', 'product': {'name': 'Rockwell Automation Arena: <=16.20.05', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.06', 'product': {'name': 'Rockwell Automation Arena: <=16.20.06', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.08', 'product': {'name': 'Rockwell Automation Arena: <=16.20.08', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena 32 bit', 'branches': [{'name': '<=16.20.07', 'product': {'name': 'Rockwell Automation Arena 32 bit: <=16.20.07', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena 32 bit', 'branches': [{'name': '<=16.20.06', 'product': {'name': 'Rockwell Automation Arena 32 bit: <=16.20.06', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2024-11155', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'A "use after free" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/416.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11155', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2024-11156', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'An "out of bounds write" code execution vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0002']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11156', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}], 'product_status': {'known_affected': ['CSAFPID-0002']}}, {'cve': 'CVE-2024-11158', 'cwe': {'id': 'CWE-665', 'name': 'Improper Initialization'}, 'notes': [{'text': 'An "uninitialized variable" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to access a variable before it is initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/665.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11158', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2024-12130', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'An "out of bounds read" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to read beyond the boundaries of an allocated memory. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0003']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/125.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12130', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}], 'product_status': {'known_affected': ['CSAFPID-0003']}}, {'cve': 'CVE-2024-11157', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A third-party vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0004']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11157', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}], 'product_status': {'known_affected': ['CSAFPID-0004']}}, {'cve': 'CVE-2024-12175', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Another "use after free" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0004']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/416.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12175', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}], 'product_status': {'known_affected': ['CSAFPID-0004']}}, {'cve': 'CVE-2024-12672', 'cwe': {'id': 'CWE-1395', 'name': 'Dependency on Vulnerable Third-Party Component'}, 'notes': [{'text': 'A third-party vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0006']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/1395.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12672', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}], 'product_status': {'known_affected': ['CSAFPID-0006']}}, {'cve': 'CVE-2024-11364', 'cwe': {'id': 'CWE-1395', 'name': 'Dependency on Vulnerable Third-Party Component'}, 'notes': [{'text': 'Another "uninitialized variable" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to access a variable prior to it being initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0007']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/1395.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11364', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}], 'product_status': {'known_affected': ['CSAFPID-0007']}}, {'cve': 'CVE-2025-6377', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-6377', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}, {'cve': 'CVE-2025-6376', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-6376', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}, {'cve': 'CVE-2026-6071', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products when parsing DOE files that could allow a remote attacker to write past the end of an allocated object and execute code within the context of the current process. To exploit this vulnerability, a legitimate user must visit a malicious page or open a malicious file.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-6071', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}]} | |
ot | ICSA-24-345-06 | CVE-2024-11157 | Rockwell Automation Arena (Update C) | 2024-12-10 10:00:00+03:00 | 2026-06-23 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-345-06.json | c4463823edc3b8e1b4b5b00a66d29c36ce894445fb5d06b27fb9a69e7372f2ad | 2026-05-29 09:17:34.767089+03:00 | 2026-06-24 07:37:39.992137+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could result in execution of arbitrary code.', 'title': 'Advisory Summary', 'category': 'summary'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also recommends users take the following measures to protect themselves from social engineering attacks:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Do not click web links or open attachments in unsolicited email messages.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities are not exploitable remotely.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Rockwell Automation Arena (Update C)', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-24-345-06', 'status': 'final', 'version': '4', 'generator': {'date': '2026-06-22T21:23:33.184965Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2024-12-10T07:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}, {'date': '2025-01-09T07:00:00.000000Z', 'number': '2', 'summary': 'Update A - Added CVE-2024-11157, CVE-2024-12175, CVE-2024-12672, and CVE-2024-11364.', 'legacy_version': 'Update A'}, {'date': '2026-02-03T07:00:00.000000Z', 'number': '3', 'summary': 'Update B - Added CVE-2025-6376, CVE-2025-6377, updated affected products and mitigations.', 'legacy_version': 'Update B'}, {'date': '2026-06-23T06:00:00.000000Z', 'number': '4', 'summary': 'Update C - Added CVE-2026-6071', 'legacy_version': 'Update C'}], 'current_release_date': '2026-06-23T06:00:00.000000Z', 'initial_release_date': '2024-12-10T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-345-06.json', 'summary': 'ICS Advisory ICSA-24-345-06 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-24-345-06', 'summary': 'ICSA Advisory ICSA-24-345-06 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/ncas/tips/ST04-014', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Rocco Calvi'], 'summary': 'reported these vulnerabilities to Trend Micro Zero Day Initiative', 'organization': 'TecSecurity'}, {'names': ['Mat Powell'], 'summary': 'reported these vulnerabilities to Rockwell Automation', 'organization': 'Trend Micro Zero Day Initiative'}]}, 'product_tree': {'branches': [{'name': 'Rockwell Automation', 'branches': [{'name': 'Arena', 'branches': [{'name': '<=16.20.00', 'product': {'name': 'Rockwell Automation Arena: <=16.20.00', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.03', 'product': {'name': 'Rockwell Automation Arena: <=16.20.03', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.05', 'product': {'name': 'Rockwell Automation Arena: <=16.20.05', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.06', 'product': {'name': 'Rockwell Automation Arena: <=16.20.06', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.08', 'product': {'name': 'Rockwell Automation Arena: <=16.20.08', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena 32 bit', 'branches': [{'name': '<=16.20.07', 'product': {'name': 'Rockwell Automation Arena 32 bit: <=16.20.07', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena 32 bit', 'branches': [{'name': '<=16.20.06', 'product': {'name': 'Rockwell Automation Arena 32 bit: <=16.20.06', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2024-11155', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'A "use after free" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/416.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11155', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2024-11156', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'An "out of bounds write" code execution vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0002']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11156', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}], 'product_status': {'known_affected': ['CSAFPID-0002']}}, {'cve': 'CVE-2024-11158', 'cwe': {'id': 'CWE-665', 'name': 'Improper Initialization'}, 'notes': [{'text': 'An "uninitialized variable" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to access a variable before it is initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/665.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11158', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2024-12130', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'An "out of bounds read" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to read beyond the boundaries of an allocated memory. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0003']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/125.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12130', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}], 'product_status': {'known_affected': ['CSAFPID-0003']}}, {'cve': 'CVE-2024-11157', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A third-party vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0004']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11157', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}], 'product_status': {'known_affected': ['CSAFPID-0004']}}, {'cve': 'CVE-2024-12175', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Another "use after free" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0004']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/416.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12175', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}], 'product_status': {'known_affected': ['CSAFPID-0004']}}, {'cve': 'CVE-2024-12672', 'cwe': {'id': 'CWE-1395', 'name': 'Dependency on Vulnerable Third-Party Component'}, 'notes': [{'text': 'A third-party vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0006']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/1395.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12672', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}], 'product_status': {'known_affected': ['CSAFPID-0006']}}, {'cve': 'CVE-2024-11364', 'cwe': {'id': 'CWE-1395', 'name': 'Dependency on Vulnerable Third-Party Component'}, 'notes': [{'text': 'Another "uninitialized variable" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to access a variable prior to it being initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0007']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/1395.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11364', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}], 'product_status': {'known_affected': ['CSAFPID-0007']}}, {'cve': 'CVE-2025-6377', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-6377', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}, {'cve': 'CVE-2025-6376', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-6376', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}, {'cve': 'CVE-2026-6071', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products when parsing DOE files that could allow a remote attacker to write past the end of an allocated object and execute code within the context of the current process. To exploit this vulnerability, a legitimate user must visit a malicious page or open a malicious file.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-6071', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}]} | |
it | VA-26-138-01 | CVE-2026-44159 | Tyler Technologies Tyler Identity Default Administrative Credentials | 2026-05-19 16:33:10+03:00 | 2026-05-19 16:33:10+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-138-01.json | 9836d932c4cb5f1159c843cb2ef3320cd5cb05b10ae83d644a684bba94f9f95f | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'All information products included in [https://github.com/cisagov/CSAF/tree/develop/csaf_files/IT/white](https://github.com/cisagov/CSAF/tree/develop/csaf_files/IT/white) are provided \\"as is\\" for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained within. DHS does not endorse any commercial product or service, referenced in this product or otherwise. Further dissemination of this product is governed by the Traffic Light Protocol (TLP) marking in the header. For more information about TLP, see [https://us-cert.cisa.gov/tlp/](https://us-cert.cisa.gov/tlp/).', 'title': 'Legal Notice', 'category': 'legal_disclaimer'}, {'text': 'Worldwide', 'title': 'Countries and Areas Deployed', 'category': 'other'}, {'text': 'Information Technology', 'title': 'Critical Infrastructure Sectors', 'category': 'other'}, {'text': 'Tyler Identity provider (TID-L) uses a documented, default administrative IDP credential. Users are not required to change the credentials before deployment. ', 'title': 'Risk Evaluation', 'category': 'summary'}, {'text': 'Change default passwords. TID-L has not been distributed since December 2020, and has not been supported since 2021.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'United States', 'title': 'Company Headquarters Location', 'category': 'other'}], 'title': 'Tyler Technologies Tyler Identity Default Administrative Credentials', 'category': 'csaf_vex', 'tracking': {'id': 'VA-26-138-01', 'status': 'final', 'version': '1.0.0', 'generator': {'engine': {'name': 'VINCE-NT', 'version': '1.14.0+build.80'}}, 'revision_history': [{'date': '2026-05-19T13:33:10Z', 'number': '1.0.0', 'summary': 'Initial publication'}], 'current_release_date': '2026-05-19T13:33:10Z', 'initial_release_date': '2026-05-19T13:33:10Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'https://www.cisa.gov/report', 'issuing_authority': 'CISA'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-26-138-01.json', 'summary': 'Vulnerability Advisory VA-26-138-01 CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'label': 'WHITE'}}}, 'product_tree': {'branches': [{'name': 'Tyler Technologies', 'branches': [{'name': 'TID-L', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Tyler Technologies TID-L vers:all/*', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-44159', 'cwe': {'id': 'CWE-1392', 'name': 'Use of Default Credentials'}, 'notes': [{'text': 'Tyler Identity Local (TID-L) uses documented, default administrative credentials. Users are not required to change the credentials before deployment. TID-L has not been distributed since December 2020, and has not been supported since 2021.', 'title': 'Description', 'category': 'summary'}, {'text': 'SSVCv2/E:P/A:Y/T:T/2026-05-05T14:43:39Z/', 'title': 'SSVC', 'category': 'details'}], 'title': 'Tyler Identity Local (TID-L) default administrative credentials', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'release_date': '2026-05-19T00:00:00Z', 'remediations': [{'details': 'Product is no longer supported as of 2021. Change default credentials if necessary.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}, 'acknowledgments': [{'names': ['Logan Diomedi'], 'organization': 'Depth Security'}]}]} | |
ot | ICSA-24-345-06 | CVE-2024-12175 | Rockwell Automation Arena (Update C) | 2024-12-10 10:00:00+03:00 | 2026-06-23 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-345-06.json | 9b90c276fe78a56ca09e17668feed13096ca9b517af0cedb27905c84716cafc3 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-24 07:37:39.992137+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could result in execution of arbitrary code.', 'title': 'Advisory Summary', 'category': 'summary'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also recommends users take the following measures to protect themselves from social engineering attacks:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Do not click web links or open attachments in unsolicited email messages.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities are not exploitable remotely.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Rockwell Automation Arena (Update C)', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-24-345-06', 'status': 'final', 'version': '4', 'generator': {'date': '2026-06-22T21:23:33.184965Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2024-12-10T07:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}, {'date': '2025-01-09T07:00:00.000000Z', 'number': '2', 'summary': 'Update A - Added CVE-2024-11157, CVE-2024-12175, CVE-2024-12672, and CVE-2024-11364.', 'legacy_version': 'Update A'}, {'date': '2026-02-03T07:00:00.000000Z', 'number': '3', 'summary': 'Update B - Added CVE-2025-6376, CVE-2025-6377, updated affected products and mitigations.', 'legacy_version': 'Update B'}, {'date': '2026-06-23T06:00:00.000000Z', 'number': '4', 'summary': 'Update C - Added CVE-2026-6071', 'legacy_version': 'Update C'}], 'current_release_date': '2026-06-23T06:00:00.000000Z', 'initial_release_date': '2024-12-10T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-345-06.json', 'summary': 'ICS Advisory ICSA-24-345-06 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-24-345-06', 'summary': 'ICSA Advisory ICSA-24-345-06 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/ncas/tips/ST04-014', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Rocco Calvi'], 'summary': 'reported these vulnerabilities to Trend Micro Zero Day Initiative', 'organization': 'TecSecurity'}, {'names': ['Mat Powell'], 'summary': 'reported these vulnerabilities to Rockwell Automation', 'organization': 'Trend Micro Zero Day Initiative'}]}, 'product_tree': {'branches': [{'name': 'Rockwell Automation', 'branches': [{'name': 'Arena', 'branches': [{'name': '<=16.20.00', 'product': {'name': 'Rockwell Automation Arena: <=16.20.00', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.03', 'product': {'name': 'Rockwell Automation Arena: <=16.20.03', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.05', 'product': {'name': 'Rockwell Automation Arena: <=16.20.05', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.06', 'product': {'name': 'Rockwell Automation Arena: <=16.20.06', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.08', 'product': {'name': 'Rockwell Automation Arena: <=16.20.08', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena 32 bit', 'branches': [{'name': '<=16.20.07', 'product': {'name': 'Rockwell Automation Arena 32 bit: <=16.20.07', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena 32 bit', 'branches': [{'name': '<=16.20.06', 'product': {'name': 'Rockwell Automation Arena 32 bit: <=16.20.06', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2024-11155', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'A "use after free" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/416.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11155', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2024-11156', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'An "out of bounds write" code execution vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0002']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11156', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}], 'product_status': {'known_affected': ['CSAFPID-0002']}}, {'cve': 'CVE-2024-11158', 'cwe': {'id': 'CWE-665', 'name': 'Improper Initialization'}, 'notes': [{'text': 'An "uninitialized variable" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to access a variable before it is initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/665.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11158', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2024-12130', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'An "out of bounds read" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to read beyond the boundaries of an allocated memory. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0003']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/125.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12130', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}], 'product_status': {'known_affected': ['CSAFPID-0003']}}, {'cve': 'CVE-2024-11157', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A third-party vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0004']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11157', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}], 'product_status': {'known_affected': ['CSAFPID-0004']}}, {'cve': 'CVE-2024-12175', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Another "use after free" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0004']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/416.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12175', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}], 'product_status': {'known_affected': ['CSAFPID-0004']}}, {'cve': 'CVE-2024-12672', 'cwe': {'id': 'CWE-1395', 'name': 'Dependency on Vulnerable Third-Party Component'}, 'notes': [{'text': 'A third-party vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0006']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/1395.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12672', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}], 'product_status': {'known_affected': ['CSAFPID-0006']}}, {'cve': 'CVE-2024-11364', 'cwe': {'id': 'CWE-1395', 'name': 'Dependency on Vulnerable Third-Party Component'}, 'notes': [{'text': 'Another "uninitialized variable" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to access a variable prior to it being initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0007']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/1395.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11364', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}], 'product_status': {'known_affected': ['CSAFPID-0007']}}, {'cve': 'CVE-2025-6377', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-6377', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}, {'cve': 'CVE-2025-6376', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-6376', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}, {'cve': 'CVE-2026-6071', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products when parsing DOE files that could allow a remote attacker to write past the end of an allocated object and execute code within the context of the current process. To exploit this vulnerability, a legitimate user must visit a malicious page or open a malicious file.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-6071', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}]} | |
ot | ICSA-24-345-06 | CVE-2024-12672 | Rockwell Automation Arena (Update C) | 2024-12-10 10:00:00+03:00 | 2026-06-23 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-345-06.json | a03352f60259c0fde01a31dd68b692464d6c3b56592a979357c556c33a599faf | 2026-05-29 09:17:34.767089+03:00 | 2026-06-24 07:37:39.992137+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could result in execution of arbitrary code.', 'title': 'Advisory Summary', 'category': 'summary'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also recommends users take the following measures to protect themselves from social engineering attacks:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Do not click web links or open attachments in unsolicited email messages.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities are not exploitable remotely.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Rockwell Automation Arena (Update C)', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-24-345-06', 'status': 'final', 'version': '4', 'generator': {'date': '2026-06-22T21:23:33.184965Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2024-12-10T07:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}, {'date': '2025-01-09T07:00:00.000000Z', 'number': '2', 'summary': 'Update A - Added CVE-2024-11157, CVE-2024-12175, CVE-2024-12672, and CVE-2024-11364.', 'legacy_version': 'Update A'}, {'date': '2026-02-03T07:00:00.000000Z', 'number': '3', 'summary': 'Update B - Added CVE-2025-6376, CVE-2025-6377, updated affected products and mitigations.', 'legacy_version': 'Update B'}, {'date': '2026-06-23T06:00:00.000000Z', 'number': '4', 'summary': 'Update C - Added CVE-2026-6071', 'legacy_version': 'Update C'}], 'current_release_date': '2026-06-23T06:00:00.000000Z', 'initial_release_date': '2024-12-10T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-345-06.json', 'summary': 'ICS Advisory ICSA-24-345-06 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-24-345-06', 'summary': 'ICSA Advisory ICSA-24-345-06 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/ncas/tips/ST04-014', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Rocco Calvi'], 'summary': 'reported these vulnerabilities to Trend Micro Zero Day Initiative', 'organization': 'TecSecurity'}, {'names': ['Mat Powell'], 'summary': 'reported these vulnerabilities to Rockwell Automation', 'organization': 'Trend Micro Zero Day Initiative'}]}, 'product_tree': {'branches': [{'name': 'Rockwell Automation', 'branches': [{'name': 'Arena', 'branches': [{'name': '<=16.20.00', 'product': {'name': 'Rockwell Automation Arena: <=16.20.00', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.03', 'product': {'name': 'Rockwell Automation Arena: <=16.20.03', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.05', 'product': {'name': 'Rockwell Automation Arena: <=16.20.05', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.06', 'product': {'name': 'Rockwell Automation Arena: <=16.20.06', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.08', 'product': {'name': 'Rockwell Automation Arena: <=16.20.08', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena 32 bit', 'branches': [{'name': '<=16.20.07', 'product': {'name': 'Rockwell Automation Arena 32 bit: <=16.20.07', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena 32 bit', 'branches': [{'name': '<=16.20.06', 'product': {'name': 'Rockwell Automation Arena 32 bit: <=16.20.06', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2024-11155', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'A "use after free" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/416.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11155', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2024-11156', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'An "out of bounds write" code execution vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0002']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11156', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}], 'product_status': {'known_affected': ['CSAFPID-0002']}}, {'cve': 'CVE-2024-11158', 'cwe': {'id': 'CWE-665', 'name': 'Improper Initialization'}, 'notes': [{'text': 'An "uninitialized variable" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to access a variable before it is initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/665.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11158', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2024-12130', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'An "out of bounds read" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to read beyond the boundaries of an allocated memory. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0003']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/125.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12130', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}], 'product_status': {'known_affected': ['CSAFPID-0003']}}, {'cve': 'CVE-2024-11157', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A third-party vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0004']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11157', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}], 'product_status': {'known_affected': ['CSAFPID-0004']}}, {'cve': 'CVE-2024-12175', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Another "use after free" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0004']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/416.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12175', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}], 'product_status': {'known_affected': ['CSAFPID-0004']}}, {'cve': 'CVE-2024-12672', 'cwe': {'id': 'CWE-1395', 'name': 'Dependency on Vulnerable Third-Party Component'}, 'notes': [{'text': 'A third-party vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0006']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/1395.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12672', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}], 'product_status': {'known_affected': ['CSAFPID-0006']}}, {'cve': 'CVE-2024-11364', 'cwe': {'id': 'CWE-1395', 'name': 'Dependency on Vulnerable Third-Party Component'}, 'notes': [{'text': 'Another "uninitialized variable" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to access a variable prior to it being initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0007']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/1395.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11364', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}], 'product_status': {'known_affected': ['CSAFPID-0007']}}, {'cve': 'CVE-2025-6377', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-6377', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}, {'cve': 'CVE-2025-6376', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-6376', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}, {'cve': 'CVE-2026-6071', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products when parsing DOE files that could allow a remote attacker to write past the end of an allocated object and execute code within the context of the current process. To exploit this vulnerability, a legitimate user must visit a malicious page or open a malicious file.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-6071', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}]} | |
ot | ICSA-24-345-06 | CVE-2024-11364 | Rockwell Automation Arena (Update C) | 2024-12-10 10:00:00+03:00 | 2026-06-23 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-345-06.json | b251821506d7c40396470380122901e8a256ee4b965f3cbd281ffe639c0f8a2a | 2026-05-29 09:17:34.767089+03:00 | 2026-06-24 07:37:39.992137+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could result in execution of arbitrary code.', 'title': 'Advisory Summary', 'category': 'summary'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also recommends users take the following measures to protect themselves from social engineering attacks:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Do not click web links or open attachments in unsolicited email messages.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities are not exploitable remotely.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Rockwell Automation Arena (Update C)', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-24-345-06', 'status': 'final', 'version': '4', 'generator': {'date': '2026-06-22T21:23:33.184965Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2024-12-10T07:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}, {'date': '2025-01-09T07:00:00.000000Z', 'number': '2', 'summary': 'Update A - Added CVE-2024-11157, CVE-2024-12175, CVE-2024-12672, and CVE-2024-11364.', 'legacy_version': 'Update A'}, {'date': '2026-02-03T07:00:00.000000Z', 'number': '3', 'summary': 'Update B - Added CVE-2025-6376, CVE-2025-6377, updated affected products and mitigations.', 'legacy_version': 'Update B'}, {'date': '2026-06-23T06:00:00.000000Z', 'number': '4', 'summary': 'Update C - Added CVE-2026-6071', 'legacy_version': 'Update C'}], 'current_release_date': '2026-06-23T06:00:00.000000Z', 'initial_release_date': '2024-12-10T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-345-06.json', 'summary': 'ICS Advisory ICSA-24-345-06 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-24-345-06', 'summary': 'ICSA Advisory ICSA-24-345-06 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/ncas/tips/ST04-014', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Rocco Calvi'], 'summary': 'reported these vulnerabilities to Trend Micro Zero Day Initiative', 'organization': 'TecSecurity'}, {'names': ['Mat Powell'], 'summary': 'reported these vulnerabilities to Rockwell Automation', 'organization': 'Trend Micro Zero Day Initiative'}]}, 'product_tree': {'branches': [{'name': 'Rockwell Automation', 'branches': [{'name': 'Arena', 'branches': [{'name': '<=16.20.00', 'product': {'name': 'Rockwell Automation Arena: <=16.20.00', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.03', 'product': {'name': 'Rockwell Automation Arena: <=16.20.03', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.05', 'product': {'name': 'Rockwell Automation Arena: <=16.20.05', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.06', 'product': {'name': 'Rockwell Automation Arena: <=16.20.06', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.08', 'product': {'name': 'Rockwell Automation Arena: <=16.20.08', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena 32 bit', 'branches': [{'name': '<=16.20.07', 'product': {'name': 'Rockwell Automation Arena 32 bit: <=16.20.07', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena 32 bit', 'branches': [{'name': '<=16.20.06', 'product': {'name': 'Rockwell Automation Arena 32 bit: <=16.20.06', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2024-11155', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'A "use after free" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/416.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11155', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2024-11156', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'An "out of bounds write" code execution vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0002']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11156', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}], 'product_status': {'known_affected': ['CSAFPID-0002']}}, {'cve': 'CVE-2024-11158', 'cwe': {'id': 'CWE-665', 'name': 'Improper Initialization'}, 'notes': [{'text': 'An "uninitialized variable" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to access a variable before it is initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/665.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11158', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2024-12130', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'An "out of bounds read" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to read beyond the boundaries of an allocated memory. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0003']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/125.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12130', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}], 'product_status': {'known_affected': ['CSAFPID-0003']}}, {'cve': 'CVE-2024-11157', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A third-party vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0004']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11157', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}], 'product_status': {'known_affected': ['CSAFPID-0004']}}, {'cve': 'CVE-2024-12175', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Another "use after free" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0004']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/416.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12175', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}], 'product_status': {'known_affected': ['CSAFPID-0004']}}, {'cve': 'CVE-2024-12672', 'cwe': {'id': 'CWE-1395', 'name': 'Dependency on Vulnerable Third-Party Component'}, 'notes': [{'text': 'A third-party vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0006']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/1395.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12672', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}], 'product_status': {'known_affected': ['CSAFPID-0006']}}, {'cve': 'CVE-2024-11364', 'cwe': {'id': 'CWE-1395', 'name': 'Dependency on Vulnerable Third-Party Component'}, 'notes': [{'text': 'Another "uninitialized variable" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to access a variable prior to it being initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0007']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/1395.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11364', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}], 'product_status': {'known_affected': ['CSAFPID-0007']}}, {'cve': 'CVE-2025-6377', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-6377', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}, {'cve': 'CVE-2025-6376', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-6376', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}, {'cve': 'CVE-2026-6071', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products when parsing DOE files that could allow a remote attacker to write past the end of an allocated object and execute code within the context of the current process. To exploit this vulnerability, a legitimate user must visit a malicious page or open a malicious file.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-6071', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}]} | |
ot | ICSA-24-345-06 | CVE-2025-6377 | Rockwell Automation Arena (Update C) | 2024-12-10 10:00:00+03:00 | 2026-06-23 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-345-06.json | 2968d9b6019714751ab7d9f2d4c4303ef2ddb333bf19e3296df23e3020796d07 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-24 07:37:39.992137+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could result in execution of arbitrary code.', 'title': 'Advisory Summary', 'category': 'summary'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also recommends users take the following measures to protect themselves from social engineering attacks:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Do not click web links or open attachments in unsolicited email messages.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities are not exploitable remotely.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Rockwell Automation Arena (Update C)', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-24-345-06', 'status': 'final', 'version': '4', 'generator': {'date': '2026-06-22T21:23:33.184965Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2024-12-10T07:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}, {'date': '2025-01-09T07:00:00.000000Z', 'number': '2', 'summary': 'Update A - Added CVE-2024-11157, CVE-2024-12175, CVE-2024-12672, and CVE-2024-11364.', 'legacy_version': 'Update A'}, {'date': '2026-02-03T07:00:00.000000Z', 'number': '3', 'summary': 'Update B - Added CVE-2025-6376, CVE-2025-6377, updated affected products and mitigations.', 'legacy_version': 'Update B'}, {'date': '2026-06-23T06:00:00.000000Z', 'number': '4', 'summary': 'Update C - Added CVE-2026-6071', 'legacy_version': 'Update C'}], 'current_release_date': '2026-06-23T06:00:00.000000Z', 'initial_release_date': '2024-12-10T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-345-06.json', 'summary': 'ICS Advisory ICSA-24-345-06 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-24-345-06', 'summary': 'ICSA Advisory ICSA-24-345-06 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/ncas/tips/ST04-014', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Rocco Calvi'], 'summary': 'reported these vulnerabilities to Trend Micro Zero Day Initiative', 'organization': 'TecSecurity'}, {'names': ['Mat Powell'], 'summary': 'reported these vulnerabilities to Rockwell Automation', 'organization': 'Trend Micro Zero Day Initiative'}]}, 'product_tree': {'branches': [{'name': 'Rockwell Automation', 'branches': [{'name': 'Arena', 'branches': [{'name': '<=16.20.00', 'product': {'name': 'Rockwell Automation Arena: <=16.20.00', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.03', 'product': {'name': 'Rockwell Automation Arena: <=16.20.03', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.05', 'product': {'name': 'Rockwell Automation Arena: <=16.20.05', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.06', 'product': {'name': 'Rockwell Automation Arena: <=16.20.06', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.08', 'product': {'name': 'Rockwell Automation Arena: <=16.20.08', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena 32 bit', 'branches': [{'name': '<=16.20.07', 'product': {'name': 'Rockwell Automation Arena 32 bit: <=16.20.07', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena 32 bit', 'branches': [{'name': '<=16.20.06', 'product': {'name': 'Rockwell Automation Arena 32 bit: <=16.20.06', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2024-11155', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'A "use after free" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/416.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11155', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2024-11156', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'An "out of bounds write" code execution vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0002']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11156', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}], 'product_status': {'known_affected': ['CSAFPID-0002']}}, {'cve': 'CVE-2024-11158', 'cwe': {'id': 'CWE-665', 'name': 'Improper Initialization'}, 'notes': [{'text': 'An "uninitialized variable" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to access a variable before it is initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/665.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11158', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2024-12130', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'An "out of bounds read" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to read beyond the boundaries of an allocated memory. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0003']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/125.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12130', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}], 'product_status': {'known_affected': ['CSAFPID-0003']}}, {'cve': 'CVE-2024-11157', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A third-party vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0004']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11157', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}], 'product_status': {'known_affected': ['CSAFPID-0004']}}, {'cve': 'CVE-2024-12175', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Another "use after free" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0004']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/416.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12175', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}], 'product_status': {'known_affected': ['CSAFPID-0004']}}, {'cve': 'CVE-2024-12672', 'cwe': {'id': 'CWE-1395', 'name': 'Dependency on Vulnerable Third-Party Component'}, 'notes': [{'text': 'A third-party vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0006']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/1395.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12672', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}], 'product_status': {'known_affected': ['CSAFPID-0006']}}, {'cve': 'CVE-2024-11364', 'cwe': {'id': 'CWE-1395', 'name': 'Dependency on Vulnerable Third-Party Component'}, 'notes': [{'text': 'Another "uninitialized variable" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to access a variable prior to it being initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0007']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/1395.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11364', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}], 'product_status': {'known_affected': ['CSAFPID-0007']}}, {'cve': 'CVE-2025-6377', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-6377', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}, {'cve': 'CVE-2025-6376', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-6376', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}, {'cve': 'CVE-2026-6071', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products when parsing DOE files that could allow a remote attacker to write past the end of an allocated object and execute code within the context of the current process. To exploit this vulnerability, a legitimate user must visit a malicious page or open a malicious file.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-6071', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}]} | |
ot | ICSA-24-345-06 | CVE-2025-6376 | Rockwell Automation Arena (Update C) | 2024-12-10 10:00:00+03:00 | 2026-06-23 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-345-06.json | 776acfcd33451647a996559b6638411448439326bb2b18bfc20e945c944f0359 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-24 07:37:39.992137+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could result in execution of arbitrary code.', 'title': 'Advisory Summary', 'category': 'summary'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also recommends users take the following measures to protect themselves from social engineering attacks:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Do not click web links or open attachments in unsolicited email messages.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities are not exploitable remotely.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Rockwell Automation Arena (Update C)', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-24-345-06', 'status': 'final', 'version': '4', 'generator': {'date': '2026-06-22T21:23:33.184965Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2024-12-10T07:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}, {'date': '2025-01-09T07:00:00.000000Z', 'number': '2', 'summary': 'Update A - Added CVE-2024-11157, CVE-2024-12175, CVE-2024-12672, and CVE-2024-11364.', 'legacy_version': 'Update A'}, {'date': '2026-02-03T07:00:00.000000Z', 'number': '3', 'summary': 'Update B - Added CVE-2025-6376, CVE-2025-6377, updated affected products and mitigations.', 'legacy_version': 'Update B'}, {'date': '2026-06-23T06:00:00.000000Z', 'number': '4', 'summary': 'Update C - Added CVE-2026-6071', 'legacy_version': 'Update C'}], 'current_release_date': '2026-06-23T06:00:00.000000Z', 'initial_release_date': '2024-12-10T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-345-06.json', 'summary': 'ICS Advisory ICSA-24-345-06 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-24-345-06', 'summary': 'ICSA Advisory ICSA-24-345-06 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/ncas/tips/ST04-014', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Rocco Calvi'], 'summary': 'reported these vulnerabilities to Trend Micro Zero Day Initiative', 'organization': 'TecSecurity'}, {'names': ['Mat Powell'], 'summary': 'reported these vulnerabilities to Rockwell Automation', 'organization': 'Trend Micro Zero Day Initiative'}]}, 'product_tree': {'branches': [{'name': 'Rockwell Automation', 'branches': [{'name': 'Arena', 'branches': [{'name': '<=16.20.00', 'product': {'name': 'Rockwell Automation Arena: <=16.20.00', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.03', 'product': {'name': 'Rockwell Automation Arena: <=16.20.03', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.05', 'product': {'name': 'Rockwell Automation Arena: <=16.20.05', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.06', 'product': {'name': 'Rockwell Automation Arena: <=16.20.06', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.08', 'product': {'name': 'Rockwell Automation Arena: <=16.20.08', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena 32 bit', 'branches': [{'name': '<=16.20.07', 'product': {'name': 'Rockwell Automation Arena 32 bit: <=16.20.07', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena 32 bit', 'branches': [{'name': '<=16.20.06', 'product': {'name': 'Rockwell Automation Arena 32 bit: <=16.20.06', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2024-11155', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'A "use after free" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/416.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11155', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2024-11156', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'An "out of bounds write" code execution vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0002']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11156', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}], 'product_status': {'known_affected': ['CSAFPID-0002']}}, {'cve': 'CVE-2024-11158', 'cwe': {'id': 'CWE-665', 'name': 'Improper Initialization'}, 'notes': [{'text': 'An "uninitialized variable" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to access a variable before it is initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/665.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11158', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2024-12130', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'An "out of bounds read" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to read beyond the boundaries of an allocated memory. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0003']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/125.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12130', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}], 'product_status': {'known_affected': ['CSAFPID-0003']}}, {'cve': 'CVE-2024-11157', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A third-party vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0004']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11157', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}], 'product_status': {'known_affected': ['CSAFPID-0004']}}, {'cve': 'CVE-2024-12175', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Another "use after free" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0004']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/416.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12175', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}], 'product_status': {'known_affected': ['CSAFPID-0004']}}, {'cve': 'CVE-2024-12672', 'cwe': {'id': 'CWE-1395', 'name': 'Dependency on Vulnerable Third-Party Component'}, 'notes': [{'text': 'A third-party vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0006']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/1395.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12672', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}], 'product_status': {'known_affected': ['CSAFPID-0006']}}, {'cve': 'CVE-2024-11364', 'cwe': {'id': 'CWE-1395', 'name': 'Dependency on Vulnerable Third-Party Component'}, 'notes': [{'text': 'Another "uninitialized variable" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to access a variable prior to it being initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0007']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/1395.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11364', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}], 'product_status': {'known_affected': ['CSAFPID-0007']}}, {'cve': 'CVE-2025-6377', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-6377', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}, {'cve': 'CVE-2025-6376', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-6376', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}, {'cve': 'CVE-2026-6071', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products when parsing DOE files that could allow a remote attacker to write past the end of an allocated object and execute code within the context of the current process. To exploit this vulnerability, a legitimate user must visit a malicious page or open a malicious file.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-6071', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}]} | |
ot | ICSA-24-345-06 | CVE-2026-6071 | Rockwell Automation Arena (Update C) | 2024-12-10 10:00:00+03:00 | 2026-06-23 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-345-06.json | 6ee83833c5593191edc650e12da4025bec423f76c073ef4c61c757197db9820e | 2026-06-24 07:37:39.992137+03:00 | 2026-06-24 07:37:39.992137+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could result in execution of arbitrary code.', 'title': 'Advisory Summary', 'category': 'summary'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also recommends users take the following measures to protect themselves from social engineering attacks:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Do not click web links or open attachments in unsolicited email messages.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities are not exploitable remotely.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Rockwell Automation Arena (Update C)', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-24-345-06', 'status': 'final', 'version': '4', 'generator': {'date': '2026-06-22T21:23:33.184965Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2024-12-10T07:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}, {'date': '2025-01-09T07:00:00.000000Z', 'number': '2', 'summary': 'Update A - Added CVE-2024-11157, CVE-2024-12175, CVE-2024-12672, and CVE-2024-11364.', 'legacy_version': 'Update A'}, {'date': '2026-02-03T07:00:00.000000Z', 'number': '3', 'summary': 'Update B - Added CVE-2025-6376, CVE-2025-6377, updated affected products and mitigations.', 'legacy_version': 'Update B'}, {'date': '2026-06-23T06:00:00.000000Z', 'number': '4', 'summary': 'Update C - Added CVE-2026-6071', 'legacy_version': 'Update C'}], 'current_release_date': '2026-06-23T06:00:00.000000Z', 'initial_release_date': '2024-12-10T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-345-06.json', 'summary': 'ICS Advisory ICSA-24-345-06 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-24-345-06', 'summary': 'ICSA Advisory ICSA-24-345-06 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/ncas/tips/ST04-014', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Rocco Calvi'], 'summary': 'reported these vulnerabilities to Trend Micro Zero Day Initiative', 'organization': 'TecSecurity'}, {'names': ['Mat Powell'], 'summary': 'reported these vulnerabilities to Rockwell Automation', 'organization': 'Trend Micro Zero Day Initiative'}]}, 'product_tree': {'branches': [{'name': 'Rockwell Automation', 'branches': [{'name': 'Arena', 'branches': [{'name': '<=16.20.00', 'product': {'name': 'Rockwell Automation Arena: <=16.20.00', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.03', 'product': {'name': 'Rockwell Automation Arena: <=16.20.03', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.05', 'product': {'name': 'Rockwell Automation Arena: <=16.20.05', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.06', 'product': {'name': 'Rockwell Automation Arena: <=16.20.06', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena', 'branches': [{'name': '<=16.20.08', 'product': {'name': 'Rockwell Automation Arena: <=16.20.08', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena 32 bit', 'branches': [{'name': '<=16.20.07', 'product': {'name': 'Rockwell Automation Arena 32 bit: <=16.20.07', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Arena 32 bit', 'branches': [{'name': '<=16.20.06', 'product': {'name': 'Rockwell Automation Arena 32 bit: <=16.20.06', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2024-11155', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'A "use after free" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/416.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11155', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2024-11156', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'An "out of bounds write" code execution vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0002']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11156', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002']}], 'product_status': {'known_affected': ['CSAFPID-0002']}}, {'cve': 'CVE-2024-11158', 'cwe': {'id': 'CWE-665', 'name': 'Improper Initialization'}, 'notes': [{'text': 'An "uninitialized variable" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to access a variable before it is initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/665.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11158', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2024-12130', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'An "out of bounds read" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to read beyond the boundaries of an allocated memory. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor. ', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0003']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/125.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12130', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003']}], 'product_status': {'known_affected': ['CSAFPID-0003']}}, {'cve': 'CVE-2024-11157', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A third-party vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0004']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11157', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}], 'product_status': {'known_affected': ['CSAFPID-0004']}}, {'cve': 'CVE-2024-12175', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'Another "use after free" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0004']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/416.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12175', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004']}], 'product_status': {'known_affected': ['CSAFPID-0004']}}, {'cve': 'CVE-2024-12672', 'cwe': {'id': 'CWE-1395', 'name': 'Dependency on Vulnerable Third-Party Component'}, 'notes': [{'text': 'A third-party vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0006']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/1395.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-12672', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006']}], 'product_status': {'known_affected': ['CSAFPID-0006']}}, {'cve': 'CVE-2024-11364', 'cwe': {'id': 'CWE-1395', 'name': 'Dependency on Vulnerable Third-Party Component'}, 'notes': [{'text': 'Another "uninitialized variable" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to access a variable prior to it being initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0007']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/1395.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2024-11364', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0007']}], 'product_status': {'known_affected': ['CSAFPID-0007']}}, {'cve': 'CVE-2025-6377', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-6377', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}, {'cve': 'CVE-2025-6376', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-6376', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}, {'cve': 'CVE-2026-6071', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'A remote code execution security issue exists in the affected products when parsing DOE files that could allow a remote attacker to write past the end of an allocated object and execute code within the context of the current process. To exploit this vulnerability, a legitimate user must visit a malicious page or open a malicious file.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-6071', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation recommends users upgrade to V16.20.09 or later.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'details': 'Do not load untrusted Arena model files.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Hold the control key down when loading files to help prevent the VBA file stream from loading.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight', 'details': 'For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc', 'details': 'Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html', 'details': 'For more information about these issues, please see the Rockwell Automation security advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0005']}}]} | |
ot | ICSMA-26-176-02 | CVE-2026-12473 | OHIF Viewers DICOM | 2026-06-25 09:00:00+03:00 | 2026-06-25 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsma-26-176-02.json | 0cb4642cdb73e537dce7c6b64aa2e8eb530297386db4831f62780545a16fa287 | 2026-06-26 05:15:06.578444+03:00 | 2026-06-26 05:15:06.578444+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': "Successful exploitation of this vulnerability in a custom integration version could allow an attacker to steal an authenticated clinician's token via a crafted link.", 'title': 'Advisory Summary', 'category': 'summary'}, {'text': 'Healthcare and Public Health', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also recommends users take the following measures to protect themselves from social engineering attacks:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Do not click web links or open attachments in unsolicited email messages.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'OHIF Viewers DICOM', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSMA-26-176-02', 'status': 'final', 'version': '1', 'generator': {'date': '2026-06-24T20:30:52.225304Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-06-25T06:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}], 'current_release_date': '2026-06-25T06:00:00.000000Z', 'initial_release_date': '2026-06-25T06:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsma-26-176-02.json', 'summary': 'ICS Advisory ICSMA-26-176-02 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-176-02', 'summary': 'ICSA Advisory ICSMA-26-176-02 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/ncas/tips/ST04-014', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Simon Weber', 'Volker Schönefeld'], 'summary': 'reported this vulnerability to CISA', 'organization': 'Machine Spirits UG'}]}, 'product_tree': {'branches': [{'name': 'Open Health Imaging Foundation (OHIF)', 'branches': [{'name': 'OHIF DICOM Web Viewer Framework', 'branches': [{'name': '<=v3.12.0', 'product': {'name': 'Open Health Imaging Foundation (OHIF) OHIF DICOM Web Viewer Framework: <=v3.12.0', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-12473', 'cwe': {'id': 'CWE-918', 'name': 'Server-Side Request Forgery (SSRF)'}, 'notes': [{'text': "Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter without validation. A global authentication service in OHIF automatically injects the authenticated user's OIDC Bearer token into the resulting requests, sending it to the attacker-controlled server. DICOMweb data sources are not impacted.", 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-06-24T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/918.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-12473', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'The maintainer has fixed the reported vulnerability and released version 3.12.2 (2026-05-18). The fix is located at OHIF/Viewers#5985 (master), OHIF/Viewers#5978 (release/3.12).', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Users are recommended to upgrade to v3.12.2 or later. Operators who need dicomwebproxy or dicomjson in authenticated deployments must additionally configure the new dangerouslyAllowedOriginsForAuthenticatedEnvironments allowlist in app-config.js.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Users running OHIF with authentication should remove ALL unused DicomWebProxyDataSource and DicomJSONDataSource configurations from the configuration file they are deploying with.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSMA-26-176-01 | CVE-2026-56445 | pydicom pynetdicom Library | 2026-06-25 09:00:00+03:00 | 2026-06-25 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsma-26-176-01.json | f6d1cd32e5bfd6a8a968dbcf960adb039a5d6160babc1318caf49322638783e6 | 2026-06-26 05:15:06.578444+03:00 | 2026-06-26 05:15:06.578444+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of this vulnerability could allow an unauthenticated attacker to write to arbitrary file paths.', 'title': 'Advisory Summary', 'category': 'summary'}, {'text': 'Healthcare and Public Health', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'pydicom pynetdicom Library', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSMA-26-176-01', 'status': 'final', 'version': '1', 'generator': {'date': '2026-06-24T20:30:52.424342Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-06-25T06:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}], 'current_release_date': '2026-06-25T06:00:00.000000Z', 'initial_release_date': '2026-06-25T06:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsma-26-176-01.json', 'summary': 'ICS Advisory ICSMA-26-176-01 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-176-01', 'summary': 'ICSA Advisory ICSMA-26-176-01 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Simon Weber', 'Volker Schönefeld'], 'summary': 'reported this vulnerability to CISA', 'organization': 'Machine Spirits UG'}]}, 'product_tree': {'branches': [{'name': 'pydicom', 'branches': [{'name': 'pynetdicom', 'branches': [{'name': '>=v1.0.0|<v3.0.4', 'product': {'name': 'pydicom pynetdicom: >=v1.0.0|<v3.0.4', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-56445', 'cwe': {'id': 'CWE-22', 'name': "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"}, 'notes': [{'text': "The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitization, allowing file writes to arbitrary paths.", 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-06-24T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.1, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/22.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-56445', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://github.com/pydicom/pynetdicom', 'details': 'The maintainer of pynetdicom has not responded to requests to work with CISA to mitigate this vulnerability. For update information, refer to the github page https://github.com/pydicom/pynetdicom.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-176-07 | CVE-2026-9716 | Schneider Electric PowerLogic P7 | 2026-06-09 10:00:00+03:00 | 2026-06-25 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-07.json | 717171ca04c337a79f7fcbfa7b8178479aadae66ace8a546186cc6bd91448d5d | 2026-06-26 05:15:06.578444+03:00 | 2026-06-26 05:15:06.578444+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'We strongly recommend the following industry cybersecurity best practices.\n\nhttps://www.se.com/us/en/download/document/7EN52-0390/\n* Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.\n* Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.\n* Place all controllers in locked cabinets and never leave them in the “Program” mode.\n* Never connect programming software to any network other than the network intended for that device.\n* Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.\n* Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.\n* Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.\n* When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.\nFor more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document. \n', 'title': 'General Security Recommendations', 'category': 'general'}, {'text': 'This document provides an overview of the identified vulnerability or vulnerabilities and actions required to mitigate. For more details and assistance on how to protect your installation, contact your local Schneider Electric representative or Schneider Electric Industrial Cybersecurity Services: https://www.se.com/ww/en/work/solutions/cybersecurity/. These organizations will be fully aware of this situation and can support you through the process.\nFor further information related to cybersecurity in Schneider Electric’s products, visit the company’s cybersecurity support portal page: https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp', 'title': 'For More Information', 'category': 'general'}, {'text': 'THIS NOTIFICATION DOCUMENT, THE INFORMATION CONTAINED HEREIN, AND ANY MATERIALS LINKED FROM IT (COLLECTIVELY, THIS “NOTIFICATION”) ARE INTENDED TO HELP PROVIDE AN OVERVIEW OF THE IDENTIFIED SITUATION AND SUGGESTED MITIGATION ACTIONS, REMEDIATION, FIX, AND/OR GENERAL SECURITY RECOMMENDATIONS AND IS PROVIDED ON AN “AS-IS” BASIS WITHOUT WARRANTY OR GUARANTEE OF ANY KIND. SCHNEIDER ELECTRIC DISCLAIMS ALL WARRANTIES RELATING TO THIS NOTIFICATION, EITHER EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SCHNEIDER ELECTRIC MAKES NO WARRANTY THAT THE NOTIFICATION WILL RESOLVE THE IDENTIFIED SITUATION. IN NO EVENT SHALL SCHNEIDER ELECTRIC BE LIABLE FOR ANY DAMAGES OR LOSSES WHATSOEVER IN CONNECTION WITH THIS NOTIFICATION, INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF SCHNEIDER ELECTRIC HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. YOUR USE OF THIS NOTIFICATION IS AT YOUR OWN RISK, AND YOU ARE SOLELY LIABLE FOR ANY DAMAGES TO YOUR SYSTEMS OR ASSETS OR OTHER LOSSES THAT MAY RESULT FROM YOUR USE OF THIS NOTIFICATION. SCHNEIDER ELECTRIC RESERVES THE RIGHT TO UPDATE OR CHANGE THIS NOTIFICATION AT ANY TIME AND IN ITS SOLE DISCRETION', 'title': 'LEGAL DISCLAIMER', 'category': 'legal_disclaimer'}, {'text': 'At Schneider, we believe access to energy and digital is a basic human right. We empower all to do more with less, ensuring Life Is On everywhere, for everyone, at every moment.\n\nWe provide energy and automation digital solutions for efficiency and sustainability. We combine world-leading energy technologies, real-time automation, software and services into integrated solutions for Homes, Buildings, Data Centers, Infrastructure and Industries.\n\nWe are committed to unleash the infinite possibilities of an open, global, innovative community that is passionate with our Meaningful Purpose, Inclusive and Empowered values.\n\nwww.se.com ', 'title': 'About Schneider Electric', 'category': 'general'}, {'text': 'Schneider Electric is aware of a vulnerability in its PowerLogic™ P7 product. \r\nThe PowerLogic™ P7 is a protection and control platform designed for complex and advanced electrical \r\nnetwork applications.\r\nFailure to apply the remediation provided below may risk unauthorized execution of privileged commands or \r\nloss of HMI operability and configuration functionality, which could result in loss of control over system \r\noperations and disruption of critical services.', 'title': 'Overview', 'category': 'summary'}, {'text': "The severity of vulnerabilities was calculated using the CVSS Base metrics for 4.0 ([CVSS v4.0](https://www.first.org/cvss/calculator/4.0)). CVSS v3.1 \nwill be still evaluated until the adoption of CVSS v4.0 by the industry. The severity was calculated without \nincorporating the Temporal and Environmental metrics. Schneider Electric recommends that customers score the CVSS Environmental metrics, which are specific to end-user organizations, and consider factors such as \nthe presence of mitigations in that environment. Environmental metrics may refine the relative severity posed by the vulnerabilities described in this document within a customer's environment.", 'category': 'other'}, {'text': "Customers should use appropriate patching methodologies when applying these patches to their systems. We strongly recommend the use of back-ups and evaluating the impact of these patches in a Test and Development environment or on an offline infrastructure. Contact Schneider Electric's [Customer Care Center](https://www.se.com/us/en/work/support/contacts.jsp) if you need assistance removing a patch.", 'category': 'other'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of Schneider Electric CPCERT SEVD-2026-160-03 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Schneider Electric CPCERT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Commercial Facilities, Critical Manufacturing, Energy', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'France', 'title': 'Company headquarters location', 'category': 'other'}], 'title': 'Schneider Electric PowerLogic P7', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-176-07', 'status': 'final', 'version': '2', 'generator': {'date': '2026-06-24T17:07:41.336093Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2026-06-09T07:00:00.000000Z', 'number': '1', 'summary': 'Original Release', 'legacy_version': 'Initial'}, {'date': '2026-06-25T06:00:00.000000Z', 'number': '2', 'summary': 'Initial CISA Republication of Schneider Electric CPCERT SEVD-2026-160-03 advisory', 'legacy_version': 'CISA Republication'}], 'current_release_date': '2026-06-25T06:00:00.000000Z', 'initial_release_date': '2026-06-09T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-160-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-160-03.json', 'summary': 'Multiple Vulnerabilities on PowerLogic™ P7 - SEVD-2026-160-03 CSAF Version', 'category': 'self'}, {'url': 'https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-160-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-160-03.pdf', 'summary': 'Multiple Vulnerabilities on PowerLogic™ P7 - SEVD-2026-160-03 PDF Version', 'category': 'self'}, {'url': 'https://www.se.com/ww/en/download/document/7EN52-0390', 'summary': 'Recommended Cybersecurity Best Practices', 'category': 'external'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-07.json', 'summary': 'ICS Advisory ICSA-26-176-07 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-07', 'summary': 'ICS Advisory ICSA-26-176-07 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to CISA.', 'organization': 'Schneider Electric CPCERT'}, {'summary': 'reported these vulnerabilities to Schneider Electric.', 'organization': 'Cytrics'}]}, 'product_tree': {'branches': [{'name': 'Schneider Electric', 'branches': [{'name': 'PowerLogic™ P7', 'branches': [{'name': 'vers:intdot/<=0.2.003.001.000', 'product': {'name': 'PowerLogic™ P7 version 0.2.003.001.000 and prior', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'PowerLogic™ P7', 'branches': [{'name': '0.2.003.001.000', 'product': {'name': 'PowerLogic™ version 0.2.003.001.000', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-9716', 'cwe': {'id': 'CWE-476', 'name': 'NULL Pointer Dereference'}, 'notes': [{'text': 'CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, \r\nrendering the device’s HMI and configuration functionality unavailable when malformed requests are received \r\nover exposed network interfaces.', 'title': 'CVE Description', 'category': 'description'}, {'text': 'CVSS v4.0 Base Score 8.7 | High | [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N](https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)', 'title': 'CVSS v4.0 Base Score', 'category': 'details'}], 'title': 'CVE-2026-9716', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-9716', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/476.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Version V02.004.001 of PowerLogicTM P7 includes a fix for this vulnerability\r\nand is available for download here:\r\n• Contact Schneider Electric’s Customer Care Center to download \r\nthis firmware.\r\n• Reboot needed: Yes', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'service'}}, {'details': 'If customers choose not to apply the remediation provided above, they should immediately apply the following \r\nmitigations to reduce the risk of exploit:\r\n• Restrict network access to P7 service endpoints (ports 8080 and 3702)\r\n• Monitor and alert on anomalous SOAP requests targeting wsApp\r\n• Limit administrative access and apply least privilege principles for all \r\nusers interacting with P7.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'none'}}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}, 'acknowledgments': [{'organization': 'Cytrics'}]}, {'cve': 'CVE-2026-9717', 'cwe': {'id': 'CWE-78', 'name': "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}, 'notes': [{'text': "CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability \r\nexists that could allow unauthorized execution of commands with elevated privileges, impacting system \r\nintegrity, confidentiality, and availability when a privileged authenticated user interacts with a vulnerable \r\nnetwork-exposed service.", 'title': 'CVE Description', 'category': 'description'}, {'text': 'CVSS v4.0 Base Score 8.6 | High | [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N](https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)', 'title': 'CVSS v4.0 Base Score', 'category': 'details'}], 'title': 'CVE-2026-9717', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.2, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-9717', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/78.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Version V02.004.001 of PowerLogicTM P7 includes a fix for this vulnerability\r\nand is available for download here:\r\n• Contact Schneider Electric’s Customer Care Center to download \r\nthis firmware.\r\n• Reboot needed: Yes', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'service'}}, {'details': 'If customers choose not to apply the remediation provided above, they should immediately apply the following \r\nmitigations to reduce the risk of exploit:\r\n• Restrict network access to P7 service endpoints (ports 8080 and 3702)\r\n• Monitor and alert on anomalous SOAP requests targeting wsApp\r\n• Limit administrative access and apply least privilege principles for all \r\nusers interacting with P7.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'none'}}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}, 'acknowledgments': [{'organization': 'Cytrics'}]}, {'cve': 'CVE-2026-9718', 'cwe': {'id': 'CWE-617', 'name': 'Reachable Assertion'}, 'notes': [{'text': 'CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a \r\ndenial-of-service condition, impacting system availability when a specially crafted request is sent to a \r\nvulnerable network-exposed service.', 'title': 'CVE Description', 'category': 'description'}, {'text': 'CVSS v4.0 Base Score 6.9 | Medium | [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N](https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)', 'title': 'CVSS v4.0 Base Score', 'category': 'details'}], 'title': 'CVE-2026-9718', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.9, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-9718', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/617.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Version V02.004.001 of PowerLogicTM P7 includes a fix for this vulnerability\r\nand is available for download here:\r\n• Contact Schneider Electric’s Customer Care Center to download \r\nthis firmware.\r\n• Reboot needed: Yes', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'service'}}, {'details': 'If customers choose not to apply the remediation provided above, they should immediately apply the following \r\nmitigations to reduce the risk of exploit:\r\n• Restrict network access to P7 service endpoints (ports 8080 and 3702)\r\n• Monitor and alert on anomalous SOAP requests targeting wsApp\r\n• Limit administrative access and apply least privilege principles for all \r\nusers interacting with P7.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'none'}}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}, 'acknowledgments': [{'organization': 'Cytrics'}]}]} | |
ot | ICSA-26-176-07 | CVE-2026-9717 | Schneider Electric PowerLogic P7 | 2026-06-09 10:00:00+03:00 | 2026-06-25 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-07.json | e86b0cd9f46eb27f38b8be310f4957e29c38dcadd16d768922d78a3a087c20a6 | 2026-06-26 05:15:06.578444+03:00 | 2026-06-26 05:15:06.578444+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'We strongly recommend the following industry cybersecurity best practices.\n\nhttps://www.se.com/us/en/download/document/7EN52-0390/\n* Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.\n* Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.\n* Place all controllers in locked cabinets and never leave them in the “Program” mode.\n* Never connect programming software to any network other than the network intended for that device.\n* Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.\n* Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.\n* Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.\n* When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.\nFor more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document. \n', 'title': 'General Security Recommendations', 'category': 'general'}, {'text': 'This document provides an overview of the identified vulnerability or vulnerabilities and actions required to mitigate. For more details and assistance on how to protect your installation, contact your local Schneider Electric representative or Schneider Electric Industrial Cybersecurity Services: https://www.se.com/ww/en/work/solutions/cybersecurity/. These organizations will be fully aware of this situation and can support you through the process.\nFor further information related to cybersecurity in Schneider Electric’s products, visit the company’s cybersecurity support portal page: https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp', 'title': 'For More Information', 'category': 'general'}, {'text': 'THIS NOTIFICATION DOCUMENT, THE INFORMATION CONTAINED HEREIN, AND ANY MATERIALS LINKED FROM IT (COLLECTIVELY, THIS “NOTIFICATION”) ARE INTENDED TO HELP PROVIDE AN OVERVIEW OF THE IDENTIFIED SITUATION AND SUGGESTED MITIGATION ACTIONS, REMEDIATION, FIX, AND/OR GENERAL SECURITY RECOMMENDATIONS AND IS PROVIDED ON AN “AS-IS” BASIS WITHOUT WARRANTY OR GUARANTEE OF ANY KIND. SCHNEIDER ELECTRIC DISCLAIMS ALL WARRANTIES RELATING TO THIS NOTIFICATION, EITHER EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SCHNEIDER ELECTRIC MAKES NO WARRANTY THAT THE NOTIFICATION WILL RESOLVE THE IDENTIFIED SITUATION. IN NO EVENT SHALL SCHNEIDER ELECTRIC BE LIABLE FOR ANY DAMAGES OR LOSSES WHATSOEVER IN CONNECTION WITH THIS NOTIFICATION, INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF SCHNEIDER ELECTRIC HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. YOUR USE OF THIS NOTIFICATION IS AT YOUR OWN RISK, AND YOU ARE SOLELY LIABLE FOR ANY DAMAGES TO YOUR SYSTEMS OR ASSETS OR OTHER LOSSES THAT MAY RESULT FROM YOUR USE OF THIS NOTIFICATION. SCHNEIDER ELECTRIC RESERVES THE RIGHT TO UPDATE OR CHANGE THIS NOTIFICATION AT ANY TIME AND IN ITS SOLE DISCRETION', 'title': 'LEGAL DISCLAIMER', 'category': 'legal_disclaimer'}, {'text': 'At Schneider, we believe access to energy and digital is a basic human right. We empower all to do more with less, ensuring Life Is On everywhere, for everyone, at every moment.\n\nWe provide energy and automation digital solutions for efficiency and sustainability. We combine world-leading energy technologies, real-time automation, software and services into integrated solutions for Homes, Buildings, Data Centers, Infrastructure and Industries.\n\nWe are committed to unleash the infinite possibilities of an open, global, innovative community that is passionate with our Meaningful Purpose, Inclusive and Empowered values.\n\nwww.se.com ', 'title': 'About Schneider Electric', 'category': 'general'}, {'text': 'Schneider Electric is aware of a vulnerability in its PowerLogic™ P7 product. \r\nThe PowerLogic™ P7 is a protection and control platform designed for complex and advanced electrical \r\nnetwork applications.\r\nFailure to apply the remediation provided below may risk unauthorized execution of privileged commands or \r\nloss of HMI operability and configuration functionality, which could result in loss of control over system \r\noperations and disruption of critical services.', 'title': 'Overview', 'category': 'summary'}, {'text': "The severity of vulnerabilities was calculated using the CVSS Base metrics for 4.0 ([CVSS v4.0](https://www.first.org/cvss/calculator/4.0)). CVSS v3.1 \nwill be still evaluated until the adoption of CVSS v4.0 by the industry. The severity was calculated without \nincorporating the Temporal and Environmental metrics. Schneider Electric recommends that customers score the CVSS Environmental metrics, which are specific to end-user organizations, and consider factors such as \nthe presence of mitigations in that environment. Environmental metrics may refine the relative severity posed by the vulnerabilities described in this document within a customer's environment.", 'category': 'other'}, {'text': "Customers should use appropriate patching methodologies when applying these patches to their systems. We strongly recommend the use of back-ups and evaluating the impact of these patches in a Test and Development environment or on an offline infrastructure. Contact Schneider Electric's [Customer Care Center](https://www.se.com/us/en/work/support/contacts.jsp) if you need assistance removing a patch.", 'category': 'other'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of Schneider Electric CPCERT SEVD-2026-160-03 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Schneider Electric CPCERT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Commercial Facilities, Critical Manufacturing, Energy', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'France', 'title': 'Company headquarters location', 'category': 'other'}], 'title': 'Schneider Electric PowerLogic P7', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-176-07', 'status': 'final', 'version': '2', 'generator': {'date': '2026-06-24T17:07:41.336093Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2026-06-09T07:00:00.000000Z', 'number': '1', 'summary': 'Original Release', 'legacy_version': 'Initial'}, {'date': '2026-06-25T06:00:00.000000Z', 'number': '2', 'summary': 'Initial CISA Republication of Schneider Electric CPCERT SEVD-2026-160-03 advisory', 'legacy_version': 'CISA Republication'}], 'current_release_date': '2026-06-25T06:00:00.000000Z', 'initial_release_date': '2026-06-09T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-160-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-160-03.json', 'summary': 'Multiple Vulnerabilities on PowerLogic™ P7 - SEVD-2026-160-03 CSAF Version', 'category': 'self'}, {'url': 'https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-160-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-160-03.pdf', 'summary': 'Multiple Vulnerabilities on PowerLogic™ P7 - SEVD-2026-160-03 PDF Version', 'category': 'self'}, {'url': 'https://www.se.com/ww/en/download/document/7EN52-0390', 'summary': 'Recommended Cybersecurity Best Practices', 'category': 'external'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-07.json', 'summary': 'ICS Advisory ICSA-26-176-07 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-07', 'summary': 'ICS Advisory ICSA-26-176-07 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to CISA.', 'organization': 'Schneider Electric CPCERT'}, {'summary': 'reported these vulnerabilities to Schneider Electric.', 'organization': 'Cytrics'}]}, 'product_tree': {'branches': [{'name': 'Schneider Electric', 'branches': [{'name': 'PowerLogic™ P7', 'branches': [{'name': 'vers:intdot/<=0.2.003.001.000', 'product': {'name': 'PowerLogic™ P7 version 0.2.003.001.000 and prior', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'PowerLogic™ P7', 'branches': [{'name': '0.2.003.001.000', 'product': {'name': 'PowerLogic™ version 0.2.003.001.000', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-9716', 'cwe': {'id': 'CWE-476', 'name': 'NULL Pointer Dereference'}, 'notes': [{'text': 'CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, \r\nrendering the device’s HMI and configuration functionality unavailable when malformed requests are received \r\nover exposed network interfaces.', 'title': 'CVE Description', 'category': 'description'}, {'text': 'CVSS v4.0 Base Score 8.7 | High | [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N](https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)', 'title': 'CVSS v4.0 Base Score', 'category': 'details'}], 'title': 'CVE-2026-9716', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-9716', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/476.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Version V02.004.001 of PowerLogicTM P7 includes a fix for this vulnerability\r\nand is available for download here:\r\n• Contact Schneider Electric’s Customer Care Center to download \r\nthis firmware.\r\n• Reboot needed: Yes', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'service'}}, {'details': 'If customers choose not to apply the remediation provided above, they should immediately apply the following \r\nmitigations to reduce the risk of exploit:\r\n• Restrict network access to P7 service endpoints (ports 8080 and 3702)\r\n• Monitor and alert on anomalous SOAP requests targeting wsApp\r\n• Limit administrative access and apply least privilege principles for all \r\nusers interacting with P7.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'none'}}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}, 'acknowledgments': [{'organization': 'Cytrics'}]}, {'cve': 'CVE-2026-9717', 'cwe': {'id': 'CWE-78', 'name': "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}, 'notes': [{'text': "CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability \r\nexists that could allow unauthorized execution of commands with elevated privileges, impacting system \r\nintegrity, confidentiality, and availability when a privileged authenticated user interacts with a vulnerable \r\nnetwork-exposed service.", 'title': 'CVE Description', 'category': 'description'}, {'text': 'CVSS v4.0 Base Score 8.6 | High | [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N](https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)', 'title': 'CVSS v4.0 Base Score', 'category': 'details'}], 'title': 'CVE-2026-9717', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.2, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-9717', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/78.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Version V02.004.001 of PowerLogicTM P7 includes a fix for this vulnerability\r\nand is available for download here:\r\n• Contact Schneider Electric’s Customer Care Center to download \r\nthis firmware.\r\n• Reboot needed: Yes', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'service'}}, {'details': 'If customers choose not to apply the remediation provided above, they should immediately apply the following \r\nmitigations to reduce the risk of exploit:\r\n• Restrict network access to P7 service endpoints (ports 8080 and 3702)\r\n• Monitor and alert on anomalous SOAP requests targeting wsApp\r\n• Limit administrative access and apply least privilege principles for all \r\nusers interacting with P7.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'none'}}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}, 'acknowledgments': [{'organization': 'Cytrics'}]}, {'cve': 'CVE-2026-9718', 'cwe': {'id': 'CWE-617', 'name': 'Reachable Assertion'}, 'notes': [{'text': 'CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a \r\ndenial-of-service condition, impacting system availability when a specially crafted request is sent to a \r\nvulnerable network-exposed service.', 'title': 'CVE Description', 'category': 'description'}, {'text': 'CVSS v4.0 Base Score 6.9 | Medium | [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N](https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)', 'title': 'CVSS v4.0 Base Score', 'category': 'details'}], 'title': 'CVE-2026-9718', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.9, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-9718', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/617.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Version V02.004.001 of PowerLogicTM P7 includes a fix for this vulnerability\r\nand is available for download here:\r\n• Contact Schneider Electric’s Customer Care Center to download \r\nthis firmware.\r\n• Reboot needed: Yes', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'service'}}, {'details': 'If customers choose not to apply the remediation provided above, they should immediately apply the following \r\nmitigations to reduce the risk of exploit:\r\n• Restrict network access to P7 service endpoints (ports 8080 and 3702)\r\n• Monitor and alert on anomalous SOAP requests targeting wsApp\r\n• Limit administrative access and apply least privilege principles for all \r\nusers interacting with P7.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'none'}}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}, 'acknowledgments': [{'organization': 'Cytrics'}]}]} | |
ot | ICSA-26-176-07 | CVE-2026-9718 | Schneider Electric PowerLogic P7 | 2026-06-09 10:00:00+03:00 | 2026-06-25 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-07.json | e6ce4e4eb7708e9f26f369aa38c44cd08254d8788a8d42ddb61ca1d235bc877c | 2026-06-26 05:15:06.578444+03:00 | 2026-06-26 05:15:06.578444+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'We strongly recommend the following industry cybersecurity best practices.\n\nhttps://www.se.com/us/en/download/document/7EN52-0390/\n* Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.\n* Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.\n* Place all controllers in locked cabinets and never leave them in the “Program” mode.\n* Never connect programming software to any network other than the network intended for that device.\n* Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.\n* Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.\n* Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.\n* When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.\nFor more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document. \n', 'title': 'General Security Recommendations', 'category': 'general'}, {'text': 'This document provides an overview of the identified vulnerability or vulnerabilities and actions required to mitigate. For more details and assistance on how to protect your installation, contact your local Schneider Electric representative or Schneider Electric Industrial Cybersecurity Services: https://www.se.com/ww/en/work/solutions/cybersecurity/. These organizations will be fully aware of this situation and can support you through the process.\nFor further information related to cybersecurity in Schneider Electric’s products, visit the company’s cybersecurity support portal page: https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp', 'title': 'For More Information', 'category': 'general'}, {'text': 'THIS NOTIFICATION DOCUMENT, THE INFORMATION CONTAINED HEREIN, AND ANY MATERIALS LINKED FROM IT (COLLECTIVELY, THIS “NOTIFICATION”) ARE INTENDED TO HELP PROVIDE AN OVERVIEW OF THE IDENTIFIED SITUATION AND SUGGESTED MITIGATION ACTIONS, REMEDIATION, FIX, AND/OR GENERAL SECURITY RECOMMENDATIONS AND IS PROVIDED ON AN “AS-IS” BASIS WITHOUT WARRANTY OR GUARANTEE OF ANY KIND. SCHNEIDER ELECTRIC DISCLAIMS ALL WARRANTIES RELATING TO THIS NOTIFICATION, EITHER EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SCHNEIDER ELECTRIC MAKES NO WARRANTY THAT THE NOTIFICATION WILL RESOLVE THE IDENTIFIED SITUATION. IN NO EVENT SHALL SCHNEIDER ELECTRIC BE LIABLE FOR ANY DAMAGES OR LOSSES WHATSOEVER IN CONNECTION WITH THIS NOTIFICATION, INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF SCHNEIDER ELECTRIC HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. YOUR USE OF THIS NOTIFICATION IS AT YOUR OWN RISK, AND YOU ARE SOLELY LIABLE FOR ANY DAMAGES TO YOUR SYSTEMS OR ASSETS OR OTHER LOSSES THAT MAY RESULT FROM YOUR USE OF THIS NOTIFICATION. SCHNEIDER ELECTRIC RESERVES THE RIGHT TO UPDATE OR CHANGE THIS NOTIFICATION AT ANY TIME AND IN ITS SOLE DISCRETION', 'title': 'LEGAL DISCLAIMER', 'category': 'legal_disclaimer'}, {'text': 'At Schneider, we believe access to energy and digital is a basic human right. We empower all to do more with less, ensuring Life Is On everywhere, for everyone, at every moment.\n\nWe provide energy and automation digital solutions for efficiency and sustainability. We combine world-leading energy technologies, real-time automation, software and services into integrated solutions for Homes, Buildings, Data Centers, Infrastructure and Industries.\n\nWe are committed to unleash the infinite possibilities of an open, global, innovative community that is passionate with our Meaningful Purpose, Inclusive and Empowered values.\n\nwww.se.com ', 'title': 'About Schneider Electric', 'category': 'general'}, {'text': 'Schneider Electric is aware of a vulnerability in its PowerLogic™ P7 product. \r\nThe PowerLogic™ P7 is a protection and control platform designed for complex and advanced electrical \r\nnetwork applications.\r\nFailure to apply the remediation provided below may risk unauthorized execution of privileged commands or \r\nloss of HMI operability and configuration functionality, which could result in loss of control over system \r\noperations and disruption of critical services.', 'title': 'Overview', 'category': 'summary'}, {'text': "The severity of vulnerabilities was calculated using the CVSS Base metrics for 4.0 ([CVSS v4.0](https://www.first.org/cvss/calculator/4.0)). CVSS v3.1 \nwill be still evaluated until the adoption of CVSS v4.0 by the industry. The severity was calculated without \nincorporating the Temporal and Environmental metrics. Schneider Electric recommends that customers score the CVSS Environmental metrics, which are specific to end-user organizations, and consider factors such as \nthe presence of mitigations in that environment. Environmental metrics may refine the relative severity posed by the vulnerabilities described in this document within a customer's environment.", 'category': 'other'}, {'text': "Customers should use appropriate patching methodologies when applying these patches to their systems. We strongly recommend the use of back-ups and evaluating the impact of these patches in a Test and Development environment or on an offline infrastructure. Contact Schneider Electric's [Customer Care Center](https://www.se.com/us/en/work/support/contacts.jsp) if you need assistance removing a patch.", 'category': 'other'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of Schneider Electric CPCERT SEVD-2026-160-03 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Schneider Electric CPCERT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Commercial Facilities, Critical Manufacturing, Energy', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'France', 'title': 'Company headquarters location', 'category': 'other'}], 'title': 'Schneider Electric PowerLogic P7', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-176-07', 'status': 'final', 'version': '2', 'generator': {'date': '2026-06-24T17:07:41.336093Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2026-06-09T07:00:00.000000Z', 'number': '1', 'summary': 'Original Release', 'legacy_version': 'Initial'}, {'date': '2026-06-25T06:00:00.000000Z', 'number': '2', 'summary': 'Initial CISA Republication of Schneider Electric CPCERT SEVD-2026-160-03 advisory', 'legacy_version': 'CISA Republication'}], 'current_release_date': '2026-06-25T06:00:00.000000Z', 'initial_release_date': '2026-06-09T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-160-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-160-03.json', 'summary': 'Multiple Vulnerabilities on PowerLogic™ P7 - SEVD-2026-160-03 CSAF Version', 'category': 'self'}, {'url': 'https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-160-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-160-03.pdf', 'summary': 'Multiple Vulnerabilities on PowerLogic™ P7 - SEVD-2026-160-03 PDF Version', 'category': 'self'}, {'url': 'https://www.se.com/ww/en/download/document/7EN52-0390', 'summary': 'Recommended Cybersecurity Best Practices', 'category': 'external'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-07.json', 'summary': 'ICS Advisory ICSA-26-176-07 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-07', 'summary': 'ICS Advisory ICSA-26-176-07 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to CISA.', 'organization': 'Schneider Electric CPCERT'}, {'summary': 'reported these vulnerabilities to Schneider Electric.', 'organization': 'Cytrics'}]}, 'product_tree': {'branches': [{'name': 'Schneider Electric', 'branches': [{'name': 'PowerLogic™ P7', 'branches': [{'name': 'vers:intdot/<=0.2.003.001.000', 'product': {'name': 'PowerLogic™ P7 version 0.2.003.001.000 and prior', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'PowerLogic™ P7', 'branches': [{'name': '0.2.003.001.000', 'product': {'name': 'PowerLogic™ version 0.2.003.001.000', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-9716', 'cwe': {'id': 'CWE-476', 'name': 'NULL Pointer Dereference'}, 'notes': [{'text': 'CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, \r\nrendering the device’s HMI and configuration functionality unavailable when malformed requests are received \r\nover exposed network interfaces.', 'title': 'CVE Description', 'category': 'description'}, {'text': 'CVSS v4.0 Base Score 8.7 | High | [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N](https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)', 'title': 'CVSS v4.0 Base Score', 'category': 'details'}], 'title': 'CVE-2026-9716', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-9716', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/476.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Version V02.004.001 of PowerLogicTM P7 includes a fix for this vulnerability\r\nand is available for download here:\r\n• Contact Schneider Electric’s Customer Care Center to download \r\nthis firmware.\r\n• Reboot needed: Yes', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'service'}}, {'details': 'If customers choose not to apply the remediation provided above, they should immediately apply the following \r\nmitigations to reduce the risk of exploit:\r\n• Restrict network access to P7 service endpoints (ports 8080 and 3702)\r\n• Monitor and alert on anomalous SOAP requests targeting wsApp\r\n• Limit administrative access and apply least privilege principles for all \r\nusers interacting with P7.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'none'}}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}, 'acknowledgments': [{'organization': 'Cytrics'}]}, {'cve': 'CVE-2026-9717', 'cwe': {'id': 'CWE-78', 'name': "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}, 'notes': [{'text': "CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability \r\nexists that could allow unauthorized execution of commands with elevated privileges, impacting system \r\nintegrity, confidentiality, and availability when a privileged authenticated user interacts with a vulnerable \r\nnetwork-exposed service.", 'title': 'CVE Description', 'category': 'description'}, {'text': 'CVSS v4.0 Base Score 8.6 | High | [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N](https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)', 'title': 'CVSS v4.0 Base Score', 'category': 'details'}], 'title': 'CVE-2026-9717', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.2, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-9717', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/78.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Version V02.004.001 of PowerLogicTM P7 includes a fix for this vulnerability\r\nand is available for download here:\r\n• Contact Schneider Electric’s Customer Care Center to download \r\nthis firmware.\r\n• Reboot needed: Yes', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'service'}}, {'details': 'If customers choose not to apply the remediation provided above, they should immediately apply the following \r\nmitigations to reduce the risk of exploit:\r\n• Restrict network access to P7 service endpoints (ports 8080 and 3702)\r\n• Monitor and alert on anomalous SOAP requests targeting wsApp\r\n• Limit administrative access and apply least privilege principles for all \r\nusers interacting with P7.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'none'}}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}, 'acknowledgments': [{'organization': 'Cytrics'}]}, {'cve': 'CVE-2026-9718', 'cwe': {'id': 'CWE-617', 'name': 'Reachable Assertion'}, 'notes': [{'text': 'CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a \r\ndenial-of-service condition, impacting system availability when a specially crafted request is sent to a \r\nvulnerable network-exposed service.', 'title': 'CVE Description', 'category': 'description'}, {'text': 'CVSS v4.0 Base Score 6.9 | Medium | [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N](https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)', 'title': 'CVSS v4.0 Base Score', 'category': 'details'}], 'title': 'CVE-2026-9718', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 4.9, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-9718', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/617.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Version V02.004.001 of PowerLogicTM P7 includes a fix for this vulnerability\r\nand is available for download here:\r\n• Contact Schneider Electric’s Customer Care Center to download \r\nthis firmware.\r\n• Reboot needed: Yes', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'service'}}, {'details': 'If customers choose not to apply the remediation provided above, they should immediately apply the following \r\nmitigations to reduce the risk of exploit:\r\n• Restrict network access to P7 service endpoints (ports 8080 and 3702)\r\n• Monitor and alert on anomalous SOAP requests targeting wsApp\r\n• Limit administrative access and apply least privilege principles for all \r\nusers interacting with P7.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'none'}}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}, 'acknowledgments': [{'organization': 'Cytrics'}]}]} | |
ot | ICSA-26-176-06 | CVE-2026-12578 | Delta Electronics DTM Soft | 2026-06-25 09:00:00+03:00 | 2026-06-25 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-06.json | 7188b11aca070cef02ae92570792167f4dcfe82ad0db7dddf0d730521eac14ad | 2026-06-26 05:15:06.578444+03:00 | 2026-06-26 05:15:06.578444+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code.', 'title': 'Advisory Summary', 'category': 'summary'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Taiwan', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also recommends users take the following measures to protect themselves from social engineering attacks:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Do not click web links or open attachments in unsolicited email messages.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Delta Electronics DTM Soft', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-176-06', 'status': 'final', 'version': '1', 'generator': {'date': '2026-06-24T20:30:52.356613Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-06-25T06:00:00.000000Z', 'number': '1', 'summary': 'Initial Republication of Delta Electronics Product Cybersecurity Advisory Delta-PCSA-2026-00010', 'legacy_version': 'Initial'}], 'current_release_date': '2026-06-25T06:00:00.000000Z', 'initial_release_date': '2026-06-25T06:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-06.json', 'summary': 'ICS Advisory ICSA-26-176-06 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-06', 'summary': 'ICSA Advisory ICSA-26-176-06 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/ncas/tips/ST04-014', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['kimiya'], 'summary': 'reported this vulnerability to CISA', 'organization': 'TrendAI Zero Day Initiative'}]}, 'product_tree': {'branches': [{'name': 'Delta Electronics', 'branches': [{'name': 'DTMSoft', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Delta Electronics DTMSoft: vers:all/*', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-12578', 'cwe': {'id': 'CWE-502', 'name': 'Deserialization of Untrusted Data'}, 'notes': [{'text': 'The affected product is vulnerable to a deserialization of untrusted data, which may allow an attacker to execute arbitrary code.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-06-24T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/502.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-12578', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Delta Electronics is aware of the vulnerability and is currently working on a fix.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Delta Electronics recommends users apply the following workarounds:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Do not open unsolicited project files: Do not open or import unsolicited project files, untrusted Internet links, or unexpected attachments from emails, network shares, or USB drives. Always verify the source of the file before opening it.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Avoid running as administrator: Do not use the "Run as Administrator" option when launching the software. Running the software with standard user privileges effectively limits the damage of potential malicious code.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.deltaww.com/en-US/service-support/product-cybersecurity/advisory', 'details': "For more information refer to Delta Electronic's advisory page https://www.deltaww.com/en-US/service-support/product-cybersecurity/advisory.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-176-05 | CVE-2026-55975 | H.VIEW HV-500S6 IP Camera | 2026-06-25 09:00:00+03:00 | 2026-06-25 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-05.json | d508e107ffe6967da1bb3f331b9020f963ed5ee1d64469b7e0140ef55a02db92 | 2026-06-26 05:15:06.578444+03:00 | 2026-06-26 05:15:06.578444+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code and upload malicious files to the affected device.', 'title': 'Advisory Summary', 'category': 'summary'}, {'text': 'Commercial Facilities', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'China', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also recommends users take the following measures to protect themselves from social engineering attacks:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Do not click web links or open attachments in unsolicited email messages.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'H.VIEW HV-500S6 IP Camera', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-176-05', 'status': 'final', 'version': '1', 'generator': {'date': '2026-06-25T20:04:34.781574Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-06-25T06:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}], 'current_release_date': '2026-06-25T06:00:00.000000Z', 'initial_release_date': '2026-06-25T06:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-05.json', 'summary': 'ICS Advisory ICSA-26-176-05 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-05', 'summary': 'ICSA Advisory ICSA-26-176-05 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/ncas/tips/ST04-014', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Fukuhara Rikuto'], 'summary': 'reported these vulnerabilities to CISA', 'organization': 'Smooth Inc. (CTO) and Hosei University'}]}, 'product_tree': {'branches': [{'name': 'H.VIEW', 'branches': [{'name': 'HV-500S6 IP Camera', 'branches': [{'name': 'IPCAM_V4.06.88.251229', 'product': {'name': 'H.VIEW HV-500S6 IP Camera: IPCAM_V4.06.88.251229', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-55975', 'cwe': {'id': 'CWE-78', 'name': "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}, 'notes': [{'text': "A vulnerability exists in H.View IP cameras that could allow an authenticated user to supply unsanitized XML fields to the device's certificate generation interface, which are incorporated into a backend certificate creation command without proper input validation. This may allow for command execution with elevated privileges during certificate generation.", 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-06-25T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/78.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-55975', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://hviewsmart.com/pages/contact-us', 'details': "H.View did not respond to CISA's request to coordinate. Users are encouraged to reach out to H.View for support. https://hviewsmart.com/pages/contact-us", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-56414', 'cwe': {'id': 'CWE-434', 'name': 'Unrestricted Upload of File with Dangerous Type'}, 'notes': [{'text': 'A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arbitrary file content to fixed, persistent filesystem locations without validating file type, structure, or size. This design omission enables the placement of unexpected or malformed data in locations intended for trusted certificate material, which could affect system integrity or behavior even after reboot.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-06-25T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/434.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-56414', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://hviewsmart.com/pages/contact-us', 'details': "H.View did not respond to CISA's request to coordinate. Users are encouraged to reach out to H.View for support. https://hviewsmart.com/pages/contact-us", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-176-05 | CVE-2026-56414 | H.VIEW HV-500S6 IP Camera | 2026-06-25 09:00:00+03:00 | 2026-06-25 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-05.json | 14a9fefd2e8974a122db590331b2ca394d604ed6537a1c847672655a7cc918fa | 2026-06-26 05:15:06.578444+03:00 | 2026-06-26 05:15:06.578444+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code and upload malicious files to the affected device.', 'title': 'Advisory Summary', 'category': 'summary'}, {'text': 'Commercial Facilities', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'China', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also recommends users take the following measures to protect themselves from social engineering attacks:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Do not click web links or open attachments in unsolicited email messages.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'H.VIEW HV-500S6 IP Camera', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-176-05', 'status': 'final', 'version': '1', 'generator': {'date': '2026-06-25T20:04:34.781574Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-06-25T06:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}], 'current_release_date': '2026-06-25T06:00:00.000000Z', 'initial_release_date': '2026-06-25T06:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-05.json', 'summary': 'ICS Advisory ICSA-26-176-05 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-05', 'summary': 'ICSA Advisory ICSA-26-176-05 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/ncas/tips/ST04-014', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Fukuhara Rikuto'], 'summary': 'reported these vulnerabilities to CISA', 'organization': 'Smooth Inc. (CTO) and Hosei University'}]}, 'product_tree': {'branches': [{'name': 'H.VIEW', 'branches': [{'name': 'HV-500S6 IP Camera', 'branches': [{'name': 'IPCAM_V4.06.88.251229', 'product': {'name': 'H.VIEW HV-500S6 IP Camera: IPCAM_V4.06.88.251229', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-55975', 'cwe': {'id': 'CWE-78', 'name': "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}, 'notes': [{'text': "A vulnerability exists in H.View IP cameras that could allow an authenticated user to supply unsanitized XML fields to the device's certificate generation interface, which are incorporated into a backend certificate creation command without proper input validation. This may allow for command execution with elevated privileges during certificate generation.", 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-06-25T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/78.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-55975', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://hviewsmart.com/pages/contact-us', 'details': "H.View did not respond to CISA's request to coordinate. Users are encouraged to reach out to H.View for support. https://hviewsmart.com/pages/contact-us", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-56414', 'cwe': {'id': 'CWE-434', 'name': 'Unrestricted Upload of File with Dangerous Type'}, 'notes': [{'text': 'A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arbitrary file content to fixed, persistent filesystem locations without validating file type, structure, or size. This design omission enables the placement of unexpected or malformed data in locations intended for trusted certificate material, which could affect system integrity or behavior even after reboot.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-06-25T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/434.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-56414', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://hviewsmart.com/pages/contact-us', 'details': "H.View did not respond to CISA's request to coordinate. Users are encouraged to reach out to H.View for support. https://hviewsmart.com/pages/contact-us", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-176-04 | CVE-2026-28701 | Daktronics Controller Firmware | 2026-06-25 09:00:00+03:00 | 2026-06-25 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-04.json | e701fc90bff712e515b09eba1a369960065e1c7165592f5e3d6917171424e169 | 2026-06-26 05:15:06.578444+03:00 | 2026-06-26 05:15:06.578444+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could could provide an unauthenticated user with complete root-level access and control of the system.', 'title': 'Advisory Summary', 'category': 'summary'}, {'text': 'Commercial Facilities, Information Technology, Emergency Services, Healthcare and Public Health', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Daktronics Controller Firmware', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-176-04', 'status': 'final', 'version': '1', 'generator': {'date': '2026-06-24T20:04:31.639123Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-06-25T06:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}], 'current_release_date': '2026-06-25T06:00:00.000000Z', 'initial_release_date': '2026-06-25T06:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-04.json', 'summary': 'ICS Advisory ICSA-26-176-04 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-04', 'summary': 'ICSA Advisory ICSA-26-176-04 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Thomas Jou'], 'summary': 'reported these vulnerabilities to CISA', 'organization': 'Princeton University'}]}, 'product_tree': {'branches': [{'name': 'Daktronics', 'branches': [{'name': 'VFC-DMP-5000', 'branches': [{'name': '<v8.117.x.x', 'product': {'name': 'Daktronics VFC-DMP-5000: <v8.117.x.x', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VFC-DMP-5000', 'branches': [{'name': '<v9.43.x.x', 'product': {'name': 'Daktronics VFC-DMP-5000: <v9.43.x.x', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VFC-DMP-5000', 'branches': [{'name': '<v10.34.x.x', 'product': {'name': 'Daktronics VFC-DMP-5000: <v10.34.x.x', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DMP-5000', 'branches': [{'name': '<v10.34.x.x', 'product': {'name': 'Daktronics DMP-5000: <v10.34.x.x', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DMP-5000', 'branches': [{'name': '<v8.117.x.x', 'product': {'name': 'Daktronics DMP-5000: <v8.117.x.x', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DMP-5000', 'branches': [{'name': '<v9.43.x.x', 'product': {'name': 'Daktronics DMP-5000: <v9.43.x.x', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DMP-8000', 'branches': [{'name': '<v10.34.x.x', 'product': {'name': 'Daktronics DMP-8000: <v10.34.x.x', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DMP-8000', 'branches': [{'name': '<v8.117.x.x', 'product': {'name': 'Daktronics DMP-8000: <v8.117.x.x', 'product_id': 'CSAFPID-0008'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DMP-8000', 'branches': [{'name': '<v9.43.x.x', 'product': {'name': 'Daktronics DMP-8000: <v9.43.x.x', 'product_id': 'CSAFPID-0009'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-28701', 'cwe': {'id': 'CWE-22', 'name': "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"}, 'notes': [{'text': 'Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and enumerate arbitrary file system paths.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-06-24T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/22.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-28701', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Daktronics recommends users update their device software to one of the following versions (based on product configuration in use): 8.117.0.x, 9.43.0.x, or 10.34.0.x', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}, {'details': 'Daktronics recommends updating the default passwords and encourages using strong, unique credentials per device.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}}, {'cve': 'CVE-2026-33560', 'cwe': {'id': 'CWE-434', 'name': 'Unrestricted Upload of File with Dangerous Type'}, 'notes': [{'text': 'The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable binaries and scripts to be accepted and written directly to the server. ', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-06-24T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/434.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-33560', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Daktronics recommends users update their device software to one of the following versions (based on product configuration in use): 8.117.0.x, 9.43.0.x, or 10.34.0.x', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}, {'details': 'Daktronics recommends updating the default passwords and encourages using strong, unique credentials per device.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}}, {'cve': 'CVE-2026-31928', 'cwe': {'id': 'CWE-798', 'name': 'Use of Hard-coded Credentials'}, 'notes': [{'text': 'The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation. Using these accounts provides full system access.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-06-24T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/798.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-31928', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Daktronics recommends users update their device software to one of the following versions (based on product configuration in use): 8.117.0.x, 9.43.0.x, or 10.34.0.x', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}, {'details': 'Daktronics recommends updating the default passwords and encourages using strong, unique credentials per device.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}}]} | |
ot | ICSA-26-176-04 | CVE-2026-33560 | Daktronics Controller Firmware | 2026-06-25 09:00:00+03:00 | 2026-06-25 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-04.json | b49521e7cefd4ba8c2d318f60621fe4d18178b77f500e4c83d62b7873db3a9e7 | 2026-06-26 05:15:06.578444+03:00 | 2026-06-26 05:15:06.578444+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could could provide an unauthenticated user with complete root-level access and control of the system.', 'title': 'Advisory Summary', 'category': 'summary'}, {'text': 'Commercial Facilities, Information Technology, Emergency Services, Healthcare and Public Health', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Daktronics Controller Firmware', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-176-04', 'status': 'final', 'version': '1', 'generator': {'date': '2026-06-24T20:04:31.639123Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-06-25T06:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}], 'current_release_date': '2026-06-25T06:00:00.000000Z', 'initial_release_date': '2026-06-25T06:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-04.json', 'summary': 'ICS Advisory ICSA-26-176-04 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-04', 'summary': 'ICSA Advisory ICSA-26-176-04 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Thomas Jou'], 'summary': 'reported these vulnerabilities to CISA', 'organization': 'Princeton University'}]}, 'product_tree': {'branches': [{'name': 'Daktronics', 'branches': [{'name': 'VFC-DMP-5000', 'branches': [{'name': '<v8.117.x.x', 'product': {'name': 'Daktronics VFC-DMP-5000: <v8.117.x.x', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VFC-DMP-5000', 'branches': [{'name': '<v9.43.x.x', 'product': {'name': 'Daktronics VFC-DMP-5000: <v9.43.x.x', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VFC-DMP-5000', 'branches': [{'name': '<v10.34.x.x', 'product': {'name': 'Daktronics VFC-DMP-5000: <v10.34.x.x', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DMP-5000', 'branches': [{'name': '<v10.34.x.x', 'product': {'name': 'Daktronics DMP-5000: <v10.34.x.x', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DMP-5000', 'branches': [{'name': '<v8.117.x.x', 'product': {'name': 'Daktronics DMP-5000: <v8.117.x.x', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DMP-5000', 'branches': [{'name': '<v9.43.x.x', 'product': {'name': 'Daktronics DMP-5000: <v9.43.x.x', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DMP-8000', 'branches': [{'name': '<v10.34.x.x', 'product': {'name': 'Daktronics DMP-8000: <v10.34.x.x', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DMP-8000', 'branches': [{'name': '<v8.117.x.x', 'product': {'name': 'Daktronics DMP-8000: <v8.117.x.x', 'product_id': 'CSAFPID-0008'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DMP-8000', 'branches': [{'name': '<v9.43.x.x', 'product': {'name': 'Daktronics DMP-8000: <v9.43.x.x', 'product_id': 'CSAFPID-0009'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-28701', 'cwe': {'id': 'CWE-22', 'name': "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"}, 'notes': [{'text': 'Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and enumerate arbitrary file system paths.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-06-24T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/22.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-28701', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Daktronics recommends users update their device software to one of the following versions (based on product configuration in use): 8.117.0.x, 9.43.0.x, or 10.34.0.x', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}, {'details': 'Daktronics recommends updating the default passwords and encourages using strong, unique credentials per device.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}}, {'cve': 'CVE-2026-33560', 'cwe': {'id': 'CWE-434', 'name': 'Unrestricted Upload of File with Dangerous Type'}, 'notes': [{'text': 'The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable binaries and scripts to be accepted and written directly to the server. ', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-06-24T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/434.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-33560', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Daktronics recommends users update their device software to one of the following versions (based on product configuration in use): 8.117.0.x, 9.43.0.x, or 10.34.0.x', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}, {'details': 'Daktronics recommends updating the default passwords and encourages using strong, unique credentials per device.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}}, {'cve': 'CVE-2026-31928', 'cwe': {'id': 'CWE-798', 'name': 'Use of Hard-coded Credentials'}, 'notes': [{'text': 'The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation. Using these accounts provides full system access.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-06-24T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/798.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-31928', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Daktronics recommends users update their device software to one of the following versions (based on product configuration in use): 8.117.0.x, 9.43.0.x, or 10.34.0.x', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}, {'details': 'Daktronics recommends updating the default passwords and encourages using strong, unique credentials per device.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}}]} | |
ot | ICSA-26-176-04 | CVE-2026-31928 | Daktronics Controller Firmware | 2026-06-25 09:00:00+03:00 | 2026-06-25 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-04.json | 228b44968cd4b854aaf5ff95da7d3abd7660460729e21ea7794b0a7e63e55102 | 2026-06-26 05:15:06.578444+03:00 | 2026-06-26 05:15:06.578444+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could could provide an unauthenticated user with complete root-level access and control of the system.', 'title': 'Advisory Summary', 'category': 'summary'}, {'text': 'Commercial Facilities, Information Technology, Emergency Services, Healthcare and Public Health', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Daktronics Controller Firmware', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-176-04', 'status': 'final', 'version': '1', 'generator': {'date': '2026-06-24T20:04:31.639123Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-06-25T06:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}], 'current_release_date': '2026-06-25T06:00:00.000000Z', 'initial_release_date': '2026-06-25T06:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-04.json', 'summary': 'ICS Advisory ICSA-26-176-04 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-04', 'summary': 'ICSA Advisory ICSA-26-176-04 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Thomas Jou'], 'summary': 'reported these vulnerabilities to CISA', 'organization': 'Princeton University'}]}, 'product_tree': {'branches': [{'name': 'Daktronics', 'branches': [{'name': 'VFC-DMP-5000', 'branches': [{'name': '<v8.117.x.x', 'product': {'name': 'Daktronics VFC-DMP-5000: <v8.117.x.x', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VFC-DMP-5000', 'branches': [{'name': '<v9.43.x.x', 'product': {'name': 'Daktronics VFC-DMP-5000: <v9.43.x.x', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VFC-DMP-5000', 'branches': [{'name': '<v10.34.x.x', 'product': {'name': 'Daktronics VFC-DMP-5000: <v10.34.x.x', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DMP-5000', 'branches': [{'name': '<v10.34.x.x', 'product': {'name': 'Daktronics DMP-5000: <v10.34.x.x', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DMP-5000', 'branches': [{'name': '<v8.117.x.x', 'product': {'name': 'Daktronics DMP-5000: <v8.117.x.x', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DMP-5000', 'branches': [{'name': '<v9.43.x.x', 'product': {'name': 'Daktronics DMP-5000: <v9.43.x.x', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DMP-8000', 'branches': [{'name': '<v10.34.x.x', 'product': {'name': 'Daktronics DMP-8000: <v10.34.x.x', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DMP-8000', 'branches': [{'name': '<v8.117.x.x', 'product': {'name': 'Daktronics DMP-8000: <v8.117.x.x', 'product_id': 'CSAFPID-0008'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'DMP-8000', 'branches': [{'name': '<v9.43.x.x', 'product': {'name': 'Daktronics DMP-8000: <v9.43.x.x', 'product_id': 'CSAFPID-0009'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-28701', 'cwe': {'id': 'CWE-22', 'name': "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"}, 'notes': [{'text': 'Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and enumerate arbitrary file system paths.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-06-24T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/22.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-28701', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Daktronics recommends users update their device software to one of the following versions (based on product configuration in use): 8.117.0.x, 9.43.0.x, or 10.34.0.x', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}, {'details': 'Daktronics recommends updating the default passwords and encourages using strong, unique credentials per device.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}}, {'cve': 'CVE-2026-33560', 'cwe': {'id': 'CWE-434', 'name': 'Unrestricted Upload of File with Dangerous Type'}, 'notes': [{'text': 'The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable binaries and scripts to be accepted and written directly to the server. ', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-06-24T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/434.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-33560', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Daktronics recommends users update their device software to one of the following versions (based on product configuration in use): 8.117.0.x, 9.43.0.x, or 10.34.0.x', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}, {'details': 'Daktronics recommends updating the default passwords and encourages using strong, unique credentials per device.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}}, {'cve': 'CVE-2026-31928', 'cwe': {'id': 'CWE-798', 'name': 'Use of Hard-coded Credentials'}, 'notes': [{'text': 'The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation. Using these accounts provides full system access.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-06-24T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/798.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-31928', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Daktronics recommends users update their device software to one of the following versions (based on product configuration in use): 8.117.0.x, 9.43.0.x, or 10.34.0.x', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}, {'details': 'Daktronics recommends updating the default passwords and encourages using strong, unique credentials per device.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}}]} | |
ot | ICSA-26-176-03 | CVE-2026-12897 | Horner Automation Cscape | 2026-06-25 09:00:00+03:00 | 2026-06-25 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-03.json | 0e396495ff4bb2742ceeb8b1126aa1d9efbbba568903f539237667c6d7ac6752 | 2026-06-26 05:15:06.578444+03:00 | 2026-06-26 05:15:06.578444+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of this vulnerability could allow a local attacker to disclose information and execute arbitrary code.', 'title': 'Advisory Summary', 'category': 'summary'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also recommends users take the following measures to protect themselves from social engineering attacks:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Do not click web links or open attachments in unsolicited email messages.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Horner Automation Cscape', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-176-03', 'status': 'final', 'version': '1', 'generator': {'date': '2026-06-22T16:54:27.640658Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-06-25T06:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}], 'current_release_date': '2026-06-25T06:00:00.000000Z', 'initial_release_date': '2026-06-25T06:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-03.json', 'summary': 'ICS Advisory ICSA-26-176-03 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-03', 'summary': 'ICSA Advisory ICSA-26-176-03 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/ncas/tips/ST04-014', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Michael Heinzl'], 'summary': 'reported this vulnerability to CISA'}]}, 'product_tree': {'branches': [{'name': 'Horner Automation', 'branches': [{'name': 'Cscape', 'branches': [{'name': '<10.2_SP3', 'product': {'name': 'Horner Automation Cscape: <10.2_SP3', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-12897', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'Horner Automation Cscape versions prior to 10.2 SP3 are vulnerable to an Out-of-Bounds Read vulnerability through parsing CSP files. Successful exploitation of this vulnerability could allow an attacker to disclose information and execute arbitrary code. ', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-06-22T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/125.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-12897', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Horner Automation has released Cscape 10.2 SP3 for users to download.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://hornerautomation.com/cscape-software-free/cscape-software/', 'details': 'For more information, see the Cscape 10.2 SP3 release notes (https://hornerautomation.com/cscape-software-free/cscape-software/).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-176-01 | CVE-2026-11833 | Yokogawa FAST/TOOLS and CI Server | 2026-06-25 09:00:00+03:00 | 2026-06-25 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-01.json | 537ccd5457c9388caf07f665056064b9ae98f918f12be4daaec984f1947798c9 | 2026-06-26 05:15:06.578444+03:00 | 2026-06-26 05:15:06.578444+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of this vulnerability may return a response containing the CI Server setting information.', 'title': 'Advisory Summary', 'category': 'summary'}, {'text': 'Critical Manufacturing, Energy, Food and Agriculture', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Japan', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Yokogawa FAST/TOOLS and CI Server', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-176-01', 'status': 'final', 'version': '1', 'generator': {'date': '2026-06-24T20:40:41.108165Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-06-25T06:00:00.000000Z', 'number': '1', 'summary': 'Initial CISA Republication of Yokogawa Security Advisory Report YSAR-26-0004', 'legacy_version': 'Initial'}], 'current_release_date': '2026-06-25T06:00:00.000000Z', 'initial_release_date': '2026-06-25T06:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-01.json', 'summary': 'ICS Advisory ICSA-26-176-01 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-01', 'summary': 'ICSA Advisory ICSA-26-176-01 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported this vulnerability to JPCERT/CC', 'organization': 'Yokogawa'}]}, 'product_tree': {'branches': [{'name': 'Yokogawa', 'branches': [{'name': 'FAST/TOOLS', 'branches': [{'name': '>=R9.01|<=R10.04', 'product': {'name': 'Yokogawa FAST/TOOLS: >=R9.01|<=R10.04', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Collaborative Information Server (CI Server)', 'branches': [{'name': '>=R1.01|<=R1.04', 'product': {'name': 'Yokogawa Collaborative Information Server (CI Server): >=R1.01|<=R1.04', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-11833', 'cwe': {'id': 'CWE-319', 'name': 'Cleartext Transmission of Sensitive Information'}, 'notes': [{'text': 'The web server may return a response containing the CI Server setting information. This information could be exploited by an attacker for other attacks.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-06-24T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/319.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-11833', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Yokogawa recommends users update FAST/TOOLS up to R10.04 and apply patch software (R10.04 SP4).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Yokogawa recommends users update Collaborative Information Server (CI Server) up to R1.05.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002']}, {'url': 'https://web-material3.yokogawa.com/1/39777/files/YSAR-26-0004-E.pdf', 'details': 'For more information and details on implementing these mitigations, users should see the Yokogawa security advisory report YSAR-26-0004 at https://web-material3.yokogawa.com/1/39777/files/YSAR-26-0004-E.pdf', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002']}, {'url': 'https://contact.yokogawa.com/cs/gw?c-id=000498', 'details': 'For questions related to this report, please contact the below.https://contact.yokogawa.com/cs/gw?c-id=000498', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002']}}]} | |
ot | ICSA-26-169-02 | CVE-2026-12921 | AzeoTech DAQFactory (Update A) | 2026-06-18 09:00:00+03:00 | 2026-06-25 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-169-02.json | 2a18a216e0a83b0b453af1dee962ea8ba3ddba4deae698f2bb0ad58e35baba44 | 2026-06-26 05:15:06.578444+03:00 | 2026-06-26 05:15:06.578444+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could allow an attacker to upload malicious .ctl files that may lead to arbitrary code execution.', 'title': 'Advisory Summary', 'category': 'summary'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities are not exploitable remotely.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'AzeoTech DAQFactory (Update A)', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-169-02', 'status': 'final', 'version': '2', 'generator': {'date': '2026-06-22T16:54:27.560587Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-06-18T06:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}, {'date': '2026-06-25T06:00:00.000000Z', 'number': '2', 'summary': 'Update A - Adding additional CVE and updating wording', 'legacy_version': 'Update A'}], 'current_release_date': '2026-06-25T06:00:00.000000Z', 'initial_release_date': '2026-06-18T06:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-169-02.json', 'summary': 'ICS Advisory ICSA-26-169-02 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-169-02', 'summary': 'ICSA Advisory ICSA-26-169-02 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Rocco Calvi (@TecR0c)'], 'summary': 'reported these vulnerabilities to CISA', 'organization': 'TecSecurity'}, {'names': ['rgod'], 'summary': 'reported these vulnerabilities to CISA', 'organization': 'TrendAI Zero Day Initiative'}]}, 'product_tree': {'branches': [{'name': 'AzeoTech', 'branches': [{'name': 'DAQFactory', 'branches': [{'name': '<=21.1', 'product': {'name': 'AzeoTech DAQFactory: <=21.1', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-12390', 'cwe': {'id': 'CWE-843', 'name': "Access of Resource Using Incompatible Type ('Type Confusion')"}, 'notes': [{'text': 'In AzeoTech DAQFactory versions 21.1 and prior, a Type Confusion vulnerability can be exploited by an attacker using specially crafted .ctl files which can result in code execution.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-06-22T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/843.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-12390', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Users are discouraged from using documents from unknown/untrusted sources.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Users are encouraged to store .ctl files in a folder only writeable by admin-level users.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Users are encouraged to operate in "Safe Mode" when loading documents that have been out of their control.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Users are encouraged to apply a document editing password to their documents.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-12921', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'In AzeoTech DAQFactory versions 21.1 and prior, a Use After Free vulnerability can be exploited by an attacker using specially crafted .ctl files which can result in code execution.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-06-22T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/416.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-12921', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Users are discouraged from using documents from unknown/untrusted sources.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Users are encouraged to store .ctl files in a folder only writeable by admin-level users.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Users are encouraged to operate in "Safe Mode" when loading documents that have been out of their control.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Users are encouraged to apply a document editing password to their documents.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-176-02 | CVE-2026-40702 | EVoke Systems Charging Station Management System | 2026-06-25 08:00:00+03:00 | 2026-06-25 08:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-02.json | 3e4c2522432aa33725a7abbe25795d35e08dce540dd19384edd0aaa675dcb15e | 2026-06-26 05:15:06.578444+03:00 | 2026-06-26 05:15:06.578444+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks.', 'title': 'Advisory Summary', 'category': 'summary'}, {'text': 'Energy, Transportation Systems', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'EVoke Systems Charging Station Management System', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-176-02', 'status': 'final', 'version': '1', 'generator': {'date': '2026-06-22T17:32:37.903639Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-06-25T05:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}], 'current_release_date': '2026-06-25T05:00:00.000000Z', 'initial_release_date': '2026-06-25T05:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-02.json', 'summary': 'ICS Advisory ICSA-26-176-02 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-02', 'summary': 'ICSA Advisory ICSA-26-176-02 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Khaled Sarieddine', 'Mohammad Ali Sayed'], 'summary': 'reported these vulnerabilities to CISA'}]}, 'product_tree': {'branches': [{'name': 'EVoke Systems', 'branches': [{'name': 'EVoke CSMS', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'EVoke Systems EVoke CSMS: vers:all/*', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40702', 'cwe': {'id': 'CWE-306', 'name': 'Missing Authentication for Critical Function'}, 'notes': [{'text': 'WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-06-22T05:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.4, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/306.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-40702', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'EVoke states that as a hardware-agnostic platform supporting multiple charger Original Equipment Manufacturers OEMs, EVoke must interoperate with EVSE devices that support different OCPP security profiles depending on the firmware capabilities of the charger. EVoke CSMS currently supports all OCPP security profiles (0–3). However, the effective security configuration for a charger connection is determined by the security profile implemented in the EVSE firmware. Some legacy chargers deployed in the network support only Security Profile 0 or 1. These chargers were installed prior to the broader industry adoption of stronger authentication mechanisms defined in OCPP Security Profiles 2 and 3. EVoke is actively working with charger OEM partners to migrate supported devices to Security Profile 2 (TLS encryption with basic authentication) or Security Profile 3 (Mutual TLS authentication using client certificates). For OEMs that continue to support firmware updates, EVoke will prioritize upgrades to enable Security Profiles 2 or 3.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that certain legacy charger models deployed on the network are no longer supported by the manufacturer (for example, chargers originally produced by EVBox). These devices cannot be upgraded to support stronger security profiles. For chargers limited to Security Profiles 0 or 1, EVoke is implementing additional server-side protections to mitigate spoofing risks. Allow-listed chargers will only be accepted from chargers whose IDs are registered in the EVoke CSMS inventory database. Unknown charger identifiers will be rejected.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to reduce the risk of duplicate sessions, only a single active connection per charger ID will be permitted. If a second connection using the same charger ID is detected, the new connection will be rejected or the previous session will be terminated. This prevents unauthorized actors from establishing parallel sessions using spoofed charger identifiers.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that the platform will monitor session anomalies including repeated connection attempts, unexpected IP address changes, and abnormal message patterns. Security events will be logged and flagged for operational review.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to address the risk of denial-of-service via repeated authentication attempts, EVoke will implement connection rate limiting at the WebSocket gateway layer. These controls will restrict excessive connection attempts from the same source and temporarily block abusive traffic patterns.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states they are developing a lifecycle policy for legacy chargers that cannot support modern OCPP security profiles. This policy will include identification of unsupported EVSE models and risk classification Migration planning with site operators where possible', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://evokesystems.com/contact-us/', 'details': 'Contact EVoke using their contact page: https://evokesystems.com/contact-us/ for more information.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-50176', 'cwe': {'id': 'CWE-307', 'name': 'Improper Restriction of Excessive Authentication Attempts'}, 'notes': [{'text': 'The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-06-22T05:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/307.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-50176', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'EVoke states that as a hardware-agnostic platform supporting multiple charger Original Equipment Manufacturers OEMs, EVoke must interoperate with EVSE devices that support different OCPP security profiles depending on the firmware capabilities of the charger. EVoke CSMS currently supports all OCPP security profiles (0–3). However, the effective security configuration for a charger connection is determined by the security profile implemented in the EVSE firmware. Some legacy chargers deployed in the network support only Security Profile 0 or 1. These chargers were installed prior to the broader industry adoption of stronger authentication mechanisms defined in OCPP Security Profiles 2 and 3. EVoke is actively working with charger OEM partners to migrate supported devices to Security Profile 2 (TLS encryption with basic authentication) or Security Profile 3 (Mutual TLS authentication using client certificates). For OEMs that continue to support firmware updates, EVoke will prioritize upgrades to enable Security Profiles 2 or 3.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that certain legacy charger models deployed on the network are no longer supported by the manufacturer (for example, chargers originally produced by EVBox). These devices cannot be upgraded to support stronger security profiles. For chargers limited to Security Profiles 0 or 1, EVoke is implementing additional server-side protections to mitigate spoofing risks. Allow-listed chargers will only be accepted from chargers whose IDs are registered in the EVoke CSMS inventory database. Unknown charger identifiers will be rejected.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to reduce the risk of duplicate sessions, only a single active connection per charger ID will be permitted. If a second connection using the same charger ID is detected, the new connection will be rejected or the previous session will be terminated. This prevents unauthorized actors from establishing parallel sessions using spoofed charger identifiers.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that the platform will monitor session anomalies including repeated connection attempts, unexpected IP address changes, and abnormal message patterns. Security events will be logged and flagged for operational review.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to address the risk of denial-of-service via repeated authentication attempts, EVoke will implement connection rate limiting at the WebSocket gateway layer. These controls will restrict excessive connection attempts from the same source and temporarily block abusive traffic patterns.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states they are developing a lifecycle policy for legacy chargers that cannot support modern OCPP security profiles. This policy will include identification of unsupported EVSE models and risk classification Migration planning with site operators where possible', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://evokesystems.com/contact-us/', 'details': 'Contact EVoke using their contact page: https://evokesystems.com/contact-us/ for more information.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-54479', 'cwe': {'id': 'CWE-613', 'name': 'Insufficient Session Expiration'}, 'notes': [{'text': 'The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-06-22T05:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/613.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-54479', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'EVoke states that as a hardware-agnostic platform supporting multiple charger Original Equipment Manufacturers OEMs, EVoke must interoperate with EVSE devices that support different OCPP security profiles depending on the firmware capabilities of the charger. EVoke CSMS currently supports all OCPP security profiles (0–3). However, the effective security configuration for a charger connection is determined by the security profile implemented in the EVSE firmware. Some legacy chargers deployed in the network support only Security Profile 0 or 1. These chargers were installed prior to the broader industry adoption of stronger authentication mechanisms defined in OCPP Security Profiles 2 and 3. EVoke is actively working with charger OEM partners to migrate supported devices to Security Profile 2 (TLS encryption with basic authentication) or Security Profile 3 (Mutual TLS authentication using client certificates). For OEMs that continue to support firmware updates, EVoke will prioritize upgrades to enable Security Profiles 2 or 3.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that certain legacy charger models deployed on the network are no longer supported by the manufacturer (for example, chargers originally produced by EVBox). These devices cannot be upgraded to support stronger security profiles. For chargers limited to Security Profiles 0 or 1, EVoke is implementing additional server-side protections to mitigate spoofing risks. Allow-listed chargers will only be accepted from chargers whose IDs are registered in the EVoke CSMS inventory database. Unknown charger identifiers will be rejected.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to reduce the risk of duplicate sessions, only a single active connection per charger ID will be permitted. If a second connection using the same charger ID is detected, the new connection will be rejected or the previous session will be terminated. This prevents unauthorized actors from establishing parallel sessions using spoofed charger identifiers.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that the platform will monitor session anomalies including repeated connection attempts, unexpected IP address changes, and abnormal message patterns. Security events will be logged and flagged for operational review.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to address the risk of denial-of-service via repeated authentication attempts, EVoke will implement connection rate limiting at the WebSocket gateway layer. These controls will restrict excessive connection attempts from the same source and temporarily block abusive traffic patterns.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states they are developing a lifecycle policy for legacy chargers that cannot support modern OCPP security profiles. This policy will include identification of unsupported EVSE models and risk classification Migration planning with site operators where possible', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://evokesystems.com/contact-us/', 'details': 'Contact EVoke using their contact page: https://evokesystems.com/contact-us/ for more information.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-44622', 'cwe': {'id': 'CWE-522', 'name': 'Insufficiently Protected Credentials'}, 'notes': [{'text': 'Charging station authentication identifiers are publicly accessible via web-based mapping platforms.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-06-22T05:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/522.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-44622', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'EVoke states that as a hardware-agnostic platform supporting multiple charger Original Equipment Manufacturers OEMs, EVoke must interoperate with EVSE devices that support different OCPP security profiles depending on the firmware capabilities of the charger. EVoke CSMS currently supports all OCPP security profiles (0–3). However, the effective security configuration for a charger connection is determined by the security profile implemented in the EVSE firmware. Some legacy chargers deployed in the network support only Security Profile 0 or 1. These chargers were installed prior to the broader industry adoption of stronger authentication mechanisms defined in OCPP Security Profiles 2 and 3. EVoke is actively working with charger OEM partners to migrate supported devices to Security Profile 2 (TLS encryption with basic authentication) or Security Profile 3 (Mutual TLS authentication using client certificates). For OEMs that continue to support firmware updates, EVoke will prioritize upgrades to enable Security Profiles 2 or 3.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that certain legacy charger models deployed on the network are no longer supported by the manufacturer (for example, chargers originally produced by EVBox). These devices cannot be upgraded to support stronger security profiles. For chargers limited to Security Profiles 0 or 1, EVoke is implementing additional server-side protections to mitigate spoofing risks. Allow-listed chargers will only be accepted from chargers whose IDs are registered in the EVoke CSMS inventory database. Unknown charger identifiers will be rejected.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to reduce the risk of duplicate sessions, only a single active connection per charger ID will be permitted. If a second connection using the same charger ID is detected, the new connection will be rejected or the previous session will be terminated. This prevents unauthorized actors from establishing parallel sessions using spoofed charger identifiers.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that the platform will monitor session anomalies including repeated connection attempts, unexpected IP address changes, and abnormal message patterns. Security events will be logged and flagged for operational review.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to address the risk of denial-of-service via repeated authentication attempts, EVoke will implement connection rate limiting at the WebSocket gateway layer. These controls will restrict excessive connection attempts from the same source and temporarily block abusive traffic patterns.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states they are developing a lifecycle policy for legacy chargers that cannot support modern OCPP security profiles. This policy will include identification of unsupported EVSE models and risk classification Migration planning with site operators where possible', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://evokesystems.com/contact-us/', 'details': 'Contact EVoke using their contact page: https://evokesystems.com/contact-us/ for more information.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-176-02 | CVE-2026-50176 | EVoke Systems Charging Station Management System | 2026-06-25 08:00:00+03:00 | 2026-06-25 08:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-02.json | d6ae6e1d3471cfb0bb97a26fc851c0c0a6919a99460fa50dff3a8d7b1f92cbab | 2026-06-26 05:15:06.578444+03:00 | 2026-06-26 05:15:06.578444+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks.', 'title': 'Advisory Summary', 'category': 'summary'}, {'text': 'Energy, Transportation Systems', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'EVoke Systems Charging Station Management System', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-176-02', 'status': 'final', 'version': '1', 'generator': {'date': '2026-06-22T17:32:37.903639Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-06-25T05:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}], 'current_release_date': '2026-06-25T05:00:00.000000Z', 'initial_release_date': '2026-06-25T05:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-02.json', 'summary': 'ICS Advisory ICSA-26-176-02 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-02', 'summary': 'ICSA Advisory ICSA-26-176-02 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Khaled Sarieddine', 'Mohammad Ali Sayed'], 'summary': 'reported these vulnerabilities to CISA'}]}, 'product_tree': {'branches': [{'name': 'EVoke Systems', 'branches': [{'name': 'EVoke CSMS', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'EVoke Systems EVoke CSMS: vers:all/*', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40702', 'cwe': {'id': 'CWE-306', 'name': 'Missing Authentication for Critical Function'}, 'notes': [{'text': 'WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-06-22T05:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.4, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/306.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-40702', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'EVoke states that as a hardware-agnostic platform supporting multiple charger Original Equipment Manufacturers OEMs, EVoke must interoperate with EVSE devices that support different OCPP security profiles depending on the firmware capabilities of the charger. EVoke CSMS currently supports all OCPP security profiles (0–3). However, the effective security configuration for a charger connection is determined by the security profile implemented in the EVSE firmware. Some legacy chargers deployed in the network support only Security Profile 0 or 1. These chargers were installed prior to the broader industry adoption of stronger authentication mechanisms defined in OCPP Security Profiles 2 and 3. EVoke is actively working with charger OEM partners to migrate supported devices to Security Profile 2 (TLS encryption with basic authentication) or Security Profile 3 (Mutual TLS authentication using client certificates). For OEMs that continue to support firmware updates, EVoke will prioritize upgrades to enable Security Profiles 2 or 3.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that certain legacy charger models deployed on the network are no longer supported by the manufacturer (for example, chargers originally produced by EVBox). These devices cannot be upgraded to support stronger security profiles. For chargers limited to Security Profiles 0 or 1, EVoke is implementing additional server-side protections to mitigate spoofing risks. Allow-listed chargers will only be accepted from chargers whose IDs are registered in the EVoke CSMS inventory database. Unknown charger identifiers will be rejected.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to reduce the risk of duplicate sessions, only a single active connection per charger ID will be permitted. If a second connection using the same charger ID is detected, the new connection will be rejected or the previous session will be terminated. This prevents unauthorized actors from establishing parallel sessions using spoofed charger identifiers.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that the platform will monitor session anomalies including repeated connection attempts, unexpected IP address changes, and abnormal message patterns. Security events will be logged and flagged for operational review.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to address the risk of denial-of-service via repeated authentication attempts, EVoke will implement connection rate limiting at the WebSocket gateway layer. These controls will restrict excessive connection attempts from the same source and temporarily block abusive traffic patterns.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states they are developing a lifecycle policy for legacy chargers that cannot support modern OCPP security profiles. This policy will include identification of unsupported EVSE models and risk classification Migration planning with site operators where possible', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://evokesystems.com/contact-us/', 'details': 'Contact EVoke using their contact page: https://evokesystems.com/contact-us/ for more information.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-50176', 'cwe': {'id': 'CWE-307', 'name': 'Improper Restriction of Excessive Authentication Attempts'}, 'notes': [{'text': 'The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-06-22T05:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/307.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-50176', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'EVoke states that as a hardware-agnostic platform supporting multiple charger Original Equipment Manufacturers OEMs, EVoke must interoperate with EVSE devices that support different OCPP security profiles depending on the firmware capabilities of the charger. EVoke CSMS currently supports all OCPP security profiles (0–3). However, the effective security configuration for a charger connection is determined by the security profile implemented in the EVSE firmware. Some legacy chargers deployed in the network support only Security Profile 0 or 1. These chargers were installed prior to the broader industry adoption of stronger authentication mechanisms defined in OCPP Security Profiles 2 and 3. EVoke is actively working with charger OEM partners to migrate supported devices to Security Profile 2 (TLS encryption with basic authentication) or Security Profile 3 (Mutual TLS authentication using client certificates). For OEMs that continue to support firmware updates, EVoke will prioritize upgrades to enable Security Profiles 2 or 3.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that certain legacy charger models deployed on the network are no longer supported by the manufacturer (for example, chargers originally produced by EVBox). These devices cannot be upgraded to support stronger security profiles. For chargers limited to Security Profiles 0 or 1, EVoke is implementing additional server-side protections to mitigate spoofing risks. Allow-listed chargers will only be accepted from chargers whose IDs are registered in the EVoke CSMS inventory database. Unknown charger identifiers will be rejected.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to reduce the risk of duplicate sessions, only a single active connection per charger ID will be permitted. If a second connection using the same charger ID is detected, the new connection will be rejected or the previous session will be terminated. This prevents unauthorized actors from establishing parallel sessions using spoofed charger identifiers.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that the platform will monitor session anomalies including repeated connection attempts, unexpected IP address changes, and abnormal message patterns. Security events will be logged and flagged for operational review.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to address the risk of denial-of-service via repeated authentication attempts, EVoke will implement connection rate limiting at the WebSocket gateway layer. These controls will restrict excessive connection attempts from the same source and temporarily block abusive traffic patterns.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states they are developing a lifecycle policy for legacy chargers that cannot support modern OCPP security profiles. This policy will include identification of unsupported EVSE models and risk classification Migration planning with site operators where possible', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://evokesystems.com/contact-us/', 'details': 'Contact EVoke using their contact page: https://evokesystems.com/contact-us/ for more information.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-54479', 'cwe': {'id': 'CWE-613', 'name': 'Insufficient Session Expiration'}, 'notes': [{'text': 'The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-06-22T05:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/613.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-54479', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'EVoke states that as a hardware-agnostic platform supporting multiple charger Original Equipment Manufacturers OEMs, EVoke must interoperate with EVSE devices that support different OCPP security profiles depending on the firmware capabilities of the charger. EVoke CSMS currently supports all OCPP security profiles (0–3). However, the effective security configuration for a charger connection is determined by the security profile implemented in the EVSE firmware. Some legacy chargers deployed in the network support only Security Profile 0 or 1. These chargers were installed prior to the broader industry adoption of stronger authentication mechanisms defined in OCPP Security Profiles 2 and 3. EVoke is actively working with charger OEM partners to migrate supported devices to Security Profile 2 (TLS encryption with basic authentication) or Security Profile 3 (Mutual TLS authentication using client certificates). For OEMs that continue to support firmware updates, EVoke will prioritize upgrades to enable Security Profiles 2 or 3.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that certain legacy charger models deployed on the network are no longer supported by the manufacturer (for example, chargers originally produced by EVBox). These devices cannot be upgraded to support stronger security profiles. For chargers limited to Security Profiles 0 or 1, EVoke is implementing additional server-side protections to mitigate spoofing risks. Allow-listed chargers will only be accepted from chargers whose IDs are registered in the EVoke CSMS inventory database. Unknown charger identifiers will be rejected.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to reduce the risk of duplicate sessions, only a single active connection per charger ID will be permitted. If a second connection using the same charger ID is detected, the new connection will be rejected or the previous session will be terminated. This prevents unauthorized actors from establishing parallel sessions using spoofed charger identifiers.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that the platform will monitor session anomalies including repeated connection attempts, unexpected IP address changes, and abnormal message patterns. Security events will be logged and flagged for operational review.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to address the risk of denial-of-service via repeated authentication attempts, EVoke will implement connection rate limiting at the WebSocket gateway layer. These controls will restrict excessive connection attempts from the same source and temporarily block abusive traffic patterns.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states they are developing a lifecycle policy for legacy chargers that cannot support modern OCPP security profiles. This policy will include identification of unsupported EVSE models and risk classification Migration planning with site operators where possible', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://evokesystems.com/contact-us/', 'details': 'Contact EVoke using their contact page: https://evokesystems.com/contact-us/ for more information.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-44622', 'cwe': {'id': 'CWE-522', 'name': 'Insufficiently Protected Credentials'}, 'notes': [{'text': 'Charging station authentication identifiers are publicly accessible via web-based mapping platforms.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-06-22T05:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/522.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-44622', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'EVoke states that as a hardware-agnostic platform supporting multiple charger Original Equipment Manufacturers OEMs, EVoke must interoperate with EVSE devices that support different OCPP security profiles depending on the firmware capabilities of the charger. EVoke CSMS currently supports all OCPP security profiles (0–3). However, the effective security configuration for a charger connection is determined by the security profile implemented in the EVSE firmware. Some legacy chargers deployed in the network support only Security Profile 0 or 1. These chargers were installed prior to the broader industry adoption of stronger authentication mechanisms defined in OCPP Security Profiles 2 and 3. EVoke is actively working with charger OEM partners to migrate supported devices to Security Profile 2 (TLS encryption with basic authentication) or Security Profile 3 (Mutual TLS authentication using client certificates). For OEMs that continue to support firmware updates, EVoke will prioritize upgrades to enable Security Profiles 2 or 3.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that certain legacy charger models deployed on the network are no longer supported by the manufacturer (for example, chargers originally produced by EVBox). These devices cannot be upgraded to support stronger security profiles. For chargers limited to Security Profiles 0 or 1, EVoke is implementing additional server-side protections to mitigate spoofing risks. Allow-listed chargers will only be accepted from chargers whose IDs are registered in the EVoke CSMS inventory database. Unknown charger identifiers will be rejected.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to reduce the risk of duplicate sessions, only a single active connection per charger ID will be permitted. If a second connection using the same charger ID is detected, the new connection will be rejected or the previous session will be terminated. This prevents unauthorized actors from establishing parallel sessions using spoofed charger identifiers.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that the platform will monitor session anomalies including repeated connection attempts, unexpected IP address changes, and abnormal message patterns. Security events will be logged and flagged for operational review.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to address the risk of denial-of-service via repeated authentication attempts, EVoke will implement connection rate limiting at the WebSocket gateway layer. These controls will restrict excessive connection attempts from the same source and temporarily block abusive traffic patterns.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states they are developing a lifecycle policy for legacy chargers that cannot support modern OCPP security profiles. This policy will include identification of unsupported EVSE models and risk classification Migration planning with site operators where possible', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://evokesystems.com/contact-us/', 'details': 'Contact EVoke using their contact page: https://evokesystems.com/contact-us/ for more information.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-176-02 | CVE-2026-54479 | EVoke Systems Charging Station Management System | 2026-06-25 08:00:00+03:00 | 2026-06-25 08:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-02.json | de75404c11c4428f0831f66f4996105e75b1fcdba1c7b7dca12e10752f08756a | 2026-06-26 05:15:06.578444+03:00 | 2026-06-26 05:15:06.578444+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks.', 'title': 'Advisory Summary', 'category': 'summary'}, {'text': 'Energy, Transportation Systems', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'EVoke Systems Charging Station Management System', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-176-02', 'status': 'final', 'version': '1', 'generator': {'date': '2026-06-22T17:32:37.903639Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-06-25T05:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}], 'current_release_date': '2026-06-25T05:00:00.000000Z', 'initial_release_date': '2026-06-25T05:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-02.json', 'summary': 'ICS Advisory ICSA-26-176-02 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-02', 'summary': 'ICSA Advisory ICSA-26-176-02 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Khaled Sarieddine', 'Mohammad Ali Sayed'], 'summary': 'reported these vulnerabilities to CISA'}]}, 'product_tree': {'branches': [{'name': 'EVoke Systems', 'branches': [{'name': 'EVoke CSMS', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'EVoke Systems EVoke CSMS: vers:all/*', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40702', 'cwe': {'id': 'CWE-306', 'name': 'Missing Authentication for Critical Function'}, 'notes': [{'text': 'WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-06-22T05:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.4, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/306.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-40702', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'EVoke states that as a hardware-agnostic platform supporting multiple charger Original Equipment Manufacturers OEMs, EVoke must interoperate with EVSE devices that support different OCPP security profiles depending on the firmware capabilities of the charger. EVoke CSMS currently supports all OCPP security profiles (0–3). However, the effective security configuration for a charger connection is determined by the security profile implemented in the EVSE firmware. Some legacy chargers deployed in the network support only Security Profile 0 or 1. These chargers were installed prior to the broader industry adoption of stronger authentication mechanisms defined in OCPP Security Profiles 2 and 3. EVoke is actively working with charger OEM partners to migrate supported devices to Security Profile 2 (TLS encryption with basic authentication) or Security Profile 3 (Mutual TLS authentication using client certificates). For OEMs that continue to support firmware updates, EVoke will prioritize upgrades to enable Security Profiles 2 or 3.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that certain legacy charger models deployed on the network are no longer supported by the manufacturer (for example, chargers originally produced by EVBox). These devices cannot be upgraded to support stronger security profiles. For chargers limited to Security Profiles 0 or 1, EVoke is implementing additional server-side protections to mitigate spoofing risks. Allow-listed chargers will only be accepted from chargers whose IDs are registered in the EVoke CSMS inventory database. Unknown charger identifiers will be rejected.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to reduce the risk of duplicate sessions, only a single active connection per charger ID will be permitted. If a second connection using the same charger ID is detected, the new connection will be rejected or the previous session will be terminated. This prevents unauthorized actors from establishing parallel sessions using spoofed charger identifiers.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that the platform will monitor session anomalies including repeated connection attempts, unexpected IP address changes, and abnormal message patterns. Security events will be logged and flagged for operational review.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to address the risk of denial-of-service via repeated authentication attempts, EVoke will implement connection rate limiting at the WebSocket gateway layer. These controls will restrict excessive connection attempts from the same source and temporarily block abusive traffic patterns.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states they are developing a lifecycle policy for legacy chargers that cannot support modern OCPP security profiles. This policy will include identification of unsupported EVSE models and risk classification Migration planning with site operators where possible', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://evokesystems.com/contact-us/', 'details': 'Contact EVoke using their contact page: https://evokesystems.com/contact-us/ for more information.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-50176', 'cwe': {'id': 'CWE-307', 'name': 'Improper Restriction of Excessive Authentication Attempts'}, 'notes': [{'text': 'The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-06-22T05:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/307.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-50176', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'EVoke states that as a hardware-agnostic platform supporting multiple charger Original Equipment Manufacturers OEMs, EVoke must interoperate with EVSE devices that support different OCPP security profiles depending on the firmware capabilities of the charger. EVoke CSMS currently supports all OCPP security profiles (0–3). However, the effective security configuration for a charger connection is determined by the security profile implemented in the EVSE firmware. Some legacy chargers deployed in the network support only Security Profile 0 or 1. These chargers were installed prior to the broader industry adoption of stronger authentication mechanisms defined in OCPP Security Profiles 2 and 3. EVoke is actively working with charger OEM partners to migrate supported devices to Security Profile 2 (TLS encryption with basic authentication) or Security Profile 3 (Mutual TLS authentication using client certificates). For OEMs that continue to support firmware updates, EVoke will prioritize upgrades to enable Security Profiles 2 or 3.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that certain legacy charger models deployed on the network are no longer supported by the manufacturer (for example, chargers originally produced by EVBox). These devices cannot be upgraded to support stronger security profiles. For chargers limited to Security Profiles 0 or 1, EVoke is implementing additional server-side protections to mitigate spoofing risks. Allow-listed chargers will only be accepted from chargers whose IDs are registered in the EVoke CSMS inventory database. Unknown charger identifiers will be rejected.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to reduce the risk of duplicate sessions, only a single active connection per charger ID will be permitted. If a second connection using the same charger ID is detected, the new connection will be rejected or the previous session will be terminated. This prevents unauthorized actors from establishing parallel sessions using spoofed charger identifiers.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that the platform will monitor session anomalies including repeated connection attempts, unexpected IP address changes, and abnormal message patterns. Security events will be logged and flagged for operational review.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to address the risk of denial-of-service via repeated authentication attempts, EVoke will implement connection rate limiting at the WebSocket gateway layer. These controls will restrict excessive connection attempts from the same source and temporarily block abusive traffic patterns.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states they are developing a lifecycle policy for legacy chargers that cannot support modern OCPP security profiles. This policy will include identification of unsupported EVSE models and risk classification Migration planning with site operators where possible', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://evokesystems.com/contact-us/', 'details': 'Contact EVoke using their contact page: https://evokesystems.com/contact-us/ for more information.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-54479', 'cwe': {'id': 'CWE-613', 'name': 'Insufficient Session Expiration'}, 'notes': [{'text': 'The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-06-22T05:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/613.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-54479', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'EVoke states that as a hardware-agnostic platform supporting multiple charger Original Equipment Manufacturers OEMs, EVoke must interoperate with EVSE devices that support different OCPP security profiles depending on the firmware capabilities of the charger. EVoke CSMS currently supports all OCPP security profiles (0–3). However, the effective security configuration for a charger connection is determined by the security profile implemented in the EVSE firmware. Some legacy chargers deployed in the network support only Security Profile 0 or 1. These chargers were installed prior to the broader industry adoption of stronger authentication mechanisms defined in OCPP Security Profiles 2 and 3. EVoke is actively working with charger OEM partners to migrate supported devices to Security Profile 2 (TLS encryption with basic authentication) or Security Profile 3 (Mutual TLS authentication using client certificates). For OEMs that continue to support firmware updates, EVoke will prioritize upgrades to enable Security Profiles 2 or 3.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that certain legacy charger models deployed on the network are no longer supported by the manufacturer (for example, chargers originally produced by EVBox). These devices cannot be upgraded to support stronger security profiles. For chargers limited to Security Profiles 0 or 1, EVoke is implementing additional server-side protections to mitigate spoofing risks. Allow-listed chargers will only be accepted from chargers whose IDs are registered in the EVoke CSMS inventory database. Unknown charger identifiers will be rejected.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to reduce the risk of duplicate sessions, only a single active connection per charger ID will be permitted. If a second connection using the same charger ID is detected, the new connection will be rejected or the previous session will be terminated. This prevents unauthorized actors from establishing parallel sessions using spoofed charger identifiers.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that the platform will monitor session anomalies including repeated connection attempts, unexpected IP address changes, and abnormal message patterns. Security events will be logged and flagged for operational review.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to address the risk of denial-of-service via repeated authentication attempts, EVoke will implement connection rate limiting at the WebSocket gateway layer. These controls will restrict excessive connection attempts from the same source and temporarily block abusive traffic patterns.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states they are developing a lifecycle policy for legacy chargers that cannot support modern OCPP security profiles. This policy will include identification of unsupported EVSE models and risk classification Migration planning with site operators where possible', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://evokesystems.com/contact-us/', 'details': 'Contact EVoke using their contact page: https://evokesystems.com/contact-us/ for more information.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-44622', 'cwe': {'id': 'CWE-522', 'name': 'Insufficiently Protected Credentials'}, 'notes': [{'text': 'Charging station authentication identifiers are publicly accessible via web-based mapping platforms.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-06-22T05:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/522.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-44622', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'EVoke states that as a hardware-agnostic platform supporting multiple charger Original Equipment Manufacturers OEMs, EVoke must interoperate with EVSE devices that support different OCPP security profiles depending on the firmware capabilities of the charger. EVoke CSMS currently supports all OCPP security profiles (0–3). However, the effective security configuration for a charger connection is determined by the security profile implemented in the EVSE firmware. Some legacy chargers deployed in the network support only Security Profile 0 or 1. These chargers were installed prior to the broader industry adoption of stronger authentication mechanisms defined in OCPP Security Profiles 2 and 3. EVoke is actively working with charger OEM partners to migrate supported devices to Security Profile 2 (TLS encryption with basic authentication) or Security Profile 3 (Mutual TLS authentication using client certificates). For OEMs that continue to support firmware updates, EVoke will prioritize upgrades to enable Security Profiles 2 or 3.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that certain legacy charger models deployed on the network are no longer supported by the manufacturer (for example, chargers originally produced by EVBox). These devices cannot be upgraded to support stronger security profiles. For chargers limited to Security Profiles 0 or 1, EVoke is implementing additional server-side protections to mitigate spoofing risks. Allow-listed chargers will only be accepted from chargers whose IDs are registered in the EVoke CSMS inventory database. Unknown charger identifiers will be rejected.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to reduce the risk of duplicate sessions, only a single active connection per charger ID will be permitted. If a second connection using the same charger ID is detected, the new connection will be rejected or the previous session will be terminated. This prevents unauthorized actors from establishing parallel sessions using spoofed charger identifiers.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that the platform will monitor session anomalies including repeated connection attempts, unexpected IP address changes, and abnormal message patterns. Security events will be logged and flagged for operational review.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to address the risk of denial-of-service via repeated authentication attempts, EVoke will implement connection rate limiting at the WebSocket gateway layer. These controls will restrict excessive connection attempts from the same source and temporarily block abusive traffic patterns.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states they are developing a lifecycle policy for legacy chargers that cannot support modern OCPP security profiles. This policy will include identification of unsupported EVSE models and risk classification Migration planning with site operators where possible', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://evokesystems.com/contact-us/', 'details': 'Contact EVoke using their contact page: https://evokesystems.com/contact-us/ for more information.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-176-02 | CVE-2026-44622 | EVoke Systems Charging Station Management System | 2026-06-25 08:00:00+03:00 | 2026-06-25 08:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-02.json | 62418db8b4063470cabfb61b74224b8ca4d3cc3448593e857ae1002f0f41b1aa | 2026-06-26 05:15:06.578444+03:00 | 2026-06-26 05:15:06.578444+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks.', 'title': 'Advisory Summary', 'category': 'summary'}, {'text': 'Energy, Transportation Systems', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'EVoke Systems Charging Station Management System', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-176-02', 'status': 'final', 'version': '1', 'generator': {'date': '2026-06-22T17:32:37.903639Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-06-25T05:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}], 'current_release_date': '2026-06-25T05:00:00.000000Z', 'initial_release_date': '2026-06-25T05:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-176-02.json', 'summary': 'ICS Advisory ICSA-26-176-02 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-176-02', 'summary': 'ICSA Advisory ICSA-26-176-02 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Khaled Sarieddine', 'Mohammad Ali Sayed'], 'summary': 'reported these vulnerabilities to CISA'}]}, 'product_tree': {'branches': [{'name': 'EVoke Systems', 'branches': [{'name': 'EVoke CSMS', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'EVoke Systems EVoke CSMS: vers:all/*', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40702', 'cwe': {'id': 'CWE-306', 'name': 'Missing Authentication for Critical Function'}, 'notes': [{'text': 'WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-06-22T05:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.4, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/306.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-40702', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'EVoke states that as a hardware-agnostic platform supporting multiple charger Original Equipment Manufacturers OEMs, EVoke must interoperate with EVSE devices that support different OCPP security profiles depending on the firmware capabilities of the charger. EVoke CSMS currently supports all OCPP security profiles (0–3). However, the effective security configuration for a charger connection is determined by the security profile implemented in the EVSE firmware. Some legacy chargers deployed in the network support only Security Profile 0 or 1. These chargers were installed prior to the broader industry adoption of stronger authentication mechanisms defined in OCPP Security Profiles 2 and 3. EVoke is actively working with charger OEM partners to migrate supported devices to Security Profile 2 (TLS encryption with basic authentication) or Security Profile 3 (Mutual TLS authentication using client certificates). For OEMs that continue to support firmware updates, EVoke will prioritize upgrades to enable Security Profiles 2 or 3.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that certain legacy charger models deployed on the network are no longer supported by the manufacturer (for example, chargers originally produced by EVBox). These devices cannot be upgraded to support stronger security profiles. For chargers limited to Security Profiles 0 or 1, EVoke is implementing additional server-side protections to mitigate spoofing risks. Allow-listed chargers will only be accepted from chargers whose IDs are registered in the EVoke CSMS inventory database. Unknown charger identifiers will be rejected.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to reduce the risk of duplicate sessions, only a single active connection per charger ID will be permitted. If a second connection using the same charger ID is detected, the new connection will be rejected or the previous session will be terminated. This prevents unauthorized actors from establishing parallel sessions using spoofed charger identifiers.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that the platform will monitor session anomalies including repeated connection attempts, unexpected IP address changes, and abnormal message patterns. Security events will be logged and flagged for operational review.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to address the risk of denial-of-service via repeated authentication attempts, EVoke will implement connection rate limiting at the WebSocket gateway layer. These controls will restrict excessive connection attempts from the same source and temporarily block abusive traffic patterns.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states they are developing a lifecycle policy for legacy chargers that cannot support modern OCPP security profiles. This policy will include identification of unsupported EVSE models and risk classification Migration planning with site operators where possible', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://evokesystems.com/contact-us/', 'details': 'Contact EVoke using their contact page: https://evokesystems.com/contact-us/ for more information.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-50176', 'cwe': {'id': 'CWE-307', 'name': 'Improper Restriction of Excessive Authentication Attempts'}, 'notes': [{'text': 'The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-06-22T05:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/307.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-50176', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'EVoke states that as a hardware-agnostic platform supporting multiple charger Original Equipment Manufacturers OEMs, EVoke must interoperate with EVSE devices that support different OCPP security profiles depending on the firmware capabilities of the charger. EVoke CSMS currently supports all OCPP security profiles (0–3). However, the effective security configuration for a charger connection is determined by the security profile implemented in the EVSE firmware. Some legacy chargers deployed in the network support only Security Profile 0 or 1. These chargers were installed prior to the broader industry adoption of stronger authentication mechanisms defined in OCPP Security Profiles 2 and 3. EVoke is actively working with charger OEM partners to migrate supported devices to Security Profile 2 (TLS encryption with basic authentication) or Security Profile 3 (Mutual TLS authentication using client certificates). For OEMs that continue to support firmware updates, EVoke will prioritize upgrades to enable Security Profiles 2 or 3.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that certain legacy charger models deployed on the network are no longer supported by the manufacturer (for example, chargers originally produced by EVBox). These devices cannot be upgraded to support stronger security profiles. For chargers limited to Security Profiles 0 or 1, EVoke is implementing additional server-side protections to mitigate spoofing risks. Allow-listed chargers will only be accepted from chargers whose IDs are registered in the EVoke CSMS inventory database. Unknown charger identifiers will be rejected.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to reduce the risk of duplicate sessions, only a single active connection per charger ID will be permitted. If a second connection using the same charger ID is detected, the new connection will be rejected or the previous session will be terminated. This prevents unauthorized actors from establishing parallel sessions using spoofed charger identifiers.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that the platform will monitor session anomalies including repeated connection attempts, unexpected IP address changes, and abnormal message patterns. Security events will be logged and flagged for operational review.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to address the risk of denial-of-service via repeated authentication attempts, EVoke will implement connection rate limiting at the WebSocket gateway layer. These controls will restrict excessive connection attempts from the same source and temporarily block abusive traffic patterns.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states they are developing a lifecycle policy for legacy chargers that cannot support modern OCPP security profiles. This policy will include identification of unsupported EVSE models and risk classification Migration planning with site operators where possible', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://evokesystems.com/contact-us/', 'details': 'Contact EVoke using their contact page: https://evokesystems.com/contact-us/ for more information.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-54479', 'cwe': {'id': 'CWE-613', 'name': 'Insufficient Session Expiration'}, 'notes': [{'text': 'The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-06-22T05:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/613.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-54479', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'EVoke states that as a hardware-agnostic platform supporting multiple charger Original Equipment Manufacturers OEMs, EVoke must interoperate with EVSE devices that support different OCPP security profiles depending on the firmware capabilities of the charger. EVoke CSMS currently supports all OCPP security profiles (0–3). However, the effective security configuration for a charger connection is determined by the security profile implemented in the EVSE firmware. Some legacy chargers deployed in the network support only Security Profile 0 or 1. These chargers were installed prior to the broader industry adoption of stronger authentication mechanisms defined in OCPP Security Profiles 2 and 3. EVoke is actively working with charger OEM partners to migrate supported devices to Security Profile 2 (TLS encryption with basic authentication) or Security Profile 3 (Mutual TLS authentication using client certificates). For OEMs that continue to support firmware updates, EVoke will prioritize upgrades to enable Security Profiles 2 or 3.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that certain legacy charger models deployed on the network are no longer supported by the manufacturer (for example, chargers originally produced by EVBox). These devices cannot be upgraded to support stronger security profiles. For chargers limited to Security Profiles 0 or 1, EVoke is implementing additional server-side protections to mitigate spoofing risks. Allow-listed chargers will only be accepted from chargers whose IDs are registered in the EVoke CSMS inventory database. Unknown charger identifiers will be rejected.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to reduce the risk of duplicate sessions, only a single active connection per charger ID will be permitted. If a second connection using the same charger ID is detected, the new connection will be rejected or the previous session will be terminated. This prevents unauthorized actors from establishing parallel sessions using spoofed charger identifiers.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that the platform will monitor session anomalies including repeated connection attempts, unexpected IP address changes, and abnormal message patterns. Security events will be logged and flagged for operational review.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to address the risk of denial-of-service via repeated authentication attempts, EVoke will implement connection rate limiting at the WebSocket gateway layer. These controls will restrict excessive connection attempts from the same source and temporarily block abusive traffic patterns.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states they are developing a lifecycle policy for legacy chargers that cannot support modern OCPP security profiles. This policy will include identification of unsupported EVSE models and risk classification Migration planning with site operators where possible', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://evokesystems.com/contact-us/', 'details': 'Contact EVoke using their contact page: https://evokesystems.com/contact-us/ for more information.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-44622', 'cwe': {'id': 'CWE-522', 'name': 'Insufficiently Protected Credentials'}, 'notes': [{'text': 'Charging station authentication identifiers are publicly accessible via web-based mapping platforms.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-06-22T05:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/522.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-44622', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'EVoke states that as a hardware-agnostic platform supporting multiple charger Original Equipment Manufacturers OEMs, EVoke must interoperate with EVSE devices that support different OCPP security profiles depending on the firmware capabilities of the charger. EVoke CSMS currently supports all OCPP security profiles (0–3). However, the effective security configuration for a charger connection is determined by the security profile implemented in the EVSE firmware. Some legacy chargers deployed in the network support only Security Profile 0 or 1. These chargers were installed prior to the broader industry adoption of stronger authentication mechanisms defined in OCPP Security Profiles 2 and 3. EVoke is actively working with charger OEM partners to migrate supported devices to Security Profile 2 (TLS encryption with basic authentication) or Security Profile 3 (Mutual TLS authentication using client certificates). For OEMs that continue to support firmware updates, EVoke will prioritize upgrades to enable Security Profiles 2 or 3.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that certain legacy charger models deployed on the network are no longer supported by the manufacturer (for example, chargers originally produced by EVBox). These devices cannot be upgraded to support stronger security profiles. For chargers limited to Security Profiles 0 or 1, EVoke is implementing additional server-side protections to mitigate spoofing risks. Allow-listed chargers will only be accepted from chargers whose IDs are registered in the EVoke CSMS inventory database. Unknown charger identifiers will be rejected.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to reduce the risk of duplicate sessions, only a single active connection per charger ID will be permitted. If a second connection using the same charger ID is detected, the new connection will be rejected or the previous session will be terminated. This prevents unauthorized actors from establishing parallel sessions using spoofed charger identifiers.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that the platform will monitor session anomalies including repeated connection attempts, unexpected IP address changes, and abnormal message patterns. Security events will be logged and flagged for operational review.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states that to address the risk of denial-of-service via repeated authentication attempts, EVoke will implement connection rate limiting at the WebSocket gateway layer. These controls will restrict excessive connection attempts from the same source and temporarily block abusive traffic patterns.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'EVoke states they are developing a lifecycle policy for legacy chargers that cannot support modern OCPP security profiles. This policy will include identification of unsupported EVSE models and risk classification Migration planning with site operators where possible', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://evokesystems.com/contact-us/', 'details': 'Contact EVoke using their contact page: https://evokesystems.com/contact-us/ for more information.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
it | VA-26-177-01 | CVE-2026-56876 | extract-zip unvalidated symlink path traversal | 2026-06-26 19:08:29+03:00 | 2026-06-26 19:08:29+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-177-01.json | 948afbf5b996a7072e781d2748570ad8da4196b70ed4f192dbda25e6ed6a9e95 | 2026-06-27 00:23:54.628574+03:00 | 2026-06-27 00:23:54.628574+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'All information products included in [https://github.com/cisagov/CSAF/tree/develop/csaf_files/IT/white](https://github.com/cisagov/CSAF/tree/develop/csaf_files/IT/white) are provided \\"as is\\" for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained within. DHS does not endorse any commercial product or service, referenced in this product or otherwise. Further dissemination of this product is governed by the Traffic Light Protocol (TLP) marking in the header. For more information about TLP, see [https://us-cert.cisa.gov/tlp/](https://us-cert.cisa.gov/tlp/).', 'title': 'Legal Notice', 'category': 'legal_disclaimer'}, {'text': 'Worldwide', 'title': 'Countries and Areas Deployed', 'category': 'other'}, {'text': 'Information Technology', 'title': 'Critical Infrastructure Sectors', 'category': 'other'}, {'text': "extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/passwd', extract-zip will extract the symlink without validation, allowing it to point outside the extraction directory. Depending on how extract-zip is used, an attacker could read or write to arbitrary files.", 'title': 'Risk Evaluation', 'category': 'summary'}, {'text': 'Consider using alternatives such as cthackers/adm-zip.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'United States', 'title': 'Company Headquarters Location', 'category': 'other'}], 'title': 'extract-zip unvalidated symlink path traversal', 'category': 'csaf_vex', 'tracking': {'id': 'VA-26-177-01', 'status': 'final', 'version': '1.0.0', 'generator': {'engine': {'name': 'VINCE-NT', 'version': '1.15.0+build.89'}}, 'revision_history': [{'date': '2026-06-26T16:08:29Z', 'number': '1.0.0', 'summary': 'Initial publication'}], 'current_release_date': '2026-06-26T16:08:29Z', 'initial_release_date': '2026-06-26T16:08:29Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'https://www.cisa.gov/report', 'issuing_authority': 'CISA'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-177-01.json', 'summary': 'Vulnerability Advisory VA-26-177-01 CSAF', 'category': 'self'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'label': 'WHITE'}}}, 'product_tree': {'branches': [{'name': 'max-mapper', 'branches': [{'name': 'extract-zip', 'branches': [{'name': '<*', 'product': {'name': 'max-mapper extract-zip <*', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-56876', 'cwe': {'id': 'CWE-22', 'name': "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"}, 'notes': [{'text': "extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/passwd', extract-zip will extract the symlink without validation, allowing it to point outside the extraction directory. Depending on how extract-zip is used, an attacker could read or write to arbitrary files.", 'title': 'Description', 'category': 'summary'}, {'text': 'SSVCv2/E:P/A:N/T:T/2026-06-23T15:08:40Z/', 'title': 'SSVC', 'category': 'details'}], 'title': 'extract-zip unvalidated symlink path traversal', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://github.com/ziad626/extract-zip-security-research/security/advisories/GHSA-x7jf-2287-qcpf', 'summary': 'github.com', 'category': 'external'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-177-01.json', 'summary': 'VA-26-177-01', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-56876', 'summary': 'CVE-2026-56876', 'category': 'external'}], 'release_date': '2026-06-15T00:00:00Z', 'remediations': [{'url': 'https://github.com/cthackers/adm-zip', 'details': 'Consider using alternatives such as cthackers/adm-zip.', 'category': 'none_available', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}, 'acknowledgments': [{'names': ['Ziad Salah'], 'organization': 'Independent'}]}]} | |
ot | ICSA-26-141-03 | CVE-2015-3717 | ABB B&R Automation Studio | 2026-02-18 03:30:00+03:00 | 2026-05-21 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-141-03.json | 21f07940a3e86aec71ecdb8fade3ee1e03e62aff0623e76e15549ae491616216 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'ABB became aware of vulnerability in the product versions listed as affected in the advisory. An update is available that replaces an outdated third-party component.\n\nAlthough no successful exploitation was observed during testing of the affected B&R products, the identified vulnerabilities could present potential attack vectors that might enable unauthorized access, data exposure, or remote code execution.\n', 'title': 'Summary', 'category': 'summary'}, {'text': 'For additional instructions and support please contact your local B&R service organization. For contact information, see https://www.br-automation.com/en/about-us/locations/.\n\nInformation about ABB’s cyber security program and capabilities can be found at www.abb.com/cybersecurity.\n\n', 'title': 'Support', 'category': 'other'}, {'text': 'The information in this document is subject to change without notice, and should not be construed as a commitment by B&R.\n\nB&R provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall B&R or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if B&R or its suppliers have been advised of the possibility of such damages.\n\nThis document and parts hereof must not be reproduced or copied without written permission from B&R, and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose.\n\nAll rights to registrations and trademarks reside with their respective owners.', 'title': 'Notice', 'category': 'legal_disclaimer'}, {'text': 'For any installation of software related ABB products we strongly recommend the following (non-exhaustive) list of cyber security practices:\n\n– Isolate special purpose networks (e.g. for automation systems) and remote devices behind firewalls and separate them from any general purpose network (e.g. office or home networks).\n\n– Install physical controls so no unauthorized personnel can access your devices, components, peripheral equipment, and networks.\n\n– Never connect programming software or computers containing programing software to any network other than the network for the devices that it is intended for.\n\n– Scan all data imported into your environment before use to detect potential malware infections.\n\n– Minimize network exposure for all applications and endpoints to ensure that they are not accessible from the Internet unless they are designed for such exposure and the intended use requires such.\n\n– Ensure all nodes are always up to date in terms of installed software, operating system, and firmware patches as well as anti-virus and firewall.\n\n– When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.\n\nMore information on recommended practices can be found in the following documents:\n\nDefense in Depth for B&R products - https://www.br-automation.com/fileadmin/Cyber_Security_-_Defense_in_Depth_for_BR_Products-bdd37e82.pdf\n', 'title': 'General security recommendations', 'category': 'other'}, {'text': 'B&R has a rigorous internal cyber security continuous improvement process which involves regular testing with industry leading tools and periodic assessments to identify potential product issues. Occasionally an issue is determined to be a design or coding flaw with implications that may impact product cyber security.\n\nWhen a potential product vulnerability is identified or reported, B&R immediately initiates our vulnerability handling process. This entails validating if the issue is in fact a product issue, identifying root causes, determining what related products may be impacted, developing a remediation, and notifying end users and governmental organizations.\n\nThe resulting Cyber Security Advisory intends to notify customers of the vulnerability and provide details on which products are impacted, how to mitigate the vulnerability or explain workarounds that minimize the potential risk as much as possible. The release of a Cyber Security Advisory should not be misconstrued as an affirmation or indication of an active threat or ongoing campaign targeting the products mentioned here. If B&R is aware of any specific threats, it will be clearly mentioned in the communication.\n\nThe publication of this Cyber Security Advisory is an example of B&R’s commitment to the user community in support of this critical topic. Responsible disclosure is an important element in the chain of trust we work to maintain with our many customers. The release of an Advisory provides timely information which is essential to help ensure our customers are fully informed.', 'title': 'Purpose', 'category': 'other'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of ABB PSIRT SA25P007 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact ABB PSIRT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Energy', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Switzerland', 'title': 'Company headquarters location', 'category': 'other'}], 'title': 'ABB B&R Automation Studio', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-141-03', 'status': 'final', 'version': '2', 'generator': {'date': '2026-05-19T15:18:28.715456Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2026-02-18T00:30:00.000000Z', 'number': '1', 'summary': 'Initial version.', 'legacy_version': 'Initial'}, {'date': '2026-05-21T06:00:00.000000Z', 'number': '2', 'summary': 'Initial CISA Republication of ABB PSIRT SA25P007 advisory', 'legacy_version': 'CISA Republication'}], 'current_release_date': '2026-05-21T06:00:00.000000Z', 'initial_release_date': '2026-02-18T00:30:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://psirt.abb.com/csaf/2026/sa25p007.json', 'summary': 'ABB CYBERSECURITY ADVISORY - CSAF Version ', 'category': 'self'}, {'url': 'https://www.br-automation.com/fileadmin/SA25P007-097a386d.pdf', 'summary': 'ABB CYBERSECURITY ADVISORY - PDF Version ', 'category': 'self'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-141-03.json', 'summary': 'ICS Advisory ICSA-26-141-03 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-141-03', 'summary': 'ICS Advisory ICSA-26-141-03 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to CISA.', 'organization': 'ABB PSIRT'}]}, 'product_tree': {'branches': [{'name': 'ABB', 'branches': [{'name': 'B&R Automation Studio', 'branches': [{'name': '<6.5', 'product': {'name': 'ABB B&R Automation Studio <6.5', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}, {'name': '6.5', 'product': {'name': 'ABB B&R Automation Studio 6.5', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-6965', 'cwe': {'id': 'CWE-197', 'name': 'Numeric Truncation Error'}, 'notes': [{'text': 'There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2025-6965', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C', 'temporalScore': 8.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.8, 'privilegesRequired': 'NONE', 'exploitCodeMaturity': 'PROOF_OF_CONCEPT', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-6965', 'summary': 'NVD - CVE-2025-6965', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-6965', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/197.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'The problem is corrected in the following product versions:\n\nB&R Automation Studio 6.5\n\nB&R recommends that customers apply the update at earliest convenience.\n\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Refer to section “General security recommendations” for advice on how to keep your system secure.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-3277', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'notes': [{'text': "An integer overflow vulnerability exists in SQLite's concat_ws() function that can lead to a massive heap buffer overflow. When triggered, the integer overflow results in a truncated size value being used for buffer allocation, while the original untruncated size is used for writing the resulting string, causing a heap buffer overflow of approximately 4GB.", 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2025-3277', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C', 'temporalScore': 8.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.8, 'privilegesRequired': 'NONE', 'exploitCodeMaturity': 'PROOF_OF_CONCEPT', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2025-3277', 'summary': 'NVD - CVE-2025-3277', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-3277', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/122.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'The problem is corrected in the following product versions:\n\nB&R Automation Studio 6.5\n\nB&R recommends that customers apply the update at earliest convenience.\n\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Refer to section “General security recommendations” for advice on how to keep your system secure.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2023-7104', 'cwe': {'id': 'CWE-122', 'name': 'Heap-based Buffer Overflow'}, 'notes': [{'text': 'A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2023-7104', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C', 'temporalScore': 6.6, 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'LOW', 'environmentalScore': 6.6, 'privilegesRequired': 'NONE', 'exploitCodeMaturity': 'PROOF_OF_CONCEPT', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2023-7104', 'summary': 'NVD - CVE-2023-7104', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2023-7104', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/122.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'The problem is corrected in the following product versions:\n\nB&R Automation Studio 6.5\n\nB&R recommends that customers apply the update at earliest convenience.\n\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Refer to section “General security recommendations” for advice on how to keep your system secure.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2022-35737', 'cwe': {'id': 'CWE-119', 'name': 'Improper Restriction of Operations within the Bounds of a Memory Buffer'}, 'notes': [{'text': 'SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2022-35737', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C', 'temporalScore': 6.7, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 6.7, 'privilegesRequired': 'NONE', 'exploitCodeMaturity': 'PROOF_OF_CONCEPT', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2022-35737', 'summary': 'NVD - CVE-2022-35737', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2022-35737', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/119.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'The problem is corrected in the following product versions:\n\nB&R Automation Studio 6.5\n\nB&R recommends that customers apply the update at earliest convenience.\n\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Refer to section “General security recommendations” for advice on how to keep your system secure.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2020-15358', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2020-15358', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C', 'temporalScore': 5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 5, 'privilegesRequired': 'LOW', 'exploitCodeMaturity': 'PROOF_OF_CONCEPT', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2020-15358', 'summary': 'NVD - CVE-2020-15358', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2020-15358', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'The problem is corrected in the following product versions:\n\nB&R Automation Studio 6.5\n\nB&R recommends that customers apply the update at earliest convenience.\n\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Refer to section “General security recommendations” for advice on how to keep your system secure.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2020-13632', 'cwe': {'id': 'CWE-476', 'name': 'NULL Pointer Dereference'}, 'notes': [{'text': 'There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2020-13632', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C', 'temporalScore': 5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 5, 'privilegesRequired': 'LOW', 'exploitCodeMaturity': 'PROOF_OF_CONCEPT', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2020-13632', 'summary': 'NVD - CVE-2020-13632', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2020-13632', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/476.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'The problem is corrected in the following product versions:\n\nB&R Automation Studio 6.5\n\nB&R recommends that customers apply the update at earliest convenience.\n\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Refer to section “General security recommendations” for advice on how to keep your system secure.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2020-13631', 'cwe': {'id': 'CWE-286', 'name': 'Incorrect User Management'}, 'notes': [{'text': 'SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2020-13631', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:P/RL:O/RC:C', 'temporalScore': 5, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'NONE', 'environmentalScore': 5, 'privilegesRequired': 'LOW', 'exploitCodeMaturity': 'PROOF_OF_CONCEPT', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2020-13631', 'summary': 'NVD - CVE-2020-13631', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2020-13631', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/286.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:P/RL:O/RC:C', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'The problem is corrected in the following product versions:\n\nB&R Automation Studio 6.5\n\nB&R recommends that customers apply the update at earliest convenience.\n\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Refer to section “General security recommendations” for advice on how to keep your system secure.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2020-13630', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2020-13630', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 7, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C', 'temporalScore': 6.3, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 6.3, 'privilegesRequired': 'LOW', 'exploitCodeMaturity': 'PROOF_OF_CONCEPT', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2020-13630', 'summary': 'NVD - CVE-2020-13630', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2020-13630', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/416.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'The problem is corrected in the following product versions:\n\nB&R Automation Studio 6.5\n\nB&R recommends that customers apply the update at earliest convenience.\n\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Refer to section “General security recommendations” for advice on how to keep your system secure.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2020-13435', 'cwe': {'id': 'CWE-476', 'name': 'NULL Pointer Dereference'}, 'notes': [{'text': 'SQLite through 3.32.0 has a segmentation fault in sqlite3ExprCodeTarget in expr.c.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2020-13435', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C', 'temporalScore': 6.7, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 6.7, 'privilegesRequired': 'NONE', 'exploitCodeMaturity': 'PROOF_OF_CONCEPT', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2020-13435', 'summary': 'NVD - CVE-2020-13435', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2020-13435', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/476.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'The problem is corrected in the following product versions:\n\nB&R Automation Studio 6.5\n\nB&R recommends that customers apply the update at earliest convenience.\n\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Refer to section “General security recommendations” for advice on how to keep your system secure.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2020-13434', 'cwe': {'id': 'CWE-190', 'name': 'Integer Overflow or Wraparound'}, 'notes': [{'text': 'SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2020-13434', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C', 'temporalScore': 5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 5, 'privilegesRequired': 'LOW', 'exploitCodeMaturity': 'PROOF_OF_CONCEPT', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2020-13434', 'summary': 'NVD - CVE-2020-13434', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2020-13434', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/190.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'The problem is corrected in the following product versions:\n\nB&R Automation Studio 6.5\n\nB&R recommends that customers apply the update at earliest convenience.\n\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Refer to section “General security recommendations” for advice on how to keep your system secure.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2020-11656', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2020-11656', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C', 'temporalScore': 6.7, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 6.7, 'privilegesRequired': 'NONE', 'exploitCodeMaturity': 'PROOF_OF_CONCEPT', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2020-11656', 'summary': 'NVD - CVE-2020-11656', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2020-11656', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/416.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'The problem is corrected in the following product versions:\n\nB&R Automation Studio 6.5\n\nB&R recommends that customers apply the update at earliest convenience.\n\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Refer to section “General security recommendations” for advice on how to keep your system secure.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2020-11655', 'cwe': {'id': 'CWE-754', 'name': 'Improper Check for Unusual or Exceptional Conditions'}, 'notes': [{'text': "SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled.", 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2020-11655', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C', 'temporalScore': 6.7, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 6.7, 'privilegesRequired': 'NONE', 'exploitCodeMaturity': 'PROOF_OF_CONCEPT', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2020-11655', 'summary': 'NVD - CVE-2020-11655', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2020-11655', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/754.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'The problem is corrected in the following product versions:\n\nB&R Automation Studio 6.5\n\nB&R recommends that customers apply the update at earliest convenience.\n\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Refer to section “General security recommendations” for advice on how to keep your system secure.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2019-19646', 'cwe': {'id': 'CWE-754', 'name': 'Improper Check for Unusual or Exceptional Conditions'}, 'notes': [{'text': 'pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2019-19646', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C', 'temporalScore': 8.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.8, 'privilegesRequired': 'NONE', 'exploitCodeMaturity': 'PROOF_OF_CONCEPT', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2019-19646', 'summary': 'NVD - CVE-2019-19646', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2019-19646', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/754.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'The problem is corrected in the following product versions:\n\nB&R Automation Studio 6.5\n\nB&R recommends that customers apply the update at earliest convenience.\n\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Refer to section “General security recommendations” for advice on how to keep your system secure.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2019-19645', 'cwe': {'id': 'CWE-674', 'name': 'Uncontrolled Recursion'}, 'notes': [{'text': 'alter.c in SQLite through 3.30.1 allows attackers to trigger infinite recursion via certain types of self-referential views in conjunction with ALTER TABLE statements.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2019-19645', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.5, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C', 'temporalScore': 5, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 5, 'privilegesRequired': 'LOW', 'exploitCodeMaturity': 'PROOF_OF_CONCEPT', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2019-19645', 'summary': 'NVD - CVE-2019-19645', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2019-19645', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/674.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'The problem is corrected in the following product versions:\n\nB&R Automation Studio 6.5\n\nB&R recommends that customers apply the update at earliest convenience.\n\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Refer to section “General security recommendations” for advice on how to keep your system secure.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2019-8457', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2019-8457', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C', 'temporalScore': 8.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.8, 'privilegesRequired': 'NONE', 'exploitCodeMaturity': 'PROOF_OF_CONCEPT', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2019-8457', 'summary': 'NVD - CVE-2019-8457', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2019-8457', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/125.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'The problem is corrected in the following product versions:\n\nB&R Automation Studio 6.5\n\nB&R recommends that customers apply the update at earliest convenience.\n\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Refer to section “General security recommendations” for advice on how to keep your system secure.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2018-20506', 'cwe': {'id': 'CWE-190', 'name': 'Integer Overflow or Wraparound'}, 'notes': [{'text': 'SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries in a "merge" operation that occurs after crafted changes to FTS3 shadow tables, allow-ing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases). This is a different vulnerability than CVE-2018-20346.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2018-20506', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 8.1, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C', 'temporalScore': 7.3, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.3, 'privilegesRequired': 'NONE', 'exploitCodeMaturity': 'PROOF_OF_CONCEPT', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2018-20506', 'summary': 'NVD - CVE-2018-20506', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2018-20506', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/190.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'The problem is corrected in the following product versions:\n\nB&R Automation Studio 6.5\n\nB&R recommends that customers apply the update at earliest convenience.\n\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Refer to section “General security recommendations” for advice on how to keep your system secure.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2018-20505', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers to cause a denial of service (application crash) by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases).', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2018-20505', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C', 'temporalScore': 6.7, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 6.7, 'privilegesRequired': 'NONE', 'exploitCodeMaturity': 'PROOF_OF_CONCEPT', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2018-20505', 'summary': 'NVD - CVE-2018-20505', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2018-20505', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'The problem is corrected in the following product versions:\n\nB&R Automation Studio 6.5\n\nB&R recommends that customers apply the update at earliest convenience.\n\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Refer to section “General security recommendations” for advice on how to keep your system secure.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2018-20346', 'cwe': {'id': 'CWE-190', 'name': 'Integer Overflow or Wraparound'}, 'notes': [{'text': 'SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases), aka Magellan.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2018-20346', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 8.1, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C', 'temporalScore': 7.3, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7.3, 'privilegesRequired': 'NONE', 'exploitCodeMaturity': 'PROOF_OF_CONCEPT', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2018-20346', 'summary': 'NVD - CVE-2018-20346', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2018-20346', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/190.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'The problem is corrected in the following product versions:\n\nB&R Automation Studio 6.5\n\nB&R recommends that customers apply the update at earliest convenience.\n\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Refer to section “General security recommendations” for advice on how to keep your system secure.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2018-8740', 'cwe': {'id': 'CWE-476', 'name': 'NULL Pointer Dereference'}, 'notes': [{'text': 'In SQLite through 3.22.0, databases whose schema is corrupted using a CREATE TABLE AS statement could cause a NULL pointer dereference, related to build.c and prepare.c.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2018-8740', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C', 'temporalScore': 6.7, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 6.7, 'privilegesRequired': 'NONE', 'exploitCodeMaturity': 'PROOF_OF_CONCEPT', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2018-8740', 'summary': 'NVD - CVE-2018-8740', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2018-8740', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/476.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'The problem is corrected in the following product versions:\n\nB&R Automation Studio 6.5\n\nB&R recommends that customers apply the update at earliest convenience.\n\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Refer to section “General security recommendations” for advice on how to keep your system secure.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2017-10989', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mis-handles undersized RTree blobs in a crafted database, leading to a heap-based buffer over-read or possibly un-specified other impact.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2017-10989', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C', 'temporalScore': 8.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.8, 'privilegesRequired': 'NONE', 'exploitCodeMaturity': 'PROOF_OF_CONCEPT', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2017-10989', 'summary': 'NVD - CVE-2017-10989', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2017-10989', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/125.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'The problem is corrected in the following product versions:\n\nB&R Automation Studio 6.5\n\nB&R recommends that customers apply the update at earliest convenience.\n\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Refer to section “General security recommendations” for advice on how to keep your system secure.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2016-6153', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2016-6153', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 5.9, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C', 'temporalScore': 5.3, 'integrityImpact': 'LOW', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'LOW', 'environmentalScore': 5.3, 'privilegesRequired': 'NONE', 'exploitCodeMaturity': 'PROOF_OF_CONCEPT', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2016-6153', 'summary': 'NVD - CVE-2016-6153', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2016-6153', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'The problem is corrected in the following product versions:\n\nB&R Automation Studio 6.5\n\nB&R recommends that customers apply the update at earliest convenience.\n\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Refer to section “General security recommendations” for advice on how to keep your system secure.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2015-6607', 'cwe': {'id': 'CWE-286', 'name': 'Incorrect User Management'}, 'notes': [{'text': 'SQLite before 3.8.9, as used in Android before 5.1.1 LMY48T, allows attackers to gain privileges via a crafted application, aka internal bug 20099586.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2015-6607', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 3.7, 'attackVector': 'NETWORK', 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C', 'temporalScore': 3.4, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'temporalSeverity': 'LOW', 'availabilityImpact': 'NONE', 'environmentalScore': 3.4, 'privilegesRequired': 'NONE', 'exploitCodeMaturity': 'PROOF_OF_CONCEPT', 'confidentialityImpact': 'LOW', 'environmentalSeverity': 'LOW'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2015-6607', 'summary': 'NVD - CVE-2015-6607', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2015-6607', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/286.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'The problem is corrected in the following product versions:\n\nB&R Automation Studio 6.5\n\nB&R recommends that customers apply the update at earliest convenience.\n\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Refer to section “General security recommendations” for advice on how to keep your system secure.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2015-5895', 'cwe': {'id': 'CWE-200', 'name': 'Exposure of Sensitive Information to an Unauthorized Actor'}, 'notes': [{'text': 'Multiple unspecified vulnerabilities in SQLite before 3.8.10.2, as used in Apple iOS before 9, have unknown im-pact and attack vectors.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2015-5895', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C', 'temporalScore': 8.8, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 8.8, 'privilegesRequired': 'NONE', 'exploitCodeMaturity': 'PROOF_OF_CONCEPT', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2015-5895', 'summary': 'NVD - CVE-2015-5895', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2015-5895', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/200.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'The problem is corrected in the following product versions:\n\nB&R Automation Studio 6.5\n\nB&R recommends that customers apply the update at earliest convenience.\n\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Refer to section “General security recommendations” for advice on how to keep your system secure.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2015-3717', 'cwe': {'id': 'CWE-120', 'name': "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"}, 'notes': [{'text': 'Multiple buffer overflows in the printf functionality in SQLite, as used in Apple iOS before 8.4 and OS X before 10.10.4, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via un-specified vectors.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2015-3717', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C', 'temporalScore': 6.7, 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'temporalSeverity': 'MEDIUM', 'availabilityImpact': 'HIGH', 'environmentalScore': 6.7, 'privilegesRequired': 'NONE', 'exploitCodeMaturity': 'PROOF_OF_CONCEPT', 'confidentialityImpact': 'NONE', 'environmentalSeverity': 'MEDIUM'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2015-3717', 'summary': 'NVD - CVE-2015-3717', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2015-3717', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/120.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'The problem is corrected in the following product versions:\n\nB&R Automation Studio 6.5\n\nB&R recommends that customers apply the update at earliest convenience.\n\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Refer to section “General security recommendations” for advice on how to keep your system secure.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2015-3416', 'cwe': {'id': 'CWE-190', 'name': 'Integer Overflow or Wraparound'}, 'notes': [{'text': 'The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point conversions, which allows context-dependent attackers to cause a denial of service (integer overflow and stack-based buffer overflow) or possibly have unspecified other impact via large integers in a crafted printf function call in a SELECT statement.', 'title': 'CVE description', 'category': 'description'}], 'title': 'CVE-2015-3416', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.0', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C', 'temporalScore': 7, 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'remediationLevel': 'OFFICIAL_FIX', 'reportConfidence': 'CONFIRMED', 'temporalSeverity': 'HIGH', 'availabilityImpact': 'HIGH', 'environmentalScore': 7, 'privilegesRequired': 'LOW', 'exploitCodeMaturity': 'PROOF_OF_CONCEPT', 'confidentialityImpact': 'HIGH', 'environmentalSeverity': 'HIGH'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://nvd.nist.gov/vuln/detail/CVE-2015-3416', 'summary': 'NVD - CVE-2015-3416', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2015-3416', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/190.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'The problem is corrected in the following product versions:\n\nB&R Automation Studio 6.5\n\nB&R recommends that customers apply the update at earliest convenience.\n\nThe process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Refer to section “General security recommendations” for advice on how to keep your system secure.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-134-01 | CVE-2026-40175 | Siemens gWAP | 2026-05-12 03:00:00+03:00 | 2026-05-14 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-01.json | 3b559ba92927ef0880286a94d1974abd5e04ad026e2c1470c2128d1a652a1696 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Siemens gPROMS Web Applications Publisher (gWAP) is affected by a remote code execution vulnerability introduced through a third-party component, namely the Axios HTTP client library. The vulnerability stems from a specific "Gadget" attack chain that allows prototype pollution in other third-party libraries, potentially allowing an attacker to execute arbitrary code.\n\nSiemens has released a new version for gWAP and recommends to update to the latest version.', 'title': 'Summary', 'category': 'summary'}, {'text': "As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals.\nAdditional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity", 'title': 'General Recommendations', 'category': 'general'}, {'text': 'For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.', 'title': 'Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of Siemens ProductCERT SSA-876049 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Germany', 'title': 'Company headquarters location', 'category': 'other'}], 'title': 'Siemens gWAP', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-134-01', 'status': 'final', 'version': '2', 'generator': {'date': '2026-05-13T16:54:14.668169Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2026-05-12T00:00:00.000000Z', 'number': '1', 'summary': 'Publication Date', 'legacy_version': 'Initial'}, {'date': '2026-05-14T06:00:00.000000Z', 'number': '2', 'summary': 'Initial CISA Republication of Siemens ProductCERT SSA-876049 advisory', 'legacy_version': 'CISA Republication'}], 'current_release_date': '2026-05-14T06:00:00.000000Z', 'initial_release_date': '2026-05-12T00:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://cert-portal.siemens.com/productcert/csaf/ssa-876049.json', 'summary': 'SSA-876049: Prototype Pollution Vulnerability in Axios Library Affecting Siemens gWAP Before V3.1.1 - CSAF Version', 'category': 'self'}, {'url': 'https://cert-portal.siemens.com/productcert/html/ssa-876049.html', 'summary': 'SSA-876049: Prototype Pollution Vulnerability in Axios Library Affecting Siemens gWAP Before V3.1.1 - HTML Version', 'category': 'self'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-01.json', 'summary': 'ICS Advisory ICSA-26-134-01 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-01', 'summary': 'ICS Advisory ICSA-26-134-01 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported this vulnerability to CISA.', 'organization': 'Siemens ProductCERT'}]}, 'product_tree': {'branches': [{'name': 'Siemens', 'branches': [{'name': 'gWAP', 'branches': [{'name': 'vers:intdot/<3.1.1', 'product': {'name': 'gWAP', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-40175', 'cwe': {'id': 'CWE-113', 'name': "Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')"}, 'notes': [{'text': 'Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.3.1, the Axios library is vulnerable to a specific "Gadget" attack chain that allows Prototype Pollution in any third-party dependency to be escalated into Remote Code Execution (RCE) or Full Cloud Compromise (via AWS IMDSv2 bypass). This vulnerability is fixed in 1.15.0 and 0.3.1.', 'title': 'Summary', 'category': 'summary'}, {'text': 'An attacker would need privileged access to the application in order to exploit.', 'title': 'For gWAP', 'category': 'summary'}], 'title': 'CVE-2026-40175', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-40175', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/113.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://support.sw.siemens.com/product/284395347/', 'details': 'Update to V3.1.1 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-24-331-03 | CVE-2023-6409 | Schneider Electric EcoStruxure Control Expert, EcoStruxure Process Expert, and Modicon M340, M580 and M580 Safety PLCs | 2024-02-13 15:41:43+03:00 | 2026-05-07 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-331-03.json | 2d33765187c3a3f125f8c3e5275f74615f22e5e2cda4289ea638ffb29a49e0a0 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'We strongly recommend the following industry cybersecurity best practices.\n\n* Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.\n* Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.\n* Place all controllers in locked cabinets and never leave them in the “Program” mode.\n* Never connect programming software to any network other than the network intended for that device.\n* Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.\n* Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.\n* Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.\n* When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.\n\nFor more information refer to the Schneider Electric [Recommended Cybersecurity Best Practices](https://www.se.com/us/en/download/document/7EN52-0390/) document.', 'title': 'General Security Recommendations', 'category': 'general'}, {'text': "This document provides an overview of the identified vulnerability or vulnerabilities and actions required to mitigate. For more details and assistance on how to protect your installation, contact your local Schneider Electric representative or Schneider Electric Industrial Cybersecurity Services: https://www.se.com/ww/en/work/solutions/cybersecurity/. These organizations will be fully aware of this situation and can support you through the process.\n\nFor further information related to cybersecurity in Schneider Electric's products, visit the company's cybersecurity support portal page: https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp", 'title': 'For More Information', 'category': 'general'}, {'text': 'THIS NOTIFICATION DOCUMENT, THE INFORMATION CONTAINED HEREIN, AND ANY MATERIALS LINKED FROM IT (COLLECTIVELY, THIS “NOTIFICATION”) ARE INTENDED TO HELP PROVIDE AN OVERVIEW OF THE IDENTIFIED SITUATION AND SUGGESTED MITIGATION ACTIONS, REMEDIATION, FIX, AND/OR GENERAL SECURITY RECOMMENDATIONS AND IS PROVIDED ON AN “AS-IS” BASIS WITHOUT WARRANTY OR GUARANTEE OF ANY KIND. SCHNEIDER ELECTRIC DISCLAIMS ALL WARRANTIES RELATING TO THIS NOTIFICATION, EITHER EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SCHNEIDER ELECTRIC MAKES NO WARRANTY THAT THE NOTIFICATION WILL RESOLVE THE IDENTIFIED SITUATION. IN NO EVENT SHALL SCHNEIDER ELECTRIC BE LIABLE FOR ANY DAMAGES OR LOSSES WHATSOEVER IN CONNECTION WITH THIS NOTIFICATION, INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF SCHNEIDER ELECTRIC HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. YOUR USE OF THIS NOTIFICATION IS AT YOUR OWN RISK, AND YOU ARE SOLELY LIABLE FOR ANY DAMAGES TO YOUR SYSTEMS OR ASSETS OR OTHER LOSSES THAT MAY RESULT FROM YOUR USE OF THIS NOTIFICATION. SCHNEIDER ELECTRIC RESERVES THE RIGHT TO UPDATE OR CHANGE THIS NOTIFICATION AT ANY TIME AND IN ITS SOLE DISCRETION', 'title': 'LEGAL DISCLAIMER', 'category': 'legal_disclaimer'}, {'text': "Schneider's purpose is to create Impact by empowering all to make the most of our energy and resources, bridging progress and\r\nsustainability for all. We call this Life Is On.\n\nOur mission is to be the trusted partner in Sustainability and Efficiency.\n\nWe are a global industrial technology leader bringing world-leading expertise in electrification, automation and digitization to smart\r\nindustries, resilient infrastructure, future-proof data centers, intelligent buildings, and intuitive homes. Anchored by our deep\r\ndomain expertise, we provide integrated end-to-end lifecycle AI enabled Industrial IoT solutions with connected products, automation,\r\nsoftware and services, delivering digital twins to enable profitable growth for our customers.\n\nWe are a people company with an ecosystem of 150,000 colleagues and more than a million partners operating in over 100 countries\r\nto ensure proximity to our customers and stakeholders. We embrace diversity and inclusion in everything we do, guided by our\r\nmeaningful purpose of a sustainable future for all. \n\n www.se.com", 'title': 'About Schneider Electric', 'category': 'general'}, {'text': 'Schneider Electric is aware of multiple vulnerabilities in its EcoStruxure Control Expert ,\r\nEcoStruxure Process Expert and Modicon M340, M580 PLCs (Programmable Logic\r\nControllers).\r\nModicon PLCs control and monitor industrial operations. EcoStruxure Control Expert is the\r\ncommon programming, debugging and operating software for Modicon PLCs. EcoStruxure\r\nProcess Expert DCS is a single automation system to engineer, operate, and maintain an entire\r\nplant Infrastructure.\r\nFailure to apply the remediations provided below may risk unauthorized access to your PLC,\r\nwhich could result in the possibility of denial of service and loss of confidentiality, integrity of the\r\ncontroller.\r\n\r\nNote regarding vulnerability details: The severity of vulnerabilities was calculated using the\r\nCVSS Base metrics in version 3.1 (CVSS v3.1) without incorporating the Temporal and\r\nEnvironmental metrics. Schneider Electric recommends that customers score the CVSS\r\nEnvironmental metrics, which are specific to end-user organizations, and consider factors such\r\nas the presence of mitigations in that environment. Environmental metrics may refine the\r\nrelative severity posed by the vulnerabilities described in this document within a customer’s \renvironment', 'title': 'Overview', 'category': 'summary'}, {'text': "The severity of vulnerabilities was calculated using the CVSS Base metrics for 4.0 ([CVSS v4.0](https://www.first.org/cvss/calculator/4.0)). CVSS v3.1 \nwill be still evaluated until the adoption of CVSS v4.0 by the industry. The severity was calculated without \nincorporating the Temporal and Environmental metrics. Schneider Electric recommends that customers score the CVSS Environmental metrics, which are specific to end-user organizations, and consider factors such as \nthe presence of mitigations in that environment. Environmental metrics may refine the relative severity posed by the vulnerabilities described in this document within a customer's environment.", 'category': 'other'}, {'text': "Customers should use appropriate patching methodologies when applying these patches to their systems. We strongly recommend the use of back-ups and evaluating the impact of these patches in a Test and Development environment or on an offline infrastructure. Contact Schneider Electric's [Customer Care Center](https://www.se.com/us/en/work/support/contacts.jsp) if you need assistance removing a patch. ", 'category': 'other'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of Schneider Electric CPCERT SEVD-2024-044-01 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Schneider Electric CPCERT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'France', 'title': 'Company headquarters location', 'category': 'other'}], 'title': 'Schneider Electric EcoStruxure Control Expert, EcoStruxure Process Expert, and Modicon M340, M580 and M580 Safety PLCs', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-24-331-03', 'status': 'final', 'version': '5', 'generator': {'date': '2026-05-04T16:22:57.138968Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2024-02-13T12:41:43.000000Z', 'number': '1', 'summary': 'Original Release', 'legacy_version': 'Initial'}, {'date': '2024-07-09T00:00:00.000000Z', 'number': '2', 'summary': 'Modicon MC80 and Momentum M1E PLCs have been identified as impacted by the CVE-2023-6408. Mitigations are now available', 'legacy_version': 'Additional Release 1'}, {'date': '2024-08-13T00:00:00.000000Z', 'number': '3', 'summary': 'A remediation is available for the Modicon M580 CPU Safety (page 3).', 'legacy_version': 'Additional Release 2'}, {'date': '2026-04-14T07:00:00.000000Z', 'number': '4', 'summary': 'Remediation is available for Modicon Momentum controller ', 'legacy_version': 'Additional Release 3'}, {'date': '2026-05-07T06:00:00.000000Z', 'number': '5', 'summary': 'CISA Republication update based on Schneider Electric CPCERT SEVD-2024-044-01 advisory', 'legacy_version': 'Latest Updated CISA Republication'}], 'current_release_date': '2026-05-07T06:00:00.000000Z', 'initial_release_date': '2024-02-13T12:41:43.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-044-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2024-044-01.json', 'summary': 'EcoStruxure Control Expert, EcoStruxure Process Expert and Modicon M340, M580 and M580 Safety PLCs - SEVD-2024-044-01 CSAF Version', 'category': 'self'}, {'url': 'https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-044-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-044-01.pdf', 'summary': 'EcoStruxure Control Expert, EcoStruxure Process Expert and Modicon M340, M580 and M580 Safety PLCs - SEVD-2024-044-01 PDF Version', 'category': 'self'}, {'url': 'https://www.se.com/ww/en/download/document/7EN52-0390/', 'summary': 'Recommended Cybersecurity Best Practices', 'category': 'external'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-331-03.json', 'summary': 'ICS Advisory ICSA-24-331-03 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-24-331-03', 'summary': 'ICS Advisory ICSA-24-331-03 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Gao Jian', 'Jianshuang Ding', 'Kaikai Yang'], 'summary': 'reporting these vulnerabilities to Schneider Electric.'}, {'summary': 'reported these vulnerabilities to CISA.', 'organization': 'Schneider Electric CPCERT'}]}, 'product_tree': {'branches': [{'name': 'Schneider Electric', 'branches': [{'name': 'Modicon M340 CPU (part numbers BMXP34*)', 'branches': [{'name': 'vers:generic/<SV3.60', 'product': {'name': 'Modicon M340 CPU (part numbers BMXP34*) Versions prior to sv3.60', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Modicon M580 CPU (part numbers BMEP* and BMEH* excluding M580 CPU Safety)', 'branches': [{'name': 'vers:generic/<SV4.20', 'product': {'name': 'Modicon M580 CPU (part numbers BMEP* and BMEH* excluding M580 CPU Safety) Versions prior to sv4.20', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Modicon M580 CPU Safety', 'branches': [{'name': 'vers:generic/<SV4.21', 'product': {'name': 'Modicon M580 CPU Safety (part numbers BMEP58*S and BMEH58*S) Versions prior to SV4.21', 'product_id': 'CSAFPID-0003', 'product_identification_helper': {'model_numbers': ['BMEP58*S', 'BMEH58*S']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Modicon M580 CPU Safety', 'branches': [{'name': 'vers:generic/SV4.21', 'product': {'name': 'Modicon M580 CPU Safety (part numbers BMEP58*S and BMEH58*S) Version SV4.21', 'product_id': 'CSAFPID-0004', 'product_identification_helper': {'model_numbers': ['BMEP58*S', 'BMEH58*S']}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'EcoStruxure Control Expert', 'branches': [{'name': 'vers:intdot/<16.0', 'product': {'name': 'EcoStruxure Control Expert Versions prior to v16.0', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'EcoStruxure Process Expert', 'branches': [{'name': 'vers:generic/<2023', 'product': {'name': 'EcoStruxure Process Expert Versions prior to v2023', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Modicon M340 CPU (part numbers BMXP34*)', 'branches': [{'name': 'SV3.60', 'product': {'name': 'Modicon M340 CPU (part numbers BMXP34*) SV3.60', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Modicon M580 CPU (part numbers BMEP* and BMEH*, excluding M580 CPU Safety)', 'branches': [{'name': 'SV4.20', 'product': {'name': 'Modicon M580 CPU (part numbers BMEP* and BMEH*, excluding M580 CPU Safety) SV4.20', 'product_id': 'CSAFPID-0008'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'EcoStruxure Control Expert', 'branches': [{'name': '16.0', 'product': {'name': 'EcoStruxure Control Expert Version 16.0', 'product_id': 'CSAFPID-0009'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'EcoStruxure Process Expert', 'branches': [{'name': '15.3_HF008', 'product': {'name': 'EcoStruxure Process Expert Version 15.3 HF008', 'product_id': 'CSAFPID-0010'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Modicon MC80 (part numbers BMKC80)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Modicon MC80 (part numbers BMKC80) All Versions', 'product_id': 'CSAFPID-0011'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Modicon Momentum Unity M1E Processor Firmware', 'branches': [{'name': 'vers:generic/<SV2.90', 'product': {'name': 'Modicon Momentum Unity M1E Processor Firmware Versions prior to SV2.90', 'product_id': 'CSAFPID-0012'}, 'category': 'product_version_range'}, {'name': 'SV2.90', 'product': {'name': 'Modicon Momentum Unity M1E Processor Firmware Version SV2.90', 'product_id': 'CSAFPID-0013'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Modicon Momentum Unity M1E Processor Controller', 'product': {'name': 'Modicon Momentum Unity M1E Processor Controller', 'product_id': 'CSAFPID-0014', 'product_identification_helper': {'model_numbers': ['171CBU*']}}, 'category': 'product_name'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Modicon Momentum Unity M1E Processor Firmware Versions prior to SV2.90 installed on Modicon Momentum Unity M1E Processor Controller', 'product_id': 'CSAFPID-0015', 'product_identification_helper': {'model_numbers': ['171CBU*']}}, 'product_reference': 'CSAFPID-0012', 'relates_to_product_reference': 'CSAFPID-0014'}, {'category': 'installed_on', 'full_product_name': {'name': 'Modicon Momentum Unity M1E Processor Firmware Version SV2.90 installed on Modicon Momentum Unity M1E Processor Controller', 'product_id': 'CSAFPID-0016', 'product_identification_helper': {'model_numbers': ['171CBU*']}}, 'product_reference': 'CSAFPID-0013', 'relates_to_product_reference': 'CSAFPID-0014'}]}, 'vulnerabilities': [{'cve': 'CVE-2023-6408', 'cwe': {'id': 'CWE-924', 'name': 'Improper Enforcement of Message Integrity During Transmission in a Communication Channel'}, 'notes': [{'text': 'A CWE-924: Improper Enforcement of Message Integrity During Transmission in a\r\nCommunication Channel vulnerability exists that could cause a denial of service and loss of\r\nconfidentiality, integrity of controllers when conducting a Man in the Middle attack.', 'title': 'CVE Description', 'category': 'description'}, {'text': 'CVSS v4.0 Base Score 9.2 | Critical | [CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N](https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)', 'title': 'CVSS v4.0 Score', 'category': 'details'}], 'title': 'CVE-2023-6408', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.1, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0011', 'CSAFPID-0015']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-6408', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/924.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1468-modicon-m340', 'details': 'SV3.60 of Modicon M340 firmware includes a fix for this\r\nvulnerability and is available for download here:\r\nhttps://www.se.com/ww/en/product-range/1468-\r\nmodicon-m340', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/product-range/62098-%20modicon-m580-epac/%20-%20software-and-firmware', 'details': 'SV4.20 of Modicon M580 firmware includes a fix for this\r\nvulnerability and is available for download here:\r\nhttps://www.se.com/ww/en/product-range/62098-\r\nmodicon-m580-epac/ - software-and-firmware', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/in/en/product-range/548-ecostruxure-control-expert-unity-pro/', 'details': 'Version 16.0 of EcoStruxure Control Expert includes a fix\r\nfor these vulnerabilities and is available for download\r\nhere:\r\nhttps://www.se.com/ww/en/product-range/548-\r\necostruxure-control-expert-unity-pro/\r\nReboot the computer after installation is completed', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005'], 'restart_required': {'category': 'system'}}, {'url': 'https://www.se.com/ww/en/product-range/548-ecostruxure-control-expert-unity-pro/', 'details': 'Version 15.3 HF008 of EcoStruxure Control Expert\r\nincludes the fix for these vulnerabilities and are available\r\nfor download here:\r\nhttps://www.se.com/ww/en/product-range/548-\r\necostruxure-control-expert-unity-pro/', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0006'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/product-range/62098-modicon-m580-pac-controller/#software-andfirmware', 'details': 'Firmware SV4.21 includes a fix for this vulnerability and \r\nis available for download here: https://www.se.com/ww/en/product-range/62098-modicon-m580-pac-controller/#software-andfirmware\r\nImportant: customer needs to use version of \r\nEcoStruxure Control Expert v16.0 HF001 minimum to \r\nconnect with the latest version of M580 CPU Safety. The \r\nsoftware is available for download here:\r\nhttps://www.se.com/ww/en/product-range/548-ecostruxure-control-expert-unity-pro/#software-andfirmware', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/31007131K01000/', 'details': 'Setup an application password in the project properties\r\n• Setup network segmentation and implement a firewall to block all\r\nunauthorized access to port 502/TCP\r\n• Configure the Access Control List following the recommendations of the\r\nuser manuals: “Modicon M340 for Ethernet Communications Modules\r\nand Processors User Manual” in chapter “Messaging Configuration\r\nParameters”:\r\nhttps://www.se.com/ww/en/download/document/31007131K01000/\r\n• Setup a secure communication according to the following guideline\r\n“Modicon Controllers Platform Cyber Security Reference Manual,” in\r\nchapter “Setup secured communications”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• Consider use of external firewall devices such as EAGLE40-07 from\r\nBelden to establish VPN connections for M340 & M580 architectures.\r\nFor more details refer to the chapter “How to protect M580 and M340\r\narchitectures with EAGLE40 using VPN”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• Ensure the M340 CPU is running with the memory protection activated\r\nby configuring the input bit to a physical input, for more details refer to\r\nthe following guideline “Modicon Controllers Platform Cyber Security\r\nReference Manual”, “CPU Memory Protection section”:\r\n• https://www.se.com/ww/en/download/document/EIO0000001999/', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/EIO0000001578/', 'details': 'Setup an application password in the project properties\r\n• Setup network segmentation and implement a firewall to block all\r\nunauthorized access to port 502/TCP\r\n• Configure the Access Control List following the recommendations of the\r\nuser manuals: “Modicon M580, Hardware, Reference Manual”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001578/\r\nSetup a secure communication according to the following guideline\r\n“Modicon Controllers Platform Cyber Security Reference Manual,” in\r\nchapter “Setup secured communications”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• use a BMENOC module and follow the instructions to configure\r\nIPSEC feature as described in the guideline “Modicon M580 -\r\nBMENOC03.1 Ethernet Communications Schneider Electric\r\nSecurity Notification Module, Installation and Configuration\r\nGuide” in the chapter “Configuring IPSEC communications”:\r\nhttps://www.se.com/ww/en/download/document/HRB62665/\r\nOR\r\n• Use a BMENUA0100 module and follow the instructions to configure\r\nIPSEC feature as described in the chapter “Configuring the\r\nBMENUA0100 Cybersecurity Settings”:\r\nhttps://www.se.com/ww/en/download/document/PHA83350\r\nOR\r\n• Consider use of external firewall devices such as EAGLE40-07 from\r\nBelden to establish VPN connections for M340 & M580 architectures.\r\nFor more details refer to the chapter “How to protect M580 and M340\r\narchitectures with EAGLE40 using VPN”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• Ensure the M580 CPU is running with the memory protection activated\r\nby configuring the input bit to a physical input, for more details refer to\r\nthe following guideline “Modicon Controllers Platform Cyber Security\r\nReference Manual”, “CPU Memory Protection section”:\r\nhttps://www.schneiderelectric.com/en/download/document/EIO0000001999/\r\nNOTE: The CPU memory protection cannot be configured with M580 Hot\r\nStandby CPUs. In such cases, use IPsec encrypted communication.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/EIO0000001578/', 'details': 'If customers choose not to apply the remediation then they are encouraged to immediately apply the following mitigations to reduce the risk of exploit:\r\n• Setup an application password in the project properties\r\n• Setup network segmentation and implement a firewall to block all\r\nunauthorized access to port 502/TCP\r\n• Configure the Access Control List following the recommendations of the\r\nuser manuals: “Modicon M580, Hardware, Reference Manual”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001578/\r\n• Setup a secure communication according to the following guideline\r\n“Modicon Controllers Platform Cyber Security Reference Manual,” in\r\nchapter “Setup secured communications”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• use a BMENOC module and follow the instructions to configure\r\nIPSEC feature as described in the guideline “Modicon M580 -\r\nBMENOC03.1 Ethernet Communications Schneider Electric\r\nSecurity Notification Module, Installation and Configuration Guide” in the chapter “Configuring IPSEC communications”:\r\nhttps://www.se.com/ww/en/download/document/HRB62665/\r\nOR\r\n• Use a BMENUA0100 module and follow the instructions to configure\r\nIPSEC feature as described in the chapter “Configuring the\r\nBMENUA0100 Cybersecurity Settings”:\r\nhttps://www.se.com/ww/en/download/document/PHA83350\r\nOR\r\n• Consider use of external firewall devices such as EAGLE40-07 from\r\nBelden to establish VPN connections for M340 & M580 architectures.\r\nFor more details refer to the chapter “How to protect M580 and M340\r\narchitectures with EAGLE40 using VPN”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• Ensure the M580 CPU is running with the memory protection activated\r\nby configuring the input bit to a physical input, for more details refer to\r\nthe following guideline “Modicon Controllers Platform Cyber Security\r\nReference Manual”, “CPU Memory Protection section”:\r\nhttps://www.schneiderelectric.com/en/download/document/EIO0000001999/\r\nNOTE: The CPU memory protection cannot be configured with M580\r\nHot Standby CPUs. In such cases, use IPsec encrypted\r\ncommunication.\r\n• To further reduce the attack surface on Modicon M580 CPU\r\nSafety:\r\nEnsure the CPU is running in Safety mode and maintenance input is\r\nconfigured to maintain this Safety mode during operation – refer to\r\nthe document Modicon M580 - Safety System Planning Guide - in\r\nthe chapter “Operating Mode Transitions”:\r\nhttps://www.se.com/ww/en/download/document/QGH60283/ ', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/EIO0000004778/', 'details': 'Enable encryption on application project and store application files in\r\nsecure location with restricted access only for legitimate users.\r\n• Schneider Electric recommends using McAfee Application and Change\r\nControl software for application control. Refer to the Cybersecurity\r\nApplication Note available here.\r\n• Follow workstation, network and site-hardening guidelines in the\r\nRecommended Cybersecurity Best Practices available for download\r\nhere.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/EIO0000004778/', 'details': 'EcoStruxure Process Expert manages application files within its\r\ndatabase in secure way. Do not export & store them outside the\r\napplication.\r\n• Schneider Electric recommends using McAfee Application and Change\r\nControl software for application control. Refer to the Cybersecurity\r\nApplication Note available here.\r\n• Follow workstation, network and site-hardening guidelines in the\r\nRecommended Cybersecurity Best Practices available for download\r\nhere.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/EIO0000001999/', 'details': 'Setup an application password in the project properties• Setup network segmentation and implement a firewall to block all unauthorized access to port 502/TCP• Configure the Access Control List following the recommendations of the user manuals:• “Modicon MC80 Programmable Logic Controller (PLC) manual” in the chapter “Access Control List (ACL)”:https://www.se.com/ww/en/download/document/EIO0000002071/Setup a secure communication according to the following guideline “Modicon Controller Systems Cybersecurity, User Guide” in chapter “Set Up Encrypted Communication”:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0011'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/EIO0000001999/', 'details': 'Setup an application password in the project properties• Setup network segmentation and implement a firewall to block all unauthorized access to port 502/TCP• Setup a secure communication according to the following guideline “Modicon Controller Systems Cybersecurity, User Guide” in chapter “Set Up Encrypted Communication”:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0015']}, {'url': 'https://www.se.com/ww/en/product-range/535-modicon-momentum/', 'details': 'Firmware SV2.90 includes a fix for this vulnerability and is \navailable for download here: \n \nhttps://www.se.com/ww/en/product-range/535-modicon-momentum/ \n \nImportant: customer needs to use version of EcoStruxure \nControl Expert v16.2 HF003 minimum to connect with the latest \nversion of Modicon Momentum. The software is available for \ndownload here: \n \nhttps://www.se.com/ww/en/product-range/548-ecostruxure\ncontrol-expert-unity-pro/#software-and-firmware', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0015'], 'restart_required': {'category': 'system'}}], 'product_status': {'fixed': ['CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0004', 'CSAFPID-0016'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0011', 'CSAFPID-0015']}, 'acknowledgments': [{'names': ['Gao Jian']}]}, {'cve': 'CVE-2023-6409', 'cwe': {'id': 'CWE-798', 'name': 'Use of Hard-coded Credentials'}, 'notes': [{'text': 'A CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized\r\naccess to a project file protected with application password when opening the file with\r\nEcoStruxure Control Expert.', 'title': 'CVE Description', 'category': 'description'}, {'text': 'CVSS v4.0 Base Score 8.5 | High | [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N](https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N)', 'title': 'CVSS v4.0 Score', 'category': 'details'}], 'title': 'CVE-2023-6409', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.7, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0005', 'CSAFPID-0006']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-6409', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/798.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1468-modicon-m340', 'details': 'SV3.60 of Modicon M340 firmware includes a fix for this\r\nvulnerability and is available for download here:\r\nhttps://www.se.com/ww/en/product-range/1468-\r\nmodicon-m340', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/product-range/62098-%20modicon-m580-epac/%20-%20software-and-firmware', 'details': 'SV4.20 of Modicon M580 firmware includes a fix for this\r\nvulnerability and is available for download here:\r\nhttps://www.se.com/ww/en/product-range/62098-\r\nmodicon-m580-epac/ - software-and-firmware', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/in/en/product-range/548-ecostruxure-control-expert-unity-pro/', 'details': 'Version 16.0 of EcoStruxure Control Expert includes a fix\r\nfor these vulnerabilities and is available for download\r\nhere:\r\nhttps://www.se.com/ww/en/product-range/548-\r\necostruxure-control-expert-unity-pro/\r\nReboot the computer after installation is completed', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005'], 'restart_required': {'category': 'system'}}, {'url': 'https://www.se.com/ww/en/product-range/548-ecostruxure-control-expert-unity-pro/', 'details': 'Version 15.3 HF008 of EcoStruxure Control Expert\r\nincludes the fix for these vulnerabilities and are available\r\nfor download here:\r\nhttps://www.se.com/ww/en/product-range/548-\r\necostruxure-control-expert-unity-pro/', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0006'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/31007131K01000/', 'details': 'Setup an application password in the project properties\r\n• Setup network segmentation and implement a firewall to block all\r\nunauthorized access to port 502/TCP\r\n• Configure the Access Control List following the recommendations of the\r\nuser manuals: “Modicon M340 for Ethernet Communications Modules\r\nand Processors User Manual” in chapter “Messaging Configuration\r\nParameters”:\r\nhttps://www.se.com/ww/en/download/document/31007131K01000/\r\n• Setup a secure communication according to the following guideline\r\n“Modicon Controllers Platform Cyber Security Reference Manual,” in\r\nchapter “Setup secured communications”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• Consider use of external firewall devices such as EAGLE40-07 from\r\nBelden to establish VPN connections for M340 & M580 architectures.\r\nFor more details refer to the chapter “How to protect M580 and M340\r\narchitectures with EAGLE40 using VPN”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• Ensure the M340 CPU is running with the memory protection activated\r\nby configuring the input bit to a physical input, for more details refer to\r\nthe following guideline “Modicon Controllers Platform Cyber Security\r\nReference Manual”, “CPU Memory Protection section”:\r\n• https://www.se.com/ww/en/download/document/EIO0000001999/', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/EIO0000001578/', 'details': 'Setup an application password in the project properties\r\n• Setup network segmentation and implement a firewall to block all\r\nunauthorized access to port 502/TCP\r\n• Configure the Access Control List following the recommendations of the\r\nuser manuals: “Modicon M580, Hardware, Reference Manual”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001578/\r\nSetup a secure communication according to the following guideline\r\n“Modicon Controllers Platform Cyber Security Reference Manual,” in\r\nchapter “Setup secured communications”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• use a BMENOC module and follow the instructions to configure\r\nIPSEC feature as described in the guideline “Modicon M580 -\r\nBMENOC03.1 Ethernet Communications Schneider Electric\r\nSecurity Notification Module, Installation and Configuration\r\nGuide” in the chapter “Configuring IPSEC communications”:\r\nhttps://www.se.com/ww/en/download/document/HRB62665/\r\nOR\r\n• Use a BMENUA0100 module and follow the instructions to configure\r\nIPSEC feature as described in the chapter “Configuring the\r\nBMENUA0100 Cybersecurity Settings”:\r\nhttps://www.se.com/ww/en/download/document/PHA83350\r\nOR\r\n• Consider use of external firewall devices such as EAGLE40-07 from\r\nBelden to establish VPN connections for M340 & M580 architectures.\r\nFor more details refer to the chapter “How to protect M580 and M340\r\narchitectures with EAGLE40 using VPN”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• Ensure the M580 CPU is running with the memory protection activated\r\nby configuring the input bit to a physical input, for more details refer to\r\nthe following guideline “Modicon Controllers Platform Cyber Security\r\nReference Manual”, “CPU Memory Protection section”:\r\nhttps://www.schneiderelectric.com/en/download/document/EIO0000001999/\r\nNOTE: The CPU memory protection cannot be configured with M580 Hot\r\nStandby CPUs. In such cases, use IPsec encrypted communication.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/EIO0000001578/', 'details': 'Schneider Electric is establishing a remediation plan for all future versions\r\nof EcoStruxure Process Expert that will include a fix for this vulnerability.\r\nWe will update this document when the remediation is available. Until then,\r\ncustomers should immediately apply the following mitigations to reduce the\r\nrisk of exploit:\r\n• Setup an application password in the project properties\r\n• Setup network segmentation and implement a firewall to block all\r\nunauthorized access to port 502/TCP\r\n• Configure the Access Control List following the recommendations of the\r\nuser manuals: “Modicon M580, Hardware, Reference Manual”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001578/\r\n• Setup a secure communication according to the following guideline\r\n“Modicon Controllers Platform Cyber Security Reference Manual,” in\r\nchapter “Setup secured communications”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• use a BMENOC module and follow the instructions to configure\r\nIPSEC feature as described in the guideline “Modicon M580 -\r\nBMENOC03.1 Ethernet Communications Schneider Electric\r\nSecurity Notification Module, Installation and Configuration Guide” in the chapter “Configuring IPSEC communications”:\r\nhttps://www.se.com/ww/en/download/document/HRB62665/\r\nOR\r\n• Use a BMENUA0100 module and follow the instructions to configure\r\nIPSEC feature as described in the chapter “Configuring the\r\nBMENUA0100 Cybersecurity Settings”:\r\nhttps://www.se.com/ww/en/download/document/PHA83350\r\nOR\r\n• Consider use of external firewall devices such as EAGLE40-07 from\r\nBelden to establish VPN connections for M340 & M580 architectures.\r\nFor more details refer to the chapter “How to protect M580 and M340\r\narchitectures with EAGLE40 using VPN”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• Ensure the M580 CPU is running with the memory protection activated\r\nby configuring the input bit to a physical input, for more details refer to\r\nthe following guideline “Modicon Controllers Platform Cyber Security\r\nReference Manual”, “CPU Memory Protection section”:\r\nhttps://www.schneiderelectric.com/en/download/document/EIO0000001999/\r\nNOTE: The CPU memory protection cannot be configured with M580\r\nHot Standby CPUs. In such cases, use IPsec encrypted\r\ncommunication.\r\n• To further reduce the attack surface on Modicon M580 CPU\r\nSafety:\r\nEnsure the CPU is running in Safety mode and maintenance input is\r\nconfigured to maintain this Safety mode during operation – refer to\r\nthe document Modicon M580 - Safety System Planning Guide - in\r\nthe chapter “Operating Mode Transitions”:\r\nhttps://www.se.com/ww/en/download/document/QGH60283/ ', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/EIO0000004778/', 'details': 'Enable encryption on application project and store application files in\r\nsecure location with restricted access only for legitimate users.\r\n• Schneider Electric recommends using McAfee Application and Change\r\nControl software for application control. Refer to the Cybersecurity\r\nApplication Note available here.\r\n• Follow workstation, network and site-hardening guidelines in the\r\nRecommended Cybersecurity Best Practices available for download\r\nhere.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/EIO0000004778/', 'details': 'EcoStruxure Process Expert manages application files within its\r\ndatabase in secure way. Do not export & store them outside the\r\napplication.\r\n• Schneider Electric recommends using McAfee Application and Change\r\nControl software for application control. Refer to the Cybersecurity\r\nApplication Note available here.\r\n• Follow workstation, network and site-hardening guidelines in the\r\nRecommended Cybersecurity Best Practices available for download\r\nhere.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006'], 'restart_required': {'category': 'none'}}], 'product_status': {'fixed': ['CSAFPID-0009', 'CSAFPID-0010'], 'known_affected': ['CSAFPID-0005', 'CSAFPID-0006']}, 'acknowledgments': [{'names': ['Jianshuang Ding']}]}, {'cve': 'CVE-2023-27975', 'cwe': {'id': 'CWE-522', 'name': 'Insufficiently Protected Credentials'}, 'notes': [{'text': 'A CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause\r\nunauthorized access to the project file in EcoStruxure Control Expert when a local user\r\ntampers with the memory of the engineering workstation.', 'title': 'CVE Description', 'category': 'description'}, {'text': 'CVSS v4.0 Base Score 7.2 | High | [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N](https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N)', 'title': 'CVSS v4.0 Score', 'category': 'details'}], 'title': 'CVE-2023-27975', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.1, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0005', 'CSAFPID-0006']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-27975', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/522.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1468-modicon-m340', 'details': 'SV3.60 of Modicon M340 firmware includes a fix for this\r\nvulnerability and is available for download here:\r\nhttps://www.se.com/ww/en/product-range/1468-\r\nmodicon-m340', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/product-range/62098-%20modicon-m580-epac/%20-%20software-and-firmware', 'details': 'SV4.20 of Modicon M580 firmware includes a fix for this\r\nvulnerability and is available for download here:\r\nhttps://www.se.com/ww/en/product-range/62098-\r\nmodicon-m580-epac/ - software-and-firmware', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/in/en/product-range/548-ecostruxure-control-expert-unity-pro/', 'details': 'Version 16.0 of EcoStruxure Control Expert includes a fix\r\nfor these vulnerabilities and is available for download\r\nhere:\r\nhttps://www.se.com/ww/en/product-range/548-\r\necostruxure-control-expert-unity-pro/\r\nReboot the computer after installation is completed', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005'], 'restart_required': {'category': 'system'}}, {'url': 'https://www.se.com/ww/en/product-range/548-ecostruxure-control-expert-unity-pro/', 'details': 'Version 15.3 HF008 of EcoStruxure Control Expert\r\nincludes the fix for these vulnerabilities and are available\r\nfor download here:\r\nhttps://www.se.com/ww/en/product-range/548-\r\necostruxure-control-expert-unity-pro/', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0006'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/31007131K01000/', 'details': 'Setup an application password in the project properties\r\n• Setup network segmentation and implement a firewall to block all\r\nunauthorized access to port 502/TCP\r\n• Configure the Access Control List following the recommendations of the\r\nuser manuals: “Modicon M340 for Ethernet Communications Modules\r\nand Processors User Manual” in chapter “Messaging Configuration\r\nParameters”:\r\nhttps://www.se.com/ww/en/download/document/31007131K01000/\r\n• Setup a secure communication according to the following guideline\r\n“Modicon Controllers Platform Cyber Security Reference Manual,” in\r\nchapter “Setup secured communications”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• Consider use of external firewall devices such as EAGLE40-07 from\r\nBelden to establish VPN connections for M340 & M580 architectures.\r\nFor more details refer to the chapter “How to protect M580 and M340\r\narchitectures with EAGLE40 using VPN”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• Ensure the M340 CPU is running with the memory protection activated\r\nby configuring the input bit to a physical input, for more details refer to\r\nthe following guideline “Modicon Controllers Platform Cyber Security\r\nReference Manual”, “CPU Memory Protection section”:\r\n• https://www.se.com/ww/en/download/document/EIO0000001999/', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/EIO0000001578/', 'details': 'Setup an application password in the project properties\r\n• Setup network segmentation and implement a firewall to block all\r\nunauthorized access to port 502/TCP\r\n• Configure the Access Control List following the recommendations of the\r\nuser manuals: “Modicon M580, Hardware, Reference Manual”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001578/\r\nSetup a secure communication according to the following guideline\r\n“Modicon Controllers Platform Cyber Security Reference Manual,” in\r\nchapter “Setup secured communications”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• use a BMENOC module and follow the instructions to configure\r\nIPSEC feature as described in the guideline “Modicon M580 -\r\nBMENOC03.1 Ethernet Communications Schneider Electric\r\nSecurity Notification Module, Installation and Configuration\r\nGuide” in the chapter “Configuring IPSEC communications”:\r\nhttps://www.se.com/ww/en/download/document/HRB62665/\r\nOR\r\n• Use a BMENUA0100 module and follow the instructions to configure\r\nIPSEC feature as described in the chapter “Configuring the\r\nBMENUA0100 Cybersecurity Settings”:\r\nhttps://www.se.com/ww/en/download/document/PHA83350\r\nOR\r\n• Consider use of external firewall devices such as EAGLE40-07 from\r\nBelden to establish VPN connections for M340 & M580 architectures.\r\nFor more details refer to the chapter “How to protect M580 and M340\r\narchitectures with EAGLE40 using VPN”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• Ensure the M580 CPU is running with the memory protection activated\r\nby configuring the input bit to a physical input, for more details refer to\r\nthe following guideline “Modicon Controllers Platform Cyber Security\r\nReference Manual”, “CPU Memory Protection section”:\r\nhttps://www.schneiderelectric.com/en/download/document/EIO0000001999/\r\nNOTE: The CPU memory protection cannot be configured with M580 Hot\r\nStandby CPUs. In such cases, use IPsec encrypted communication.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/EIO0000001578/', 'details': 'Schneider Electric is establishing a remediation plan for all future versions\r\nof EcoStruxure Process Expert that will include a fix for this vulnerability.\r\nWe will update this document when the remediation is available. Until then,\r\ncustomers should immediately apply the following mitigations to reduce the\r\nrisk of exploit:\r\n• Setup an application password in the project properties\r\n• Setup network segmentation and implement a firewall to block all\r\nunauthorized access to port 502/TCP\r\n• Configure the Access Control List following the recommendations of the\r\nuser manuals: “Modicon M580, Hardware, Reference Manual”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001578/\r\n• Setup a secure communication according to the following guideline\r\n“Modicon Controllers Platform Cyber Security Reference Manual,” in\r\nchapter “Setup secured communications”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• use a BMENOC module and follow the instructions to configure\r\nIPSEC feature as described in the guideline “Modicon M580 -\r\nBMENOC03.1 Ethernet Communications Schneider Electric\r\nSecurity Notification Module, Installation and Configuration Guide” in the chapter “Configuring IPSEC communications”:\r\nhttps://www.se.com/ww/en/download/document/HRB62665/\r\nOR\r\n• Use a BMENUA0100 module and follow the instructions to configure\r\nIPSEC feature as described in the chapter “Configuring the\r\nBMENUA0100 Cybersecurity Settings”:\r\nhttps://www.se.com/ww/en/download/document/PHA83350\r\nOR\r\n• Consider use of external firewall devices such as EAGLE40-07 from\r\nBelden to establish VPN connections for M340 & M580 architectures.\r\nFor more details refer to the chapter “How to protect M580 and M340\r\narchitectures with EAGLE40 using VPN”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• Ensure the M580 CPU is running with the memory protection activated\r\nby configuring the input bit to a physical input, for more details refer to\r\nthe following guideline “Modicon Controllers Platform Cyber Security\r\nReference Manual”, “CPU Memory Protection section”:\r\nhttps://www.schneiderelectric.com/en/download/document/EIO0000001999/\r\nNOTE: The CPU memory protection cannot be configured with M580\r\nHot Standby CPUs. In such cases, use IPsec encrypted\r\ncommunication.\r\n• To further reduce the attack surface on Modicon M580 CPU\r\nSafety:\r\nEnsure the CPU is running in Safety mode and maintenance input is\r\nconfigured to maintain this Safety mode during operation – refer to\r\nthe document Modicon M580 - Safety System Planning Guide - in\r\nthe chapter “Operating Mode Transitions”:\r\nhttps://www.se.com/ww/en/download/document/QGH60283/ ', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/EIO0000004778/', 'details': 'Enable encryption on application project and store application files in\r\nsecure location with restricted access only for legitimate users.\r\n• Schneider Electric recommends using McAfee Application and Change\r\nControl software for application control. Refer to the Cybersecurity\r\nApplication Note available here.\r\n• Follow workstation, network and site-hardening guidelines in the\r\nRecommended Cybersecurity Best Practices available for download\r\nhere.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/EIO0000004778/', 'details': 'EcoStruxure Process Expert manages application files within its\r\ndatabase in secure way. Do not export & store them outside the\r\napplication.\r\n• Schneider Electric recommends using McAfee Application and Change\r\nControl software for application control. Refer to the Cybersecurity\r\nApplication Note available here.\r\n• Follow workstation, network and site-hardening guidelines in the\r\nRecommended Cybersecurity Best Practices available for download\r\nhere.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006'], 'restart_required': {'category': 'none'}}], 'product_status': {'fixed': ['CSAFPID-0009', 'CSAFPID-0010'], 'known_affected': ['CSAFPID-0005', 'CSAFPID-0006']}, 'acknowledgments': [{'names': ['Kaikai Yang']}]}]} | |
ot | ICSA-24-331-03 | CVE-2023-27975 | Schneider Electric EcoStruxure Control Expert, EcoStruxure Process Expert, and Modicon M340, M580 and M580 Safety PLCs | 2024-02-13 15:41:43+03:00 | 2026-05-07 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-331-03.json | 9c4a79d52eb0306c546803d2f7313d9b98e98b47d316846b96cb74fc71624a23 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'We strongly recommend the following industry cybersecurity best practices.\n\n* Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.\n* Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.\n* Place all controllers in locked cabinets and never leave them in the “Program” mode.\n* Never connect programming software to any network other than the network intended for that device.\n* Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.\n* Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.\n* Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.\n* When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.\n\nFor more information refer to the Schneider Electric [Recommended Cybersecurity Best Practices](https://www.se.com/us/en/download/document/7EN52-0390/) document.', 'title': 'General Security Recommendations', 'category': 'general'}, {'text': "This document provides an overview of the identified vulnerability or vulnerabilities and actions required to mitigate. For more details and assistance on how to protect your installation, contact your local Schneider Electric representative or Schneider Electric Industrial Cybersecurity Services: https://www.se.com/ww/en/work/solutions/cybersecurity/. These organizations will be fully aware of this situation and can support you through the process.\n\nFor further information related to cybersecurity in Schneider Electric's products, visit the company's cybersecurity support portal page: https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp", 'title': 'For More Information', 'category': 'general'}, {'text': 'THIS NOTIFICATION DOCUMENT, THE INFORMATION CONTAINED HEREIN, AND ANY MATERIALS LINKED FROM IT (COLLECTIVELY, THIS “NOTIFICATION”) ARE INTENDED TO HELP PROVIDE AN OVERVIEW OF THE IDENTIFIED SITUATION AND SUGGESTED MITIGATION ACTIONS, REMEDIATION, FIX, AND/OR GENERAL SECURITY RECOMMENDATIONS AND IS PROVIDED ON AN “AS-IS” BASIS WITHOUT WARRANTY OR GUARANTEE OF ANY KIND. SCHNEIDER ELECTRIC DISCLAIMS ALL WARRANTIES RELATING TO THIS NOTIFICATION, EITHER EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SCHNEIDER ELECTRIC MAKES NO WARRANTY THAT THE NOTIFICATION WILL RESOLVE THE IDENTIFIED SITUATION. IN NO EVENT SHALL SCHNEIDER ELECTRIC BE LIABLE FOR ANY DAMAGES OR LOSSES WHATSOEVER IN CONNECTION WITH THIS NOTIFICATION, INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF SCHNEIDER ELECTRIC HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. YOUR USE OF THIS NOTIFICATION IS AT YOUR OWN RISK, AND YOU ARE SOLELY LIABLE FOR ANY DAMAGES TO YOUR SYSTEMS OR ASSETS OR OTHER LOSSES THAT MAY RESULT FROM YOUR USE OF THIS NOTIFICATION. SCHNEIDER ELECTRIC RESERVES THE RIGHT TO UPDATE OR CHANGE THIS NOTIFICATION AT ANY TIME AND IN ITS SOLE DISCRETION', 'title': 'LEGAL DISCLAIMER', 'category': 'legal_disclaimer'}, {'text': "Schneider's purpose is to create Impact by empowering all to make the most of our energy and resources, bridging progress and\r\nsustainability for all. We call this Life Is On.\n\nOur mission is to be the trusted partner in Sustainability and Efficiency.\n\nWe are a global industrial technology leader bringing world-leading expertise in electrification, automation and digitization to smart\r\nindustries, resilient infrastructure, future-proof data centers, intelligent buildings, and intuitive homes. Anchored by our deep\r\ndomain expertise, we provide integrated end-to-end lifecycle AI enabled Industrial IoT solutions with connected products, automation,\r\nsoftware and services, delivering digital twins to enable profitable growth for our customers.\n\nWe are a people company with an ecosystem of 150,000 colleagues and more than a million partners operating in over 100 countries\r\nto ensure proximity to our customers and stakeholders. We embrace diversity and inclusion in everything we do, guided by our\r\nmeaningful purpose of a sustainable future for all. \n\n www.se.com", 'title': 'About Schneider Electric', 'category': 'general'}, {'text': 'Schneider Electric is aware of multiple vulnerabilities in its EcoStruxure Control Expert ,\r\nEcoStruxure Process Expert and Modicon M340, M580 PLCs (Programmable Logic\r\nControllers).\r\nModicon PLCs control and monitor industrial operations. EcoStruxure Control Expert is the\r\ncommon programming, debugging and operating software for Modicon PLCs. EcoStruxure\r\nProcess Expert DCS is a single automation system to engineer, operate, and maintain an entire\r\nplant Infrastructure.\r\nFailure to apply the remediations provided below may risk unauthorized access to your PLC,\r\nwhich could result in the possibility of denial of service and loss of confidentiality, integrity of the\r\ncontroller.\r\n\r\nNote regarding vulnerability details: The severity of vulnerabilities was calculated using the\r\nCVSS Base metrics in version 3.1 (CVSS v3.1) without incorporating the Temporal and\r\nEnvironmental metrics. Schneider Electric recommends that customers score the CVSS\r\nEnvironmental metrics, which are specific to end-user organizations, and consider factors such\r\nas the presence of mitigations in that environment. Environmental metrics may refine the\r\nrelative severity posed by the vulnerabilities described in this document within a customer’s \renvironment', 'title': 'Overview', 'category': 'summary'}, {'text': "The severity of vulnerabilities was calculated using the CVSS Base metrics for 4.0 ([CVSS v4.0](https://www.first.org/cvss/calculator/4.0)). CVSS v3.1 \nwill be still evaluated until the adoption of CVSS v4.0 by the industry. The severity was calculated without \nincorporating the Temporal and Environmental metrics. Schneider Electric recommends that customers score the CVSS Environmental metrics, which are specific to end-user organizations, and consider factors such as \nthe presence of mitigations in that environment. Environmental metrics may refine the relative severity posed by the vulnerabilities described in this document within a customer's environment.", 'category': 'other'}, {'text': "Customers should use appropriate patching methodologies when applying these patches to their systems. We strongly recommend the use of back-ups and evaluating the impact of these patches in a Test and Development environment or on an offline infrastructure. Contact Schneider Electric's [Customer Care Center](https://www.se.com/us/en/work/support/contacts.jsp) if you need assistance removing a patch. ", 'category': 'other'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of Schneider Electric CPCERT SEVD-2024-044-01 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Schneider Electric CPCERT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'France', 'title': 'Company headquarters location', 'category': 'other'}], 'title': 'Schneider Electric EcoStruxure Control Expert, EcoStruxure Process Expert, and Modicon M340, M580 and M580 Safety PLCs', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-24-331-03', 'status': 'final', 'version': '5', 'generator': {'date': '2026-05-04T16:22:57.138968Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2024-02-13T12:41:43.000000Z', 'number': '1', 'summary': 'Original Release', 'legacy_version': 'Initial'}, {'date': '2024-07-09T00:00:00.000000Z', 'number': '2', 'summary': 'Modicon MC80 and Momentum M1E PLCs have been identified as impacted by the CVE-2023-6408. Mitigations are now available', 'legacy_version': 'Additional Release 1'}, {'date': '2024-08-13T00:00:00.000000Z', 'number': '3', 'summary': 'A remediation is available for the Modicon M580 CPU Safety (page 3).', 'legacy_version': 'Additional Release 2'}, {'date': '2026-04-14T07:00:00.000000Z', 'number': '4', 'summary': 'Remediation is available for Modicon Momentum controller ', 'legacy_version': 'Additional Release 3'}, {'date': '2026-05-07T06:00:00.000000Z', 'number': '5', 'summary': 'CISA Republication update based on Schneider Electric CPCERT SEVD-2024-044-01 advisory', 'legacy_version': 'Latest Updated CISA Republication'}], 'current_release_date': '2026-05-07T06:00:00.000000Z', 'initial_release_date': '2024-02-13T12:41:43.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-044-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2024-044-01.json', 'summary': 'EcoStruxure Control Expert, EcoStruxure Process Expert and Modicon M340, M580 and M580 Safety PLCs - SEVD-2024-044-01 CSAF Version', 'category': 'self'}, {'url': 'https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-044-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-044-01.pdf', 'summary': 'EcoStruxure Control Expert, EcoStruxure Process Expert and Modicon M340, M580 and M580 Safety PLCs - SEVD-2024-044-01 PDF Version', 'category': 'self'}, {'url': 'https://www.se.com/ww/en/download/document/7EN52-0390/', 'summary': 'Recommended Cybersecurity Best Practices', 'category': 'external'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-331-03.json', 'summary': 'ICS Advisory ICSA-24-331-03 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-24-331-03', 'summary': 'ICS Advisory ICSA-24-331-03 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Gao Jian', 'Jianshuang Ding', 'Kaikai Yang'], 'summary': 'reporting these vulnerabilities to Schneider Electric.'}, {'summary': 'reported these vulnerabilities to CISA.', 'organization': 'Schneider Electric CPCERT'}]}, 'product_tree': {'branches': [{'name': 'Schneider Electric', 'branches': [{'name': 'Modicon M340 CPU (part numbers BMXP34*)', 'branches': [{'name': 'vers:generic/<SV3.60', 'product': {'name': 'Modicon M340 CPU (part numbers BMXP34*) Versions prior to sv3.60', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Modicon M580 CPU (part numbers BMEP* and BMEH* excluding M580 CPU Safety)', 'branches': [{'name': 'vers:generic/<SV4.20', 'product': {'name': 'Modicon M580 CPU (part numbers BMEP* and BMEH* excluding M580 CPU Safety) Versions prior to sv4.20', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Modicon M580 CPU Safety', 'branches': [{'name': 'vers:generic/<SV4.21', 'product': {'name': 'Modicon M580 CPU Safety (part numbers BMEP58*S and BMEH58*S) Versions prior to SV4.21', 'product_id': 'CSAFPID-0003', 'product_identification_helper': {'model_numbers': ['BMEP58*S', 'BMEH58*S']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Modicon M580 CPU Safety', 'branches': [{'name': 'vers:generic/SV4.21', 'product': {'name': 'Modicon M580 CPU Safety (part numbers BMEP58*S and BMEH58*S) Version SV4.21', 'product_id': 'CSAFPID-0004', 'product_identification_helper': {'model_numbers': ['BMEP58*S', 'BMEH58*S']}}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'EcoStruxure Control Expert', 'branches': [{'name': 'vers:intdot/<16.0', 'product': {'name': 'EcoStruxure Control Expert Versions prior to v16.0', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'EcoStruxure Process Expert', 'branches': [{'name': 'vers:generic/<2023', 'product': {'name': 'EcoStruxure Process Expert Versions prior to v2023', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Modicon M340 CPU (part numbers BMXP34*)', 'branches': [{'name': 'SV3.60', 'product': {'name': 'Modicon M340 CPU (part numbers BMXP34*) SV3.60', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Modicon M580 CPU (part numbers BMEP* and BMEH*, excluding M580 CPU Safety)', 'branches': [{'name': 'SV4.20', 'product': {'name': 'Modicon M580 CPU (part numbers BMEP* and BMEH*, excluding M580 CPU Safety) SV4.20', 'product_id': 'CSAFPID-0008'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'EcoStruxure Control Expert', 'branches': [{'name': '16.0', 'product': {'name': 'EcoStruxure Control Expert Version 16.0', 'product_id': 'CSAFPID-0009'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'EcoStruxure Process Expert', 'branches': [{'name': '15.3_HF008', 'product': {'name': 'EcoStruxure Process Expert Version 15.3 HF008', 'product_id': 'CSAFPID-0010'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Modicon MC80 (part numbers BMKC80)', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Modicon MC80 (part numbers BMKC80) All Versions', 'product_id': 'CSAFPID-0011'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Modicon Momentum Unity M1E Processor Firmware', 'branches': [{'name': 'vers:generic/<SV2.90', 'product': {'name': 'Modicon Momentum Unity M1E Processor Firmware Versions prior to SV2.90', 'product_id': 'CSAFPID-0012'}, 'category': 'product_version_range'}, {'name': 'SV2.90', 'product': {'name': 'Modicon Momentum Unity M1E Processor Firmware Version SV2.90', 'product_id': 'CSAFPID-0013'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Modicon Momentum Unity M1E Processor Controller', 'product': {'name': 'Modicon Momentum Unity M1E Processor Controller', 'product_id': 'CSAFPID-0014', 'product_identification_helper': {'model_numbers': ['171CBU*']}}, 'category': 'product_name'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Modicon Momentum Unity M1E Processor Firmware Versions prior to SV2.90 installed on Modicon Momentum Unity M1E Processor Controller', 'product_id': 'CSAFPID-0015', 'product_identification_helper': {'model_numbers': ['171CBU*']}}, 'product_reference': 'CSAFPID-0012', 'relates_to_product_reference': 'CSAFPID-0014'}, {'category': 'installed_on', 'full_product_name': {'name': 'Modicon Momentum Unity M1E Processor Firmware Version SV2.90 installed on Modicon Momentum Unity M1E Processor Controller', 'product_id': 'CSAFPID-0016', 'product_identification_helper': {'model_numbers': ['171CBU*']}}, 'product_reference': 'CSAFPID-0013', 'relates_to_product_reference': 'CSAFPID-0014'}]}, 'vulnerabilities': [{'cve': 'CVE-2023-6408', 'cwe': {'id': 'CWE-924', 'name': 'Improper Enforcement of Message Integrity During Transmission in a Communication Channel'}, 'notes': [{'text': 'A CWE-924: Improper Enforcement of Message Integrity During Transmission in a\r\nCommunication Channel vulnerability exists that could cause a denial of service and loss of\r\nconfidentiality, integrity of controllers when conducting a Man in the Middle attack.', 'title': 'CVE Description', 'category': 'description'}, {'text': 'CVSS v4.0 Base Score 9.2 | Critical | [CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N](https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)', 'title': 'CVSS v4.0 Score', 'category': 'details'}], 'title': 'CVE-2023-6408', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.1, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'HIGH', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0011', 'CSAFPID-0015']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-6408', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/924.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1468-modicon-m340', 'details': 'SV3.60 of Modicon M340 firmware includes a fix for this\r\nvulnerability and is available for download here:\r\nhttps://www.se.com/ww/en/product-range/1468-\r\nmodicon-m340', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/product-range/62098-%20modicon-m580-epac/%20-%20software-and-firmware', 'details': 'SV4.20 of Modicon M580 firmware includes a fix for this\r\nvulnerability and is available for download here:\r\nhttps://www.se.com/ww/en/product-range/62098-\r\nmodicon-m580-epac/ - software-and-firmware', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/in/en/product-range/548-ecostruxure-control-expert-unity-pro/', 'details': 'Version 16.0 of EcoStruxure Control Expert includes a fix\r\nfor these vulnerabilities and is available for download\r\nhere:\r\nhttps://www.se.com/ww/en/product-range/548-\r\necostruxure-control-expert-unity-pro/\r\nReboot the computer after installation is completed', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005'], 'restart_required': {'category': 'system'}}, {'url': 'https://www.se.com/ww/en/product-range/548-ecostruxure-control-expert-unity-pro/', 'details': 'Version 15.3 HF008 of EcoStruxure Control Expert\r\nincludes the fix for these vulnerabilities and are available\r\nfor download here:\r\nhttps://www.se.com/ww/en/product-range/548-\r\necostruxure-control-expert-unity-pro/', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0006'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/product-range/62098-modicon-m580-pac-controller/#software-andfirmware', 'details': 'Firmware SV4.21 includes a fix for this vulnerability and \r\nis available for download here: https://www.se.com/ww/en/product-range/62098-modicon-m580-pac-controller/#software-andfirmware\r\nImportant: customer needs to use version of \r\nEcoStruxure Control Expert v16.0 HF001 minimum to \r\nconnect with the latest version of M580 CPU Safety. The \r\nsoftware is available for download here:\r\nhttps://www.se.com/ww/en/product-range/548-ecostruxure-control-expert-unity-pro/#software-andfirmware', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/31007131K01000/', 'details': 'Setup an application password in the project properties\r\n• Setup network segmentation and implement a firewall to block all\r\nunauthorized access to port 502/TCP\r\n• Configure the Access Control List following the recommendations of the\r\nuser manuals: “Modicon M340 for Ethernet Communications Modules\r\nand Processors User Manual” in chapter “Messaging Configuration\r\nParameters”:\r\nhttps://www.se.com/ww/en/download/document/31007131K01000/\r\n• Setup a secure communication according to the following guideline\r\n“Modicon Controllers Platform Cyber Security Reference Manual,” in\r\nchapter “Setup secured communications”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• Consider use of external firewall devices such as EAGLE40-07 from\r\nBelden to establish VPN connections for M340 & M580 architectures.\r\nFor more details refer to the chapter “How to protect M580 and M340\r\narchitectures with EAGLE40 using VPN”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• Ensure the M340 CPU is running with the memory protection activated\r\nby configuring the input bit to a physical input, for more details refer to\r\nthe following guideline “Modicon Controllers Platform Cyber Security\r\nReference Manual”, “CPU Memory Protection section”:\r\n• https://www.se.com/ww/en/download/document/EIO0000001999/', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/EIO0000001578/', 'details': 'Setup an application password in the project properties\r\n• Setup network segmentation and implement a firewall to block all\r\nunauthorized access to port 502/TCP\r\n• Configure the Access Control List following the recommendations of the\r\nuser manuals: “Modicon M580, Hardware, Reference Manual”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001578/\r\nSetup a secure communication according to the following guideline\r\n“Modicon Controllers Platform Cyber Security Reference Manual,” in\r\nchapter “Setup secured communications”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• use a BMENOC module and follow the instructions to configure\r\nIPSEC feature as described in the guideline “Modicon M580 -\r\nBMENOC03.1 Ethernet Communications Schneider Electric\r\nSecurity Notification Module, Installation and Configuration\r\nGuide” in the chapter “Configuring IPSEC communications”:\r\nhttps://www.se.com/ww/en/download/document/HRB62665/\r\nOR\r\n• Use a BMENUA0100 module and follow the instructions to configure\r\nIPSEC feature as described in the chapter “Configuring the\r\nBMENUA0100 Cybersecurity Settings”:\r\nhttps://www.se.com/ww/en/download/document/PHA83350\r\nOR\r\n• Consider use of external firewall devices such as EAGLE40-07 from\r\nBelden to establish VPN connections for M340 & M580 architectures.\r\nFor more details refer to the chapter “How to protect M580 and M340\r\narchitectures with EAGLE40 using VPN”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• Ensure the M580 CPU is running with the memory protection activated\r\nby configuring the input bit to a physical input, for more details refer to\r\nthe following guideline “Modicon Controllers Platform Cyber Security\r\nReference Manual”, “CPU Memory Protection section”:\r\nhttps://www.schneiderelectric.com/en/download/document/EIO0000001999/\r\nNOTE: The CPU memory protection cannot be configured with M580 Hot\r\nStandby CPUs. In such cases, use IPsec encrypted communication.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/EIO0000001578/', 'details': 'If customers choose not to apply the remediation then they are encouraged to immediately apply the following mitigations to reduce the risk of exploit:\r\n• Setup an application password in the project properties\r\n• Setup network segmentation and implement a firewall to block all\r\nunauthorized access to port 502/TCP\r\n• Configure the Access Control List following the recommendations of the\r\nuser manuals: “Modicon M580, Hardware, Reference Manual”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001578/\r\n• Setup a secure communication according to the following guideline\r\n“Modicon Controllers Platform Cyber Security Reference Manual,” in\r\nchapter “Setup secured communications”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• use a BMENOC module and follow the instructions to configure\r\nIPSEC feature as described in the guideline “Modicon M580 -\r\nBMENOC03.1 Ethernet Communications Schneider Electric\r\nSecurity Notification Module, Installation and Configuration Guide” in the chapter “Configuring IPSEC communications”:\r\nhttps://www.se.com/ww/en/download/document/HRB62665/\r\nOR\r\n• Use a BMENUA0100 module and follow the instructions to configure\r\nIPSEC feature as described in the chapter “Configuring the\r\nBMENUA0100 Cybersecurity Settings”:\r\nhttps://www.se.com/ww/en/download/document/PHA83350\r\nOR\r\n• Consider use of external firewall devices such as EAGLE40-07 from\r\nBelden to establish VPN connections for M340 & M580 architectures.\r\nFor more details refer to the chapter “How to protect M580 and M340\r\narchitectures with EAGLE40 using VPN”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• Ensure the M580 CPU is running with the memory protection activated\r\nby configuring the input bit to a physical input, for more details refer to\r\nthe following guideline “Modicon Controllers Platform Cyber Security\r\nReference Manual”, “CPU Memory Protection section”:\r\nhttps://www.schneiderelectric.com/en/download/document/EIO0000001999/\r\nNOTE: The CPU memory protection cannot be configured with M580\r\nHot Standby CPUs. In such cases, use IPsec encrypted\r\ncommunication.\r\n• To further reduce the attack surface on Modicon M580 CPU\r\nSafety:\r\nEnsure the CPU is running in Safety mode and maintenance input is\r\nconfigured to maintain this Safety mode during operation – refer to\r\nthe document Modicon M580 - Safety System Planning Guide - in\r\nthe chapter “Operating Mode Transitions”:\r\nhttps://www.se.com/ww/en/download/document/QGH60283/ ', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/EIO0000004778/', 'details': 'Enable encryption on application project and store application files in\r\nsecure location with restricted access only for legitimate users.\r\n• Schneider Electric recommends using McAfee Application and Change\r\nControl software for application control. Refer to the Cybersecurity\r\nApplication Note available here.\r\n• Follow workstation, network and site-hardening guidelines in the\r\nRecommended Cybersecurity Best Practices available for download\r\nhere.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/EIO0000004778/', 'details': 'EcoStruxure Process Expert manages application files within its\r\ndatabase in secure way. Do not export & store them outside the\r\napplication.\r\n• Schneider Electric recommends using McAfee Application and Change\r\nControl software for application control. Refer to the Cybersecurity\r\nApplication Note available here.\r\n• Follow workstation, network and site-hardening guidelines in the\r\nRecommended Cybersecurity Best Practices available for download\r\nhere.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/EIO0000001999/', 'details': 'Setup an application password in the project properties• Setup network segmentation and implement a firewall to block all unauthorized access to port 502/TCP• Configure the Access Control List following the recommendations of the user manuals:• “Modicon MC80 Programmable Logic Controller (PLC) manual” in the chapter “Access Control List (ACL)”:https://www.se.com/ww/en/download/document/EIO0000002071/Setup a secure communication according to the following guideline “Modicon Controller Systems Cybersecurity, User Guide” in chapter “Set Up Encrypted Communication”:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0011'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/EIO0000001999/', 'details': 'Setup an application password in the project properties• Setup network segmentation and implement a firewall to block all unauthorized access to port 502/TCP• Setup a secure communication according to the following guideline “Modicon Controller Systems Cybersecurity, User Guide” in chapter “Set Up Encrypted Communication”:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0015']}, {'url': 'https://www.se.com/ww/en/product-range/535-modicon-momentum/', 'details': 'Firmware SV2.90 includes a fix for this vulnerability and is \navailable for download here: \n \nhttps://www.se.com/ww/en/product-range/535-modicon-momentum/ \n \nImportant: customer needs to use version of EcoStruxure \nControl Expert v16.2 HF003 minimum to connect with the latest \nversion of Modicon Momentum. The software is available for \ndownload here: \n \nhttps://www.se.com/ww/en/product-range/548-ecostruxure\ncontrol-expert-unity-pro/#software-and-firmware', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0015'], 'restart_required': {'category': 'system'}}], 'product_status': {'fixed': ['CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0004', 'CSAFPID-0016'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0011', 'CSAFPID-0015']}, 'acknowledgments': [{'names': ['Gao Jian']}]}, {'cve': 'CVE-2023-6409', 'cwe': {'id': 'CWE-798', 'name': 'Use of Hard-coded Credentials'}, 'notes': [{'text': 'A CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized\r\naccess to a project file protected with application password when opening the file with\r\nEcoStruxure Control Expert.', 'title': 'CVE Description', 'category': 'description'}, {'text': 'CVSS v4.0 Base Score 8.5 | High | [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N](https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N)', 'title': 'CVSS v4.0 Score', 'category': 'details'}], 'title': 'CVE-2023-6409', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.7, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0005', 'CSAFPID-0006']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-6409', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/798.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1468-modicon-m340', 'details': 'SV3.60 of Modicon M340 firmware includes a fix for this\r\nvulnerability and is available for download here:\r\nhttps://www.se.com/ww/en/product-range/1468-\r\nmodicon-m340', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/product-range/62098-%20modicon-m580-epac/%20-%20software-and-firmware', 'details': 'SV4.20 of Modicon M580 firmware includes a fix for this\r\nvulnerability and is available for download here:\r\nhttps://www.se.com/ww/en/product-range/62098-\r\nmodicon-m580-epac/ - software-and-firmware', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/in/en/product-range/548-ecostruxure-control-expert-unity-pro/', 'details': 'Version 16.0 of EcoStruxure Control Expert includes a fix\r\nfor these vulnerabilities and is available for download\r\nhere:\r\nhttps://www.se.com/ww/en/product-range/548-\r\necostruxure-control-expert-unity-pro/\r\nReboot the computer after installation is completed', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005'], 'restart_required': {'category': 'system'}}, {'url': 'https://www.se.com/ww/en/product-range/548-ecostruxure-control-expert-unity-pro/', 'details': 'Version 15.3 HF008 of EcoStruxure Control Expert\r\nincludes the fix for these vulnerabilities and are available\r\nfor download here:\r\nhttps://www.se.com/ww/en/product-range/548-\r\necostruxure-control-expert-unity-pro/', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0006'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/31007131K01000/', 'details': 'Setup an application password in the project properties\r\n• Setup network segmentation and implement a firewall to block all\r\nunauthorized access to port 502/TCP\r\n• Configure the Access Control List following the recommendations of the\r\nuser manuals: “Modicon M340 for Ethernet Communications Modules\r\nand Processors User Manual” in chapter “Messaging Configuration\r\nParameters”:\r\nhttps://www.se.com/ww/en/download/document/31007131K01000/\r\n• Setup a secure communication according to the following guideline\r\n“Modicon Controllers Platform Cyber Security Reference Manual,” in\r\nchapter “Setup secured communications”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• Consider use of external firewall devices such as EAGLE40-07 from\r\nBelden to establish VPN connections for M340 & M580 architectures.\r\nFor more details refer to the chapter “How to protect M580 and M340\r\narchitectures with EAGLE40 using VPN”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• Ensure the M340 CPU is running with the memory protection activated\r\nby configuring the input bit to a physical input, for more details refer to\r\nthe following guideline “Modicon Controllers Platform Cyber Security\r\nReference Manual”, “CPU Memory Protection section”:\r\n• https://www.se.com/ww/en/download/document/EIO0000001999/', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/EIO0000001578/', 'details': 'Setup an application password in the project properties\r\n• Setup network segmentation and implement a firewall to block all\r\nunauthorized access to port 502/TCP\r\n• Configure the Access Control List following the recommendations of the\r\nuser manuals: “Modicon M580, Hardware, Reference Manual”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001578/\r\nSetup a secure communication according to the following guideline\r\n“Modicon Controllers Platform Cyber Security Reference Manual,” in\r\nchapter “Setup secured communications”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• use a BMENOC module and follow the instructions to configure\r\nIPSEC feature as described in the guideline “Modicon M580 -\r\nBMENOC03.1 Ethernet Communications Schneider Electric\r\nSecurity Notification Module, Installation and Configuration\r\nGuide” in the chapter “Configuring IPSEC communications”:\r\nhttps://www.se.com/ww/en/download/document/HRB62665/\r\nOR\r\n• Use a BMENUA0100 module and follow the instructions to configure\r\nIPSEC feature as described in the chapter “Configuring the\r\nBMENUA0100 Cybersecurity Settings”:\r\nhttps://www.se.com/ww/en/download/document/PHA83350\r\nOR\r\n• Consider use of external firewall devices such as EAGLE40-07 from\r\nBelden to establish VPN connections for M340 & M580 architectures.\r\nFor more details refer to the chapter “How to protect M580 and M340\r\narchitectures with EAGLE40 using VPN”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• Ensure the M580 CPU is running with the memory protection activated\r\nby configuring the input bit to a physical input, for more details refer to\r\nthe following guideline “Modicon Controllers Platform Cyber Security\r\nReference Manual”, “CPU Memory Protection section”:\r\nhttps://www.schneiderelectric.com/en/download/document/EIO0000001999/\r\nNOTE: The CPU memory protection cannot be configured with M580 Hot\r\nStandby CPUs. In such cases, use IPsec encrypted communication.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/EIO0000001578/', 'details': 'Schneider Electric is establishing a remediation plan for all future versions\r\nof EcoStruxure Process Expert that will include a fix for this vulnerability.\r\nWe will update this document when the remediation is available. Until then,\r\ncustomers should immediately apply the following mitigations to reduce the\r\nrisk of exploit:\r\n• Setup an application password in the project properties\r\n• Setup network segmentation and implement a firewall to block all\r\nunauthorized access to port 502/TCP\r\n• Configure the Access Control List following the recommendations of the\r\nuser manuals: “Modicon M580, Hardware, Reference Manual”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001578/\r\n• Setup a secure communication according to the following guideline\r\n“Modicon Controllers Platform Cyber Security Reference Manual,” in\r\nchapter “Setup secured communications”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• use a BMENOC module and follow the instructions to configure\r\nIPSEC feature as described in the guideline “Modicon M580 -\r\nBMENOC03.1 Ethernet Communications Schneider Electric\r\nSecurity Notification Module, Installation and Configuration Guide” in the chapter “Configuring IPSEC communications”:\r\nhttps://www.se.com/ww/en/download/document/HRB62665/\r\nOR\r\n• Use a BMENUA0100 module and follow the instructions to configure\r\nIPSEC feature as described in the chapter “Configuring the\r\nBMENUA0100 Cybersecurity Settings”:\r\nhttps://www.se.com/ww/en/download/document/PHA83350\r\nOR\r\n• Consider use of external firewall devices such as EAGLE40-07 from\r\nBelden to establish VPN connections for M340 & M580 architectures.\r\nFor more details refer to the chapter “How to protect M580 and M340\r\narchitectures with EAGLE40 using VPN”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• Ensure the M580 CPU is running with the memory protection activated\r\nby configuring the input bit to a physical input, for more details refer to\r\nthe following guideline “Modicon Controllers Platform Cyber Security\r\nReference Manual”, “CPU Memory Protection section”:\r\nhttps://www.schneiderelectric.com/en/download/document/EIO0000001999/\r\nNOTE: The CPU memory protection cannot be configured with M580\r\nHot Standby CPUs. In such cases, use IPsec encrypted\r\ncommunication.\r\n• To further reduce the attack surface on Modicon M580 CPU\r\nSafety:\r\nEnsure the CPU is running in Safety mode and maintenance input is\r\nconfigured to maintain this Safety mode during operation – refer to\r\nthe document Modicon M580 - Safety System Planning Guide - in\r\nthe chapter “Operating Mode Transitions”:\r\nhttps://www.se.com/ww/en/download/document/QGH60283/ ', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/EIO0000004778/', 'details': 'Enable encryption on application project and store application files in\r\nsecure location with restricted access only for legitimate users.\r\n• Schneider Electric recommends using McAfee Application and Change\r\nControl software for application control. Refer to the Cybersecurity\r\nApplication Note available here.\r\n• Follow workstation, network and site-hardening guidelines in the\r\nRecommended Cybersecurity Best Practices available for download\r\nhere.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/EIO0000004778/', 'details': 'EcoStruxure Process Expert manages application files within its\r\ndatabase in secure way. Do not export & store them outside the\r\napplication.\r\n• Schneider Electric recommends using McAfee Application and Change\r\nControl software for application control. Refer to the Cybersecurity\r\nApplication Note available here.\r\n• Follow workstation, network and site-hardening guidelines in the\r\nRecommended Cybersecurity Best Practices available for download\r\nhere.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006'], 'restart_required': {'category': 'none'}}], 'product_status': {'fixed': ['CSAFPID-0009', 'CSAFPID-0010'], 'known_affected': ['CSAFPID-0005', 'CSAFPID-0006']}, 'acknowledgments': [{'names': ['Jianshuang Ding']}]}, {'cve': 'CVE-2023-27975', 'cwe': {'id': 'CWE-522', 'name': 'Insufficiently Protected Credentials'}, 'notes': [{'text': 'A CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause\r\nunauthorized access to the project file in EcoStruxure Control Expert when a local user\r\ntampers with the memory of the engineering workstation.', 'title': 'CVE Description', 'category': 'description'}, {'text': 'CVSS v4.0 Base Score 7.2 | High | [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N](https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N)', 'title': 'CVSS v4.0 Score', 'category': 'details'}], 'title': 'CVE-2023-27975', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.1, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0005', 'CSAFPID-0006']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-27975', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/522.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1468-modicon-m340', 'details': 'SV3.60 of Modicon M340 firmware includes a fix for this\r\nvulnerability and is available for download here:\r\nhttps://www.se.com/ww/en/product-range/1468-\r\nmodicon-m340', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/product-range/62098-%20modicon-m580-epac/%20-%20software-and-firmware', 'details': 'SV4.20 of Modicon M580 firmware includes a fix for this\r\nvulnerability and is available for download here:\r\nhttps://www.se.com/ww/en/product-range/62098-\r\nmodicon-m580-epac/ - software-and-firmware', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/in/en/product-range/548-ecostruxure-control-expert-unity-pro/', 'details': 'Version 16.0 of EcoStruxure Control Expert includes a fix\r\nfor these vulnerabilities and is available for download\r\nhere:\r\nhttps://www.se.com/ww/en/product-range/548-\r\necostruxure-control-expert-unity-pro/\r\nReboot the computer after installation is completed', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005'], 'restart_required': {'category': 'system'}}, {'url': 'https://www.se.com/ww/en/product-range/548-ecostruxure-control-expert-unity-pro/', 'details': 'Version 15.3 HF008 of EcoStruxure Control Expert\r\nincludes the fix for these vulnerabilities and are available\r\nfor download here:\r\nhttps://www.se.com/ww/en/product-range/548-\r\necostruxure-control-expert-unity-pro/', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0006'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/31007131K01000/', 'details': 'Setup an application password in the project properties\r\n• Setup network segmentation and implement a firewall to block all\r\nunauthorized access to port 502/TCP\r\n• Configure the Access Control List following the recommendations of the\r\nuser manuals: “Modicon M340 for Ethernet Communications Modules\r\nand Processors User Manual” in chapter “Messaging Configuration\r\nParameters”:\r\nhttps://www.se.com/ww/en/download/document/31007131K01000/\r\n• Setup a secure communication according to the following guideline\r\n“Modicon Controllers Platform Cyber Security Reference Manual,” in\r\nchapter “Setup secured communications”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• Consider use of external firewall devices such as EAGLE40-07 from\r\nBelden to establish VPN connections for M340 & M580 architectures.\r\nFor more details refer to the chapter “How to protect M580 and M340\r\narchitectures with EAGLE40 using VPN”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• Ensure the M340 CPU is running with the memory protection activated\r\nby configuring the input bit to a physical input, for more details refer to\r\nthe following guideline “Modicon Controllers Platform Cyber Security\r\nReference Manual”, “CPU Memory Protection section”:\r\n• https://www.se.com/ww/en/download/document/EIO0000001999/', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/EIO0000001578/', 'details': 'Setup an application password in the project properties\r\n• Setup network segmentation and implement a firewall to block all\r\nunauthorized access to port 502/TCP\r\n• Configure the Access Control List following the recommendations of the\r\nuser manuals: “Modicon M580, Hardware, Reference Manual”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001578/\r\nSetup a secure communication according to the following guideline\r\n“Modicon Controllers Platform Cyber Security Reference Manual,” in\r\nchapter “Setup secured communications”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• use a BMENOC module and follow the instructions to configure\r\nIPSEC feature as described in the guideline “Modicon M580 -\r\nBMENOC03.1 Ethernet Communications Schneider Electric\r\nSecurity Notification Module, Installation and Configuration\r\nGuide” in the chapter “Configuring IPSEC communications”:\r\nhttps://www.se.com/ww/en/download/document/HRB62665/\r\nOR\r\n• Use a BMENUA0100 module and follow the instructions to configure\r\nIPSEC feature as described in the chapter “Configuring the\r\nBMENUA0100 Cybersecurity Settings”:\r\nhttps://www.se.com/ww/en/download/document/PHA83350\r\nOR\r\n• Consider use of external firewall devices such as EAGLE40-07 from\r\nBelden to establish VPN connections for M340 & M580 architectures.\r\nFor more details refer to the chapter “How to protect M580 and M340\r\narchitectures with EAGLE40 using VPN”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• Ensure the M580 CPU is running with the memory protection activated\r\nby configuring the input bit to a physical input, for more details refer to\r\nthe following guideline “Modicon Controllers Platform Cyber Security\r\nReference Manual”, “CPU Memory Protection section”:\r\nhttps://www.schneiderelectric.com/en/download/document/EIO0000001999/\r\nNOTE: The CPU memory protection cannot be configured with M580 Hot\r\nStandby CPUs. In such cases, use IPsec encrypted communication.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/EIO0000001578/', 'details': 'Schneider Electric is establishing a remediation plan for all future versions\r\nof EcoStruxure Process Expert that will include a fix for this vulnerability.\r\nWe will update this document when the remediation is available. Until then,\r\ncustomers should immediately apply the following mitigations to reduce the\r\nrisk of exploit:\r\n• Setup an application password in the project properties\r\n• Setup network segmentation and implement a firewall to block all\r\nunauthorized access to port 502/TCP\r\n• Configure the Access Control List following the recommendations of the\r\nuser manuals: “Modicon M580, Hardware, Reference Manual”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001578/\r\n• Setup a secure communication according to the following guideline\r\n“Modicon Controllers Platform Cyber Security Reference Manual,” in\r\nchapter “Setup secured communications”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• use a BMENOC module and follow the instructions to configure\r\nIPSEC feature as described in the guideline “Modicon M580 -\r\nBMENOC03.1 Ethernet Communications Schneider Electric\r\nSecurity Notification Module, Installation and Configuration Guide” in the chapter “Configuring IPSEC communications”:\r\nhttps://www.se.com/ww/en/download/document/HRB62665/\r\nOR\r\n• Use a BMENUA0100 module and follow the instructions to configure\r\nIPSEC feature as described in the chapter “Configuring the\r\nBMENUA0100 Cybersecurity Settings”:\r\nhttps://www.se.com/ww/en/download/document/PHA83350\r\nOR\r\n• Consider use of external firewall devices such as EAGLE40-07 from\r\nBelden to establish VPN connections for M340 & M580 architectures.\r\nFor more details refer to the chapter “How to protect M580 and M340\r\narchitectures with EAGLE40 using VPN”:\r\nhttps://www.se.com/ww/en/download/document/EIO0000001999/\r\n• Ensure the M580 CPU is running with the memory protection activated\r\nby configuring the input bit to a physical input, for more details refer to\r\nthe following guideline “Modicon Controllers Platform Cyber Security\r\nReference Manual”, “CPU Memory Protection section”:\r\nhttps://www.schneiderelectric.com/en/download/document/EIO0000001999/\r\nNOTE: The CPU memory protection cannot be configured with M580\r\nHot Standby CPUs. In such cases, use IPsec encrypted\r\ncommunication.\r\n• To further reduce the attack surface on Modicon M580 CPU\r\nSafety:\r\nEnsure the CPU is running in Safety mode and maintenance input is\r\nconfigured to maintain this Safety mode during operation – refer to\r\nthe document Modicon M580 - Safety System Planning Guide - in\r\nthe chapter “Operating Mode Transitions”:\r\nhttps://www.se.com/ww/en/download/document/QGH60283/ ', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/EIO0000004778/', 'details': 'Enable encryption on application project and store application files in\r\nsecure location with restricted access only for legitimate users.\r\n• Schneider Electric recommends using McAfee Application and Change\r\nControl software for application control. Refer to the Cybersecurity\r\nApplication Note available here.\r\n• Follow workstation, network and site-hardening guidelines in the\r\nRecommended Cybersecurity Best Practices available for download\r\nhere.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/EIO0000004778/', 'details': 'EcoStruxure Process Expert manages application files within its\r\ndatabase in secure way. Do not export & store them outside the\r\napplication.\r\n• Schneider Electric recommends using McAfee Application and Change\r\nControl software for application control. Refer to the Cybersecurity\r\nApplication Note available here.\r\n• Follow workstation, network and site-hardening guidelines in the\r\nRecommended Cybersecurity Best Practices available for download\r\nhere.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0006'], 'restart_required': {'category': 'none'}}], 'product_status': {'fixed': ['CSAFPID-0009', 'CSAFPID-0010'], 'known_affected': ['CSAFPID-0005', 'CSAFPID-0006']}, 'acknowledgments': [{'names': ['Kaikai Yang']}]}]} | |
ot | ICSA-21-075-02 | CVE-2013-2566 | GE UR Family (Update A) | 2021-03-16 09:00:00+03:00 | 2026-04-16 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2021/icsa-21-075-02.json | d3f7218ff6a92dd0d176cdcf51483d3b7535be084cdd889b06730720c690b78f | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could allow an attacker to access sensitive information, reboot the UR, gain privileged access, or cause a denial-of-service condition.', 'title': 'Risk evaluation', 'category': 'summary'}, {'text': 'Communications, Critical Manufacturing, Energy, Healthcare and Public Health, Transportation Systems, Water and Wastewater Systems', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'GE UR Family (Update A)', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-21-075-02', 'status': 'final', 'version': '2', 'generator': {'date': '2026-04-15T16:42:03.600539Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2021-03-16T06:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}, {'date': '2026-04-16T06:00:00.000000Z', 'number': '2', 'summary': 'Update A - revised advisory content into modern format.', 'legacy_version': 'Update A'}], 'current_release_date': '2026-04-16T06:00:00.000000Z', 'initial_release_date': '2021-03-16T06:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2021/icsa-21-075-02.json', 'summary': 'ICS Advisory ICSA-21-075-02 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-21-075-02', 'summary': 'ICSA Advisory ICSA-21-075-02 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to GE', 'organization': 'SCADA-X'}, {'summary': 'reported these vulnerabilities to GE', 'organization': "DOE's Cyber Testing for Resilient Industrial Control Systems (CyTRICS) program"}, {'summary': 'reported these vulnerabilities to GE', 'organization': 'Verve Industrial'}, {'summary': 'reported these vulnerabilities to GE', 'organization': 'VuMetric'}]}, 'product_tree': {'branches': [{'name': 'GE Veronva', 'branches': [{'name': 'UR B30', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR B30: <8.10', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR B90', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR B90: <8.10', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR C30', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR C30: <8.10', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR C60', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR C60: <8.10', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR C70', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR C70: <8.10', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR C95', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR C95: <8.10', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR D30', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR D30: <8.10', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR D60', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR D60: <8.10', 'product_id': 'CSAFPID-0008'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR F35', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR F35: <8.10', 'product_id': 'CSAFPID-0009'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR F60', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR F60: <8.10', 'product_id': 'CSAFPID-0010'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR G30', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR G30: <8.10', 'product_id': 'CSAFPID-0011'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR G60', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR G60: <8.10', 'product_id': 'CSAFPID-0012'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR L30', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR L30: <8.10', 'product_id': 'CSAFPID-0013'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR L60', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR L60: <8.10', 'product_id': 'CSAFPID-0014'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR L90', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR L90: <8.10', 'product_id': 'CSAFPID-0015'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR M60', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR M60: <8.10', 'product_id': 'CSAFPID-0016'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR N60', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR N60: <8.10', 'product_id': 'CSAFPID-0017'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR T35', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR T35: <8.10', 'product_id': 'CSAFPID-0018'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR T60', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR T60: <8.10', 'product_id': 'CSAFPID-0019'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2016-2183', 'cwe': {'id': 'CWE-326', 'name': 'Inadequate Encryption Strength'}, 'notes': [{'text': 'Prior to UR firmware Version 8.1x, UR supported various encryption and MAC algorithms for SSH communication, some of which are weak. The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-04-15T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/326.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2016-2183', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.gegridsolutions.com/Passport/Login.aspx', 'details': 'GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10 or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 at https://www.gegridsolutions.com/Passport/Login.aspx (login required).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}}, {'cve': 'CVE-2013-2566', 'cwe': {'id': 'CWE-326', 'name': 'Inadequate Encryption Strength'}, 'notes': [{'text': 'Prior to UR firmware Version 8.1x, UR supported various encryption and MAC algorithms for SSH communication, some of which are weak. The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-04-15T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/326.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2013-2566', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.gegridsolutions.com/Passport/Login.aspx', 'details': 'GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10 or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 at https://www.gegridsolutions.com/Passport/Login.aspx (login required).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}}, {'cve': 'CVE-1999-1085', 'cwe': {'id': 'CWE-384', 'name': 'Session Fixation'}, 'notes': [{'text': 'Prior to firmware Version 7.4x, UR supported only SSHv2. Starting from firmware Version 7.4x, UR added support to SSHv1. SSHv1 has known vulnerabilities (SSH protocol session key retrieval and insertion attack). SSH 1.2.25, 1.2.23, and other versions, when used in in CBC (Cipher Block Chaining) or CFB (Cipher Feedback 64 bits) modes, allows remote attackers to insert arbitrary data into an existing stream between an SSH client and server by using a known plaintext attack and computing a valid CRC-32 checksum for the packet, aka the "SSH insertion attack."', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-04-15T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/384.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-1999-1085', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.gegridsolutions.com/Passport/Login.aspx', 'details': 'GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10 or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 at https://www.gegridsolutions.com/Passport/Login.aspx (login required).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}}, {'cve': 'CVE-2021-27422', 'cwe': {'id': 'CWE-200', 'name': 'Exposure of Sensitive Information to an Unauthorized Actor'}, 'notes': [{'text': 'GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure without authentication.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-04-15T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/200.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2021-27422', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.gegridsolutions.com/Passport/Login.aspx', 'details': 'GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10 or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 at https://www.gegridsolutions.com/Passport/Login.aspx (login required).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}}, {'cve': 'CVE-2021-27418', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'GE UR firmware versions prior to version 8.1x supports web interface with read-only access. The device fails to properly validate user input, making it possible to perform cross-site scripting attacks, which may be used to send a malicious script. Also, UR Firmware web server does not perform HTML encoding of user-supplied strings.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-04-15T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2021-27418', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.gegridsolutions.com/Passport/Login.aspx', 'details': 'GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10 or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 at https://www.gegridsolutions.com/Passport/Login.aspx (login required).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}}, {'cve': 'CVE-2021-27420', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'GE UR firmware versions prior to version 8.1x web server task does not properly handle receipt of unsupported HTTP verbs, resulting in the web server becoming temporarily unresponsive after receiving a series of unsupported HTTP requests. When unresponsive, the web server is inaccessible. By itself, this is not particularly significant as the relay remains effective in all other functionality and communication channels.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-04-15T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2021-27420', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.gegridsolutions.com/Passport/Login.aspx', 'details': 'GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10 or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 at https://www.gegridsolutions.com/Passport/Login.aspx (login required).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}}, {'cve': 'CVE-2021-27428', 'cwe': {'id': 'CWE-434', 'name': 'Unrestricted Upload of File with Dangerous Type'}, 'notes': [{'text': 'GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup configuration tool – Enervista UR Setup. This UR Setup tool validates the authenticity and integrity of firmware file before uploading the UR IED. An illegitimate user could upgrade firmware without appropriate privileges. The weakness is assessed, and mitigation is implemented in firmware Version 8.10.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-04-15T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/434.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2021-27428', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.gegridsolutions.com/Passport/Login.aspx', 'details': 'GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10 or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 at https://www.gegridsolutions.com/Passport/Login.aspx (login required).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}}, {'cve': 'CVE-2021-27426', 'cwe': {'id': 'CWE-453', 'name': 'Insecure Default Variable Initialization'}, 'notes': [{'text': 'GE UR IED firmware versions prior to version 8.1x with "Basic" security variant does not allow the disabling of the "Factory Mode," which is used for servicing the IED by a "Factory" user.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-04-15T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/453.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2021-27426', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.gegridsolutions.com/Passport/Login.aspx', 'details': 'GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10 or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 at https://www.gegridsolutions.com/Passport/Login.aspx (login required).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}}, {'cve': 'CVE-2021-27424', 'cwe': {'id': 'CWE-200', 'name': 'Exposure of Sensitive Information to an Unauthorized Actor'}, 'notes': [{'text': 'GE UR firmware versions prior to version 8.1x shares MODBUS memory map as part of the communications guide. GE was made aware a "Last-key pressed" MODBUS register can be used to gain unauthorized information.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-04-15T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/200.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2021-27424', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.gegridsolutions.com/Passport/Login.aspx', 'details': 'GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10 or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 at https://www.gegridsolutions.com/Passport/Login.aspx (login required).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}}, {'cve': 'CVE-2021-27430', 'cwe': {'id': 'CWE-798', 'name': 'Use of Hard-coded Credentials'}, 'notes': [{'text': 'GE UR bootloader binary Version 7.00, 7.01 and 7.02 included unused hardcoded credentials. Additionally, a user with physical access to the UR IED can interrupt the boot sequence by rebooting the UR.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-04-15T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/798.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2021-27430', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.gegridsolutions.com/Passport/Login.aspx', 'details': 'GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10 or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 at https://www.gegridsolutions.com/Passport/Login.aspx (login required).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}}]} | |
ot | ICSA-21-075-02 | CVE-1999-1085 | GE UR Family (Update A) | 2021-03-16 09:00:00+03:00 | 2026-04-16 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2021/icsa-21-075-02.json | 32337bb24b04dabd30ef3fcf54759d4b8339a88e364f38bd0e1ad87624912847 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could allow an attacker to access sensitive information, reboot the UR, gain privileged access, or cause a denial-of-service condition.', 'title': 'Risk evaluation', 'category': 'summary'}, {'text': 'Communications, Critical Manufacturing, Energy, Healthcare and Public Health, Transportation Systems, Water and Wastewater Systems', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'GE UR Family (Update A)', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-21-075-02', 'status': 'final', 'version': '2', 'generator': {'date': '2026-04-15T16:42:03.600539Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2021-03-16T06:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}, {'date': '2026-04-16T06:00:00.000000Z', 'number': '2', 'summary': 'Update A - revised advisory content into modern format.', 'legacy_version': 'Update A'}], 'current_release_date': '2026-04-16T06:00:00.000000Z', 'initial_release_date': '2021-03-16T06:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2021/icsa-21-075-02.json', 'summary': 'ICS Advisory ICSA-21-075-02 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-21-075-02', 'summary': 'ICSA Advisory ICSA-21-075-02 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to GE', 'organization': 'SCADA-X'}, {'summary': 'reported these vulnerabilities to GE', 'organization': "DOE's Cyber Testing for Resilient Industrial Control Systems (CyTRICS) program"}, {'summary': 'reported these vulnerabilities to GE', 'organization': 'Verve Industrial'}, {'summary': 'reported these vulnerabilities to GE', 'organization': 'VuMetric'}]}, 'product_tree': {'branches': [{'name': 'GE Veronva', 'branches': [{'name': 'UR B30', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR B30: <8.10', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR B90', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR B90: <8.10', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR C30', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR C30: <8.10', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR C60', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR C60: <8.10', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR C70', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR C70: <8.10', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR C95', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR C95: <8.10', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR D30', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR D30: <8.10', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR D60', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR D60: <8.10', 'product_id': 'CSAFPID-0008'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR F35', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR F35: <8.10', 'product_id': 'CSAFPID-0009'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR F60', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR F60: <8.10', 'product_id': 'CSAFPID-0010'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR G30', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR G30: <8.10', 'product_id': 'CSAFPID-0011'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR G60', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR G60: <8.10', 'product_id': 'CSAFPID-0012'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR L30', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR L30: <8.10', 'product_id': 'CSAFPID-0013'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR L60', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR L60: <8.10', 'product_id': 'CSAFPID-0014'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR L90', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR L90: <8.10', 'product_id': 'CSAFPID-0015'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR M60', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR M60: <8.10', 'product_id': 'CSAFPID-0016'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR N60', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR N60: <8.10', 'product_id': 'CSAFPID-0017'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR T35', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR T35: <8.10', 'product_id': 'CSAFPID-0018'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR T60', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR T60: <8.10', 'product_id': 'CSAFPID-0019'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2016-2183', 'cwe': {'id': 'CWE-326', 'name': 'Inadequate Encryption Strength'}, 'notes': [{'text': 'Prior to UR firmware Version 8.1x, UR supported various encryption and MAC algorithms for SSH communication, some of which are weak. The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-04-15T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/326.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2016-2183', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.gegridsolutions.com/Passport/Login.aspx', 'details': 'GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10 or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 at https://www.gegridsolutions.com/Passport/Login.aspx (login required).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}}, {'cve': 'CVE-2013-2566', 'cwe': {'id': 'CWE-326', 'name': 'Inadequate Encryption Strength'}, 'notes': [{'text': 'Prior to UR firmware Version 8.1x, UR supported various encryption and MAC algorithms for SSH communication, some of which are weak. The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-04-15T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/326.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2013-2566', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.gegridsolutions.com/Passport/Login.aspx', 'details': 'GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10 or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 at https://www.gegridsolutions.com/Passport/Login.aspx (login required).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}}, {'cve': 'CVE-1999-1085', 'cwe': {'id': 'CWE-384', 'name': 'Session Fixation'}, 'notes': [{'text': 'Prior to firmware Version 7.4x, UR supported only SSHv2. Starting from firmware Version 7.4x, UR added support to SSHv1. SSHv1 has known vulnerabilities (SSH protocol session key retrieval and insertion attack). SSH 1.2.25, 1.2.23, and other versions, when used in in CBC (Cipher Block Chaining) or CFB (Cipher Feedback 64 bits) modes, allows remote attackers to insert arbitrary data into an existing stream between an SSH client and server by using a known plaintext attack and computing a valid CRC-32 checksum for the packet, aka the "SSH insertion attack."', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-04-15T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/384.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-1999-1085', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.gegridsolutions.com/Passport/Login.aspx', 'details': 'GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10 or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 at https://www.gegridsolutions.com/Passport/Login.aspx (login required).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}}, {'cve': 'CVE-2021-27422', 'cwe': {'id': 'CWE-200', 'name': 'Exposure of Sensitive Information to an Unauthorized Actor'}, 'notes': [{'text': 'GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure without authentication.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-04-15T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/200.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2021-27422', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.gegridsolutions.com/Passport/Login.aspx', 'details': 'GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10 or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 at https://www.gegridsolutions.com/Passport/Login.aspx (login required).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}}, {'cve': 'CVE-2021-27418', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'GE UR firmware versions prior to version 8.1x supports web interface with read-only access. The device fails to properly validate user input, making it possible to perform cross-site scripting attacks, which may be used to send a malicious script. Also, UR Firmware web server does not perform HTML encoding of user-supplied strings.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-04-15T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2021-27418', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.gegridsolutions.com/Passport/Login.aspx', 'details': 'GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10 or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 at https://www.gegridsolutions.com/Passport/Login.aspx (login required).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}}, {'cve': 'CVE-2021-27420', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'GE UR firmware versions prior to version 8.1x web server task does not properly handle receipt of unsupported HTTP verbs, resulting in the web server becoming temporarily unresponsive after receiving a series of unsupported HTTP requests. When unresponsive, the web server is inaccessible. By itself, this is not particularly significant as the relay remains effective in all other functionality and communication channels.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-04-15T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2021-27420', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.gegridsolutions.com/Passport/Login.aspx', 'details': 'GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10 or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 at https://www.gegridsolutions.com/Passport/Login.aspx (login required).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}}, {'cve': 'CVE-2021-27428', 'cwe': {'id': 'CWE-434', 'name': 'Unrestricted Upload of File with Dangerous Type'}, 'notes': [{'text': 'GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup configuration tool – Enervista UR Setup. This UR Setup tool validates the authenticity and integrity of firmware file before uploading the UR IED. An illegitimate user could upgrade firmware without appropriate privileges. The weakness is assessed, and mitigation is implemented in firmware Version 8.10.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-04-15T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/434.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2021-27428', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.gegridsolutions.com/Passport/Login.aspx', 'details': 'GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10 or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 at https://www.gegridsolutions.com/Passport/Login.aspx (login required).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}}, {'cve': 'CVE-2021-27426', 'cwe': {'id': 'CWE-453', 'name': 'Insecure Default Variable Initialization'}, 'notes': [{'text': 'GE UR IED firmware versions prior to version 8.1x with "Basic" security variant does not allow the disabling of the "Factory Mode," which is used for servicing the IED by a "Factory" user.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-04-15T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/453.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2021-27426', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.gegridsolutions.com/Passport/Login.aspx', 'details': 'GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10 or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 at https://www.gegridsolutions.com/Passport/Login.aspx (login required).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}}, {'cve': 'CVE-2021-27424', 'cwe': {'id': 'CWE-200', 'name': 'Exposure of Sensitive Information to an Unauthorized Actor'}, 'notes': [{'text': 'GE UR firmware versions prior to version 8.1x shares MODBUS memory map as part of the communications guide. GE was made aware a "Last-key pressed" MODBUS register can be used to gain unauthorized information.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-04-15T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/200.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2021-27424', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.gegridsolutions.com/Passport/Login.aspx', 'details': 'GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10 or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 at https://www.gegridsolutions.com/Passport/Login.aspx (login required).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}}, {'cve': 'CVE-2021-27430', 'cwe': {'id': 'CWE-798', 'name': 'Use of Hard-coded Credentials'}, 'notes': [{'text': 'GE UR bootloader binary Version 7.00, 7.01 and 7.02 included unused hardcoded credentials. Additionally, a user with physical access to the UR IED can interrupt the boot sequence by rebooting the UR.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-04-15T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/798.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2021-27430', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.gegridsolutions.com/Passport/Login.aspx', 'details': 'GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10 or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 at https://www.gegridsolutions.com/Passport/Login.aspx (login required).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}}]} | |
ot | ICSA-21-075-02 | CVE-2021-27422 | GE UR Family (Update A) | 2021-03-16 09:00:00+03:00 | 2026-04-16 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2021/icsa-21-075-02.json | d1b766359097897bf9f1954a76d1bdadfd3484da70543a48f88edbbf6c2e6b1b | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could allow an attacker to access sensitive information, reboot the UR, gain privileged access, or cause a denial-of-service condition.', 'title': 'Risk evaluation', 'category': 'summary'}, {'text': 'Communications, Critical Manufacturing, Energy, Healthcare and Public Health, Transportation Systems, Water and Wastewater Systems', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'GE UR Family (Update A)', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-21-075-02', 'status': 'final', 'version': '2', 'generator': {'date': '2026-04-15T16:42:03.600539Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2021-03-16T06:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}, {'date': '2026-04-16T06:00:00.000000Z', 'number': '2', 'summary': 'Update A - revised advisory content into modern format.', 'legacy_version': 'Update A'}], 'current_release_date': '2026-04-16T06:00:00.000000Z', 'initial_release_date': '2021-03-16T06:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2021/icsa-21-075-02.json', 'summary': 'ICS Advisory ICSA-21-075-02 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-21-075-02', 'summary': 'ICSA Advisory ICSA-21-075-02 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to GE', 'organization': 'SCADA-X'}, {'summary': 'reported these vulnerabilities to GE', 'organization': "DOE's Cyber Testing for Resilient Industrial Control Systems (CyTRICS) program"}, {'summary': 'reported these vulnerabilities to GE', 'organization': 'Verve Industrial'}, {'summary': 'reported these vulnerabilities to GE', 'organization': 'VuMetric'}]}, 'product_tree': {'branches': [{'name': 'GE Veronva', 'branches': [{'name': 'UR B30', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR B30: <8.10', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR B90', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR B90: <8.10', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR C30', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR C30: <8.10', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR C60', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR C60: <8.10', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR C70', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR C70: <8.10', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR C95', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR C95: <8.10', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR D30', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR D30: <8.10', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR D60', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR D60: <8.10', 'product_id': 'CSAFPID-0008'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR F35', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR F35: <8.10', 'product_id': 'CSAFPID-0009'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR F60', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR F60: <8.10', 'product_id': 'CSAFPID-0010'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR G30', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR G30: <8.10', 'product_id': 'CSAFPID-0011'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR G60', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR G60: <8.10', 'product_id': 'CSAFPID-0012'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR L30', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR L30: <8.10', 'product_id': 'CSAFPID-0013'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR L60', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR L60: <8.10', 'product_id': 'CSAFPID-0014'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR L90', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR L90: <8.10', 'product_id': 'CSAFPID-0015'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR M60', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR M60: <8.10', 'product_id': 'CSAFPID-0016'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR N60', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR N60: <8.10', 'product_id': 'CSAFPID-0017'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR T35', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR T35: <8.10', 'product_id': 'CSAFPID-0018'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'UR T60', 'branches': [{'name': '<8.10', 'product': {'name': 'GE Veronva UR T60: <8.10', 'product_id': 'CSAFPID-0019'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2016-2183', 'cwe': {'id': 'CWE-326', 'name': 'Inadequate Encryption Strength'}, 'notes': [{'text': 'Prior to UR firmware Version 8.1x, UR supported various encryption and MAC algorithms for SSH communication, some of which are weak. The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-04-15T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/326.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2016-2183', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.gegridsolutions.com/Passport/Login.aspx', 'details': 'GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10 or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 at https://www.gegridsolutions.com/Passport/Login.aspx (login required).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}}, {'cve': 'CVE-2013-2566', 'cwe': {'id': 'CWE-326', 'name': 'Inadequate Encryption Strength'}, 'notes': [{'text': 'Prior to UR firmware Version 8.1x, UR supported various encryption and MAC algorithms for SSH communication, some of which are weak. The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-04-15T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/326.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2013-2566', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.gegridsolutions.com/Passport/Login.aspx', 'details': 'GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10 or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 at https://www.gegridsolutions.com/Passport/Login.aspx (login required).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}}, {'cve': 'CVE-1999-1085', 'cwe': {'id': 'CWE-384', 'name': 'Session Fixation'}, 'notes': [{'text': 'Prior to firmware Version 7.4x, UR supported only SSHv2. Starting from firmware Version 7.4x, UR added support to SSHv1. SSHv1 has known vulnerabilities (SSH protocol session key retrieval and insertion attack). SSH 1.2.25, 1.2.23, and other versions, when used in in CBC (Cipher Block Chaining) or CFB (Cipher Feedback 64 bits) modes, allows remote attackers to insert arbitrary data into an existing stream between an SSH client and server by using a known plaintext attack and computing a valid CRC-32 checksum for the packet, aka the "SSH insertion attack."', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-04-15T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/384.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-1999-1085', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.gegridsolutions.com/Passport/Login.aspx', 'details': 'GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10 or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 at https://www.gegridsolutions.com/Passport/Login.aspx (login required).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}}, {'cve': 'CVE-2021-27422', 'cwe': {'id': 'CWE-200', 'name': 'Exposure of Sensitive Information to an Unauthorized Actor'}, 'notes': [{'text': 'GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure without authentication.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-04-15T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/200.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2021-27422', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.gegridsolutions.com/Passport/Login.aspx', 'details': 'GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10 or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 at https://www.gegridsolutions.com/Passport/Login.aspx (login required).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}}, {'cve': 'CVE-2021-27418', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'GE UR firmware versions prior to version 8.1x supports web interface with read-only access. The device fails to properly validate user input, making it possible to perform cross-site scripting attacks, which may be used to send a malicious script. Also, UR Firmware web server does not perform HTML encoding of user-supplied strings.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-04-15T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2021-27418', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.gegridsolutions.com/Passport/Login.aspx', 'details': 'GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10 or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 at https://www.gegridsolutions.com/Passport/Login.aspx (login required).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}}, {'cve': 'CVE-2021-27420', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'GE UR firmware versions prior to version 8.1x web server task does not properly handle receipt of unsupported HTTP verbs, resulting in the web server becoming temporarily unresponsive after receiving a series of unsupported HTTP requests. When unresponsive, the web server is inaccessible. By itself, this is not particularly significant as the relay remains effective in all other functionality and communication channels.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-04-15T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2021-27420', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.gegridsolutions.com/Passport/Login.aspx', 'details': 'GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10 or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 at https://www.gegridsolutions.com/Passport/Login.aspx (login required).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}}, {'cve': 'CVE-2021-27428', 'cwe': {'id': 'CWE-434', 'name': 'Unrestricted Upload of File with Dangerous Type'}, 'notes': [{'text': 'GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup configuration tool – Enervista UR Setup. This UR Setup tool validates the authenticity and integrity of firmware file before uploading the UR IED. An illegitimate user could upgrade firmware without appropriate privileges. The weakness is assessed, and mitigation is implemented in firmware Version 8.10.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-04-15T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/434.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2021-27428', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.gegridsolutions.com/Passport/Login.aspx', 'details': 'GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10 or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 at https://www.gegridsolutions.com/Passport/Login.aspx (login required).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}}, {'cve': 'CVE-2021-27426', 'cwe': {'id': 'CWE-453', 'name': 'Insecure Default Variable Initialization'}, 'notes': [{'text': 'GE UR IED firmware versions prior to version 8.1x with "Basic" security variant does not allow the disabling of the "Factory Mode," which is used for servicing the IED by a "Factory" user.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-04-15T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/453.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2021-27426', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.gegridsolutions.com/Passport/Login.aspx', 'details': 'GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10 or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 at https://www.gegridsolutions.com/Passport/Login.aspx (login required).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}}, {'cve': 'CVE-2021-27424', 'cwe': {'id': 'CWE-200', 'name': 'Exposure of Sensitive Information to an Unauthorized Actor'}, 'notes': [{'text': 'GE UR firmware versions prior to version 8.1x shares MODBUS memory map as part of the communications guide. GE was made aware a "Last-key pressed" MODBUS register can be used to gain unauthorized information.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-04-15T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/200.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2021-27424', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.gegridsolutions.com/Passport/Login.aspx', 'details': 'GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10 or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 at https://www.gegridsolutions.com/Passport/Login.aspx (login required).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}}, {'cve': 'CVE-2021-27430', 'cwe': {'id': 'CWE-798', 'name': 'Use of Hard-coded Credentials'}, 'notes': [{'text': 'GE UR bootloader binary Version 7.00, 7.01 and 7.02 included unused hardcoded credentials. Additionally, a user with physical access to the UR IED can interrupt the boot sequence by rebooting the UR.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-04-15T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/798.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2021-27430', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.gegridsolutions.com/Passport/Login.aspx', 'details': 'GE strongly recommends users with impacted firmware versions update their UR devices to UR firmware Version 8.10 or greater to resolve these vulnerabilities. GE provides additional mitigations and information about these vulnerabilities in GE Publication Number: GES-2021-004 at https://www.gegridsolutions.com/Passport/Login.aspx (login required).', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends protecting UR IED by using network defense-in-depth practices. This includes, but is not limited to, placing UR IED inside the control system network security perimeter, and having access controls, monitoring (such as an Intrusion Detection System), and other mitigating technologies in place.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'GE recommends users refer to the UR Deployment guide for secure configuration of UR IED and system.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}}]} | |
ot | ICSA-25-217-01 | CVE-2025-7376 | Mitsubishi Electric Iconics Digital Solutions Multiple Products (Update B) | 2025-08-05 08:00:00+03:00 | 2026-04-07 08:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-217-01.json | ff5f3b7524fa6f1aab2fd30e0d70de2951fd1ddd76c5ea8b4cece3ffa429d3ee | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'Successful exploitation of this vulnerability could allow a local attacker to make an unauthorized write to arbitrary files, by creating a symbolic link from a file used as a write destination by the processes of the affected products to a target file. This could allow the attacker to destroy the file on a PC with the affected products installed, resulting in a denial-of-service (DoS) condition on the PC if the destroyed file is necessary for the operation of the PC.', 'title': 'Risk evaluation', 'category': 'summary'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of Mitsubishi Electric 2025-009 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Mitsubishi Electric directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'Japan', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Mitsubishi Electric Iconics Digital Solutions Multiple Products (Update B)', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-25-217-01', 'status': 'final', 'version': '3', 'generator': {'date': '2026-04-01T20:08:49.100380Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2025-08-05T05:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}, {'date': '2025-09-04T05:00:00.000000Z', 'number': '2', 'summary': 'Update A - Modified the vulnerability description in section 3.2.1 to clarify the privilege level required by the attacker, modified the company name in section 4.0 to Mitsubishi Electric Iconics Digital Solutions, and added a statement from Mitsubishi regarding a patched version of GENESIS64 that is in development.', 'legacy_version': 'Additional Release 1'}, {'date': '2026-04-07T00:00:00.000000Z', 'number': '3', 'summary': 'Update B - Added MobileHMI, Hyper Historian, AnalytiX, and IoTWorX as affected products, and added information on affected versions and vendor fix for GENESIS64, GENESIS, MobileHMI, Hyper Historian, AnalytiX, and IoTWorX.', 'legacy_version': 'Additional Release 2'}], 'current_release_date': '2026-04-07T05:00:00.000000Z', 'initial_release_date': '2025-08-05T05:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-217-01.json', 'summary': 'ICS Advisory ICSA-25-217-01 JSON', 'category': 'self'}, {'url': 'https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-009_en.pdf', 'summary': 'Mitsubishi Electric Advisory 2025-009', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-25-217-01', 'summary': 'ICS Advisory ICSA-25-217-01 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to CISA', 'organization': 'Mitsubishi Electric'}]}, 'product_tree': {'branches': [{'name': 'Mitsubishi Electric', 'branches': [{'name': 'GENESIS64', 'branches': [{'name': '<=10.97.3', 'product': {'name': 'Mitsubishi Electric GENESIS64: <=10.97.3', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'ICONICS Suite', 'branches': [{'name': '<=10.97.3', 'product': {'name': 'Mitsubishi Electric ICONICS Suite: <=10.97.3', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'MobileHMI', 'branches': [{'name': '<=10.97.3', 'product': {'name': 'Mitsubishi Electric MobileHMI: <=10.97.3', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Hyper Historian', 'branches': [{'name': '<=10.97.3', 'product': {'name': 'Mitsubishi Electric Hyper Historian: <=10.97.3', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'AnalytiX', 'branches': [{'name': '<=10.97.3', 'product': {'name': 'Mitsubishi Electric AnalytiX: <=10.97.3', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'IoTWorX', 'branches': [{'name': '10.95', 'product': {'name': 'Mitsubishi Electric IoTWorX: 10.95', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'MC Works 64', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Mitsubishi Electric MC Works 64: vers:all/*', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'GENESIS', 'branches': [{'name': '11.00', 'product': {'name': 'Mitsubishi Electric GENESIS: 11.00', 'product_id': 'CSAFPID-0008'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'vendor'}, {'name': 'Mitsubishi Electric Iconics Digital Solutions', 'branches': [{'name': 'GENESIS64', 'branches': [{'name': '<=10.97.3', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions GENESIS64: <=10.97.3', 'product_id': 'CSAFPID-0009'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'ICONICS Suite', 'branches': [{'name': '<=10.97.3', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions ICONICS Suite: <=10.97.3', 'product_id': 'CSAFPID-0010'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'MobileHMI', 'branches': [{'name': '<=10.97.3', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions MobileHMI: <=10.97.3', 'product_id': 'CSAFPID-0011'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Hyper Historian', 'branches': [{'name': '<=10.97.3', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions Hyper Historian: <=10.97.3', 'product_id': 'CSAFPID-0012'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'AnalytiX', 'branches': [{'name': '<=10.97.3', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions AnalytiX: <=10.97.3', 'product_id': 'CSAFPID-0013'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'IoTWorX', 'branches': [{'name': '10.95', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions IoTWorX: 10.95', 'product_id': 'CSAFPID-0014'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'GENESIS', 'branches': [{'name': '11.00', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions GENESIS: 11.00', 'product_id': 'CSAFPID-0015'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-7376', 'cwe': {'id': 'CWE-64', 'name': 'Windows Shortcut Following (.LNK)'}, 'notes': [{'text': 'An information tampering vulnerability due to Windows Shortcut Following (.LNK) exists in multiple processes in GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian, AnalytiX, IoTWorX, MC Works64, and GENESIS. A local attacker needs low-privilege to exploit this vulnerability. By creating a symbolic link, an attacker can cause the processes to make unauthorized writes to arbitrary files on the file system in any location that is accessible to the user under which the elevated processes are running, resulting in a denial-of-service (DoS) condition on the PC if the modified file is necessary for the operation of the PC.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/T:P/2026-04-07T00:00:00Z/', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-7376', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/64.html', 'summary': 'cwe.mitre.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-009_en.pdf', 'details': 'Mitsubishi Electric is releasing fixed version 11.01 or later for GENESIS. Please download the fixed version from the link "https://iconicsinc.my.site.com/community/s/resource-center/product-downloads" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-009_en.pdf".', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0008']}, {'url': 'https://iconics.com/about/security/cert', 'details': 'Mitsubishi Electric Iconics Digital Solutions is releasing fixed version 11.01 or later for GENESIS. Please download the fixed version from the link "https://iconicsinc.my.site.com/community/s/resource-center/product-downloads" and install it. For more information on the fixed version, refer to the Mitsubishi Electric Iconics Digital Solutions whitepaper on security vulnerabilities which can be found at "https://iconics.com/about/security/cert".', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0015']}, {'url': 'https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-009_en.pdf', 'details': 'Mitsubishi Electric is releasing fixed version 10.98 or later for GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian, and AnalytiX. Please download the fixed version from the link "https://iconicsinc.my.site.com/community/s/resource-center/product-downloads?tabset-a9d51=51905" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-009_en.pdf".', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005']}, {'url': 'https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-009_en.pdf', 'details': 'Mitsubishi Electric is releasing fixed version 10.96 or later for IoTWorX. Please download the fixed version from the link "https://iconicsinc.my.site.com/community/s/iconics-software/a375a000004qDU8AAM/iotworx" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-009_en.pdf".', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://iconics.com/about/security/cert', 'details': 'Mitsubishi Electric Iconics Digital Solutions is releasing fixed version 10.98 or later for GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian, and AnalytiX. Please download the fixed version from the link "https://iconicsinc.my.site.com/community/s/resource-center/product-downloads?tabset-a9d51=51905" and install it. For more information on the fixed version, refer to the Mitsubishi Electric Iconics Digital Solutions whitepaper on security vulnerabilities which can be found at "https://iconics.com/about/security/cert".', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013']}, {'url': 'https://iconics.com/about/security/cert', 'details': 'Mitsubishi Electric Iconics Digital Solutions is releasing fixed version 10.96 or later for IoTWorX. Please download the fixed version from the link "https://iconicsinc.my.site.com/community/s/iconics-software/a375a000004qDU8AAM/iotworx" and install it. For more information on the fixed version, refer to the Mitsubishi Electric Iconics Digital Solutions whitepaper on security vulnerabilities which can be found at "https://iconics.com/about/security/cert".', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0014']}, {'details': 'There are no plans to release fixed version for MC Works64.', 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0007']}, {'details': 'For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric and Mitsubishi Electric Iconics Digital Solutions recommend configuring the PCs with the affected product installed so that only an administrator can log in, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015']}, {'details': 'For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric and Mitsubishi Electric Iconics Digital Solutions recommend using the PCs with the affected product installed in the LAN and blocking remote login from untrusted networks and hosts, and from non-administrator users, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015']}, {'details': 'For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric and Mitsubishi Electric Iconics Digital Solutions recommend blocking unauthorized access by using a firewall, virtual private network (VPN), etc. and allowing remote login only to administrator when connecting the PCs with the affected product installed to the Internet, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015']}, {'details': 'For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric and Mitsubishi Electric Iconics Digital Solutions recommend restricting physical access to the PC with the affected product installed and to the network to which the PC is connected, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015']}, {'details': 'For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric and Mitsubishi Electric Iconics Digital Solutions recommend preventing the user from clicking on web links in emails from untrusted sources, or from opening attachments in untrusted emails, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015']}}]} | |
ot | ICSA-25-140-04 | CVE-2025-0921 | Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric Products (Update F) | 2025-05-20 07:00:00+03:00 | 2026-04-07 08:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-140-04.json | 812b82cbc3070548be09ab4088b0062483571d6d0522668bb89d92e1c99e35b3 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'Successful exploitation of this vulnerability could allow a local attacker to make an unauthorized write to arbitrary files by creating a symbolic link from a file used as a write destination by the services of the affected products to a target file, enabling the attacker to destroy the file on a PC with affected products installed and thereby cause a denial-of-service (DoS) condition on the PC if the destroyed file is necessary for the operation of the PC.', 'title': 'Risk evaluation', 'category': 'summary'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of Mitsubishi Electric 2025-002 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Mitsubishi Electric directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'Japan', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric Products (Update F)', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-25-140-04', 'status': 'final', 'version': '7', 'generator': {'date': '2026-04-01T20:08:48.448403Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2025-05-20T04:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}, {'date': '2025-08-07T04:00:00.000000Z', 'number': '2', 'summary': 'Update A - Removed AlarmWorX64 wording from the Affected Products section, added reference to other services in the vulnerability overview, removed the multi-agent service disablement mitigation action, and updated CVE description and CVSS score.', 'legacy_version': 'Additional Release 1'}, {'date': '2025-08-28T04:00:00.000000Z', 'number': '3', 'summary': 'Update B - Modified company name to "Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric" and added a statement from Mitsubishi regarding a patched version of GENESIS64 that is in development.', 'legacy_version': 'Additional Release 2'}, {'date': '2026-01-08T05:00:00.000000Z', 'number': '4', 'summary': 'Update C - Added BizViz and GENESIS32 as affected products, added GENESIS32 and BizViz to the vulnerability description, and added relevant mitigations strategies for GENESIS32 and BizViz as requested by Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric', 'legacy_version': 'Additional Release 3'}, {'date': '2026-01-29T05:00:00.000000Z', 'number': '5', 'summary': 'Update D - Added ICONICS Suite to the affected products list and adjusted the brand name of MC Works64 to Mitsubishi Electric MC Works64', 'legacy_version': 'Additional Release 4'}, {'date': '2026-02-12T05:00:00.000000Z', 'number': '6', 'summary': 'Update E - Updated product list to correct vendor associations in the CSAF', 'legacy_version': 'Additional Release 5'}, {'date': '2026-04-07T00:00:00.000000Z', 'number': '7', 'summary': 'Update F -Added MobileHMI, Hyper Historian, AnalytiX, and IoTWorX as affected products, and added information on affected versions and vendor fix for GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian, AnalytiX, and IoTWorX.', 'legacy_version': 'Additional Release 6'}], 'current_release_date': '2026-04-07T05:00:00.000000Z', 'initial_release_date': '2025-05-20T04:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-140-04.json', 'summary': 'ICS Advisory ICSA-25-140-04 JSON', 'category': 'self'}, {'url': 'https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-002_en.pdf', 'summary': 'Mitsubishi Electric Advisory 2025-002', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-25-140-04', 'summary': 'ICS Advisory ICSA-25-140-04 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Asher Davila'], 'summary': 'reported this vulnerability to Mitsubishi Electric and CISA', 'organization': 'Palo Alto Networks'}, {'names': ['Malav Vyas'], 'summary': 'reported this vulnerability to Mitsubishi Electric and CISA', 'organization': 'Palo Alto Networks'}]}, 'product_tree': {'branches': [{'name': 'Mitsubishi Electric', 'branches': [{'name': 'GENESIS64', 'branches': [{'name': '<=10.97.3', 'product': {'name': 'Mitsubishi Electric GENESIS64: <=10.97.3', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'ICONICS Suite', 'branches': [{'name': '<=10.97.3', 'product': {'name': 'Mitsubishi Electric ICONICS Suite: <=10.97.3', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'MobileHMI', 'branches': [{'name': '<=10.97.3', 'product': {'name': 'Mitsubishi Electric MobileHMI: <=10.97.3', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Hyper Historian', 'branches': [{'name': '<=10.97.3', 'product': {'name': 'Mitsubishi Electric Hyper Historian: <=10.97.3', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'AnalytiX', 'branches': [{'name': '<=10.97.3', 'product': {'name': 'Mitsubishi Electric AnalytiX: <=10.97.3', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'IoTWorX', 'branches': [{'name': '10.95', 'product': {'name': 'Mitsubishi Electric IoTWorX: 10.95', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'GENESIS32', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Mitsubishi Electric GENESIS32: vers:all/*', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'BizViz', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Mitsubishi Electric BizViz: vers:all/*', 'product_id': 'CSAFPID-0008'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'GENESIS', 'branches': [{'name': '11.00', 'product': {'name': 'Mitsubishi Electric GENESIS: 11.00', 'product_id': 'CSAFPID-0009'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'MC Works64', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Mitsubishi Electric MC Works64: vers:all/*', 'product_id': 'CSAFPID-0010'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}, {'name': 'Mitsubishi Electric Iconics Digital Solutions', 'branches': [{'name': 'GENESIS64', 'branches': [{'name': '<=10.97.3', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions GENESIS64: <=10.97.3', 'product_id': 'CSAFPID-0011'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'ICONICS Suite', 'branches': [{'name': '<=10.97.3', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions ICONICS Suite: <=10.97.3', 'product_id': 'CSAFPID-0012'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'MobileHMI', 'branches': [{'name': '<=10.97.3', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions MobileHMI: <=10.97.3', 'product_id': 'CSAFPID-0013'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Hyper Historian', 'branches': [{'name': '<=10.97.3', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions Hyper Historian: <=10.97.3', 'product_id': 'CSAFPID-0014'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'AnalytiX', 'branches': [{'name': '<=10.97.3', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions AnalytiX: <=10.97.3', 'product_id': 'CSAFPID-0015'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'IoTWorX', 'branches': [{'name': '10.95', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions IoTWorX: 10.95', 'product_id': 'CSAFPID-0016'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'GENESIS32', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions GENESIS32: vers:all/*', 'product_id': 'CSAFPID-0017'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'BizViz', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions BizViz: vers:all/*', 'product_id': 'CSAFPID-0018'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'GENESIS', 'branches': [{'name': '11.00', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions GENESIS: 11.00', 'product_id': 'CSAFPID-0019'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-0921', 'cwe': {'id': 'CWE-250', 'name': 'Execution with Unnecessary Privileges'}, 'notes': [{'text': 'An information tampering vulnerability due to Execution with Unnecessary Privileges exists in multiple services in GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian, AnalytiX, IoTWorX, MC Works64, GENESIS, GENESIS32, and BizViz. This vulnerability could allow a local attacker to make an unauthorized write to arbitrary files by creating a symbolic link from a file used as a write destination by the services of the affected products to a target file. This could allow the attacker to destroy the target file on a PC with affected products installed, resulting in a denial-of-service (DoS) condition on the PC if the destroyed file is necessary for the operation of the PC.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/T:P/2026-04-07T00:00:00Z/', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-0921', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/250.html', 'summary': 'cwe.mitre.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-002_en.pdf', 'details': 'Mitsubishi Electric is releasing fixed version 10.98 or later for GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian, and AnalytiX. Please download the fixed version from the link "https://iconicsinc.my.site.com/community/s/resource-center/product-downloads?tabset-a9d51=51905" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-002_en.pdf".', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005']}, {'url': 'https://iconics.com/about/security/cert', 'details': 'Mitsubishi Electric Iconics Digital Solutions is releasing fixed version 10.98 or later for GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian, and AnalytiX. Please download the fixed version from the link "https://iconicsinc.my.site.com/community/s/resource-center/product-downloads?tabset-a9d51=51905" and install it. For more information on the fixed version, refer to the Mitsubishi Electric Iconics Digital Solutions whitepaper on security vulnerabilities which can be found at "https://iconics.com/about/security/cert".', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015']}, {'url': 'https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-002_en.pdf', 'details': 'Mitsubishi Electric is releasing fixed version 10.96 or later for IoTWorX. Please download the fixed version from the link "https://iconicsinc.my.site.com/community/s/iconics-software/a375a000004qDU8AAM/iotworx" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-002_en.pdf".', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0006']}, {'url': 'https://iconics.com/about/security/cert', 'details': 'Mitsubishi Electric Iconics Digital Solutions is releasing fixed version 10.96 or later for IoTWorX. Please download the fixed version from the link "https://iconicsinc.my.site.com/community/s/iconics-software/a375a000004qDU8AAM/iotworx" and install it. For more information on the fixed version, refer to the Mitsubishi Electric Iconics Digital Solutions whitepaper on security vulnerabilities which can be found at "https://iconics.com/about/security/cert".', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0016']}, {'url': 'https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-002_en.pdf', 'details': 'Mitsubishi Electric is releasing fixed version 11.01 or later for GENESIS. Please download the fixed version from the link "https://iconicsinc.my.site.com/community/s/resource-center/product-downloads" and install it. For more information on the fixed version, refer to the Mitsubishi Electric security advisory at "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-002_en.pdf".', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://iconics.com/about/security/cert', 'details': 'Mitsubishi Electric Iconics Digital Solutions is releasing fixed version 11.01 or later for GENESIS. Please download the fixed version from the link "https://iconicsinc.my.site.com/community/s/resource-center/product-downloads" and install it. For more information on the fixed version, refer to the Mitsubishi Electric Iconics Digital Solutions whitepaper on security vulnerabilities which can be found at "https://iconics.com/about/security/cert".', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0019']}, {'url': 'https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-002_en.pdf', 'details': 'Mitsubishi Electric has no plans to release fixed versions for MC Works64, GENESIS32, and BizViz. For users of MC Works64, GENESIS32, and BizViz, refer to the Mitsubishi Electric security advisory "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-002_en.pdf", and take the actions described there.', 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0010']}, {'url': 'https://iconics.com/about/security/cert', 'details': 'Mitsubishi Electric Iconics Digital Solutions has no plans to release fixed versions for GENESIS32 and BizViz. For users of GENESIS32 and BizViz, refer to the Mitsubishi Electric Iconics Digital Solutions whitepaper on security vulnerabilities which can be found at "https://iconics.com/about/security/cert", and take the actions described there.', 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0017', 'CSAFPID-0018']}, {'details': 'For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric and Mitsubishi Electric Iconics Digital Solutions recommend configuring the PCs with the affected product installed so that only an administrator can log in, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric and Mitsubishi Electric Iconics Digital Solutions recommend using the PCs with the affected product installed in the LAN and blocking remote login from untrusted networks and hosts, and from non-administrator users, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric and Mitsubishi Electric Iconics Digital Solutions recommend blocking unauthorized access by using a firewall, virtual private network (VPN), etc. and allowing remote login only to administrator when internet access is required, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric and Mitsubishi Electric Iconics Digital Solutions recommend restricting physical access to the PC with the affected product installed and the network to which the PC is connected, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}, {'details': 'For customers of products that do not have a fixed version or who cannot immediately update the product, Mitsubishi Electric and Mitsubishi Electric Iconics Digital Solutions recommend preventing the user from clicking on web links in emails from untrusted sources, or from opening attachments in untrusted emails, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019']}}]} | |
ot | ICSA-26-078-06 | CVE-2026-31904 | CTEK Chargeportal | 2026-03-19 08:00:00+03:00 | 2026-03-19 08:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-078-06.json | 674ba8916bca88d18bf277b359db8c01f5ad2e7221bf72b6df31f66571a5f7f0 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks.', 'title': 'Risk evaluation', 'category': 'summary'}, {'text': 'Energy, Transportation Systems', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Sweden', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'CTEK Chargeportal', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-078-06', 'status': 'final', 'version': '1', 'generator': {'date': '2026-03-18T16:41:21.937841Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-03-19T05:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}], 'current_release_date': '2026-03-19T05:00:00.000000Z', 'initial_release_date': '2026-03-19T05:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-078-06.json', 'summary': 'ICS Advisory ICSA-26-078-06 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-078-06', 'summary': 'ICSA Advisory ICSA-26-078-06 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Khaled Sarieddine', 'Mohammad Ali Sayed'], 'summary': 'reported these vulnerabilities to CISA'}]}, 'product_tree': {'branches': [{'name': 'CTEK', 'branches': [{'name': 'Chargeportal', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'CTEK Chargeportal: vers:all/*', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-25192', 'cwe': {'id': 'CWE-306', 'name': 'Missing Authentication for Critical Function'}, 'notes': [{'text': 'WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then issue or receive OCPP commands as a legitimate charger. Given that no authentication is required, this can lead to privilege escalation, unauthorized control of charging infrastructure, and corruption of charging network data reported to the backend.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-03-18T05:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.4, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/306.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25192', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.ctek.com/support', 'details': 'CTEK will be sunsetting this product in April 2026. Please contact CTEK for more information https://www.ctek.com/support.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-31904', 'cwe': {'id': 'CWE-307', 'name': 'Improper Restriction of Excessive Authentication Attempts'}, 'notes': [{'text': 'The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct brute-force attacks to gain unauthorized access.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-03-18T05:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/307.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-31904', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.ctek.com/support', 'details': 'CTEK will be sunsetting this product in April 2026. Please contact CTEK for more information https://www.ctek.com/support.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-27649', 'cwe': {'id': 'CWE-613', 'name': 'Insufficient Session Expiration'}, 'notes': [{'text': 'The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the most recent connection displaces the legitimate charging station and receives backend commands intended for that station. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-03-18T05:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/613.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-27649', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.ctek.com/support', 'details': 'CTEK will be sunsetting this product in April 2026. Please contact CTEK for more information https://www.ctek.com/support.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-28204', 'cwe': {'id': 'CWE-522', 'name': 'Insufficiently Protected Credentials'}, 'notes': [{'text': 'Charging station authentication identifiers are publicly accessible via web-based mapping platforms.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-03-18T05:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/522.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-28204', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.ctek.com/support', 'details': 'CTEK will be sunsetting this product in April 2026. Please contact CTEK for more information https://www.ctek.com/support.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-078-06 | CVE-2026-27649 | CTEK Chargeportal | 2026-03-19 08:00:00+03:00 | 2026-03-19 08:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-078-06.json | cc4e48fc94060a4a14175e44a66da91fca36abc4ff649f607d871c517beac341 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks.', 'title': 'Risk evaluation', 'category': 'summary'}, {'text': 'Energy, Transportation Systems', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Sweden', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'CTEK Chargeportal', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-078-06', 'status': 'final', 'version': '1', 'generator': {'date': '2026-03-18T16:41:21.937841Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-03-19T05:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}], 'current_release_date': '2026-03-19T05:00:00.000000Z', 'initial_release_date': '2026-03-19T05:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-078-06.json', 'summary': 'ICS Advisory ICSA-26-078-06 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-078-06', 'summary': 'ICSA Advisory ICSA-26-078-06 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Khaled Sarieddine', 'Mohammad Ali Sayed'], 'summary': 'reported these vulnerabilities to CISA'}]}, 'product_tree': {'branches': [{'name': 'CTEK', 'branches': [{'name': 'Chargeportal', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'CTEK Chargeportal: vers:all/*', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-25192', 'cwe': {'id': 'CWE-306', 'name': 'Missing Authentication for Critical Function'}, 'notes': [{'text': 'WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then issue or receive OCPP commands as a legitimate charger. Given that no authentication is required, this can lead to privilege escalation, unauthorized control of charging infrastructure, and corruption of charging network data reported to the backend.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-03-18T05:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.4, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/306.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25192', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.ctek.com/support', 'details': 'CTEK will be sunsetting this product in April 2026. Please contact CTEK for more information https://www.ctek.com/support.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-31904', 'cwe': {'id': 'CWE-307', 'name': 'Improper Restriction of Excessive Authentication Attempts'}, 'notes': [{'text': 'The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct brute-force attacks to gain unauthorized access.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-03-18T05:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/307.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-31904', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.ctek.com/support', 'details': 'CTEK will be sunsetting this product in April 2026. Please contact CTEK for more information https://www.ctek.com/support.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-27649', 'cwe': {'id': 'CWE-613', 'name': 'Insufficient Session Expiration'}, 'notes': [{'text': 'The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the most recent connection displaces the legitimate charging station and receives backend commands intended for that station. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-03-18T05:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/613.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-27649', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.ctek.com/support', 'details': 'CTEK will be sunsetting this product in April 2026. Please contact CTEK for more information https://www.ctek.com/support.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-28204', 'cwe': {'id': 'CWE-522', 'name': 'Insufficiently Protected Credentials'}, 'notes': [{'text': 'Charging station authentication identifiers are publicly accessible via web-based mapping platforms.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-03-18T05:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/522.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-28204', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.ctek.com/support', 'details': 'CTEK will be sunsetting this product in April 2026. Please contact CTEK for more information https://www.ctek.com/support.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-078-06 | CVE-2026-28204 | CTEK Chargeportal | 2026-03-19 08:00:00+03:00 | 2026-03-19 08:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-078-06.json | 49300a7afd1043add024857c984441d0146ddd3bf476cff7098e0d4b2ccd1d6a | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks.', 'title': 'Risk evaluation', 'category': 'summary'}, {'text': 'Energy, Transportation Systems', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Sweden', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'CTEK Chargeportal', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-078-06', 'status': 'final', 'version': '1', 'generator': {'date': '2026-03-18T16:41:21.937841Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-03-19T05:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}], 'current_release_date': '2026-03-19T05:00:00.000000Z', 'initial_release_date': '2026-03-19T05:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-078-06.json', 'summary': 'ICS Advisory ICSA-26-078-06 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-078-06', 'summary': 'ICSA Advisory ICSA-26-078-06 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Khaled Sarieddine', 'Mohammad Ali Sayed'], 'summary': 'reported these vulnerabilities to CISA'}]}, 'product_tree': {'branches': [{'name': 'CTEK', 'branches': [{'name': 'Chargeportal', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'CTEK Chargeportal: vers:all/*', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-25192', 'cwe': {'id': 'CWE-306', 'name': 'Missing Authentication for Critical Function'}, 'notes': [{'text': 'WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then issue or receive OCPP commands as a legitimate charger. Given that no authentication is required, this can lead to privilege escalation, unauthorized control of charging infrastructure, and corruption of charging network data reported to the backend.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-03-18T05:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.4, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/306.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25192', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.ctek.com/support', 'details': 'CTEK will be sunsetting this product in April 2026. Please contact CTEK for more information https://www.ctek.com/support.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-31904', 'cwe': {'id': 'CWE-307', 'name': 'Improper Restriction of Excessive Authentication Attempts'}, 'notes': [{'text': 'The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct brute-force attacks to gain unauthorized access.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-03-18T05:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/307.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-31904', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.ctek.com/support', 'details': 'CTEK will be sunsetting this product in April 2026. Please contact CTEK for more information https://www.ctek.com/support.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-27649', 'cwe': {'id': 'CWE-613', 'name': 'Insufficient Session Expiration'}, 'notes': [{'text': 'The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the most recent connection displaces the legitimate charging station and receives backend commands intended for that station. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-03-18T05:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/613.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-27649', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.ctek.com/support', 'details': 'CTEK will be sunsetting this product in April 2026. Please contact CTEK for more information https://www.ctek.com/support.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-28204', 'cwe': {'id': 'CWE-522', 'name': 'Insufficiently Protected Credentials'}, 'notes': [{'text': 'Charging station authentication identifiers are publicly accessible via web-based mapping platforms.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-03-18T05:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/522.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-28204', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.ctek.com/support', 'details': 'CTEK will be sunsetting this product in April 2026. Please contact CTEK for more information https://www.ctek.com/support.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-076-04 | CVE-2026-25569 | Siemens SICAM SIAPP SDK | 2026-03-10 03:00:00+03:00 | 2026-03-17 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-04.json | 290168e7edc8d8b3bb980d05df8b754890362059002096da1ed5825ce9a95b42 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'The SICAM SIAPP SDK contains multiple vulnerabilities that could allow an attacker to disrupt the customer-developed SIAPP or its simulation environment. Potential impacts include denial of service within the SIAPP, corruption of SIAPP data, or exploit the simulation environment. These vulnerabilities are only exploitable if the API is used improperly or hardening measures are not applied.\n\nSiemens has released a new version for SICAM SIAPP SDK and recommends to update to the latest version.', 'title': 'Summary', 'category': 'summary'}, {'text': "Operators of critical power systems (e.g. TSOs or DSOs) worldwide are usually required by regulations to build resilience into the power grids by applying multi-level redundant secondary protection schemes. It is therefore recommended that the operators check whether appropriate resilient protection measures are in place. The risk of cyber incidents impacting the grid's reliability can thus be minimized by virtue of the grid design.\nSiemens strongly recommends applying the provided security updates using the corresponding tooling and documented procedures made available with the product. If supported by the product, an automated means to apply the security updates across multiple product instances may be used. Siemens strongly recommends prior validation of any security update before being applied, and supervision by trained staff of the update process in the target environment. \nAs a general security measure Siemens strongly recommends to protect network access with appropriate mechanisms (e.g. firewalls, segmentation, VPN). It is advised to configure the environment according to our operational guidelines in order to run the devices in a protected IT environment.\n\nRecommended security guidelines can be found at:\nhttps://www.siemens.com/gridsecurity", 'title': 'General Recommendations', 'category': 'general'}, {'text': 'For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.', 'title': 'Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of Siemens ProductCERT SSA-903736 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Germany', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Siemens SICAM SIAPP SDK', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-076-04', 'status': 'final', 'version': '2', 'generator': {'date': '2026-03-13T16:30:34.082361Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2026-03-10T00:00:00.000000Z', 'number': '1', 'summary': 'Publication Date', 'legacy_version': 'Initial'}, {'date': '2026-03-17T06:00:00.000000Z', 'number': '2', 'summary': 'Initial CISA Republication of Siemens ProductCERT SSA-903736 advisory', 'legacy_version': 'CISA Republication'}], 'current_release_date': '2026-03-17T06:00:00.000000Z', 'initial_release_date': '2026-03-10T00:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://cert-portal.siemens.com/productcert/csaf/ssa-903736.json', 'summary': 'SSA-903736: Multiple vulnerabilities in SICAM SIAPP SDK before V2.1.7 - CSAF Version', 'category': 'self'}, {'url': 'https://cert-portal.siemens.com/productcert/html/ssa-903736.html', 'summary': 'SSA-903736: Multiple vulnerabilities in SICAM SIAPP SDK before V2.1.7 - HTML Version', 'category': 'self'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-04.json', 'summary': 'ICS Advisory ICSA-26-076-04 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-076-04', 'summary': 'ICS Advisory ICSA-26-076-04 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to CISA.', 'organization': 'Siemens ProductCERT'}, {'names': ['Maxime Rossi Bellom'], 'summary': 'reported these vulnerabilities to Siemens.', 'organization': 'Secmate'}]}, 'product_tree': {'branches': [{'name': 'Siemens', 'branches': [{'name': 'SICAM SIAPP SDK', 'branches': [{'name': 'vers:intdot/<2.1.7', 'product': {'name': 'SICAM SIAPP SDK', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-25569', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'An out-of-bounds write vulnerability exists in SICAM SIAPP SDK. This could allow an attacker to write data beyond the intended buffer, potentially leading to denial of service, or arbitrary code execution.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25569', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25569', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25570', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'The SICAM SIAPP SDK does not perform checks on input values potentially resulting in stack overflow. This could allow an attacker to perform code execution and denial of service.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25570', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25570', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25571', 'cwe': {'id': 'CWE-130', 'name': 'Improper Handling of Length Parameter Inconsistency'}, 'notes': [{'text': 'The SICAM SIAPP SDK client component does not enforce maximum length checks on certain variables before use. This could allow an attacker to send an oversized input that could trigger a stack overflow crashing the process and potentially causing denial of service.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25571', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25571', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/130.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25572', 'cwe': {'id': 'CWE-130', 'name': 'Improper Handling of Length Parameter Inconsistency'}, 'notes': [{'text': 'The SICAM SIAPP SDK server component does not enforce maximum length checks on certain variables before use. This could allow an attacker to send an oversized input that could trigger a stack overflow crashing the process and potentially causing denial of service.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25572', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25572', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/130.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25573', 'cwe': {'id': 'CWE-73', 'name': 'External Control of File Name or Path'}, 'notes': [{'text': 'The affected application builds shell commands with caller-provided strings and executes them. An attacker could influence the executed command, potentially resulting in command injection and full system compromise.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25573', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25573', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/73.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25605', 'cwe': {'id': 'CWE-73', 'name': 'External Control of File Name or Path'}, 'notes': [{'text': 'The affected application performs file deletion without properly validating the file path or target. An attacker could delete files or sockets that the affected process has permission to remove, potentially resulting in denial of service or service disruption.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25605', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25605', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/73.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-076-04 | CVE-2026-25570 | Siemens SICAM SIAPP SDK | 2026-03-10 03:00:00+03:00 | 2026-03-17 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-04.json | 20c43b796c8ec7c63d41fdc1c3e0708fa8bd13e872d7b19767a5c97b4f2e8706 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'The SICAM SIAPP SDK contains multiple vulnerabilities that could allow an attacker to disrupt the customer-developed SIAPP or its simulation environment. Potential impacts include denial of service within the SIAPP, corruption of SIAPP data, or exploit the simulation environment. These vulnerabilities are only exploitable if the API is used improperly or hardening measures are not applied.\n\nSiemens has released a new version for SICAM SIAPP SDK and recommends to update to the latest version.', 'title': 'Summary', 'category': 'summary'}, {'text': "Operators of critical power systems (e.g. TSOs or DSOs) worldwide are usually required by regulations to build resilience into the power grids by applying multi-level redundant secondary protection schemes. It is therefore recommended that the operators check whether appropriate resilient protection measures are in place. The risk of cyber incidents impacting the grid's reliability can thus be minimized by virtue of the grid design.\nSiemens strongly recommends applying the provided security updates using the corresponding tooling and documented procedures made available with the product. If supported by the product, an automated means to apply the security updates across multiple product instances may be used. Siemens strongly recommends prior validation of any security update before being applied, and supervision by trained staff of the update process in the target environment. \nAs a general security measure Siemens strongly recommends to protect network access with appropriate mechanisms (e.g. firewalls, segmentation, VPN). It is advised to configure the environment according to our operational guidelines in order to run the devices in a protected IT environment.\n\nRecommended security guidelines can be found at:\nhttps://www.siemens.com/gridsecurity", 'title': 'General Recommendations', 'category': 'general'}, {'text': 'For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.', 'title': 'Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of Siemens ProductCERT SSA-903736 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Germany', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Siemens SICAM SIAPP SDK', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-076-04', 'status': 'final', 'version': '2', 'generator': {'date': '2026-03-13T16:30:34.082361Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2026-03-10T00:00:00.000000Z', 'number': '1', 'summary': 'Publication Date', 'legacy_version': 'Initial'}, {'date': '2026-03-17T06:00:00.000000Z', 'number': '2', 'summary': 'Initial CISA Republication of Siemens ProductCERT SSA-903736 advisory', 'legacy_version': 'CISA Republication'}], 'current_release_date': '2026-03-17T06:00:00.000000Z', 'initial_release_date': '2026-03-10T00:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://cert-portal.siemens.com/productcert/csaf/ssa-903736.json', 'summary': 'SSA-903736: Multiple vulnerabilities in SICAM SIAPP SDK before V2.1.7 - CSAF Version', 'category': 'self'}, {'url': 'https://cert-portal.siemens.com/productcert/html/ssa-903736.html', 'summary': 'SSA-903736: Multiple vulnerabilities in SICAM SIAPP SDK before V2.1.7 - HTML Version', 'category': 'self'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-04.json', 'summary': 'ICS Advisory ICSA-26-076-04 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-076-04', 'summary': 'ICS Advisory ICSA-26-076-04 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to CISA.', 'organization': 'Siemens ProductCERT'}, {'names': ['Maxime Rossi Bellom'], 'summary': 'reported these vulnerabilities to Siemens.', 'organization': 'Secmate'}]}, 'product_tree': {'branches': [{'name': 'Siemens', 'branches': [{'name': 'SICAM SIAPP SDK', 'branches': [{'name': 'vers:intdot/<2.1.7', 'product': {'name': 'SICAM SIAPP SDK', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-25569', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'An out-of-bounds write vulnerability exists in SICAM SIAPP SDK. This could allow an attacker to write data beyond the intended buffer, potentially leading to denial of service, or arbitrary code execution.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25569', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25569', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25570', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'The SICAM SIAPP SDK does not perform checks on input values potentially resulting in stack overflow. This could allow an attacker to perform code execution and denial of service.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25570', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25570', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25571', 'cwe': {'id': 'CWE-130', 'name': 'Improper Handling of Length Parameter Inconsistency'}, 'notes': [{'text': 'The SICAM SIAPP SDK client component does not enforce maximum length checks on certain variables before use. This could allow an attacker to send an oversized input that could trigger a stack overflow crashing the process and potentially causing denial of service.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25571', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25571', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/130.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25572', 'cwe': {'id': 'CWE-130', 'name': 'Improper Handling of Length Parameter Inconsistency'}, 'notes': [{'text': 'The SICAM SIAPP SDK server component does not enforce maximum length checks on certain variables before use. This could allow an attacker to send an oversized input that could trigger a stack overflow crashing the process and potentially causing denial of service.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25572', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25572', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/130.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25573', 'cwe': {'id': 'CWE-73', 'name': 'External Control of File Name or Path'}, 'notes': [{'text': 'The affected application builds shell commands with caller-provided strings and executes them. An attacker could influence the executed command, potentially resulting in command injection and full system compromise.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25573', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25573', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/73.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25605', 'cwe': {'id': 'CWE-73', 'name': 'External Control of File Name or Path'}, 'notes': [{'text': 'The affected application performs file deletion without properly validating the file path or target. An attacker could delete files or sockets that the affected process has permission to remove, potentially resulting in denial of service or service disruption.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25605', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25605', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/73.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-076-04 | CVE-2026-25571 | Siemens SICAM SIAPP SDK | 2026-03-10 03:00:00+03:00 | 2026-03-17 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-04.json | 88fa091d9b430836cd75c8ac89e8d8ed2afdf6f57a45b5353e451e0c7d0ef55c | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'The SICAM SIAPP SDK contains multiple vulnerabilities that could allow an attacker to disrupt the customer-developed SIAPP or its simulation environment. Potential impacts include denial of service within the SIAPP, corruption of SIAPP data, or exploit the simulation environment. These vulnerabilities are only exploitable if the API is used improperly or hardening measures are not applied.\n\nSiemens has released a new version for SICAM SIAPP SDK and recommends to update to the latest version.', 'title': 'Summary', 'category': 'summary'}, {'text': "Operators of critical power systems (e.g. TSOs or DSOs) worldwide are usually required by regulations to build resilience into the power grids by applying multi-level redundant secondary protection schemes. It is therefore recommended that the operators check whether appropriate resilient protection measures are in place. The risk of cyber incidents impacting the grid's reliability can thus be minimized by virtue of the grid design.\nSiemens strongly recommends applying the provided security updates using the corresponding tooling and documented procedures made available with the product. If supported by the product, an automated means to apply the security updates across multiple product instances may be used. Siemens strongly recommends prior validation of any security update before being applied, and supervision by trained staff of the update process in the target environment. \nAs a general security measure Siemens strongly recommends to protect network access with appropriate mechanisms (e.g. firewalls, segmentation, VPN). It is advised to configure the environment according to our operational guidelines in order to run the devices in a protected IT environment.\n\nRecommended security guidelines can be found at:\nhttps://www.siemens.com/gridsecurity", 'title': 'General Recommendations', 'category': 'general'}, {'text': 'For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.', 'title': 'Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of Siemens ProductCERT SSA-903736 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Germany', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Siemens SICAM SIAPP SDK', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-076-04', 'status': 'final', 'version': '2', 'generator': {'date': '2026-03-13T16:30:34.082361Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2026-03-10T00:00:00.000000Z', 'number': '1', 'summary': 'Publication Date', 'legacy_version': 'Initial'}, {'date': '2026-03-17T06:00:00.000000Z', 'number': '2', 'summary': 'Initial CISA Republication of Siemens ProductCERT SSA-903736 advisory', 'legacy_version': 'CISA Republication'}], 'current_release_date': '2026-03-17T06:00:00.000000Z', 'initial_release_date': '2026-03-10T00:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://cert-portal.siemens.com/productcert/csaf/ssa-903736.json', 'summary': 'SSA-903736: Multiple vulnerabilities in SICAM SIAPP SDK before V2.1.7 - CSAF Version', 'category': 'self'}, {'url': 'https://cert-portal.siemens.com/productcert/html/ssa-903736.html', 'summary': 'SSA-903736: Multiple vulnerabilities in SICAM SIAPP SDK before V2.1.7 - HTML Version', 'category': 'self'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-04.json', 'summary': 'ICS Advisory ICSA-26-076-04 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-076-04', 'summary': 'ICS Advisory ICSA-26-076-04 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to CISA.', 'organization': 'Siemens ProductCERT'}, {'names': ['Maxime Rossi Bellom'], 'summary': 'reported these vulnerabilities to Siemens.', 'organization': 'Secmate'}]}, 'product_tree': {'branches': [{'name': 'Siemens', 'branches': [{'name': 'SICAM SIAPP SDK', 'branches': [{'name': 'vers:intdot/<2.1.7', 'product': {'name': 'SICAM SIAPP SDK', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-25569', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'An out-of-bounds write vulnerability exists in SICAM SIAPP SDK. This could allow an attacker to write data beyond the intended buffer, potentially leading to denial of service, or arbitrary code execution.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25569', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25569', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25570', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'The SICAM SIAPP SDK does not perform checks on input values potentially resulting in stack overflow. This could allow an attacker to perform code execution and denial of service.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25570', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25570', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25571', 'cwe': {'id': 'CWE-130', 'name': 'Improper Handling of Length Parameter Inconsistency'}, 'notes': [{'text': 'The SICAM SIAPP SDK client component does not enforce maximum length checks on certain variables before use. This could allow an attacker to send an oversized input that could trigger a stack overflow crashing the process and potentially causing denial of service.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25571', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25571', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/130.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25572', 'cwe': {'id': 'CWE-130', 'name': 'Improper Handling of Length Parameter Inconsistency'}, 'notes': [{'text': 'The SICAM SIAPP SDK server component does not enforce maximum length checks on certain variables before use. This could allow an attacker to send an oversized input that could trigger a stack overflow crashing the process and potentially causing denial of service.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25572', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25572', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/130.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25573', 'cwe': {'id': 'CWE-73', 'name': 'External Control of File Name or Path'}, 'notes': [{'text': 'The affected application builds shell commands with caller-provided strings and executes them. An attacker could influence the executed command, potentially resulting in command injection and full system compromise.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25573', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25573', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/73.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25605', 'cwe': {'id': 'CWE-73', 'name': 'External Control of File Name or Path'}, 'notes': [{'text': 'The affected application performs file deletion without properly validating the file path or target. An attacker could delete files or sockets that the affected process has permission to remove, potentially resulting in denial of service or service disruption.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25605', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25605', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/73.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-076-04 | CVE-2026-25572 | Siemens SICAM SIAPP SDK | 2026-03-10 03:00:00+03:00 | 2026-03-17 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-04.json | cf3297907518ee3ecf3ca190664d58819630a07646cee5f1b8946ed782709ac9 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'The SICAM SIAPP SDK contains multiple vulnerabilities that could allow an attacker to disrupt the customer-developed SIAPP or its simulation environment. Potential impacts include denial of service within the SIAPP, corruption of SIAPP data, or exploit the simulation environment. These vulnerabilities are only exploitable if the API is used improperly or hardening measures are not applied.\n\nSiemens has released a new version for SICAM SIAPP SDK and recommends to update to the latest version.', 'title': 'Summary', 'category': 'summary'}, {'text': "Operators of critical power systems (e.g. TSOs or DSOs) worldwide are usually required by regulations to build resilience into the power grids by applying multi-level redundant secondary protection schemes. It is therefore recommended that the operators check whether appropriate resilient protection measures are in place. The risk of cyber incidents impacting the grid's reliability can thus be minimized by virtue of the grid design.\nSiemens strongly recommends applying the provided security updates using the corresponding tooling and documented procedures made available with the product. If supported by the product, an automated means to apply the security updates across multiple product instances may be used. Siemens strongly recommends prior validation of any security update before being applied, and supervision by trained staff of the update process in the target environment. \nAs a general security measure Siemens strongly recommends to protect network access with appropriate mechanisms (e.g. firewalls, segmentation, VPN). It is advised to configure the environment according to our operational guidelines in order to run the devices in a protected IT environment.\n\nRecommended security guidelines can be found at:\nhttps://www.siemens.com/gridsecurity", 'title': 'General Recommendations', 'category': 'general'}, {'text': 'For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.', 'title': 'Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of Siemens ProductCERT SSA-903736 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Germany', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Siemens SICAM SIAPP SDK', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-076-04', 'status': 'final', 'version': '2', 'generator': {'date': '2026-03-13T16:30:34.082361Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2026-03-10T00:00:00.000000Z', 'number': '1', 'summary': 'Publication Date', 'legacy_version': 'Initial'}, {'date': '2026-03-17T06:00:00.000000Z', 'number': '2', 'summary': 'Initial CISA Republication of Siemens ProductCERT SSA-903736 advisory', 'legacy_version': 'CISA Republication'}], 'current_release_date': '2026-03-17T06:00:00.000000Z', 'initial_release_date': '2026-03-10T00:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://cert-portal.siemens.com/productcert/csaf/ssa-903736.json', 'summary': 'SSA-903736: Multiple vulnerabilities in SICAM SIAPP SDK before V2.1.7 - CSAF Version', 'category': 'self'}, {'url': 'https://cert-portal.siemens.com/productcert/html/ssa-903736.html', 'summary': 'SSA-903736: Multiple vulnerabilities in SICAM SIAPP SDK before V2.1.7 - HTML Version', 'category': 'self'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-04.json', 'summary': 'ICS Advisory ICSA-26-076-04 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-076-04', 'summary': 'ICS Advisory ICSA-26-076-04 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to CISA.', 'organization': 'Siemens ProductCERT'}, {'names': ['Maxime Rossi Bellom'], 'summary': 'reported these vulnerabilities to Siemens.', 'organization': 'Secmate'}]}, 'product_tree': {'branches': [{'name': 'Siemens', 'branches': [{'name': 'SICAM SIAPP SDK', 'branches': [{'name': 'vers:intdot/<2.1.7', 'product': {'name': 'SICAM SIAPP SDK', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-25569', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'An out-of-bounds write vulnerability exists in SICAM SIAPP SDK. This could allow an attacker to write data beyond the intended buffer, potentially leading to denial of service, or arbitrary code execution.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25569', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25569', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25570', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'The SICAM SIAPP SDK does not perform checks on input values potentially resulting in stack overflow. This could allow an attacker to perform code execution and denial of service.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25570', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25570', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25571', 'cwe': {'id': 'CWE-130', 'name': 'Improper Handling of Length Parameter Inconsistency'}, 'notes': [{'text': 'The SICAM SIAPP SDK client component does not enforce maximum length checks on certain variables before use. This could allow an attacker to send an oversized input that could trigger a stack overflow crashing the process and potentially causing denial of service.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25571', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25571', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/130.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25572', 'cwe': {'id': 'CWE-130', 'name': 'Improper Handling of Length Parameter Inconsistency'}, 'notes': [{'text': 'The SICAM SIAPP SDK server component does not enforce maximum length checks on certain variables before use. This could allow an attacker to send an oversized input that could trigger a stack overflow crashing the process and potentially causing denial of service.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25572', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25572', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/130.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25573', 'cwe': {'id': 'CWE-73', 'name': 'External Control of File Name or Path'}, 'notes': [{'text': 'The affected application builds shell commands with caller-provided strings and executes them. An attacker could influence the executed command, potentially resulting in command injection and full system compromise.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25573', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25573', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/73.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25605', 'cwe': {'id': 'CWE-73', 'name': 'External Control of File Name or Path'}, 'notes': [{'text': 'The affected application performs file deletion without properly validating the file path or target. An attacker could delete files or sockets that the affected process has permission to remove, potentially resulting in denial of service or service disruption.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25605', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25605', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/73.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-076-04 | CVE-2026-25573 | Siemens SICAM SIAPP SDK | 2026-03-10 03:00:00+03:00 | 2026-03-17 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-04.json | 12e7feaf013418717271705576d1f979ed1d784fb0b3f9231a582e9d61c62ac4 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'The SICAM SIAPP SDK contains multiple vulnerabilities that could allow an attacker to disrupt the customer-developed SIAPP or its simulation environment. Potential impacts include denial of service within the SIAPP, corruption of SIAPP data, or exploit the simulation environment. These vulnerabilities are only exploitable if the API is used improperly or hardening measures are not applied.\n\nSiemens has released a new version for SICAM SIAPP SDK and recommends to update to the latest version.', 'title': 'Summary', 'category': 'summary'}, {'text': "Operators of critical power systems (e.g. TSOs or DSOs) worldwide are usually required by regulations to build resilience into the power grids by applying multi-level redundant secondary protection schemes. It is therefore recommended that the operators check whether appropriate resilient protection measures are in place. The risk of cyber incidents impacting the grid's reliability can thus be minimized by virtue of the grid design.\nSiemens strongly recommends applying the provided security updates using the corresponding tooling and documented procedures made available with the product. If supported by the product, an automated means to apply the security updates across multiple product instances may be used. Siemens strongly recommends prior validation of any security update before being applied, and supervision by trained staff of the update process in the target environment. \nAs a general security measure Siemens strongly recommends to protect network access with appropriate mechanisms (e.g. firewalls, segmentation, VPN). It is advised to configure the environment according to our operational guidelines in order to run the devices in a protected IT environment.\n\nRecommended security guidelines can be found at:\nhttps://www.siemens.com/gridsecurity", 'title': 'General Recommendations', 'category': 'general'}, {'text': 'For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.', 'title': 'Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of Siemens ProductCERT SSA-903736 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Germany', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Siemens SICAM SIAPP SDK', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-076-04', 'status': 'final', 'version': '2', 'generator': {'date': '2026-03-13T16:30:34.082361Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2026-03-10T00:00:00.000000Z', 'number': '1', 'summary': 'Publication Date', 'legacy_version': 'Initial'}, {'date': '2026-03-17T06:00:00.000000Z', 'number': '2', 'summary': 'Initial CISA Republication of Siemens ProductCERT SSA-903736 advisory', 'legacy_version': 'CISA Republication'}], 'current_release_date': '2026-03-17T06:00:00.000000Z', 'initial_release_date': '2026-03-10T00:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://cert-portal.siemens.com/productcert/csaf/ssa-903736.json', 'summary': 'SSA-903736: Multiple vulnerabilities in SICAM SIAPP SDK before V2.1.7 - CSAF Version', 'category': 'self'}, {'url': 'https://cert-portal.siemens.com/productcert/html/ssa-903736.html', 'summary': 'SSA-903736: Multiple vulnerabilities in SICAM SIAPP SDK before V2.1.7 - HTML Version', 'category': 'self'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-04.json', 'summary': 'ICS Advisory ICSA-26-076-04 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-076-04', 'summary': 'ICS Advisory ICSA-26-076-04 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to CISA.', 'organization': 'Siemens ProductCERT'}, {'names': ['Maxime Rossi Bellom'], 'summary': 'reported these vulnerabilities to Siemens.', 'organization': 'Secmate'}]}, 'product_tree': {'branches': [{'name': 'Siemens', 'branches': [{'name': 'SICAM SIAPP SDK', 'branches': [{'name': 'vers:intdot/<2.1.7', 'product': {'name': 'SICAM SIAPP SDK', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-25569', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'An out-of-bounds write vulnerability exists in SICAM SIAPP SDK. This could allow an attacker to write data beyond the intended buffer, potentially leading to denial of service, or arbitrary code execution.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25569', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25569', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25570', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'The SICAM SIAPP SDK does not perform checks on input values potentially resulting in stack overflow. This could allow an attacker to perform code execution and denial of service.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25570', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25570', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25571', 'cwe': {'id': 'CWE-130', 'name': 'Improper Handling of Length Parameter Inconsistency'}, 'notes': [{'text': 'The SICAM SIAPP SDK client component does not enforce maximum length checks on certain variables before use. This could allow an attacker to send an oversized input that could trigger a stack overflow crashing the process and potentially causing denial of service.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25571', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25571', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/130.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25572', 'cwe': {'id': 'CWE-130', 'name': 'Improper Handling of Length Parameter Inconsistency'}, 'notes': [{'text': 'The SICAM SIAPP SDK server component does not enforce maximum length checks on certain variables before use. This could allow an attacker to send an oversized input that could trigger a stack overflow crashing the process and potentially causing denial of service.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25572', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25572', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/130.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25573', 'cwe': {'id': 'CWE-73', 'name': 'External Control of File Name or Path'}, 'notes': [{'text': 'The affected application builds shell commands with caller-provided strings and executes them. An attacker could influence the executed command, potentially resulting in command injection and full system compromise.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25573', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25573', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/73.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25605', 'cwe': {'id': 'CWE-73', 'name': 'External Control of File Name or Path'}, 'notes': [{'text': 'The affected application performs file deletion without properly validating the file path or target. An attacker could delete files or sockets that the affected process has permission to remove, potentially resulting in denial of service or service disruption.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25605', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25605', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/73.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-076-04 | CVE-2026-25605 | Siemens SICAM SIAPP SDK | 2026-03-10 03:00:00+03:00 | 2026-03-17 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-04.json | a38a695443f675c06a634c32c8e8f29b3e7545748d22e29ba897a52009c5f3b9 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'The SICAM SIAPP SDK contains multiple vulnerabilities that could allow an attacker to disrupt the customer-developed SIAPP or its simulation environment. Potential impacts include denial of service within the SIAPP, corruption of SIAPP data, or exploit the simulation environment. These vulnerabilities are only exploitable if the API is used improperly or hardening measures are not applied.\n\nSiemens has released a new version for SICAM SIAPP SDK and recommends to update to the latest version.', 'title': 'Summary', 'category': 'summary'}, {'text': "Operators of critical power systems (e.g. TSOs or DSOs) worldwide are usually required by regulations to build resilience into the power grids by applying multi-level redundant secondary protection schemes. It is therefore recommended that the operators check whether appropriate resilient protection measures are in place. The risk of cyber incidents impacting the grid's reliability can thus be minimized by virtue of the grid design.\nSiemens strongly recommends applying the provided security updates using the corresponding tooling and documented procedures made available with the product. If supported by the product, an automated means to apply the security updates across multiple product instances may be used. Siemens strongly recommends prior validation of any security update before being applied, and supervision by trained staff of the update process in the target environment. \nAs a general security measure Siemens strongly recommends to protect network access with appropriate mechanisms (e.g. firewalls, segmentation, VPN). It is advised to configure the environment according to our operational guidelines in order to run the devices in a protected IT environment.\n\nRecommended security guidelines can be found at:\nhttps://www.siemens.com/gridsecurity", 'title': 'General Recommendations', 'category': 'general'}, {'text': 'For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.', 'title': 'Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of Siemens ProductCERT SSA-903736 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Germany', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Siemens SICAM SIAPP SDK', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-076-04', 'status': 'final', 'version': '2', 'generator': {'date': '2026-03-13T16:30:34.082361Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2026-03-10T00:00:00.000000Z', 'number': '1', 'summary': 'Publication Date', 'legacy_version': 'Initial'}, {'date': '2026-03-17T06:00:00.000000Z', 'number': '2', 'summary': 'Initial CISA Republication of Siemens ProductCERT SSA-903736 advisory', 'legacy_version': 'CISA Republication'}], 'current_release_date': '2026-03-17T06:00:00.000000Z', 'initial_release_date': '2026-03-10T00:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://cert-portal.siemens.com/productcert/csaf/ssa-903736.json', 'summary': 'SSA-903736: Multiple vulnerabilities in SICAM SIAPP SDK before V2.1.7 - CSAF Version', 'category': 'self'}, {'url': 'https://cert-portal.siemens.com/productcert/html/ssa-903736.html', 'summary': 'SSA-903736: Multiple vulnerabilities in SICAM SIAPP SDK before V2.1.7 - HTML Version', 'category': 'self'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-04.json', 'summary': 'ICS Advisory ICSA-26-076-04 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-076-04', 'summary': 'ICS Advisory ICSA-26-076-04 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to CISA.', 'organization': 'Siemens ProductCERT'}, {'names': ['Maxime Rossi Bellom'], 'summary': 'reported these vulnerabilities to Siemens.', 'organization': 'Secmate'}]}, 'product_tree': {'branches': [{'name': 'Siemens', 'branches': [{'name': 'SICAM SIAPP SDK', 'branches': [{'name': 'vers:intdot/<2.1.7', 'product': {'name': 'SICAM SIAPP SDK', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-25569', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'An out-of-bounds write vulnerability exists in SICAM SIAPP SDK. This could allow an attacker to write data beyond the intended buffer, potentially leading to denial of service, or arbitrary code execution.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25569', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25569', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25570', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'The SICAM SIAPP SDK does not perform checks on input values potentially resulting in stack overflow. This could allow an attacker to perform code execution and denial of service.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25570', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25570', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25571', 'cwe': {'id': 'CWE-130', 'name': 'Improper Handling of Length Parameter Inconsistency'}, 'notes': [{'text': 'The SICAM SIAPP SDK client component does not enforce maximum length checks on certain variables before use. This could allow an attacker to send an oversized input that could trigger a stack overflow crashing the process and potentially causing denial of service.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25571', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25571', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/130.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25572', 'cwe': {'id': 'CWE-130', 'name': 'Improper Handling of Length Parameter Inconsistency'}, 'notes': [{'text': 'The SICAM SIAPP SDK server component does not enforce maximum length checks on certain variables before use. This could allow an attacker to send an oversized input that could trigger a stack overflow crashing the process and potentially causing denial of service.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25572', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.1, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25572', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/130.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25573', 'cwe': {'id': 'CWE-73', 'name': 'External Control of File Name or Path'}, 'notes': [{'text': 'The affected application builds shell commands with caller-provided strings and executes them. An attacker could influence the executed command, potentially resulting in command injection and full system compromise.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25573', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25573', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/73.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25605', 'cwe': {'id': 'CWE-73', 'name': 'External Control of File Name or Path'}, 'notes': [{'text': 'The affected application performs file deletion without properly validating the file path or target. An attacker could delete files or sockets that the affected process has permission to remove, potentially resulting in denial of service or service disruption.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-25605', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25605', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/73.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V2.1.7 or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-076-03 | CVE-2025-13957 | Schneider Electric EcoStruxure Data Center Expert | 2026-03-10 10:00:00+03:00 | 2026-03-17 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-03.json | 20143ecf4f71fc686498951ea268541506631f966c96ba9a701ac0231154507f | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'Schneider Electric strongly recommends the following industry cybersecurity best practices: \n\n* Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.\n* Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.\n* Place all controllers in locked cabinets and never leave them in the “Program” mode.\n* Never connect programming software to any network other than the network intended for that device.\n* Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.\n* Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.\n* Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.\n* When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.\n\nFor more information refer to the Schneider Electric [Recommended Cybersecurity Best Practices](https://www.se.com/us/en/download/document/7EN52-0390/) document.', 'title': 'General Security Recommendations', 'category': 'general'}, {'text': 'This document provides an overview of the identified vulnerability or vulnerabilities and actions required to mitigate. For more details and assistance on how to protect your installation, contact your local Schneider Electric representative or Schneider Electric Industrial Cybersecurity Services: https://www.se.com/ww/en/work/solutions/cybersecurity/. These organizations will be fully aware of this situation and can support you through the process.\nFor further information related to cybersecurity in Schneider Electric’s products, visit the company’s cybersecurity support portal page: https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp', 'title': 'For More Information', 'category': 'general'}, {'text': 'THIS NOTIFICATION DOCUMENT, THE INFORMATION CONTAINED HEREIN, AND ANY MATERIALS LINKED FROM IT (COLLECTIVELY, THIS “NOTIFICATION”) ARE INTENDED TO HELP PROVIDE AN OVERVIEW OF THE IDENTIFIED SITUATION AND SUGGESTED MITIGATION ACTIONS, REMEDIATION, FIX, AND/OR GENERAL SECURITY RECOMMENDATIONS AND IS PROVIDED ON AN “AS-IS” BASIS WITHOUT WARRANTY OR GUARANTEE OF ANY KIND. SCHNEIDER ELECTRIC DISCLAIMS ALL WARRANTIES RELATING TO THIS NOTIFICATION, EITHER EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SCHNEIDER ELECTRIC MAKES NO WARRANTY THAT THE NOTIFICATION WILL RESOLVE THE IDENTIFIED SITUATION. IN NO EVENT SHALL SCHNEIDER ELECTRIC BE LIABLE FOR ANY DAMAGES OR LOSSES WHATSOEVER IN CONNECTION WITH THIS NOTIFICATION, INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF SCHNEIDER ELECTRIC HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. YOUR USE OF THIS NOTIFICATION IS AT YOUR OWN RISK, AND YOU ARE SOLELY LIABLE FOR ANY DAMAGES TO YOUR SYSTEMS OR ASSETS OR OTHER LOSSES THAT MAY RESULT FROM YOUR USE OF THIS NOTIFICATION. SCHNEIDER ELECTRIC RESERVES THE RIGHT TO UPDATE OR CHANGE THIS NOTIFICATION AT ANY TIME AND IN ITS SOLE DISCRETION', 'title': 'LEGAL DISCLAIMER', 'category': 'legal_disclaimer'}, {'text': "Schneider's purpose is to create Impact by empowering all to make the most of our energy and resources, bridging progress and sustainability for all. We call this Life Is On.\n\nOur mission is to be the trusted partner in Sustainability and Efficiency.\n\nWe are a global industrial technology leader bringing world-leading expertise in electrification, automation and digitization to smart industries, resilient infrastructure, future-proof data centers, intelligent buildings, and intuitive homes. Anchored by our deep domain expertise, we provide integrated end-to-end lifecycle AI enabled Industrial IoT solutions with connected products, automation, software and services, delivering digital twins to enable profitable growth for our customers.\n\nWe are a people company with an ecosystem of 150,000 colleagues and more than a million partners operating in over 100 countries to ensure proximity to our customers and stakeholders. We embrace diversity and inclusion in everything we do, guided by our meaningful purpose of a sustainable future for all. \n\n www.se.com", 'title': 'About Schneider Electric', 'category': 'general'}, {'text': 'Schneider Electric is aware of a hard-coded credentials vulnerability in its EcoStruxure IT Data Center Expert (DCE) product that requires administrator credentials and enabling a feature (SOCKS Proxy) that is off by default.\r\nThe EcoStruxure IT Data Center Expert product is a scalable monitoring software that collects, organizes, and distributes critical device information providing a comprehensive view of equipment.\r\nFailure to apply the remediation provided below may risk information disclosure, and remote compromise of the offer which could result in disruption of operations and access to system data.', 'title': 'Overview', 'category': 'summary'}, {'text': "The severity of vulnerabilities was calculated using the CVSS Base metrics for 4.0 ([CVSS v4.0](https://www.first.org/cvss/calculator/4.0)). CVSS v3.1 will be still evaluated until the adoption of CVSS v4.0 by the industry. The severity was calculated without incorporating the Temporal and Environmental metrics. Schneider Electric recommends that customers score the CVSS Environmental metrics, which are specific to end-user organizations, and consider factors such as the presence of mitigations in that environment. Environmental metrics may refine the relative severity posed by the vulnerabilities described in this document within a customer's environment.", 'category': 'other'}, {'text': "Customers should use appropriate patching methodologies when applying these patches to their systems. We strongly recommend the use of back-ups and evaluating the impact of these patches in a Test and Development environment or on an offline infrastructure. Contact Schneider Electric's [Customer Care Center](https://www.se.com/us/en/work/support/contacts.jsp) if you need assistance removing a patch. ", 'category': 'other'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of Schneider Electric CPCERT SEVD-2026-069-05 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Schneider Electric CPCERT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'Commercial Facilities, Energy, Food and Agriculture, Government Services and Facilities, Transportation Systems', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'France', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Schneider Electric EcoStruxure Data Center Expert', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-076-03', 'status': 'final', 'version': '2', 'generator': {'date': '2026-03-11T16:16:56.932604Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2026-03-10T07:00:00.000000Z', 'number': '1', 'summary': 'Original Release', 'legacy_version': 'Initial'}, {'date': '2026-03-17T06:00:00.000000Z', 'number': '2', 'summary': 'Initial CISA Republication of Schneider Electric SEVD-2026-069-05 advisory', 'legacy_version': 'CISA Republication'}], 'current_release_date': '2026-03-17T06:00:00.000000Z', 'initial_release_date': '2026-03-10T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-069-05&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-069-05.json', 'summary': 'Use of Hard-coded Credentials vulnerability in EcoStruxure IT Data Center Expert - SEVD-2026-069-05 CSAF Version', 'category': 'self'}, {'url': 'https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-069-05&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-069-05.pdf', 'summary': 'Use of Hard-coded Credentials vulnerability in EcoStruxure IT Data Center Expert - SEVD-2026-069-05 PDF Version', 'category': 'self'}, {'url': 'https://www.se.com/ww/en/download/document/7EN52-0390/', 'summary': 'Recommended Cybersecurity Best Practices', 'category': 'external'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-03.json', 'summary': 'ICS Advisory ICSA-26-076-03 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-076-03', 'summary': 'ICS Advisory ICSA-26-076-03 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['hassan ali'], 'summary': 'reported this vulnerability to Schneider Electric', 'organization': 'TrendAI Zero Day Initiative'}]}, 'product_tree': {'branches': [{'name': 'Schneider Electric', 'branches': [{'name': 'EcoStruxure IT Data Center Expert', 'branches': [{'name': 'vers:intdot/<=9.0', 'product': {'name': 'EcoStruxure IT Data Center Expert (Formerly known as StruxureWare Data Center Expert) v9.0 and prior', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'EcoStruxure IT Data Center Expert', 'branches': [{'name': '9.1', 'product': {'name': 'EcoStruxure IT Data Center Expert 9.1', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-13957', 'cwe': {'id': 'CWE-798', 'name': 'Use of Hard-coded Credentials'}, 'notes': [{'text': 'A hard-coded credentials vulnerability exists that could lead to information disclosure and remote code execution when SOCKS Proxy is enabled, and administrator credentials and PostgreSQL database credentials are known. SOCKS Proxy is disabled by default.', 'title': 'CVE Description', 'category': 'description'}, {'text': 'CVSS v4.0 Base Score 7.5 | High | [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N](https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)', 'title': 'CVSS v4.0 Score', 'category': 'details'}], 'title': 'CVE-2025-13957', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.2, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'HIGH', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-13957', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/798.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/en/product-range/61851-ecostruxure-it-data-center-expert/#software-and-firmware', 'details': 'v9.1 of EcoStruxure IT Data Center Expert includes a fix for this vulnerability and is available for download here:\r\nhttps://www.se.com/en/product-range/61851-ecostruxure-it-data-center-expert/#software-and-firmware', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'none'}}, {'url': 'https://community.se.com/t5/DCE-Security/EcoStruxure-IT-Data-Center-Expert-Security-Handbook/ta-p/446553', 'details': 'If users choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit:\r\n• Harden the DCE instance according to the cybersecurity best practices documented in the EcoStruxure IT Data Center Expert Security Handbook\r\n• Ensure the SOCKS Proxy is disabled as in the default configuration.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001'], 'restart_required': {'category': 'none'}}, {'url': 'https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-069-05&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-069-05.pdf', 'details': ' For more information see the associated Schneider Electric CPCERT security advisory SEVD-2026-069-05 Use of Hard-coded Credentials vulnerability in EcoStruxure IT Data Center Expert PDF Version https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-069-05&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-069-05.pdf', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-069-05&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-069-05.json', 'details': ' For more information see the associated Schneider Electric CPCERT security advisory SEVD-2026-069-05 Use of Hard-coded Credentials vulnerability in EcoStruxure IT Data Center Expert CSAF Version https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-069-05&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-069-05.json', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'fixed': ['CSAFPID-0002'], 'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-076-02 | CVE-2026-0667 | Schneider Electric SCADAPack and RemoteConnect | 2026-02-10 11:00:00+03:00 | 2026-03-17 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-02.json | 72aac40019407bddeafcf572a5549ee6c11af35bdd89fce08557b660d89acb02 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'We strongly recommend the following industry cybersecurity best practices.\n\n* Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.\n* Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.\n* Place all controllers in locked cabinets and never leave them in the “Program” mode.\n* Never connect programming software to any network other than the network intended for that device.\n* Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.\n* Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.\n* Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.\n* When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.\n\nFor more information refer to the Schneider Electric [Recommended Cybersecurity Best Practices](https://www.se.com/us/en/download/document/7EN52-0390/) document.', 'title': 'General Security Recommendations', 'category': 'general'}, {'text': "This document provides an overview of the identified vulnerability or vulnerabilities and actions required to mitigate. For more details and assistance on how to protect your installation, contact your local Schneider Electric representative or Schneider Electric Industrial Cybersecurity Services: https://www.se.com/ww/en/work/solutions/cybersecurity/. These organizations will be fully aware of this situation and can support you through the process.\n\nFor further information related to cybersecurity in Schneider Electric's products, visit the company's cybersecurity support portal page: https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp", 'title': 'For More Information', 'category': 'general'}, {'text': 'THIS NOTIFICATION DOCUMENT, THE INFORMATION CONTAINED HEREIN, AND ANY MATERIALS LINKED FROM IT (COLLECTIVELY, THIS “NOTIFICATION”) ARE INTENDED TO HELP PROVIDE AN OVERVIEW OF THE IDENTIFIED SITUATION AND SUGGESTED MITIGATION ACTIONS, REMEDIATION, FIX, AND/OR GENERAL SECURITY RECOMMENDATIONS AND IS PROVIDED ON AN “AS-IS” BASIS WITHOUT WARRANTY OR GUARANTEE OF ANY KIND. SCHNEIDER ELECTRIC DISCLAIMS ALL WARRANTIES RELATING TO THIS NOTIFICATION, EITHER EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SCHNEIDER ELECTRIC MAKES NO WARRANTY THAT THE NOTIFICATION WILL RESOLVE THE IDENTIFIED SITUATION. IN NO EVENT SHALL SCHNEIDER ELECTRIC BE LIABLE FOR ANY DAMAGES OR LOSSES WHATSOEVER IN CONNECTION WITH THIS NOTIFICATION, INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF SCHNEIDER ELECTRIC HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. YOUR USE OF THIS NOTIFICATION IS AT YOUR OWN RISK, AND YOU ARE SOLELY LIABLE FOR ANY DAMAGES TO YOUR SYSTEMS OR ASSETS OR OTHER LOSSES THAT MAY RESULT FROM YOUR USE OF THIS NOTIFICATION. SCHNEIDER ELECTRIC RESERVES THE RIGHT TO UPDATE OR CHANGE THIS NOTIFICATION AT ANY TIME AND IN ITS SOLE DISCRETION', 'title': 'LEGAL DISCLAIMER', 'category': 'legal_disclaimer'}, {'text': "Schneider's purpose is to create Impact by empowering all to make the most of our energy and resources, bridging progress and\r\nsustainability for all. We call this Life Is On.\n\nOur mission is to be the trusted partner in Sustainability and Efficiency.\n\nWe are a global industrial technology leader bringing world-leading expertise in electrification, automation and digitization to smart\r\nindustries, resilient infrastructure, future-proof data centers, intelligent buildings, and intuitive homes. Anchored by our deep\r\ndomain expertise, we provide integrated end-to-end lifecycle AI enabled Industrial IoT solutions with connected products, automation,\r\nsoftware and services, delivering digital twins to enable profitable growth for our customers.\n\nWe are a people company with an ecosystem of 150,000 colleagues and more than a million partners operating in over 100 countries\r\nto ensure proximity to our customers and stakeholders. We embrace diversity and inclusion in everything we do, guided by our\r\nmeaningful purpose of a sustainable future for all. \n\n www.se.com", 'title': 'About Schneider Electric', 'category': 'general'}, {'text': 'Schneider Electric is aware of a vulnerability in its SCADAPack™ x70 RTU products.\r\nThe SCADAPack™ 47xi, SCADAPack™ 47x and SCADAPack™ 57x product are Remote Terminal Units that \r\nprovide communication capabilities for remote monitoring and control.\r\nFailure to apply the remediations provided below may risk unauthorized access to your RTU, which could \r\nresult in the possibility of denial of service and loss of confidentiality, integrity of the controller.', 'title': 'Overview', 'category': 'summary'}, {'text': "The severity of vulnerabilities was calculated using the CVSS Base metrics for 4.0 ([CVSS v4.0](https://www.first.org/cvss/calculator/4.0)). CVSS v3.1 \nwill be still evaluated until the adoption of CVSS v4.0 by the industry. The severity was calculated without \nincorporating the Temporal and Environmental metrics. Schneider Electric recommends that customers score the CVSS Environmental metrics, which are specific to end-user organizations, and consider factors such as \nthe presence of mitigations in that environment. Environmental metrics may refine the relative severity posed by the vulnerabilities described in this document within a customer's environment.", 'category': 'other'}, {'text': 'Customers should use appropriate patching methodologies when applying these patches to their systems. We strongly recommend the use of back-ups and evaluating the impact of these patches in a Test and Development environment or on an offline infrastructure. Contact Schneider Electric’s Technical Support at supportRO@se.com if you need assistance.', 'category': 'other'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of Schneider Electric CPCERT SEVD-2026-041-01 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Schneider Electric CPCERT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'Energy', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'France', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Schneider Electric SCADAPack and RemoteConnect', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-076-02', 'status': 'final', 'version': '2', 'generator': {'date': '2026-03-12T21:34:20.396001Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2026-02-10T08:00:00.000000Z', 'number': '1', 'summary': 'Original Release', 'legacy_version': 'Initial'}, {'date': '2026-03-17T06:00:00.000000Z', 'number': '2', 'summary': 'Initial CISA Republication of Schneider Electric CPCERT SEVD-2026-041-01 advisory', 'legacy_version': 'CISA Republication'}], 'current_release_date': '2026-03-17T06:00:00.000000Z', 'initial_release_date': '2026-02-10T08:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-041-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-041-01.json', 'summary': 'Improper Check for Unusual or Exceptional Conditions on Multiple Products - SEVD-2026-041-01 CSAF Version', 'category': 'self'}, {'url': 'https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-041-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-041-01.pdf', 'summary': 'Improper Check for Unusual or Exceptional Conditions on Multiple Products - SEVD-2026-041-01 PDF Version', 'category': 'self'}, {'url': 'https://www.se.com/ww/en/download/document/7EN52-0390', 'summary': 'Recommended Cybersecurity Best Practices', 'category': 'external'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-076-02.json', 'summary': 'ICS Advisory ICSA-26-076-02 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-076-02', 'summary': 'ICS Advisory ICSA-26-076-02 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported this vulnerability to CISA.', 'organization': 'Schneider Electric CPCERT'}]}, 'product_tree': {'branches': [{'name': 'Schneider Electric', 'branches': [{'name': 'SCADAPack™', 'branches': [{'name': 'vers:generic/<R3.4.2', 'product': {'name': 'SCADAPack™ 47x versions prior to R3.4.2', 'product_id': 'CSAFPID-0001', 'product_identification_helper': {'model_numbers': ['47x']}}, 'category': 'product_version_range'}, {'name': 'R3.4.2', 'product': {'name': 'SCADAPack™ 47x version R3.4.2', 'product_id': 'CSAFPID-0002', 'product_identification_helper': {'model_numbers': ['47x']}}, 'category': 'product_version'}, {'name': 'vers:generic/<R3.4.2', 'product': {'name': 'SCADAPack™ 47xi versions prior to R3.4.2', 'product_id': 'CSAFPID-0003', 'product_identification_helper': {'model_numbers': ['47xi']}}, 'category': 'product_version_range'}, {'name': 'R3.4.2', 'product': {'name': 'SCADAPack™ 47xi version R3.4.2', 'product_id': 'CSAFPID-0004', 'product_identification_helper': {'model_numbers': ['47xi']}}, 'category': 'product_version'}, {'name': 'vers:all/*', 'product': {'name': 'SCADAPack™ 57x All Versions', 'product_id': 'CSAFPID-0005', 'product_identification_helper': {'model_numbers': ['57xi']}}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SCADAPack™ firmware', 'branches': [{'name': 'vers:intdot/<9.12.2', 'product': {'name': 'SCADAPack™ 47x firmware versions prior to 9.12.2', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version_range'}, {'name': '9.12.2', 'product': {'name': 'SCADAPack™ 47x firmware version 9.12.2', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version'}, {'name': 'vers:intdot/<9.12.2', 'product': {'name': 'SCADAPack™ 47xi firmware versions prior to 9.12.2', 'product_id': 'CSAFPID-0008'}, 'category': 'product_version_range'}, {'name': '9.12.2', 'product': {'name': 'SCADAPack™ 47xi firmware version 9.12.2', 'product_id': 'CSAFPID-0009'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'RemoteConnect', 'branches': [{'name': 'vers:generic/<R3.4.2', 'product': {'name': 'RemoteConnect Versions prior to R3.4.2', 'product_id': 'CSAFPID-0010'}, 'category': 'product_version_range'}, {'name': 'R3.4.2', 'product': {'name': 'RemoteConnect Version R3.4.2', 'product_id': 'CSAFPID-0011'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'SCADAPack™ 47x firmware versions prior to 9.12.2 installed on SCADAPack™ 47x versions prior to R3.4.2', 'product_id': 'CSAFPID-0012'}, 'product_reference': 'CSAFPID-0006', 'relates_to_product_reference': 'CSAFPID-0001'}, {'category': 'installed_on', 'full_product_name': {'name': 'SCADAPack™ 47x firmware version 9.12.2 installed on SCADAPack™ 47x version R3.4.2', 'product_id': 'CSAFPID-0013'}, 'product_reference': 'CSAFPID-0007', 'relates_to_product_reference': 'CSAFPID-0002'}, {'category': 'installed_on', 'full_product_name': {'name': 'SCADAPack™ 47xi firmware versions prior to 9.12.2 installed on SCADAPack™ 47xi versions prior to R3.4.2', 'product_id': 'CSAFPID-0014'}, 'product_reference': 'CSAFPID-0008', 'relates_to_product_reference': 'CSAFPID-0003'}, {'category': 'installed_on', 'full_product_name': {'name': 'SCADAPack™ 47xi firmware version 9.12.2 installed on SCADAPack™ 47xi version R3.4.2', 'product_id': 'CSAFPID-0015'}, 'product_reference': 'CSAFPID-0009', 'relates_to_product_reference': 'CSAFPID-0004'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-0667', 'cwe': {'id': 'CWE-754', 'name': 'Improper Check for Unusual or Exceptional Conditions'}, 'notes': [{'text': 'CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code \r\nexecution, denial of service and loss of confidentiality & integrity when communicating over the Modbus TCP \r\nprotocol.', 'title': 'CVE Description', 'category': 'description'}, {'text': 'CVSS v4.0 Base Score 9.3 | Critical | [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N](https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)', 'title': 'CVSS v4.0 Score', 'category': 'details'}], 'title': 'CVE-2026-0667', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 9.8, 'attackVector': 'NETWORK', 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0012', 'CSAFPID-0014', 'CSAFPID-0005', 'CSAFPID-0010']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-0667', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/754.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/download/document/RemoteConnect/', 'details': 'Version R3.4.2 (Firmware version 9.12.2) of SCADAPack™ 47x and\r\nSCADAPack™ 47xi includes a fix for this vulnerability and is available for \r\ndownload here:\r\nhttps://www.se.com/ww/en/download/document/RemoteConnect/', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012', 'CSAFPID-0014'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/RemoteConnect/', 'details': 'Version R3.4.2 of RemoteConnect includes a fix for this vulnerability and is \r\navailable for download here:\r\nhttps://www.se.com/ww/en/download/document/RemoteConnect/', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/SCADAPack_Cybersecurity_Guide/', 'details': 'If customers choose not to apply the remediation provided above, they should immediately apply the following \r\nmitigations to reduce the risk of exploit:\r\nFollow the information according to SCADAPack™ Security Guidelines in \r\nsection 8.3 Secured Communication. Also, apply the following standard \r\npractices to reduce the risk of exploit:\r\n• Setup network segmentation and implement the RTU firewall service \r\nto block all unauthorized access to services\r\n• Disable the logic debug service.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0012', 'CSAFPID-0014', 'CSAFPID-0010'], 'restart_required': {'category': 'none'}}, {'url': 'https://www.se.com/ww/en/download/document/SCADAPack_Cybersecurity_Guide/', 'details': 'Follow the information according to SCADAPack™ Security Guidelines in \r\nsection 8.3 Secured Communication. Also, apply the following standard \r\npractices to reduce the risk of exploit\r\n• Setup network segmentation and implement the RTU firewall service \r\nto block all unauthorized access to services.\r\n• Disable the logic debug service.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0005'], 'restart_required': {'category': 'none'}}], 'product_status': {'fixed': ['CSAFPID-0013', 'CSAFPID-0015', 'CSAFPID-0011'], 'known_affected': ['CSAFPID-0012', 'CSAFPID-0014', 'CSAFPID-0005', 'CSAFPID-0010']}}]} | |
ot | ICSA-26-015-10 | CVE-2025-13844 | Schneider Electric EcoStruxure Power Build Rapsody (Update A) | 2026-01-13 11:00:00+03:00 | 2026-03-17 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-015-10.json | 85afe54ef01244105da4e30f5aafa629cd42f5e54c1f227bcd2ae2c8d41dcefa | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'Schneider Electric strongly recommends the following industry cybersecurity best practices.\n\n* Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.\n* Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.\n* Place all controllers in locked cabinets and never leave them in the “Program” mode.\n* Never connect programming software to any network other than the network intended for that device.\n* Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.\n* Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.\n* Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.\n* When remote access is required, use secure methods, such as virtual private networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.\n\nFor more information refer to the Schneider Electric [Recommended Cybersecurity Best Practices](https://www.se.com/us/en/download/document/7EN52-0390/) document.', 'title': 'General Security Recommendations', 'category': 'general'}, {'text': "This document provides an overview of the identified vulnerability or vulnerabilities and actions required to mitigate. For more details and assistance on how to protect your installation, contact your local Schneider Electric representative or Schneider Electric Industrial Cybersecurity Services: https://www.se.com/ww/en/work/solutions/cybersecurity/. These organizations will be fully aware of this situation and can support you through the process.\n\nFor further information related to cybersecurity in Schneider Electric's products, visit the company's cybersecurity support portal page: https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp", 'title': 'For More Information', 'category': 'general'}, {'text': 'THIS NOTIFICATION DOCUMENT, THE INFORMATION CONTAINED HEREIN, AND ANY MATERIALS LINKED FROM IT (COLLECTIVELY, THIS “NOTIFICATION”) ARE INTENDED TO HELP PROVIDE AN OVERVIEW OF THE IDENTIFIED SITUATION AND SUGGESTED MITIGATION ACTIONS, REMEDIATION, FIX, AND/OR GENERAL SECURITY RECOMMENDATIONS AND IS PROVIDED ON AN “AS-IS” BASIS WITHOUT WARRANTY OR GUARANTEE OF ANY KIND. SCHNEIDER ELECTRIC DISCLAIMS ALL WARRANTIES RELATING TO THIS NOTIFICATION, EITHER EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SCHNEIDER ELECTRIC MAKES NO WARRANTY THAT THE NOTIFICATION WILL RESOLVE THE IDENTIFIED SITUATION. IN NO EVENT SHALL SCHNEIDER ELECTRIC BE LIABLE FOR ANY DAMAGES OR LOSSES WHATSOEVER IN CONNECTION WITH THIS NOTIFICATION, INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF SCHNEIDER ELECTRIC HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. YOUR USE OF THIS NOTIFICATION IS AT YOUR OWN RISK, AND YOU ARE SOLELY LIABLE FOR ANY DAMAGES TO YOUR SYSTEMS OR ASSETS OR OTHER LOSSES THAT MAY RESULT FROM YOUR USE OF THIS NOTIFICATION. SCHNEIDER ELECTRIC RESERVES THE RIGHT TO UPDATE OR CHANGE THIS NOTIFICATION AT ANY TIME AND IN ITS SOLE DISCRETION', 'title': 'LEGAL DISCLAIMER', 'category': 'legal_disclaimer'}, {'text': "Schneider's purpose is to create impact by empowering all to make the most of our energy and resources, bridging progress and sustainability for all. We call this Life Is On.\n\nOur mission is to be the trusted partner in sustainability and efficiency.\n\nWe are a global industrial technology leader bringing world-leading expertise in electrification, automation and digitization to smart industries, resilient infrastructure, future-proof data centers, intelligent buildings, and intuitive homes. Anchored by our deep domain expertise, we provide integrated end-to-end lifecycle AI enabled industrial IoT solutions with connected products, automation, software and services, delivering digital twins to enable profitable growth for our users.\n\nWe are a people company with an ecosystem of 150,000 colleagues and more than a million partners operating in over 100 countries to ensure proximity to our users and stakeholders. We embrace diversity and inclusion in everything we do, guided by our meaningful purpose of a sustainable future for all. \n\n www.se.com", 'title': 'About Schneider Electric', 'category': 'general'}, {'text': 'Schneider Electric is aware of a vulnerability in its EcoStruxure Power Build Rapsody software. The [EcoStruxure Power Build Rapsody](https://www.se.com/ww/en/product-country-selector/?pageType=product-range&sourceId=2309) is used to enter or import the single line diagram, to get the extensive bill of material of your switchboard, including all devices, connection items, and mounting components. \n\nFailure to apply the mitigations/remediations provided below may risk memory corruption, heap-based buffer overflow, stack-based buffer overflow, which could result in local attackers being able to exploit these issues to potentially execute arbitrary code.', 'title': 'Overview', 'category': 'summary'}, {'text': "The severity of vulnerabilities was calculated using the CVSS base metrics for 4.0 ([CVSS v4.0](https://www.first.org/cvss/calculator/4.0)). CVSS v3.1 will be still evaluated until the adoption of CVSS v4.0 by the industry. The severity was calculated without incorporating the temporal and environmental metrics. Schneider Electric recommends that users score the CVSS environmental metrics, which are specific to end-user organizations, and consider factors such as the presence of mitigations in that environment. Environmental metrics may refine the relative severity posed by the vulnerabilities described in this document within a usmer's environment.", 'category': 'other'}, {'text': "Users should employ appropriate patching methodologies when applying these patches to their systems. Schneider Electric strongly recommends the use of back-ups and evaluating the impact of these patches in a test and development environment or on an offline infrastructure. Contact Schneider Electric's Customer Care Center at [https://www.se.com/us/en/work/support/contacts.jsp](https://www.se.com/us/en/work/support/contacts.jsp) if you need assistance removing a patch. ", 'category': 'other'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a republication of Schneider Electric SEVD-2026-013-04 from a direct conversion of the vendor\'s common security advisory framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Schneider Electric directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'Energy, Critical Manufacturing, Commercial Facilities', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'France', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Schneider Electric EcoStruxure Power Build Rapsody (Update A)', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-015-10', 'status': 'final', 'version': '4', 'generator': {'date': '2026-03-16T18:55:02.983970Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2026-01-13T08:00:00.000000Z', 'number': '1', 'summary': 'Original Release', 'legacy_version': 'Initial'}, {'date': '2026-01-14T22:35:43.622072Z', 'number': '2', 'summary': 'CISA Republication - Initial Republication of Schneider Electric SEVD-2026-013-04 advisory', 'legacy_version': 'Additional Release 1'}, {'date': '2026-03-10T07:00:00.000000Z', 'number': '3', 'summary': 'Removed the link to the fix for Rapsody Belgium version, which was privately communicated to impacted users', 'legacy_version': 'Additional Release 2'}, {'date': '2026-03-17T06:00:00.000000Z', 'number': '4', 'summary': 'Update A - Removed link to the fix for Rapsody Belgium version', 'legacy_version': 'Latest Updated CISA Republication'}], 'current_release_date': '2026-03-17T06:00:00.000000Z', 'initial_release_date': '2026-01-13T08:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-013-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-013-04.json', 'summary': 'Multiple Vulnerabilities on EcoStruxure Power Build Rapsody - SEVD-2026-013-04 CSAF Version', 'category': 'self'}, {'url': 'https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-013-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-013-04.pdf', 'summary': 'Multiple Vulnerabilities on EcoStruxure Power Build Rapsody - SEVD-2026-013-04 PDF Version', 'category': 'self'}, {'url': 'https://www.se.com/ww/en/download/document/7EN52-0390/', 'summary': 'Recommended Cybersecurity Best Practices', 'category': 'external'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-015-10.json', 'summary': 'ICS Advisory ICSA-26-015-10 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-015-10', 'summary': 'ICS Advisory ICSA-26-015-10 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Rocco Calvi'], 'summary': 'independently reported these vulnerabilities to CISA.', 'organization': 'in collaboration with Trend Zero Day Initiative (ZDI)'}, {'names': ['Michael Heinzl'], 'summary': 'independently reported these vulnerabilities to CISA.'}]}, 'product_tree': {'branches': [{'name': 'Schneider Electric', 'branches': [{'name': 'EcoStruxure Power Build Rapsody software', 'branches': [{'name': 'vers:generic/<=2.8.1_FR', 'product': {'name': 'EcoStruxure Power Build Rapsody software FR 2.8.1 and prior', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}, {'name': '2.8.1.0401_FR', 'product': {'name': 'EcoStruxure Power Build Rapsody software Version FR 2.8.1.0401', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version'}, {'name': 'vers:generic/<=2.8.6_INT', 'product': {'name': 'EcoStruxure Power Build Rapsody software INT 2.8.6 and prior', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}, {'name': '2.8.6.200_INT', 'product': {'name': 'EcoStruxure Power Build Rapsody software Version INT 2.8.6.200', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version'}, {'name': 'vers:generic/<=2.8.5_ES', 'product': {'name': 'EcoStruxure Power Build Rapsody software ES 2.8.5 and prior', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}, {'name': '2.8.5.0301_ES', 'product': {'name': 'EcoStruxure Power Build Rapsody software Version ES 2.8.5.0301', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version'}, {'name': 'vers:generic/<=2.8.3_BEL(NL)', 'product': {'name': 'EcoStruxure Power Build Rapsody software BEL(NL) 2.8.3 and prior', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version_range'}, {'name': '2.8.3.0201_BELNL', 'product': {'name': 'EcoStruxure Power Build Rapsody software Version BEL(NL) 2.8.3.0201', 'product_id': 'CSAFPID-0008'}, 'category': 'product_version'}, {'name': 'vers:generic/<=2.8.8_BEL(FR)', 'product': {'name': 'EcoStruxure Power Build Rapsody software BEL(FR) 2.8.8 and prior', 'product_id': 'CSAFPID-0009'}, 'category': 'product_version_range'}, {'name': '2.8.8.0201_BELFR', 'product': {'name': 'EcoStruxure Power Build Rapsody software Version BEL(FR) 2.8.8.0201', 'product_id': 'CSAFPID-0010'}, 'category': 'product_version'}, {'name': 'vers:generic/<=2.8.1.0300_FR', 'product': {'name': 'EcoStruxure Power Build Rapsody software FR 2.8.1.0300 and prior', 'product_id': 'CSAFPID-0011'}, 'category': 'product_version_range'}, {'name': 'vers:generic/<=2.8.5.0200_ES', 'product': {'name': 'EcoStruxure Power Build Rapsody software ES 2.8.5.0200 and prior', 'product_id': 'CSAFPID-0012'}, 'category': 'product_version_range'}, {'name': 'vers:generic/<=2.8.7.0100_PT', 'product': {'name': 'EcoStruxure Power Build Rapsody software PT 2.8.7.0100 and prior', 'product_id': 'CSAFPID-0013'}, 'category': 'product_version_range'}, {'name': '2.8.7.0101_PT', 'product': {'name': 'EcoStruxure Power Build Rapsody software Version PT 2.8.7.0101', 'product_id': 'CSAFPID-0014'}, 'category': 'product_version'}, {'name': 'vers:generic/<=2.8.8.0100_BEL(FR)', 'product': {'name': 'EcoStruxure Power Build Rapsody software BEL(FR) 2.8.8.0100 and prior', 'product_id': 'CSAFPID-0015'}, 'category': 'product_version_range'}, {'name': 'vers:generic/<=2.8.3.0100_BEL(EN)', 'product': {'name': 'EcoStruxure Power Build Rapsody software BEL(EN) 2.8.3.0100 and prior', 'product_id': 'CSAFPID-0016'}, 'category': 'product_version_range'}, {'name': '2.8.3.0201_BELEN', 'product': {'name': 'EcoStruxure Power Build Rapsody software Version BEL(EN) 2.8.3.0201', 'product_id': 'CSAFPID-0017'}, 'category': 'product_version'}, {'name': 'vers:generic/<=2.8.4.0300_INT(EN)', 'product': {'name': 'EcoStruxure Power Build Rapsody software INT(EN) 2.8.4.0300 and prior', 'product_id': 'CSAFPID-0018'}, 'category': 'product_version_range'}, {'name': '2.8.4.0401_INTEN', 'product': {'name': 'EcoStruxure Power Build Rapsody software Version INT(EN) 2.8.4.0401', 'product_id': 'CSAFPID-0019'}, 'category': 'product_version'}, {'name': 'vers:generic/<=2.8.2.0000_NL', 'product': {'name': 'EcoStruxure Power Build Rapsody software NL 2.8.2.0000 and prior', 'product_id': 'CSAFPID-0020'}, 'category': 'product_version_range'}, {'name': '2.8.2.000_NL', 'product': {'name': 'EcoStruxure Power Build Rapsody software Version NL 2.8.2.000', 'product_id': 'CSAFPID-0021'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-13844', 'cwe': {'id': 'CWE-415', 'name': 'Double Free'}, 'notes': [{'text': 'A double-free vulnerability may lead to heap memory corruption when an end user imports a malicious SSD project file shared by an attacker into Rapsody.', 'title': 'CVE Description', 'category': 'description'}, {'text': 'CVSS v4.0 Base Score 4.6 | Medium | [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L](https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L)', 'title': 'CVSS 4.0 Score', 'category': 'details'}], 'title': 'CVE-2025-13844', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0005', 'CSAFPID-0007', 'CSAFPID-0009']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-13844', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/415.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-country-selector/?pageType=product-range&sourceId=2309', 'details': 'Versions FR V2.8.1.0401, INT V2.8.6.200, and ES V2.8.5.0301 of EcoStruxure Power Build Rapsody includes a fix for the CVE-2025-13844 vulnerability and is available for download here: https://www.se.com/ww/en/product-country-selector/?pageType=product-range&sourceId=2309 \n\nRestart the service after installing the new version. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0005'], 'restart_required': {'category': 'service'}}, {'details': 'Versions BEL(NL) V2.8.3.0201 and BEL(FR) V2.8.8.0201 of EcoStruxure Power Build Rapsody includes a fix for the CVE-2025-13844 vulnerability, reach out to the Schneider Electric Customer Care Center for assistance. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0007', 'CSAFPID-0009'], 'restart_required': {'category': 'service'}}, {'details': 'If users choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: For CVE-2025-13844: - Only open projects from trusted sources - Ensure use of malware scans before opening any externally created Project', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0005', 'CSAFPID-0007', 'CSAFPID-0009'], 'restart_required': {'category': 'none'}}], 'product_status': {'fixed': ['CSAFPID-0002', 'CSAFPID-0004', 'CSAFPID-0006', 'CSAFPID-0008', 'CSAFPID-0010'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0005', 'CSAFPID-0007', 'CSAFPID-0009']}, 'acknowledgments': [{'names': ['Michael Heinzl']}]}, {'cve': 'CVE-2025-13845', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'A use-after-free vulnerability may allow remote code execution when an end user imports a malicious SSD project file into Rapsody.', 'title': 'CVE Description', 'category': 'description'}, {'text': 'CVSS v4.0 Base Score 8.4 | High | [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N](https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)', 'title': 'CVSS 4.0 Score', 'category': 'details'}], 'title': 'CVE-2025-13845', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0018', 'CSAFPID-0020']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-13845', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/416.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-country-selector/?pageType=product-range&sourceId=2309', 'details': 'Versions FR V2.8.1.0401, ESP V2.8.5.0301, PT V2.8.7.0101, INT(EN) V2.8.4.0401, and NL V2.8.2.000 of EcoStruxure Power Build Rapsody includes a fix for the CVE-2025-13845 vulnerability and are available for download here: https://www.se.com/ww/en/product-country-selector/?pageType=product-range&sourceId=2309 \n\nRestart the service after installing the new version.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0018', 'CSAFPID-0020'], 'restart_required': {'category': 'service'}}, {'details': 'Versions BEL(NL)V2.8.3.0201 and BEL(FR) V2.8.8.0201 of EcoStruxure Power Build Rapsody include a fix for the CVE-2025-13845 vulnerability, reach out to the Schneider Electric Customer Care Center for assistance.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0015', 'CSAFPID-0016'], 'restart_required': {'category': 'service'}}, {'details': 'If users choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: For CVE-2025-13845: - Only open projects from trusted sources - Ensure use of malware scans before opening any externally created Project', 'category': 'mitigation', 'product_ids': ['CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0018', 'CSAFPID-0020'], 'restart_required': {'category': 'none'}}], 'product_status': {'fixed': ['CSAFPID-0002', 'CSAFPID-0006', 'CSAFPID-0014', 'CSAFPID-0010', 'CSAFPID-0017', 'CSAFPID-0019', 'CSAFPID-0021'], 'known_affected': ['CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0018', 'CSAFPID-0020']}, 'acknowledgments': [{'organization': 'ZDI'}]}]} | |
ot | ICSA-26-015-10 | CVE-2025-13845 | Schneider Electric EcoStruxure Power Build Rapsody (Update A) | 2026-01-13 11:00:00+03:00 | 2026-03-17 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-015-10.json | 8970142d41c16fd9e5ddda331066250af6180add4a978bfe639e3ac42d0cefc5 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'Schneider Electric strongly recommends the following industry cybersecurity best practices.\n\n* Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.\n* Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.\n* Place all controllers in locked cabinets and never leave them in the “Program” mode.\n* Never connect programming software to any network other than the network intended for that device.\n* Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.\n* Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.\n* Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.\n* When remote access is required, use secure methods, such as virtual private networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.\n\nFor more information refer to the Schneider Electric [Recommended Cybersecurity Best Practices](https://www.se.com/us/en/download/document/7EN52-0390/) document.', 'title': 'General Security Recommendations', 'category': 'general'}, {'text': "This document provides an overview of the identified vulnerability or vulnerabilities and actions required to mitigate. For more details and assistance on how to protect your installation, contact your local Schneider Electric representative or Schneider Electric Industrial Cybersecurity Services: https://www.se.com/ww/en/work/solutions/cybersecurity/. These organizations will be fully aware of this situation and can support you through the process.\n\nFor further information related to cybersecurity in Schneider Electric's products, visit the company's cybersecurity support portal page: https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp", 'title': 'For More Information', 'category': 'general'}, {'text': 'THIS NOTIFICATION DOCUMENT, THE INFORMATION CONTAINED HEREIN, AND ANY MATERIALS LINKED FROM IT (COLLECTIVELY, THIS “NOTIFICATION”) ARE INTENDED TO HELP PROVIDE AN OVERVIEW OF THE IDENTIFIED SITUATION AND SUGGESTED MITIGATION ACTIONS, REMEDIATION, FIX, AND/OR GENERAL SECURITY RECOMMENDATIONS AND IS PROVIDED ON AN “AS-IS” BASIS WITHOUT WARRANTY OR GUARANTEE OF ANY KIND. SCHNEIDER ELECTRIC DISCLAIMS ALL WARRANTIES RELATING TO THIS NOTIFICATION, EITHER EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SCHNEIDER ELECTRIC MAKES NO WARRANTY THAT THE NOTIFICATION WILL RESOLVE THE IDENTIFIED SITUATION. IN NO EVENT SHALL SCHNEIDER ELECTRIC BE LIABLE FOR ANY DAMAGES OR LOSSES WHATSOEVER IN CONNECTION WITH THIS NOTIFICATION, INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF SCHNEIDER ELECTRIC HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. YOUR USE OF THIS NOTIFICATION IS AT YOUR OWN RISK, AND YOU ARE SOLELY LIABLE FOR ANY DAMAGES TO YOUR SYSTEMS OR ASSETS OR OTHER LOSSES THAT MAY RESULT FROM YOUR USE OF THIS NOTIFICATION. SCHNEIDER ELECTRIC RESERVES THE RIGHT TO UPDATE OR CHANGE THIS NOTIFICATION AT ANY TIME AND IN ITS SOLE DISCRETION', 'title': 'LEGAL DISCLAIMER', 'category': 'legal_disclaimer'}, {'text': "Schneider's purpose is to create impact by empowering all to make the most of our energy and resources, bridging progress and sustainability for all. We call this Life Is On.\n\nOur mission is to be the trusted partner in sustainability and efficiency.\n\nWe are a global industrial technology leader bringing world-leading expertise in electrification, automation and digitization to smart industries, resilient infrastructure, future-proof data centers, intelligent buildings, and intuitive homes. Anchored by our deep domain expertise, we provide integrated end-to-end lifecycle AI enabled industrial IoT solutions with connected products, automation, software and services, delivering digital twins to enable profitable growth for our users.\n\nWe are a people company with an ecosystem of 150,000 colleagues and more than a million partners operating in over 100 countries to ensure proximity to our users and stakeholders. We embrace diversity and inclusion in everything we do, guided by our meaningful purpose of a sustainable future for all. \n\n www.se.com", 'title': 'About Schneider Electric', 'category': 'general'}, {'text': 'Schneider Electric is aware of a vulnerability in its EcoStruxure Power Build Rapsody software. The [EcoStruxure Power Build Rapsody](https://www.se.com/ww/en/product-country-selector/?pageType=product-range&sourceId=2309) is used to enter or import the single line diagram, to get the extensive bill of material of your switchboard, including all devices, connection items, and mounting components. \n\nFailure to apply the mitigations/remediations provided below may risk memory corruption, heap-based buffer overflow, stack-based buffer overflow, which could result in local attackers being able to exploit these issues to potentially execute arbitrary code.', 'title': 'Overview', 'category': 'summary'}, {'text': "The severity of vulnerabilities was calculated using the CVSS base metrics for 4.0 ([CVSS v4.0](https://www.first.org/cvss/calculator/4.0)). CVSS v3.1 will be still evaluated until the adoption of CVSS v4.0 by the industry. The severity was calculated without incorporating the temporal and environmental metrics. Schneider Electric recommends that users score the CVSS environmental metrics, which are specific to end-user organizations, and consider factors such as the presence of mitigations in that environment. Environmental metrics may refine the relative severity posed by the vulnerabilities described in this document within a usmer's environment.", 'category': 'other'}, {'text': "Users should employ appropriate patching methodologies when applying these patches to their systems. Schneider Electric strongly recommends the use of back-ups and evaluating the impact of these patches in a test and development environment or on an offline infrastructure. Contact Schneider Electric's Customer Care Center at [https://www.se.com/us/en/work/support/contacts.jsp](https://www.se.com/us/en/work/support/contacts.jsp) if you need assistance removing a patch. ", 'category': 'other'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a republication of Schneider Electric SEVD-2026-013-04 from a direct conversion of the vendor\'s common security advisory framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Schneider Electric directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'Energy, Critical Manufacturing, Commercial Facilities', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'France', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Schneider Electric EcoStruxure Power Build Rapsody (Update A)', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-015-10', 'status': 'final', 'version': '4', 'generator': {'date': '2026-03-16T18:55:02.983970Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2026-01-13T08:00:00.000000Z', 'number': '1', 'summary': 'Original Release', 'legacy_version': 'Initial'}, {'date': '2026-01-14T22:35:43.622072Z', 'number': '2', 'summary': 'CISA Republication - Initial Republication of Schneider Electric SEVD-2026-013-04 advisory', 'legacy_version': 'Additional Release 1'}, {'date': '2026-03-10T07:00:00.000000Z', 'number': '3', 'summary': 'Removed the link to the fix for Rapsody Belgium version, which was privately communicated to impacted users', 'legacy_version': 'Additional Release 2'}, {'date': '2026-03-17T06:00:00.000000Z', 'number': '4', 'summary': 'Update A - Removed link to the fix for Rapsody Belgium version', 'legacy_version': 'Latest Updated CISA Republication'}], 'current_release_date': '2026-03-17T06:00:00.000000Z', 'initial_release_date': '2026-01-13T08:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-013-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2026-013-04.json', 'summary': 'Multiple Vulnerabilities on EcoStruxure Power Build Rapsody - SEVD-2026-013-04 CSAF Version', 'category': 'self'}, {'url': 'https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-013-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-013-04.pdf', 'summary': 'Multiple Vulnerabilities on EcoStruxure Power Build Rapsody - SEVD-2026-013-04 PDF Version', 'category': 'self'}, {'url': 'https://www.se.com/ww/en/download/document/7EN52-0390/', 'summary': 'Recommended Cybersecurity Best Practices', 'category': 'external'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-015-10.json', 'summary': 'ICS Advisory ICSA-26-015-10 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-015-10', 'summary': 'ICS Advisory ICSA-26-015-10 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Rocco Calvi'], 'summary': 'independently reported these vulnerabilities to CISA.', 'organization': 'in collaboration with Trend Zero Day Initiative (ZDI)'}, {'names': ['Michael Heinzl'], 'summary': 'independently reported these vulnerabilities to CISA.'}]}, 'product_tree': {'branches': [{'name': 'Schneider Electric', 'branches': [{'name': 'EcoStruxure Power Build Rapsody software', 'branches': [{'name': 'vers:generic/<=2.8.1_FR', 'product': {'name': 'EcoStruxure Power Build Rapsody software FR 2.8.1 and prior', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}, {'name': '2.8.1.0401_FR', 'product': {'name': 'EcoStruxure Power Build Rapsody software Version FR 2.8.1.0401', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version'}, {'name': 'vers:generic/<=2.8.6_INT', 'product': {'name': 'EcoStruxure Power Build Rapsody software INT 2.8.6 and prior', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}, {'name': '2.8.6.200_INT', 'product': {'name': 'EcoStruxure Power Build Rapsody software Version INT 2.8.6.200', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version'}, {'name': 'vers:generic/<=2.8.5_ES', 'product': {'name': 'EcoStruxure Power Build Rapsody software ES 2.8.5 and prior', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}, {'name': '2.8.5.0301_ES', 'product': {'name': 'EcoStruxure Power Build Rapsody software Version ES 2.8.5.0301', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version'}, {'name': 'vers:generic/<=2.8.3_BEL(NL)', 'product': {'name': 'EcoStruxure Power Build Rapsody software BEL(NL) 2.8.3 and prior', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version_range'}, {'name': '2.8.3.0201_BELNL', 'product': {'name': 'EcoStruxure Power Build Rapsody software Version BEL(NL) 2.8.3.0201', 'product_id': 'CSAFPID-0008'}, 'category': 'product_version'}, {'name': 'vers:generic/<=2.8.8_BEL(FR)', 'product': {'name': 'EcoStruxure Power Build Rapsody software BEL(FR) 2.8.8 and prior', 'product_id': 'CSAFPID-0009'}, 'category': 'product_version_range'}, {'name': '2.8.8.0201_BELFR', 'product': {'name': 'EcoStruxure Power Build Rapsody software Version BEL(FR) 2.8.8.0201', 'product_id': 'CSAFPID-0010'}, 'category': 'product_version'}, {'name': 'vers:generic/<=2.8.1.0300_FR', 'product': {'name': 'EcoStruxure Power Build Rapsody software FR 2.8.1.0300 and prior', 'product_id': 'CSAFPID-0011'}, 'category': 'product_version_range'}, {'name': 'vers:generic/<=2.8.5.0200_ES', 'product': {'name': 'EcoStruxure Power Build Rapsody software ES 2.8.5.0200 and prior', 'product_id': 'CSAFPID-0012'}, 'category': 'product_version_range'}, {'name': 'vers:generic/<=2.8.7.0100_PT', 'product': {'name': 'EcoStruxure Power Build Rapsody software PT 2.8.7.0100 and prior', 'product_id': 'CSAFPID-0013'}, 'category': 'product_version_range'}, {'name': '2.8.7.0101_PT', 'product': {'name': 'EcoStruxure Power Build Rapsody software Version PT 2.8.7.0101', 'product_id': 'CSAFPID-0014'}, 'category': 'product_version'}, {'name': 'vers:generic/<=2.8.8.0100_BEL(FR)', 'product': {'name': 'EcoStruxure Power Build Rapsody software BEL(FR) 2.8.8.0100 and prior', 'product_id': 'CSAFPID-0015'}, 'category': 'product_version_range'}, {'name': 'vers:generic/<=2.8.3.0100_BEL(EN)', 'product': {'name': 'EcoStruxure Power Build Rapsody software BEL(EN) 2.8.3.0100 and prior', 'product_id': 'CSAFPID-0016'}, 'category': 'product_version_range'}, {'name': '2.8.3.0201_BELEN', 'product': {'name': 'EcoStruxure Power Build Rapsody software Version BEL(EN) 2.8.3.0201', 'product_id': 'CSAFPID-0017'}, 'category': 'product_version'}, {'name': 'vers:generic/<=2.8.4.0300_INT(EN)', 'product': {'name': 'EcoStruxure Power Build Rapsody software INT(EN) 2.8.4.0300 and prior', 'product_id': 'CSAFPID-0018'}, 'category': 'product_version_range'}, {'name': '2.8.4.0401_INTEN', 'product': {'name': 'EcoStruxure Power Build Rapsody software Version INT(EN) 2.8.4.0401', 'product_id': 'CSAFPID-0019'}, 'category': 'product_version'}, {'name': 'vers:generic/<=2.8.2.0000_NL', 'product': {'name': 'EcoStruxure Power Build Rapsody software NL 2.8.2.0000 and prior', 'product_id': 'CSAFPID-0020'}, 'category': 'product_version_range'}, {'name': '2.8.2.000_NL', 'product': {'name': 'EcoStruxure Power Build Rapsody software Version NL 2.8.2.000', 'product_id': 'CSAFPID-0021'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-13844', 'cwe': {'id': 'CWE-415', 'name': 'Double Free'}, 'notes': [{'text': 'A double-free vulnerability may lead to heap memory corruption when an end user imports a malicious SSD project file shared by an attacker into Rapsody.', 'title': 'CVE Description', 'category': 'description'}, {'text': 'CVSS v4.0 Base Score 4.6 | Medium | [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L](https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L)', 'title': 'CVSS 4.0 Score', 'category': 'details'}], 'title': 'CVE-2025-13844', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 5.3, 'attackVector': 'LOCAL', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L', 'integrityImpact': 'LOW', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'LOW', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'LOW'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0005', 'CSAFPID-0007', 'CSAFPID-0009']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-13844', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/415.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-country-selector/?pageType=product-range&sourceId=2309', 'details': 'Versions FR V2.8.1.0401, INT V2.8.6.200, and ES V2.8.5.0301 of EcoStruxure Power Build Rapsody includes a fix for the CVE-2025-13844 vulnerability and is available for download here: https://www.se.com/ww/en/product-country-selector/?pageType=product-range&sourceId=2309 \n\nRestart the service after installing the new version. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0005'], 'restart_required': {'category': 'service'}}, {'details': 'Versions BEL(NL) V2.8.3.0201 and BEL(FR) V2.8.8.0201 of EcoStruxure Power Build Rapsody includes a fix for the CVE-2025-13844 vulnerability, reach out to the Schneider Electric Customer Care Center for assistance. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0007', 'CSAFPID-0009'], 'restart_required': {'category': 'service'}}, {'details': 'If users choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: For CVE-2025-13844: - Only open projects from trusted sources - Ensure use of malware scans before opening any externally created Project', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0005', 'CSAFPID-0007', 'CSAFPID-0009'], 'restart_required': {'category': 'none'}}], 'product_status': {'fixed': ['CSAFPID-0002', 'CSAFPID-0004', 'CSAFPID-0006', 'CSAFPID-0008', 'CSAFPID-0010'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0005', 'CSAFPID-0007', 'CSAFPID-0009']}, 'acknowledgments': [{'names': ['Michael Heinzl']}]}, {'cve': 'CVE-2025-13845', 'cwe': {'id': 'CWE-416', 'name': 'Use After Free'}, 'notes': [{'text': 'A use-after-free vulnerability may allow remote code execution when an end user imports a malicious SSD project file into Rapsody.', 'title': 'CVE Description', 'category': 'description'}, {'text': 'CVSS v4.0 Base Score 8.4 | High | [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N](https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)', 'title': 'CVSS 4.0 Score', 'category': 'details'}], 'title': 'CVE-2025-13845', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.8, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0018', 'CSAFPID-0020']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-13845', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/416.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-country-selector/?pageType=product-range&sourceId=2309', 'details': 'Versions FR V2.8.1.0401, ESP V2.8.5.0301, PT V2.8.7.0101, INT(EN) V2.8.4.0401, and NL V2.8.2.000 of EcoStruxure Power Build Rapsody includes a fix for the CVE-2025-13845 vulnerability and are available for download here: https://www.se.com/ww/en/product-country-selector/?pageType=product-range&sourceId=2309 \n\nRestart the service after installing the new version.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0018', 'CSAFPID-0020'], 'restart_required': {'category': 'service'}}, {'details': 'Versions BEL(NL)V2.8.3.0201 and BEL(FR) V2.8.8.0201 of EcoStruxure Power Build Rapsody include a fix for the CVE-2025-13845 vulnerability, reach out to the Schneider Electric Customer Care Center for assistance.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0015', 'CSAFPID-0016'], 'restart_required': {'category': 'service'}}, {'details': 'If users choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: For CVE-2025-13845: - Only open projects from trusted sources - Ensure use of malware scans before opening any externally created Project', 'category': 'mitigation', 'product_ids': ['CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0018', 'CSAFPID-0020'], 'restart_required': {'category': 'none'}}], 'product_status': {'fixed': ['CSAFPID-0002', 'CSAFPID-0006', 'CSAFPID-0014', 'CSAFPID-0010', 'CSAFPID-0017', 'CSAFPID-0019', 'CSAFPID-0021'], 'known_affected': ['CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0018', 'CSAFPID-0020']}, 'acknowledgments': [{'organization': 'ZDI'}]}]} | |
ot | ICSA-25-303-01 | CVE-2025-12357 | International Standards Organization ISO 15118-2 (Update A) | 2025-10-30 08:00:00+03:00 | 2026-03-17 08:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-303-01.json | ba2eb6b0d418bd81e027a2571c76324184327b88704286c05292df4182089abe | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of this vulnerability could result in man-in-the-middle attacks.', 'title': 'Risk evaluation', 'category': 'summary'}, {'text': 'Transportation Systems', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Switzerland', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'International Standards Organization ISO 15118-2 (Update A)', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-25-303-01', 'status': 'final', 'version': '2', 'generator': {'date': '2026-03-16T19:10:55.609499Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2025-10-30T05:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}, {'date': '2026-03-17T05:00:00.000000Z', 'number': '2', 'summary': 'Update A - Adjusted CVSS score based on feedback from ISO/IEC, added SSVC vector, changed document link in mitigation section, switched Standard back to Vendor in Exec Summary to prevent error in CSAF.', 'legacy_version': 'Update A'}], 'current_release_date': '2026-03-17T05:00:00.000000Z', 'initial_release_date': '2025-10-30T05:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-303-01.json', 'summary': 'ICS Advisory ICSA-25-303-01 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-25-303-01', 'summary': 'ICSA Advisory ICSA-25-303-01 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Mark I. Johnson'], 'summary': 'reported this vulnerability to CISA', 'organization': 'Southwest Research Institute'}]}, 'product_tree': {'branches': [{'name': 'ISO/IEC', 'branches': [{'name': 'ISO 15118 standard', 'branches': [{'name': 'Part 15118-2 Network and Application Protocol Requirements', 'product': {'name': 'ISO 15118 Standard: Part 15118-2 Network and Application Protocol Requirements', 'product_id': 'CSAFPID-0001'}, 'category': 'specification'}], 'category': 'specification'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-12357', 'cwe': {'id': 'CWE-923', 'name': 'Improper Restriction of Communication Channel to Intended Endpoints'}, 'notes': [{'text': 'By manipulating the Signal Level Attenuation Characterization (SLAC) protocol with spoofed measurements, an attacker can stage a man-in-the-middle attack between an electric vehicle and chargers that comply with the ISO 15118-2 part. This vulnerability may be exploitable wirelessly, within close proximity, via electromagnetic induction.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-03-16T05:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/923.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-12357', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'ISO recommends using TLS for all communications in accordance with ISO 15118-20. While the use of TLS is recommended in ISO 15118-2, it is required in the ISO 15118-20 revision. TLS should be implemented with certificate chaining.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.iec.ch/contact?id=40499', 'details': 'For additional information, please contact the International Electrotechnical Commission here: https://www.iec.ch/contact?id=40499.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-071-06 | CVE-2025-13913 | Inductive Automation Ignition Software | 2026-03-12 09:00:00+03:00 | 2026-03-13 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-071-06.json | 09dfec5ebccde8626550b3320d8bc321347eb94477846184216e546f49562660 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of this vulnerability could allow an attacker to execute malicious code with OS application service account permissions that the authenticated, privileged application user did not intend on running.', 'title': 'Risk evaluation', 'category': 'summary'}, {'text': 'Information Technology', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also recommends users take the following measures to protect themselves from social engineering attacks:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Do not click web links or open attachments in unsolicited email messages.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Inductive Automation Ignition Software', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-071-06', 'status': 'final', 'version': '2', 'generator': {'date': '2026-03-10T19:48:53.493644Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-03-12T06:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}, {'date': '2026-03-13T06:00:00.000000Z', 'number': '2', 'summary': 'Fixed a typo regarding advisory ID in references.', 'legacy_version': 'Additional Release 1'}], 'current_release_date': '2026-03-13T06:00:00.000000Z', 'initial_release_date': '2026-03-12T06:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-071-06.json', 'summary': 'ICS Advisory ICSA-26-071-06 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-071-06', 'summary': 'ICSA Advisory ICSA-26-071-06 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/ncas/tips/ST04-014', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Nik Tsytsarkin', 'Ismail Aydemir', 'Ryan Hall'], 'summary': 'reported this vulnerability to Inductive Automation', 'organization': 'Meta'}, {'names': ['Nathan Boeger', 'Joel Specht'], 'summary': 'reported this vulnerability to CISA', 'organization': 'Inductive Automation (security@inductiveautomation.com)'}]}, 'product_tree': {'branches': [{'name': 'Inductive Automation', 'branches': [{'name': 'Ignition Software', 'branches': [{'name': '<8.3.0', 'product': {'name': 'Inductive Automation Ignition Software: <8.3.0', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-13913', 'cwe': {'id': 'CWE-502', 'name': 'Deserialization of Untrusted Data'}, 'notes': [{'text': 'A privileged Ignition user, intentionally or otherwise, imports an external file with a specially crafted payload, which executes embedded malicious code during deserialization.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/502.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-13913', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Fix - upgrade Ignition software from 8.1.x to 8.3.0 or greater.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://inductiveautomation.com/resources/article/ignition-security-hardening-guide', 'details': 'MITIGATION (8.1.x Linux). Implement Ignition Security Hardening Guide Appendix A. https://inductiveautomation.com/resources/article/ignition-security-hardening-guide', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'MITIGATION (8.1.x Windows). Covered in Ignition Security Hardening Guide Appendix A. 1. Create a new dedicated local Windows account that will be used exclusively for the Ignition service (e.g. svc-ign). a. The best security practice is that the Ignition service should not be a domain account (unless otherwise needed). b. Remove all group memberships from the service account (including Users and Administrators). c. Add to security policy to log in as a service. d. Add to "Deny log on locally" security policy. 2. Provide full read/write access only to the Ignition installation directory for the service account created in #1. a. Add read/write permissions to other directories in the local filesystem as needed (e.g.: if configured to use optional Enterprise Administration Module to write automated backups to the file system). 3. Set deny access settings for service account on other directories not needed by the Ignition service. a. Specifically the C:\\Windows, C:\\Users, and directories for any other applications in the Program Files or Program Files(x86) directories. b. Use java param to change temp directory to a location within the Ignition install directory so the Users folder can be denied access to the Ignition service account.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://docs.inductiveautomation.com/docs/8.3/tutorials/ignition-8-deployment-best-practices', 'details': 'BEST PRACTICES (8.1.x and 8.3.x)4. Restrict project imports to verified and trusted sources only, ideally using checksums or digital signatures.5. Use multiple environments (e.g. Dev, Test, Prod) with a staging workflow so that new data is never introduced directly to Production environments. See Ignition Deployment Best Practices.6. When feasible, segment or isolate Ignition gateways from corporate resources and Windows Domains.a. The Ignition service account or AD server object should never need Windows Domain or Windows Active Directory privileges. This would only be needed if an Asset Owners IT or OT department uses this for management outside Ignition.b. Ignition may be federated with Active Directory environments (e.g. OT domains) by entering "Authentication Profile" credentials within the Ignition gateway itself. This could use secure LDAP, SAML, or OpenID Connect.7. When feasible, enforce strong credential management and MFA for all users with Designer permissions (8.1.x and 8.3.x), Config Page permissions (8.1.x), and Config Write permissions (8.3.x).8. When feasible, deploy Ignition within hardened or containerized environments.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-071-05 | CVE-2025-27769 | Siemens Heliox EV Chargers | 2026-03-10 03:00:00+03:00 | 2026-03-12 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-071-05.json | d816640b31cc3099d01b993d5d00de0de817836bd35f9240b11cb697ececa13f | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'Heliox EV Chargers listed below contain improper access control vulnerability that could allow an attacker to reach unauthorized services via the charging cable.\n\nSiemens has released new versions for the affected products and recommends to update to the latest versions.', 'title': 'Summary', 'category': 'summary'}, {'text': "As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals.\nAdditional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity", 'title': 'General Recommendations', 'category': 'general'}, {'text': 'For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.', 'title': 'Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of Siemens ProductCERT SSA-126399 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Germany', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Siemens Heliox EV Chargers', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-071-05', 'status': 'final', 'version': '2', 'generator': {'date': '2026-03-11T19:40:47.769762Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2026-03-10T00:00:00.000000Z', 'number': '1', 'summary': 'Publication Date', 'legacy_version': 'Initial'}, {'date': '2026-03-12T06:00:00.000000Z', 'number': '2', 'summary': 'Initial CISA Republication of Siemens ProductCERT SSA-126399 advisory', 'legacy_version': 'CISA Republication'}], 'current_release_date': '2026-03-12T06:00:00.000000Z', 'initial_release_date': '2026-03-10T00:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://cert-portal.siemens.com/productcert/csaf/ssa-126399.json', 'summary': 'SSA-126399: Improper Access Control Vulnerability in Heliox EV Chargers - CSAF Version', 'category': 'self'}, {'url': 'https://cert-portal.siemens.com/productcert/html/ssa-126399.html', 'summary': 'SSA-126399: Improper Access Control Vulnerability in Heliox EV Chargers - HTML Version', 'category': 'self'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-071-05.json', 'summary': 'ICS Advisory ICSA-26-071-05 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-071-05', 'summary': 'ICS Advisory ICSA-26-071-05 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported this vulnerability to CISA.', 'organization': 'Siemens ProductCERT'}]}, 'product_tree': {'branches': [{'name': 'Siemens', 'branches': [{'name': 'Heliox Flex 180 kW EV Charging Station', 'branches': [{'name': '<F4.11.1', 'product': {'name': 'Heliox Flex 180 kW EV Charging Station', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Heliox Mobile DC 40 kW EV Charging Station', 'branches': [{'name': '<L4.10.1', 'product': {'name': 'Heliox Mobile DC 40 kW EV Charging Station', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-27769', 'cwe': {'id': 'CWE-923', 'name': 'Improper Restriction of Communication Channel to Intended Endpoints'}, 'notes': [{'text': 'Affected devices contain improper access control that could allow an attacker to reach unauthorized services via the charging cable.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2025-27769', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 2.6, 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-27769', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/923.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Contact customer support for patch information via OTA update', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002']}}]} | |
ot | ICSA-26-071-03 | CVE-2024-29857 | Siemens SIDIS Prime | 2026-03-10 03:00:00+03:00 | 2026-03-12 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-071-03.json | 09a85528e45d3990b5e18f1696820d8d165296a24cfcd3f37e10b39e73b9ecf0 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'SIDIS Prime before V4.0.800 is affected by multiple vulnerabilities in the components OpenSSL, SQLite, and several Node.js packages as described below.\n\nSiemens has released a new version of SIDIS Prime and recommends to update to the latest version.', 'title': 'Summary', 'category': 'summary'}, {'text': "As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals.\nAdditional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity", 'title': 'General Recommendations', 'category': 'general'}, {'text': 'For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.', 'title': 'Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of Siemens ProductCERT SSA-485750 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Germany', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Siemens SIDIS Prime', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-071-03', 'status': 'final', 'version': '2', 'generator': {'date': '2026-03-11T20:56:12.127996Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2026-03-10T00:00:00.000000Z', 'number': '1', 'summary': 'Publication Date', 'legacy_version': 'Initial'}, {'date': '2026-03-12T06:00:00.000000Z', 'number': '2', 'summary': 'Initial CISA Republication of Siemens ProductCERT SSA-485750 advisory', 'legacy_version': 'CISA Republication'}], 'current_release_date': '2026-03-12T06:00:00.000000Z', 'initial_release_date': '2026-03-10T00:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://cert-portal.siemens.com/productcert/csaf/ssa-485750.json', 'summary': 'SSA-485750: Multiple Vulnerabilities in SIDIS Prime Before V4.0.800 - CSAF Version', 'category': 'self'}, {'url': 'https://cert-portal.siemens.com/productcert/html/ssa-485750.html', 'summary': 'SSA-485750: Multiple Vulnerabilities in SIDIS Prime Before V4.0.800 - HTML Version', 'category': 'self'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-26-071-03.json', 'summary': 'ICS Advisory ICSA-26-071-03 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-071-03', 'summary': 'ICS Advisory ICSA-26-071-03 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to CISA.', 'organization': 'Siemens ProductCERT'}]}, 'product_tree': {'branches': [{'name': 'Siemens', 'branches': [{'name': 'SIDIS Prime', 'branches': [{'name': 'vers:intdot/<4.0.800', 'product': {'name': 'SIDIS Prime', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2024-29857', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': 'An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2024-29857', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2024-29857', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/125.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V4.0.800 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2024-30171', 'cwe': {'id': 'CWE-203', 'name': 'Observable Discrepancy'}, 'notes': [{'text': 'An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2024-30171', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2024-30171', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/203.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V4.0.800 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2024-30172', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2024-30172', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2024-30172', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V4.0.800 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2024-41996', 'cwe': {'id': 'CWE-295', 'name': 'Improper Certificate Validation'}, 'notes': [{'text': 'Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2024-41996', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2024-41996', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/295.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V4.0.800 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-6965', 'cwe': {'id': 'CWE-197', 'name': 'Numeric Truncation Error'}, 'notes': [{'text': 'There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2025-6965', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-6965', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/197.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V4.0.800 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-7783', 'cwe': {'id': 'CWE-330', 'name': 'Use of Insufficiently Random Values'}, 'notes': [{'text': 'Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability is associated with program files lib/form_data.Js.\r\n\r\nThis issue affects form-data: < 2.5.4, 3.0.0 - 3.0.3, 4.0.0 - 4.0.3.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2025-7783', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-7783', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/330.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V4.0.800 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-9230', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could be severe, the probability that the attacker would be able to perform it is low. Besides, password based (PWRI) encryption support in CMS messages is very rarely used. For that reason the issue was assessed as Moderate severity according to our Security Policy. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2025-9230', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.6, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-9230', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V4.0.800 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-9232', 'cwe': {'id': 'CWE-125', 'name': 'Out-of-bounds Read'}, 'notes': [{'text': "Issue summary: An application using the OpenSSL HTTP client API functions may\ntrigger an out-of-bounds read if the 'no_proxy' environment variable is set and\nthe host portion of the authority component of the HTTP URL is an IPv6 address.\n\nImpact summary: An out-of-bounds read can trigger a crash which leads to\nDenial of Service for an application.\n\nThe OpenSSL HTTP client API functions can be used directly by applications\nbut they are also used by the OCSP client functions and CMP (Certificate\nManagement Protocol) client implementation in OpenSSL. However the URLs used\nby these implementations are unlikely to be controlled by an attacker.\n\nIn this vulnerable code the out of bounds read can only trigger a crash.\nFurthermore the vulnerability requires an attacker-controlled URL to be\npassed from an application to the OpenSSL function and the user has to have\na 'no_proxy' environment variable set. For the aforementioned reasons the\nissue was assessed as Low severity.\n\nThe vulnerable code was introduced in the following patch releases:\n3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0 and 3.5.0.\n\nThe FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this\nissue, as the HTTP client implementation is outside the OpenSSL FIPS module\nboundary.", 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2025-9232', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-9232', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/125.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V4.0.800 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-9670', 'cwe': {'id': 'CWE-1333', 'name': 'Inefficient Regular Expression Complexity'}, 'notes': [{'text': 'A security flaw has been discovered in mixmark-io turndown up to 7.2.1. This affects an unknown function of the file src/commonmark-rules.js. Performing manipulation results in inefficient regular expression complexity. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2025-9670', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-9670', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/1333.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V4.0.800 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-12816', 'cwe': {'id': 'CWE-436', 'name': 'Interpretation Conflict'}, 'notes': [{'text': 'An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and security decisions.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2025-12816', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.6, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-12816', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/436.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V4.0.800 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-15284', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': "Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: < 6.14.1.\n\n\nSummaryThe arrayLimit\xa0option in qs does not enforce limits for bracket notation (a[]=1&a[]=2), allowing attackers to cause denial-of-service via memory exhaustion. Applications using arrayLimit\xa0for DoS protection are vulnerable.\n\nDetailsThe arrayLimit\xa0option only checks limits for indexed notation (a[0]=1&a[1]=2) but completely bypasses it for bracket notation (a[]=1&a[]=2).\n\nVulnerable code\xa0(lib/parse.js:159-162):\n\nif (root === '[]' && options.parseArrays) {\n obj = utils.combine([], leaf); // No arrayLimit check\n}\n\n\n\n\n\nWorking code\xa0(lib/parse.js:175):\n\nelse if (index <= options.arrayLimit) { // Limit checked here\n obj = [];\n obj[index] = leaf;\n}\n\n\n\n\n\nThe bracket notation handler at line 159 uses utils.combine([], leaf)\xa0without validating against options.arrayLimit, while indexed notation at line 175 checks index <= options.arrayLimit\xa0before creating arrays.\n\nPoCTest 1 - Basic bypass:\n\nnpm install qs\n\n\n\n\n\nconst qs = require('qs');\nconst result = qs.parse('a[]=1&a[]=2&a[]=3&a[]=4&a[]=5&a[]=6', { arrayLimit: 5 });\nconsole.log(result.a.length); // Output: 6 (should be max 5)\n\n\n\n\n\nTest 2 - DoS demonstration:\n\nconst qs = require('qs');\nconst attack = 'a[]=' + Array(10000).fill('x').join('&a[]=');\nconst result = qs.parse(attack, { arrayLimit: 100 });\nconsole.log(result.a.length); // Output: 10000 (should be max 100)\n\n\n\n\n\nConfiguration:\n\n * arrayLimit: 5\xa0(test 1) or arrayLimit: 100\xa0(test 2)\n * Use bracket notation: a[]=value\xa0(not indexed a[0]=value)\n\n\nImpactDenial of Service via memory exhaustion. Affects applications using qs.parse()\xa0with user-controlled input and arrayLimit\xa0for protection.\n\nAttack scenario:\n\n * Attacker sends HTTP request: GET /api/search?filters[]=x&filters[]=x&...&filters[]=x\xa0(100,000+ times)\n * Application parses with qs.parse(query, { arrayLimit: 100 })\n * qs ignores limit, parses all 100,000 elements into array\n * Server memory exhausted → application crashes or becomes unresponsive\n * Service unavailable for all users\nReal-world impact:\n\n * Single malicious request can crash server\n * No authentication required\n * Easy to automate and scale\n * Affects any endpoint parsing query strings with bracket notation", 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2025-15284', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-15284', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V4.0.800 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-58751', 'cwe': {'id': 'CWE-22', 'name': "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"}, 'notes': [{'text': 'Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the public directory were served bypassing the `server.fs` settings. Only apps that explicitly expose the Vite dev server to the network (using --host or `server.host` config option), use the public directory feature (enabled by default), and have a symlink in the public directory are affected. Versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20 fix the issue.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2025-58751', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-58751', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/22.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V4.0.800 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-58752', 'cwe': {'id': 'CWE-23', 'name': 'Relative Path Traversal'}, 'notes': [{'text': "Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served regardless of the `server.fs` settings. Only apps that explicitly expose the Vite dev server to the network (using --host or server.host config option) and use `appType: 'spa'` (default) or `appType: 'mpa'` are affected. This vulnerability also affects the preview server. The preview server allowed HTML files not under the output directory to be served. Versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20 fix the issue.", 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2025-58752', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-58752', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/23.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V4.0.800 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-58754', 'cwe': {'id': 'CWE-770', 'name': 'Allocation of Resources Without Limits or Throttling'}, 'notes': [{'text': "Axios is a promise based HTTP client for the browser and Node.js. When Axios starting in version 0.28.0 and prior to versions 0.30.2 and 1.12.0 runs on Node.js and is given a URL with the `data:` scheme, it does not perform HTTP. Instead, its Node http adapter decodes the entire payload into memory (`Buffer`/`Blob`) and returns a synthetic 200 response. This path ignores `maxContentLength` / `maxBodyLength` (which only protect HTTP responses), so an attacker can supply a very large `data:` URI and cause the process to allocate unbounded memory and crash (DoS), even if the caller requested `responseType: 'stream'`. Versions 0.30.2 and 1.12.0 contain a patch for the issue.", 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2025-58754', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-58754', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/770.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V4.0.800 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-62522', 'cwe': {'id': 'CWE-22', 'name': "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"}, 'notes': [{'text': 'Vite is a frontend tooling framework for JavaScript. In versions from 2.9.18 to before 3.0.0, 3.2.9 to before 4.0.0, 4.5.3 to before 5.0.0, 5.2.6 to before 5.4.21, 6.0.0 to before 6.4.1, 7.0.0 to before 7.0.8, and 7.1.0 to before 7.1.11, files denied by server.fs.deny were sent if the URL ended with \\ when the dev server is running on Windows. Only apps explicitly exposing the Vite dev server to the network and running the dev server on Windows were affected. This issue has been patched in versions 5.4.21, 6.4.1, 7.0.8, and 7.1.11.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2025-62522', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-62522', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/22.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V4.0.800 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-64718', 'cwe': {'id': 'CWE-1321', 'name': "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')"}, 'notes': [{'text': "js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (`__proto__`). All users who parse untrusted yaml documents may be impacted. The problem is patched in js-yaml 4.1.1 and 3.14.2. Users can protect against this kind of attack on the server by using `node --disable-proto=delete` or `deno` (in Deno, pollution protection is on by default).", 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2025-64718', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-64718', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/1321.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V4.0.800 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-64756', 'cwe': {'id': 'CWE-78', 'name': "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}, 'notes': [{'text': 'Glob matches files using patterns the shell uses. Starting in version 10.2.0 and prior to versions 10.5.0 and 11.1.0, the glob CLI contains a command injection vulnerability in its -c/--cmd option that allows arbitrary command execution when processing files with malicious names. When glob -c <command> <patterns> are used, matched filenames are passed to a shell with shell: true, enabling shell metacharacters in filenames to trigger command injection and achieve arbitrary code execution under the user or CI account privileges. This issue has been patched in versions 10.5.0 and 11.1.0.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2025-64756', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-64756', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/78.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V4.0.800 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-66030', 'cwe': {'id': 'CWE-190', 'name': 'Integer Overflow or Wraparound'}, 'notes': [{'text': 'Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller, trusted OIDs due to 32-bit bitwise truncation, enabling the bypass of downstream OID-based security decisions. This issue has been patched in version 1.3.2.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2025-66030', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-66030', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/190.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V4.0.800 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-66031', 'cwe': {'id': 'CWE-674', 'name': 'Uncontrolled Recursion'}, 'notes': [{'text': 'Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2025-66031', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-66031', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/674.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V4.0.800 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-66035', 'cwe': {'id': 'CWE-201', 'name': 'Insertion of Sensitive Information Into Sent Data'}, 'notes': [{'text': "Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site Request Forgery (XSRF) token to an attacker-controlled domain. Angular's HttpClient has a built-in XSRF protection mechanism that works by checking if a request URL starts with a protocol (http:// or https://) to determine if it is cross-origin. If the URL starts with protocol-relative URL (//), it is incorrectly treated as a same-origin request, and the XSRF token is automatically added to the X-XSRF-TOKEN header. This issue has been patched in versions 19.2.16, 20.3.14, and 21.0.1. A workaround for this issue involves avoiding using protocol-relative URLs (URLs starting with //) in HttpClient requests. All backend communication URLs should be hardcoded as relative paths (starting with a single /) or fully qualified, trusted absolute URLs.", 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2025-66035', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.6, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-66035', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/201.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V4.0.800 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-66412', 'cwe': {'id': 'CWE-79', 'name': "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"}, 'notes': [{'text': "Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 21.0.2, 20.3.15, and 19.2.17, A Stored Cross-Site Scripting (XSS) vulnerability has been identified in the Angular Template Compiler. It occurs because the compiler's internal security schema is incomplete, allowing attackers to bypass Angular's built-in security sanitization. Specifically, the schema fails to classify certain URL-holding attributes (e.g., those that could contain javascript: URLs) as requiring strict URL security, enabling the injection of malicious scripts. This vulnerability is fixed in 21.0.2, 20.3.15, and 19.2.17.", 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2025-66412', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-66412', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/79.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V4.0.800 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-69277', 'cwe': {'id': 'CWE-184', 'name': 'Incomplete List of Disallowed Inputs'}, 'notes': [{'text': "libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.", 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2025-69277', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-69277', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/184.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V4.0.800 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-22610', 'cwe': {'id': 'CWE-79', 'name': "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"}, 'notes': [{'text': 'Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.18, 20.3.16, 21.0.7, and 21.1.0-rc.0, a cross-site scripting (XSS) vulnerability has been identified in the Angular Template Compiler. The vulnerability exists because Angular’s internal sanitization schema fails to recognize the href and xlink:href attributes of SVG <script> elements as a Resource URL context. This issue has been patched in versions 19.2.18, 20.3.16, 21.0.7, and 21.1.0-rc.0.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2026-22610', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.0, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2026-22610', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/79.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Update to V4.0.800 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-25-350-02 | CVE-2025-61740 | Johnson Controls PowerG, IQPanel and IQHub (Update A) | 2025-12-16 10:00:00+03:00 | 2026-03-05 10:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-350-02.json | d76e91a1d25e81b81b2fdeb459c4bc4e3c27c05a6739ceca14c0646d6715f0b0 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could allow an attacker to read or write encrypted traffic or perform a replay attack.', 'title': 'Risk evaluation', 'category': 'summary'}, {'text': 'Commercial Facilities', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Ireland', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also recommends users take the following measures to protect themselves from social engineering attacks:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Do not click web links or open attachments in unsolicited email messages.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Johnson Controls PowerG, IQPanel and IQHub (Update A)', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-25-350-02', 'status': 'final', 'version': '2', 'generator': {'date': '2026-03-04T21:15:53.441194Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2025-12-16T07:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}, {'date': '2026-03-05T07:00:00.000000Z', 'number': '2', 'summary': 'Update A - Updated vulnerability description 3.2.1, added additional mitigation details and updated vendor advisory link', 'legacy_version': 'Update A'}], 'current_release_date': '2026-03-05T07:00:00.000000Z', 'initial_release_date': '2025-12-16T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-350-02.json', 'summary': 'ICS Advisory ICSA-25-350-02 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-25-350-02', 'summary': 'ICSA Advisory ICSA-25-350-02 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/ncas/tips/ST04-014', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['James Chambers', 'Sultan Qasim Khan'], 'summary': 'reported these vulnerabilities to CISA', 'organization': 'NCC Group'}]}, 'product_tree': {'branches': [{'name': 'Johnson Controls Inc.', 'branches': [{'name': 'PowerG', 'branches': [{'name': '<=53.02', 'product': {'name': 'Johnson Controls Inc. PowerG: <=53.02', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'IQHub', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Johnson Controls Inc. IQHub: vers:all/*', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'IQPanel 2', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Johnson Controls Inc. IQPanel 2: vers:all/*', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'IQPanel 2+', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Johnson Controls Inc. IQPanel 2+: vers:all/*', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'IQPanel 4', 'branches': [{'name': '<4.6.1', 'product': {'name': 'Johnson Controls Inc. IQPanel 4: <4.6.1', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-61738', 'cwe': {'id': 'CWE-319', 'name': 'Cleartext Transmission of Sensitive Information'}, 'notes': [{'text': 'Under specific circumstances, the product becomes vulnerable due to cleartext transmission of sensitive information. In these situations, an attacker can capture the network key and read or write encrypted packets on the PowerG network.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.3, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/319.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-61738', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Johnson Controls recommends the following:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005']}, {'details': 'Ensure only trusted devices are on the wireless network', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005']}, {'details': 'Prior to enrolling any devices, it is strongly recommended to update IQPanel 4 to version 4.6.1/4.6.1i or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Devices that support PowerG+ should use PowerG v53.05 or later.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'During the installation or enrollment phase of setup, enter the PIN code in the PIN Code field on the sensor enrollment screen. For additional security, Johnson Controls recommends only authorized company personnel or integrators be present during the installation/pairing/enrollment process.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005']}, {'details': 'If replacing a PowerG device, consider replacing all end-of-life products (IQ Panel 2, IQ Panel 2+, IQ Hub) with the latest IQ Panel 4 using firmware version 4.6.1 or greater.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories', 'details': 'For more detailed mitigation instructions, see Johnson Controls Product Security Advisory JCI-PSA-2025-01 v2 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005']}, {'url': 'https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories', 'details': 'Further ICS security notices and product security guidance are located at Johnson Controls Trust Center website: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005']}}, {'cve': 'CVE-2025-61739', 'cwe': {'id': 'CWE-323', 'name': 'Reusing a Nonce, Key Pair in Encryption'}, 'notes': [{'text': 'The affected product is vulnerable due to nonce reuse, which may allow an attacker to perform a replay attack or decrypt captured packets.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.6, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/323.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-61739', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Johnson Controls recommends the following:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005']}, {'details': 'Ensure only trusted devices are on the wireless network', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005']}, {'details': 'Prior to enrolling any devices, it is strongly recommended to update IQPanel 4 to version 4.6.1/4.6.1i or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Devices that support PowerG+ should use PowerG v53.05 or later.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'During the installation or enrollment phase of setup, enter the PIN code in the PIN Code field on the sensor enrollment screen. For additional security, Johnson Controls recommends only authorized company personnel or integrators be present during the installation/pairing/enrollment process.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005']}, {'details': 'If replacing a PowerG device, consider replacing all end-of-life products (IQ Panel 2, IQ Panel 2+, IQ Hub) with the latest IQ Panel 4 using firmware version 4.6.1 or greater.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories', 'details': 'For more detailed mitigation instructions, see Johnson Controls Product Security Advisory JCI-PSA-2025-01 v2 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005']}, {'url': 'https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories', 'details': 'Further ICS security notices and product security guidance are located at Johnson Controls Trust Center website: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005']}}, {'cve': 'CVE-2025-26379', 'cwe': {'id': 'CWE-338', 'name': 'Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)'}, 'notes': [{'text': 'The affected product is vulnerable due to a weak pseudo-random number generator. This may allow an attacker to read or inject encrypted PowerG packets.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.6, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/338.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-26379', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Johnson Controls recommends the following:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005']}, {'details': 'Ensure only trusted devices are on the wireless network', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005']}, {'details': 'Prior to enrolling any devices, it is strongly recommended to update IQPanel 4 to version 4.6.1/4.6.1i or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Devices that support PowerG+ should use PowerG v53.05 or later.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'During the installation or enrollment phase of setup, enter the PIN code in the PIN Code field on the sensor enrollment screen. For additional security, Johnson Controls recommends only authorized company personnel or integrators be present during the installation/pairing/enrollment process.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005']}, {'details': 'If replacing a PowerG device, consider replacing all end-of-life products (IQ Panel 2, IQ Panel 2+, IQ Hub) with the latest IQ Panel 4 using firmware version 4.6.1 or greater.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories', 'details': 'For more detailed mitigation instructions, see Johnson Controls Product Security Advisory JCI-PSA-2025-01 v2 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005']}, {'url': 'https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories', 'details': 'Further ICS security notices and product security guidance are located at Johnson Controls Trust Center website: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005']}}, {'cve': 'CVE-2025-61740', 'cwe': {'id': 'CWE-346', 'name': 'Origin Validation Error'}, 'notes': [{'text': 'The affected product is vulnerable to an authentication issue that does not verify the source of a packet. This could allow an attacker to create a denial-of-service condition or modify the configuration of the device.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.6, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/346.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-61740', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Johnson Controls recommends the following:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005']}, {'details': 'Ensure only trusted devices are on the wireless network', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005']}, {'details': 'Prior to enrolling any devices, it is strongly recommended to update IQPanel 4 to version 4.6.1/4.6.1i or later', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': 'Devices that support PowerG+ should use PowerG v53.05 or later.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'During the installation or enrollment phase of setup, enter the PIN code in the PIN Code field on the sensor enrollment screen. For additional security, Johnson Controls recommends only authorized company personnel or integrators be present during the installation/pairing/enrollment process.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005']}, {'details': 'If replacing a PowerG device, consider replacing all end-of-life products (IQ Panel 2, IQ Panel 2+, IQ Hub) with the latest IQ Panel 4 using firmware version 4.6.1 or greater.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories', 'details': 'For more detailed mitigation instructions, see Johnson Controls Product Security Advisory JCI-PSA-2025-01 v2 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005']}, {'url': 'https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories', 'details': 'Further ICS security notices and product security guidance are located at Johnson Controls Trust Center website: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005']}}]} | |
ot | ICSA-25-343-01 | CVE-2025-24857 | Universal Boot Loader (U-Boot) (Update A) | 2025-12-09 10:00:00+03:00 | 2026-03-05 10:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-343-01.json | 16870b6d25448726185443a1b7fea9d77ffe7921e068b3a4a851868e745bee3f | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of this vulnerability could result in arbitrary code execution.', 'title': 'Risk evaluation', 'category': 'summary'}, {'text': 'Chemical, Commercial Facilities, Communications, Critical Manufacturing, Dams, Defense Industrial Base, Emergency Services, Energy, Financial Services, Food and Agriculture, Government Services and Facilities, Healthcare and Public Health, Information Technology, Water and Wastewater, Transportation Systems, Water and Wastewater', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Universal Boot Loader (U-Boot) (Update A)', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-25-343-01', 'status': 'final', 'version': '2', 'generator': {'date': '2026-03-04T21:15:53.264261Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2025-12-09T07:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}, {'date': '2026-03-05T07:00:00.000000Z', 'number': '2', 'summary': 'Update A - Added Johnson Controls Airwall AW-75 to the affected products and mitigations', 'legacy_version': 'Update A'}], 'current_release_date': '2026-03-05T07:00:00.000000Z', 'initial_release_date': '2025-12-09T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-343-01.json', 'summary': 'ICS Advisory ICSA-25-343-01 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-25-343-01', 'summary': 'ICSA Advisory ICSA-25-343-01 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Harvey Phillips'], 'summary': 'reported this vulnerability to CISA', 'organization': 'Amazon Element55'}]}, 'product_tree': {'branches': [{'name': 'U-Boot', 'branches': [{'name': 'U-boot', 'branches': [{'name': '<2017.11', 'product': {'name': 'U-Boot U-boot: <2017.11', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}, {'name': 'Qualcomm', 'branches': [{'name': 'Chipset', 'branches': [{'name': 'IPQ4019', 'product': {'name': 'Qualcomm Chipset IPQ4019', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version'}, {'name': 'IPQ5018', 'product': {'name': 'Qualcomm Chipset IPQ5018', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version'}, {'name': 'IPQ5322', 'product': {'name': 'Qualcomm Chipset IPQ5322', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version'}, {'name': 'IPQ6018', 'product': {'name': 'Qualcomm Chipset IPQ6018', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version'}, {'name': 'IPQ8064', 'product': {'name': 'Qualcomm Chipset IPQ8064', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version'}, {'name': 'IPQ8074', 'product': {'name': 'Qualcomm Chipset IPQ8074', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version'}, {'name': 'IPQ9574', 'product': {'name': 'Qualcomm Chipset IPQ9574', 'product_id': 'CSAFPID-0008'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'vendor'}, {'name': 'Johnson Controls', 'branches': [{'name': 'Airwall AW-75', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Johnson Controls Airwall AW-75 vers:all/*', 'product_id': 'CSAFPID-0009'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'U-Boot U-boot: <2017.11 installed on Qualcomm Chipset IPQ4019', 'product_id': 'CSAFPID-0010'}, 'product_reference': 'CSAFPID-0001', 'relates_to_product_reference': 'CSAFPID-0002'}, {'category': 'installed_on', 'full_product_name': {'name': 'U-Boot U-boot: <2017.11 installed on Qualcomm Chipset IPQ5018', 'product_id': 'CSAFPID-0011'}, 'product_reference': 'CSAFPID-0001', 'relates_to_product_reference': 'CSAFPID-0003'}, {'category': 'installed_on', 'full_product_name': {'name': 'U-Boot U-boot: <2017.11 installed on Qualcomm Chipset IPQ5322', 'product_id': 'CSAFPID-0012'}, 'product_reference': 'CSAFPID-0001', 'relates_to_product_reference': 'CSAFPID-0004'}, {'category': 'installed_on', 'full_product_name': {'name': 'U-Boot U-boot: <2017.11 installed on Qualcomm Chipset IPQ6018', 'product_id': 'CSAFPID-0013'}, 'product_reference': 'CSAFPID-0001', 'relates_to_product_reference': 'CSAFPID-0005'}, {'category': 'installed_on', 'full_product_name': {'name': 'U-Boot U-boot: <2017.11 installed on Qualcomm Chipset IPQ8064', 'product_id': 'CSAFPID-0014'}, 'product_reference': 'CSAFPID-0001', 'relates_to_product_reference': 'CSAFPID-0006'}, {'category': 'installed_on', 'full_product_name': {'name': 'U-Boot U-boot: <2017.11 installed on Qualcomm Chipset IPQ8074', 'product_id': 'CSAFPID-0015'}, 'product_reference': 'CSAFPID-0001', 'relates_to_product_reference': 'CSAFPID-0007'}, {'category': 'installed_on', 'full_product_name': {'name': 'U-Boot U-boot: <2017.11 installed on Qualcomm Chipset IPQ9574', 'product_id': 'CSAFPID-0016'}, 'product_reference': 'CSAFPID-0001', 'relates_to_product_reference': 'CSAFPID-0008'}, {'category': 'installed_on', 'full_product_name': {'name': 'U-Boot U-boot: <2017.11 installed on Johnson Controls Airwall AW-75 vers:all/*', 'product_id': 'CSAFPID-0017'}, 'product_reference': 'CSAFPID-0001', 'relates_to_product_reference': 'CSAFPID-0009'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-24857', 'cwe': {'id': 'CWE-1274', 'name': 'Improper Access Control for Volatile Memory Containing Boot Code'}, 'notes': [{'text': 'The affected products are vulnerable to a bootloader vulnerability, which could allow an attacker to execute arbitrary code.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/1274.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-24857', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://ftp.denx.de/pub/u-boot/', 'details': 'Konsulko, the third-party maintainer of U-boot, recommends users upgrade to version v2025.4 or later and ensure the physical security of the device.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0017']}, {'url': 'https://www.qualcomm.com/support/contact', 'details': 'Qualcomm recommends users with the affected chips to contact support referencing CVE-2025-24857, QPSIIR-1969 or CR4082905.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016']}, {'url': 'https://webhelp.tempered.io/content/topics/downloads_hotfixes.html#downloads_hotfixes__section_vw4_25x_13c', 'details': "Johnson Controls recommend users to consider the following defensive measure: (1) Deploy Airwall in a physically secure location so an attacker can't plug in USB devices. (2) Restrict physical access to USB A ports (not the micro-USB console port which is not affected) by sealing them with epoxy or a similar material. (3) For Airwall 75 gateways running U-Boot version 2017.03 and before (version number is displayed on the console port as the Airwall gateway boots), install hotfix hf-3303 to update U-Boot. Hotfix can be downloaded from https://webhelp.tempered.io/content/topics/downloads_hotfixes.html#downloads_hotfixes__section_vw4_25x_13c", 'category': 'mitigation', 'product_ids': ['CSAFPID-0017']}, {'url': 'https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories', 'details': 'For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-04 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories', 'category': 'mitigation', 'product_ids': ['CSAFPID-0017']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017']}}]} | |
ot | ICSA-22-020-01 | CVE-2022-23127 | Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric HMI SCADA (Update B) | 2022-01-20 10:00:00+03:00 | 2026-03-05 10:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2022/icsa-22-020-01.json | 599d08ff003f43b014b46708d1e656e59907515e632652eeea23b11ef9d506fc | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could result in unauthorized access to information or to GENESIS64 and MC Works64 functionality, or the disabling of SQL Server in GENESIS64, ICONICS Suite, MC Works64, or GENESIS32.', 'title': 'Risk evaluation', 'category': 'summary'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States (Mitsubishi Electric Iconics Digital Solutions), Japan (Mitsubishi Electric)', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric HMI SCADA (Update B)', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-22-020-01', 'status': 'draft', 'version': '3', 'generator': {'date': '2026-03-05T00:05:34.123002Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2022-01-20T07:00:00.000000Z', 'number': '1', 'summary': 'IInitial Publication', 'legacy_version': 'Initial'}, {'date': '2026-01-08T00:00:00.000000Z', 'number': '2', 'summary': 'Update A - Added GENESIS32.', 'legacy_version': 'Update A'}, {'date': '2026-03-05T00:00:00.000000Z', 'number': '3', 'summary': 'Update B - Fixes for affected versions and typographical errors', 'legacy_version': 'Update B'}], 'current_release_date': '2026-03-05T07:00:00.000000Z', 'initial_release_date': '2022-01-20T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2022/icsa-22-020-01.json', 'summary': 'ICS Advisory ICSA-22-020-01 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-22-020-01', 'summary': 'ICSA Advisory ICSA-22-020-01 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to CISA', 'organization': 'Mitsubishi Electric Iconics Digital Solutions'}, {'summary': 'reported these vulnerabilities to CISA', 'organization': 'Mitsubishi Electric'}]}, 'product_tree': {'branches': [{'name': 'Mitsubishi Electric Iconics Digital Solutions', 'branches': [{'name': 'ICONICS Suite', 'branches': [{'name': '<=10.96.2', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions ICONICS Suite: <=10.96.2', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'ICONICS Suite', 'branches': [{'name': '>=10.95.3 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions ICONICS Suite: >=10.95.3 | <=10.97', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'ICONICS Suite', 'branches': [{'name': '>=10.90 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions ICONICS Suite: >=10.90 | <=10.97', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'ICONICS Suite', 'branches': [{'name': '<=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions ICONICS Suite: <=10.97', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'GENESIS64', 'branches': [{'name': '<=10.96.2', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions GENESIS64: <=10.96.2', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'GENESIS64', 'branches': [{'name': '>=10.95.3 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions GENESIS64: >=10.95.3 | <=10.97', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'GENESIS64', 'branches': [{'name': '>=10.90 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions GENESIS64: >=10.90 | <=10.97', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'GENESIS64', 'branches': [{'name': '<=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions GENESIS64: <=10.97', 'product_id': 'CSAFPID-0008'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Hyper Historian', 'branches': [{'name': '<=10.96.2', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions Hyper Historian: <=10.96.2', 'product_id': 'CSAFPID-0009'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Hyper Historian', 'branches': [{'name': '>=10.95.3 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions Hyper Historian: >=10.95.3 | <=10.97', 'product_id': 'CSAFPID-0010'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Hyper Historian', 'branches': [{'name': '>=10.90 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions Hyper Historian: >=10.90 | <=10.97', 'product_id': 'CSAFPID-0011'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Hyper Historian', 'branches': [{'name': '<=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions Hyper Historian: <=10.97', 'product_id': 'CSAFPID-0012'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'AnalytiX', 'branches': [{'name': '<=10.96.2', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions AnalytiX: <=10.96.2', 'product_id': 'CSAFPID-0013'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'AnalytiX', 'branches': [{'name': '>=10.95.3 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions AnalytiX: >=10.95.3 | <=10.97', 'product_id': 'CSAFPID-0014'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'AnalytiX', 'branches': [{'name': '>=10.90 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions AnalytiX: >=10.90 | <=10.97', 'product_id': 'CSAFPID-0015'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'AnalytiX', 'branches': [{'name': '<=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions AnalytiX: <=10.97', 'product_id': 'CSAFPID-0016'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'MobileHMI', 'branches': [{'name': '<=10.96.2', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions MobileHMI: <=10.96.2', 'product_id': 'CSAFPID-0017'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'MobileHMI', 'branches': [{'name': '>=10.95.3 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions MobileHMI: >=10.95.3 | <=10.97', 'product_id': 'CSAFPID-0018'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'MobileHMI', 'branches': [{'name': '>=10.90 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions MobileHMI: >=10.90 | <=10.97', 'product_id': 'CSAFPID-0019'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'MobileHMI', 'branches': [{'name': '<=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions MobileHMI: <=10.97', 'product_id': 'CSAFPID-0020'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'GENESIS32', 'branches': [{'name': '<=9.7', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions GENESIS32: <=9.7', 'product_id': 'CSAFPID-0021'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}, {'name': 'Mitsubishi Electric', 'branches': [{'name': 'ICONICS Suite', 'branches': [{'name': '10.97', 'product': {'name': 'Mitsubishi Electric ICONICS Suite: 10.97', 'product_id': 'CSAFPID-0022'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'GENESIS64', 'branches': [{'name': '10.97', 'product': {'name': 'Mitsubishi Electric GENESIS64: 10.97', 'product_id': 'CSAFPID-0023'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Hyper Historian', 'branches': [{'name': '10.97', 'product': {'name': 'Mitsubishi Electric Hyper Historian: 10.97', 'product_id': 'CSAFPID-0024'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'AnalytiX', 'branches': [{'name': '10.97', 'product': {'name': 'Mitsubishi Electric AnalytiX: 10.97', 'product_id': 'CSAFPID-0025'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'MobileHMI', 'branches': [{'name': '10.97', 'product': {'name': 'Mitsubishi Electric MobileHMI: 10.97', 'product_id': 'CSAFPID-0026'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'GENESIS32', 'branches': [{'name': '<=9.7', 'product': {'name': 'Mitsubishi Electric GENESIS32: <=9.7', 'product_id': 'CSAFPID-0027'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'MC Works64', 'branches': [{'name': '<=4.04E', 'product': {'name': 'Mitsubishi Electric MC Works64: <=4.04E', 'product_id': 'CSAFPID-0028'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'MC Works64', 'branches': [{'name': '>=4.00A | <=4.04E', 'product': {'name': 'Mitsubishi Electric MC Works64: >=4.00A | <=4.04E', 'product_id': 'CSAFPID-0029'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2022-23127', 'cwe': {'id': 'CWE-79', 'name': "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"}, 'notes': [{'text': 'Information disclosure vulnerability due to Improper Neutralization of Input During Web Page Generation (CWE-79) caused by the lack of proper input verification exists in Mitsubishi Electric Iconics Digital Solutions GENESIS64 and ICONICS Suite and Mitsubishi Electric MC Works64.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/T:P/2026-02-10T00:00:00.000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.2, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0005', 'CSAFPID-0009', 'CSAFPID-0013', 'CSAFPID-0017', 'CSAFPID-0028']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-23127', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://iconics.com/About/Security/CERT', 'details': 'Mitsubishi Electric Iconics Digital Solutions is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric Iconics Digital Solutions whitepaper on security vulnerabilities, the most recent version of which can be found here. https://iconics.com/About/Security/CERT', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0005', 'CSAFPID-0009', 'CSAFPID-0013', 'CSAFPID-0017']}, {'url': 'https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-025_en.pdf', 'details': ' Mitsubishi Electric is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric security advisory, the most recent version of which can be found here. https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-025_en.pdf', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend locating control system networks and remote devices behind firewalls and isolating them from the business network, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0005', 'CSAFPID-0009', 'CSAFPID-0013', 'CSAFPID-0017', 'CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend restricting the connection of all control system devices and systems to the network so that they can only be accessed from trusted networks and hosts, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0005', 'CSAFPID-0009', 'CSAFPID-0013', 'CSAFPID-0017', 'CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend restricting the connection of all control system devices and systems to the network so that they can only be accessed from trusted networks and hosts, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0005', 'CSAFPID-0009', 'CSAFPID-0013', 'CSAFPID-0017', 'CSAFPID-0028']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0005', 'CSAFPID-0009', 'CSAFPID-0013', 'CSAFPID-0017', 'CSAFPID-0028']}}, {'cve': 'CVE-2022-23128', 'cwe': {'id': 'CWE-184', 'name': 'Incomplete List of Disallowed Inputs'}, 'notes': [{'text': ' Authentication bypass vulnerability due to Incomplete List of Disallowed Inputs (CWE-184) exists in Mitsubishi Electric Iconics Digital Solutions GENESIS64 and ICONICS Suite Mitsubishi Electric GENESIS64, ICONICS Suite, and MC Works64.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/T:T/2026-02-10T00:00:00.000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0002', 'CSAFPID-0006', 'CSAFPID-0010', 'CSAFPID-0014', 'CSAFPID-0018', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0029']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-23128', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://iconics.com/About/Security/CERT', 'details': 'Mitsubishi Electric Iconics Digital Solutions is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric Iconics Digital Solutions whitepaper on security vulnerabilities, the most recent version of which can be found here. https://iconics.com/About/Security/CERT', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002', 'CSAFPID-0006', 'CSAFPID-0010', 'CSAFPID-0014', 'CSAFPID-0018']}, {'url': 'https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-026_en.pdf', 'details': 'Mitsubishi Electric is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric security advisory, the most recent version of which can be found here. https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-026_en.pdf', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0029']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend switching the communication method of FrameWorX server from WebSocket communication to WCF communication and setting "WebSocketTransport" element to "false" in "FwxServer.Network.config" file located in the installation folder of the products, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002', 'CSAFPID-0006', 'CSAFPID-0010', 'CSAFPID-0014', 'CSAFPID-0018', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0029']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend locating control system networks and remote devices behind firewalls and isolating them from the business network, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002', 'CSAFPID-0006', 'CSAFPID-0010', 'CSAFPID-0014', 'CSAFPID-0018', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0029']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend restricting the connection of all control system devices and systems to the network so that they can only be accessed from trusted networks and hosts, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002', 'CSAFPID-0006', 'CSAFPID-0010', 'CSAFPID-0014', 'CSAFPID-0018', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0029']}], 'product_status': {'known_affected': ['CSAFPID-0002', 'CSAFPID-0006', 'CSAFPID-0010', 'CSAFPID-0014', 'CSAFPID-0018', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0029']}}, {'cve': 'CVE-2022-23129', 'cwe': {'id': 'CWE-256', 'name': 'Plaintext Storage of a Password'}, 'notes': [{'text': 'Information disclosure vulnerability due to Plaintext Storage of a Password (CWE-256) exists in Mitsubishi Electric Iconics Digital Solutions GENESIS64 and ICONICS Suite and Mitsubishi Electric GENESIS64, ICONICS Suite, and MC Works64.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/T:T/2026-02-10T00:00:00.000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H'}, 'products': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-23129', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://iconics.com/About/Security/CERT', 'details': 'Mitsubishi Electric Iconics Digital Solutions is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric Iconics Digital Solutions whitepaper on security vulnerabilities, the most recent version of which can be found here. https://iconics.com/About/Security/CERT', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019']}, {'url': 'https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-027_en.pdf', 'details': 'Mitsubishi Electric is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric security advisory, the most recent version of which can be found here. https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-027_en.pdf', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend deleting the authentication information (password) of the SQL database in the CSV file, after exporting the configuration information of GridWorX to the CSV file, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend deleting the authentication information (password) of the SQL database, before exporting the configuration information of GridWorX to the CSV file, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend changing the configuration of the security function so that users other than administrator is not authorized to export the configuration information of GridWorX to a CSV file, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend locating control system networks and remote devices behind firewalls and isolating them from the business network, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend restricting the connection of all control system devices and systems to the network so that they can only be accessed from trusted networks and hosts, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}], 'product_status': {'known_affected': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}}, {'cve': 'CVE-2022-23130', 'cwe': {'id': 'CWE-126', 'name': 'Buffer Over-read'}, 'notes': [{'text': ' Denial-of-Service (DoS) vulnerability due to Buffer Over-read (CWE-126) exists in database server of Mitsubishi Electric Iconics Digital Solutions GENESIS64, ICONICS, and GENESIS32 Suite and Mitsubishi Electric GENESIS64, ICONICS Suite, GENESIS32, and MC Works64.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/T:P/2026-02-10T00:00:00.000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:H'}, 'products': ['CSAFPID-0004', 'CSAFPID-0008', 'CSAFPID-0012', 'CSAFPID-0016', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0029']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-23130', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://iconics.com/About/Security/CERT', 'details': 'Mitsubishi Electric Iconics Digital Solutions is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric Iconics Digital Solutions whitepaper on security vulnerabilities, the most recent version of which can be found here. https://iconics.com/About/Security/CERT', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004', 'CSAFPID-0008', 'CSAFPID-0012', 'CSAFPID-0016', 'CSAFPID-0020']}, {'url': 'https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-028_en.pdf', 'details': 'Mitsubishi Electric is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric security advisory, the most recent version of which can be found here. https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-028_en.pdf', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0029']}, {'details': 'There are no plans to release a security update for GENESIS32. To minimize the risk of exploitation of this vulnerability, please consider replacing to GENESIS64 or ICONICS Suite.', 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0021', 'CSAFPID-0027']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend locating control system networks and remote devices behind firewalls and isolating them from the business network, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004', 'CSAFPID-0008', 'CSAFPID-0012', 'CSAFPID-0016', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0029']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend restricting the connection of all control system devices and systems to the network so that they can only be accessed from trusted networks and hosts, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004', 'CSAFPID-0008', 'CSAFPID-0012', 'CSAFPID-0016', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0029']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend avoiding clicking on web links in emails etc. from untrusted sources, and avoiding opening files attached to untrusted emails, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004', 'CSAFPID-0008', 'CSAFPID-0012', 'CSAFPID-0016', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0029']}], 'product_status': {'known_affected': ['CSAFPID-0004', 'CSAFPID-0008', 'CSAFPID-0012', 'CSAFPID-0016', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0029']}}]} | |
ot | ICSA-22-020-01 | CVE-2022-23128 | Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric HMI SCADA (Update B) | 2022-01-20 10:00:00+03:00 | 2026-03-05 10:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2022/icsa-22-020-01.json | a7e20f31cfcd108efb63c211f4e99672d54a9459134f71034a7522b5c8bd04c0 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could result in unauthorized access to information or to GENESIS64 and MC Works64 functionality, or the disabling of SQL Server in GENESIS64, ICONICS Suite, MC Works64, or GENESIS32.', 'title': 'Risk evaluation', 'category': 'summary'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States (Mitsubishi Electric Iconics Digital Solutions), Japan (Mitsubishi Electric)', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric HMI SCADA (Update B)', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-22-020-01', 'status': 'draft', 'version': '3', 'generator': {'date': '2026-03-05T00:05:34.123002Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2022-01-20T07:00:00.000000Z', 'number': '1', 'summary': 'IInitial Publication', 'legacy_version': 'Initial'}, {'date': '2026-01-08T00:00:00.000000Z', 'number': '2', 'summary': 'Update A - Added GENESIS32.', 'legacy_version': 'Update A'}, {'date': '2026-03-05T00:00:00.000000Z', 'number': '3', 'summary': 'Update B - Fixes for affected versions and typographical errors', 'legacy_version': 'Update B'}], 'current_release_date': '2026-03-05T07:00:00.000000Z', 'initial_release_date': '2022-01-20T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2022/icsa-22-020-01.json', 'summary': 'ICS Advisory ICSA-22-020-01 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-22-020-01', 'summary': 'ICSA Advisory ICSA-22-020-01 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to CISA', 'organization': 'Mitsubishi Electric Iconics Digital Solutions'}, {'summary': 'reported these vulnerabilities to CISA', 'organization': 'Mitsubishi Electric'}]}, 'product_tree': {'branches': [{'name': 'Mitsubishi Electric Iconics Digital Solutions', 'branches': [{'name': 'ICONICS Suite', 'branches': [{'name': '<=10.96.2', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions ICONICS Suite: <=10.96.2', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'ICONICS Suite', 'branches': [{'name': '>=10.95.3 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions ICONICS Suite: >=10.95.3 | <=10.97', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'ICONICS Suite', 'branches': [{'name': '>=10.90 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions ICONICS Suite: >=10.90 | <=10.97', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'ICONICS Suite', 'branches': [{'name': '<=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions ICONICS Suite: <=10.97', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'GENESIS64', 'branches': [{'name': '<=10.96.2', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions GENESIS64: <=10.96.2', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'GENESIS64', 'branches': [{'name': '>=10.95.3 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions GENESIS64: >=10.95.3 | <=10.97', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'GENESIS64', 'branches': [{'name': '>=10.90 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions GENESIS64: >=10.90 | <=10.97', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'GENESIS64', 'branches': [{'name': '<=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions GENESIS64: <=10.97', 'product_id': 'CSAFPID-0008'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Hyper Historian', 'branches': [{'name': '<=10.96.2', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions Hyper Historian: <=10.96.2', 'product_id': 'CSAFPID-0009'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Hyper Historian', 'branches': [{'name': '>=10.95.3 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions Hyper Historian: >=10.95.3 | <=10.97', 'product_id': 'CSAFPID-0010'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Hyper Historian', 'branches': [{'name': '>=10.90 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions Hyper Historian: >=10.90 | <=10.97', 'product_id': 'CSAFPID-0011'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Hyper Historian', 'branches': [{'name': '<=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions Hyper Historian: <=10.97', 'product_id': 'CSAFPID-0012'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'AnalytiX', 'branches': [{'name': '<=10.96.2', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions AnalytiX: <=10.96.2', 'product_id': 'CSAFPID-0013'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'AnalytiX', 'branches': [{'name': '>=10.95.3 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions AnalytiX: >=10.95.3 | <=10.97', 'product_id': 'CSAFPID-0014'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'AnalytiX', 'branches': [{'name': '>=10.90 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions AnalytiX: >=10.90 | <=10.97', 'product_id': 'CSAFPID-0015'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'AnalytiX', 'branches': [{'name': '<=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions AnalytiX: <=10.97', 'product_id': 'CSAFPID-0016'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'MobileHMI', 'branches': [{'name': '<=10.96.2', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions MobileHMI: <=10.96.2', 'product_id': 'CSAFPID-0017'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'MobileHMI', 'branches': [{'name': '>=10.95.3 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions MobileHMI: >=10.95.3 | <=10.97', 'product_id': 'CSAFPID-0018'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'MobileHMI', 'branches': [{'name': '>=10.90 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions MobileHMI: >=10.90 | <=10.97', 'product_id': 'CSAFPID-0019'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'MobileHMI', 'branches': [{'name': '<=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions MobileHMI: <=10.97', 'product_id': 'CSAFPID-0020'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'GENESIS32', 'branches': [{'name': '<=9.7', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions GENESIS32: <=9.7', 'product_id': 'CSAFPID-0021'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}, {'name': 'Mitsubishi Electric', 'branches': [{'name': 'ICONICS Suite', 'branches': [{'name': '10.97', 'product': {'name': 'Mitsubishi Electric ICONICS Suite: 10.97', 'product_id': 'CSAFPID-0022'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'GENESIS64', 'branches': [{'name': '10.97', 'product': {'name': 'Mitsubishi Electric GENESIS64: 10.97', 'product_id': 'CSAFPID-0023'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Hyper Historian', 'branches': [{'name': '10.97', 'product': {'name': 'Mitsubishi Electric Hyper Historian: 10.97', 'product_id': 'CSAFPID-0024'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'AnalytiX', 'branches': [{'name': '10.97', 'product': {'name': 'Mitsubishi Electric AnalytiX: 10.97', 'product_id': 'CSAFPID-0025'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'MobileHMI', 'branches': [{'name': '10.97', 'product': {'name': 'Mitsubishi Electric MobileHMI: 10.97', 'product_id': 'CSAFPID-0026'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'GENESIS32', 'branches': [{'name': '<=9.7', 'product': {'name': 'Mitsubishi Electric GENESIS32: <=9.7', 'product_id': 'CSAFPID-0027'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'MC Works64', 'branches': [{'name': '<=4.04E', 'product': {'name': 'Mitsubishi Electric MC Works64: <=4.04E', 'product_id': 'CSAFPID-0028'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'MC Works64', 'branches': [{'name': '>=4.00A | <=4.04E', 'product': {'name': 'Mitsubishi Electric MC Works64: >=4.00A | <=4.04E', 'product_id': 'CSAFPID-0029'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2022-23127', 'cwe': {'id': 'CWE-79', 'name': "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"}, 'notes': [{'text': 'Information disclosure vulnerability due to Improper Neutralization of Input During Web Page Generation (CWE-79) caused by the lack of proper input verification exists in Mitsubishi Electric Iconics Digital Solutions GENESIS64 and ICONICS Suite and Mitsubishi Electric MC Works64.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/T:P/2026-02-10T00:00:00.000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.2, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0005', 'CSAFPID-0009', 'CSAFPID-0013', 'CSAFPID-0017', 'CSAFPID-0028']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-23127', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://iconics.com/About/Security/CERT', 'details': 'Mitsubishi Electric Iconics Digital Solutions is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric Iconics Digital Solutions whitepaper on security vulnerabilities, the most recent version of which can be found here. https://iconics.com/About/Security/CERT', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0005', 'CSAFPID-0009', 'CSAFPID-0013', 'CSAFPID-0017']}, {'url': 'https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-025_en.pdf', 'details': ' Mitsubishi Electric is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric security advisory, the most recent version of which can be found here. https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-025_en.pdf', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend locating control system networks and remote devices behind firewalls and isolating them from the business network, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0005', 'CSAFPID-0009', 'CSAFPID-0013', 'CSAFPID-0017', 'CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend restricting the connection of all control system devices and systems to the network so that they can only be accessed from trusted networks and hosts, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0005', 'CSAFPID-0009', 'CSAFPID-0013', 'CSAFPID-0017', 'CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend restricting the connection of all control system devices and systems to the network so that they can only be accessed from trusted networks and hosts, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0005', 'CSAFPID-0009', 'CSAFPID-0013', 'CSAFPID-0017', 'CSAFPID-0028']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0005', 'CSAFPID-0009', 'CSAFPID-0013', 'CSAFPID-0017', 'CSAFPID-0028']}}, {'cve': 'CVE-2022-23128', 'cwe': {'id': 'CWE-184', 'name': 'Incomplete List of Disallowed Inputs'}, 'notes': [{'text': ' Authentication bypass vulnerability due to Incomplete List of Disallowed Inputs (CWE-184) exists in Mitsubishi Electric Iconics Digital Solutions GENESIS64 and ICONICS Suite Mitsubishi Electric GENESIS64, ICONICS Suite, and MC Works64.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/T:T/2026-02-10T00:00:00.000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0002', 'CSAFPID-0006', 'CSAFPID-0010', 'CSAFPID-0014', 'CSAFPID-0018', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0029']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-23128', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://iconics.com/About/Security/CERT', 'details': 'Mitsubishi Electric Iconics Digital Solutions is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric Iconics Digital Solutions whitepaper on security vulnerabilities, the most recent version of which can be found here. https://iconics.com/About/Security/CERT', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002', 'CSAFPID-0006', 'CSAFPID-0010', 'CSAFPID-0014', 'CSAFPID-0018']}, {'url': 'https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-026_en.pdf', 'details': 'Mitsubishi Electric is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric security advisory, the most recent version of which can be found here. https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-026_en.pdf', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0029']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend switching the communication method of FrameWorX server from WebSocket communication to WCF communication and setting "WebSocketTransport" element to "false" in "FwxServer.Network.config" file located in the installation folder of the products, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002', 'CSAFPID-0006', 'CSAFPID-0010', 'CSAFPID-0014', 'CSAFPID-0018', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0029']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend locating control system networks and remote devices behind firewalls and isolating them from the business network, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002', 'CSAFPID-0006', 'CSAFPID-0010', 'CSAFPID-0014', 'CSAFPID-0018', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0029']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend restricting the connection of all control system devices and systems to the network so that they can only be accessed from trusted networks and hosts, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002', 'CSAFPID-0006', 'CSAFPID-0010', 'CSAFPID-0014', 'CSAFPID-0018', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0029']}], 'product_status': {'known_affected': ['CSAFPID-0002', 'CSAFPID-0006', 'CSAFPID-0010', 'CSAFPID-0014', 'CSAFPID-0018', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0029']}}, {'cve': 'CVE-2022-23129', 'cwe': {'id': 'CWE-256', 'name': 'Plaintext Storage of a Password'}, 'notes': [{'text': 'Information disclosure vulnerability due to Plaintext Storage of a Password (CWE-256) exists in Mitsubishi Electric Iconics Digital Solutions GENESIS64 and ICONICS Suite and Mitsubishi Electric GENESIS64, ICONICS Suite, and MC Works64.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/T:T/2026-02-10T00:00:00.000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H'}, 'products': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-23129', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://iconics.com/About/Security/CERT', 'details': 'Mitsubishi Electric Iconics Digital Solutions is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric Iconics Digital Solutions whitepaper on security vulnerabilities, the most recent version of which can be found here. https://iconics.com/About/Security/CERT', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019']}, {'url': 'https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-027_en.pdf', 'details': 'Mitsubishi Electric is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric security advisory, the most recent version of which can be found here. https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-027_en.pdf', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend deleting the authentication information (password) of the SQL database in the CSV file, after exporting the configuration information of GridWorX to the CSV file, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend deleting the authentication information (password) of the SQL database, before exporting the configuration information of GridWorX to the CSV file, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend changing the configuration of the security function so that users other than administrator is not authorized to export the configuration information of GridWorX to a CSV file, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend locating control system networks and remote devices behind firewalls and isolating them from the business network, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend restricting the connection of all control system devices and systems to the network so that they can only be accessed from trusted networks and hosts, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}], 'product_status': {'known_affected': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}}, {'cve': 'CVE-2022-23130', 'cwe': {'id': 'CWE-126', 'name': 'Buffer Over-read'}, 'notes': [{'text': ' Denial-of-Service (DoS) vulnerability due to Buffer Over-read (CWE-126) exists in database server of Mitsubishi Electric Iconics Digital Solutions GENESIS64, ICONICS, and GENESIS32 Suite and Mitsubishi Electric GENESIS64, ICONICS Suite, GENESIS32, and MC Works64.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/T:P/2026-02-10T00:00:00.000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:H'}, 'products': ['CSAFPID-0004', 'CSAFPID-0008', 'CSAFPID-0012', 'CSAFPID-0016', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0029']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-23130', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://iconics.com/About/Security/CERT', 'details': 'Mitsubishi Electric Iconics Digital Solutions is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric Iconics Digital Solutions whitepaper on security vulnerabilities, the most recent version of which can be found here. https://iconics.com/About/Security/CERT', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004', 'CSAFPID-0008', 'CSAFPID-0012', 'CSAFPID-0016', 'CSAFPID-0020']}, {'url': 'https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-028_en.pdf', 'details': 'Mitsubishi Electric is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric security advisory, the most recent version of which can be found here. https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-028_en.pdf', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0029']}, {'details': 'There are no plans to release a security update for GENESIS32. To minimize the risk of exploitation of this vulnerability, please consider replacing to GENESIS64 or ICONICS Suite.', 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0021', 'CSAFPID-0027']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend locating control system networks and remote devices behind firewalls and isolating them from the business network, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004', 'CSAFPID-0008', 'CSAFPID-0012', 'CSAFPID-0016', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0029']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend restricting the connection of all control system devices and systems to the network so that they can only be accessed from trusted networks and hosts, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004', 'CSAFPID-0008', 'CSAFPID-0012', 'CSAFPID-0016', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0029']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend avoiding clicking on web links in emails etc. from untrusted sources, and avoiding opening files attached to untrusted emails, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004', 'CSAFPID-0008', 'CSAFPID-0012', 'CSAFPID-0016', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0029']}], 'product_status': {'known_affected': ['CSAFPID-0004', 'CSAFPID-0008', 'CSAFPID-0012', 'CSAFPID-0016', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0029']}}]} | |
ot | ICSA-22-020-01 | CVE-2022-23129 | Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric HMI SCADA (Update B) | 2022-01-20 10:00:00+03:00 | 2026-03-05 10:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2022/icsa-22-020-01.json | a677da32c52974635b998faa293975f2d62610190b227dacb20e2750e7890b0a | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could result in unauthorized access to information or to GENESIS64 and MC Works64 functionality, or the disabling of SQL Server in GENESIS64, ICONICS Suite, MC Works64, or GENESIS32.', 'title': 'Risk evaluation', 'category': 'summary'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States (Mitsubishi Electric Iconics Digital Solutions), Japan (Mitsubishi Electric)', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric HMI SCADA (Update B)', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-22-020-01', 'status': 'draft', 'version': '3', 'generator': {'date': '2026-03-05T00:05:34.123002Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2022-01-20T07:00:00.000000Z', 'number': '1', 'summary': 'IInitial Publication', 'legacy_version': 'Initial'}, {'date': '2026-01-08T00:00:00.000000Z', 'number': '2', 'summary': 'Update A - Added GENESIS32.', 'legacy_version': 'Update A'}, {'date': '2026-03-05T00:00:00.000000Z', 'number': '3', 'summary': 'Update B - Fixes for affected versions and typographical errors', 'legacy_version': 'Update B'}], 'current_release_date': '2026-03-05T07:00:00.000000Z', 'initial_release_date': '2022-01-20T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2022/icsa-22-020-01.json', 'summary': 'ICS Advisory ICSA-22-020-01 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-22-020-01', 'summary': 'ICSA Advisory ICSA-22-020-01 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to CISA', 'organization': 'Mitsubishi Electric Iconics Digital Solutions'}, {'summary': 'reported these vulnerabilities to CISA', 'organization': 'Mitsubishi Electric'}]}, 'product_tree': {'branches': [{'name': 'Mitsubishi Electric Iconics Digital Solutions', 'branches': [{'name': 'ICONICS Suite', 'branches': [{'name': '<=10.96.2', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions ICONICS Suite: <=10.96.2', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'ICONICS Suite', 'branches': [{'name': '>=10.95.3 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions ICONICS Suite: >=10.95.3 | <=10.97', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'ICONICS Suite', 'branches': [{'name': '>=10.90 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions ICONICS Suite: >=10.90 | <=10.97', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'ICONICS Suite', 'branches': [{'name': '<=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions ICONICS Suite: <=10.97', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'GENESIS64', 'branches': [{'name': '<=10.96.2', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions GENESIS64: <=10.96.2', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'GENESIS64', 'branches': [{'name': '>=10.95.3 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions GENESIS64: >=10.95.3 | <=10.97', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'GENESIS64', 'branches': [{'name': '>=10.90 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions GENESIS64: >=10.90 | <=10.97', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'GENESIS64', 'branches': [{'name': '<=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions GENESIS64: <=10.97', 'product_id': 'CSAFPID-0008'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Hyper Historian', 'branches': [{'name': '<=10.96.2', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions Hyper Historian: <=10.96.2', 'product_id': 'CSAFPID-0009'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Hyper Historian', 'branches': [{'name': '>=10.95.3 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions Hyper Historian: >=10.95.3 | <=10.97', 'product_id': 'CSAFPID-0010'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Hyper Historian', 'branches': [{'name': '>=10.90 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions Hyper Historian: >=10.90 | <=10.97', 'product_id': 'CSAFPID-0011'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Hyper Historian', 'branches': [{'name': '<=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions Hyper Historian: <=10.97', 'product_id': 'CSAFPID-0012'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'AnalytiX', 'branches': [{'name': '<=10.96.2', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions AnalytiX: <=10.96.2', 'product_id': 'CSAFPID-0013'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'AnalytiX', 'branches': [{'name': '>=10.95.3 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions AnalytiX: >=10.95.3 | <=10.97', 'product_id': 'CSAFPID-0014'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'AnalytiX', 'branches': [{'name': '>=10.90 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions AnalytiX: >=10.90 | <=10.97', 'product_id': 'CSAFPID-0015'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'AnalytiX', 'branches': [{'name': '<=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions AnalytiX: <=10.97', 'product_id': 'CSAFPID-0016'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'MobileHMI', 'branches': [{'name': '<=10.96.2', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions MobileHMI: <=10.96.2', 'product_id': 'CSAFPID-0017'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'MobileHMI', 'branches': [{'name': '>=10.95.3 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions MobileHMI: >=10.95.3 | <=10.97', 'product_id': 'CSAFPID-0018'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'MobileHMI', 'branches': [{'name': '>=10.90 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions MobileHMI: >=10.90 | <=10.97', 'product_id': 'CSAFPID-0019'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'MobileHMI', 'branches': [{'name': '<=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions MobileHMI: <=10.97', 'product_id': 'CSAFPID-0020'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'GENESIS32', 'branches': [{'name': '<=9.7', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions GENESIS32: <=9.7', 'product_id': 'CSAFPID-0021'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}, {'name': 'Mitsubishi Electric', 'branches': [{'name': 'ICONICS Suite', 'branches': [{'name': '10.97', 'product': {'name': 'Mitsubishi Electric ICONICS Suite: 10.97', 'product_id': 'CSAFPID-0022'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'GENESIS64', 'branches': [{'name': '10.97', 'product': {'name': 'Mitsubishi Electric GENESIS64: 10.97', 'product_id': 'CSAFPID-0023'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Hyper Historian', 'branches': [{'name': '10.97', 'product': {'name': 'Mitsubishi Electric Hyper Historian: 10.97', 'product_id': 'CSAFPID-0024'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'AnalytiX', 'branches': [{'name': '10.97', 'product': {'name': 'Mitsubishi Electric AnalytiX: 10.97', 'product_id': 'CSAFPID-0025'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'MobileHMI', 'branches': [{'name': '10.97', 'product': {'name': 'Mitsubishi Electric MobileHMI: 10.97', 'product_id': 'CSAFPID-0026'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'GENESIS32', 'branches': [{'name': '<=9.7', 'product': {'name': 'Mitsubishi Electric GENESIS32: <=9.7', 'product_id': 'CSAFPID-0027'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'MC Works64', 'branches': [{'name': '<=4.04E', 'product': {'name': 'Mitsubishi Electric MC Works64: <=4.04E', 'product_id': 'CSAFPID-0028'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'MC Works64', 'branches': [{'name': '>=4.00A | <=4.04E', 'product': {'name': 'Mitsubishi Electric MC Works64: >=4.00A | <=4.04E', 'product_id': 'CSAFPID-0029'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2022-23127', 'cwe': {'id': 'CWE-79', 'name': "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"}, 'notes': [{'text': 'Information disclosure vulnerability due to Improper Neutralization of Input During Web Page Generation (CWE-79) caused by the lack of proper input verification exists in Mitsubishi Electric Iconics Digital Solutions GENESIS64 and ICONICS Suite and Mitsubishi Electric MC Works64.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/T:P/2026-02-10T00:00:00.000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.2, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0005', 'CSAFPID-0009', 'CSAFPID-0013', 'CSAFPID-0017', 'CSAFPID-0028']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-23127', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://iconics.com/About/Security/CERT', 'details': 'Mitsubishi Electric Iconics Digital Solutions is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric Iconics Digital Solutions whitepaper on security vulnerabilities, the most recent version of which can be found here. https://iconics.com/About/Security/CERT', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0005', 'CSAFPID-0009', 'CSAFPID-0013', 'CSAFPID-0017']}, {'url': 'https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-025_en.pdf', 'details': ' Mitsubishi Electric is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric security advisory, the most recent version of which can be found here. https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-025_en.pdf', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend locating control system networks and remote devices behind firewalls and isolating them from the business network, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0005', 'CSAFPID-0009', 'CSAFPID-0013', 'CSAFPID-0017', 'CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend restricting the connection of all control system devices and systems to the network so that they can only be accessed from trusted networks and hosts, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0005', 'CSAFPID-0009', 'CSAFPID-0013', 'CSAFPID-0017', 'CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend restricting the connection of all control system devices and systems to the network so that they can only be accessed from trusted networks and hosts, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0005', 'CSAFPID-0009', 'CSAFPID-0013', 'CSAFPID-0017', 'CSAFPID-0028']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0005', 'CSAFPID-0009', 'CSAFPID-0013', 'CSAFPID-0017', 'CSAFPID-0028']}}, {'cve': 'CVE-2022-23128', 'cwe': {'id': 'CWE-184', 'name': 'Incomplete List of Disallowed Inputs'}, 'notes': [{'text': ' Authentication bypass vulnerability due to Incomplete List of Disallowed Inputs (CWE-184) exists in Mitsubishi Electric Iconics Digital Solutions GENESIS64 and ICONICS Suite Mitsubishi Electric GENESIS64, ICONICS Suite, and MC Works64.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/T:T/2026-02-10T00:00:00.000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0002', 'CSAFPID-0006', 'CSAFPID-0010', 'CSAFPID-0014', 'CSAFPID-0018', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0029']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-23128', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://iconics.com/About/Security/CERT', 'details': 'Mitsubishi Electric Iconics Digital Solutions is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric Iconics Digital Solutions whitepaper on security vulnerabilities, the most recent version of which can be found here. https://iconics.com/About/Security/CERT', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002', 'CSAFPID-0006', 'CSAFPID-0010', 'CSAFPID-0014', 'CSAFPID-0018']}, {'url': 'https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-026_en.pdf', 'details': 'Mitsubishi Electric is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric security advisory, the most recent version of which can be found here. https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-026_en.pdf', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0029']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend switching the communication method of FrameWorX server from WebSocket communication to WCF communication and setting "WebSocketTransport" element to "false" in "FwxServer.Network.config" file located in the installation folder of the products, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002', 'CSAFPID-0006', 'CSAFPID-0010', 'CSAFPID-0014', 'CSAFPID-0018', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0029']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend locating control system networks and remote devices behind firewalls and isolating them from the business network, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002', 'CSAFPID-0006', 'CSAFPID-0010', 'CSAFPID-0014', 'CSAFPID-0018', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0029']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend restricting the connection of all control system devices and systems to the network so that they can only be accessed from trusted networks and hosts, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002', 'CSAFPID-0006', 'CSAFPID-0010', 'CSAFPID-0014', 'CSAFPID-0018', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0029']}], 'product_status': {'known_affected': ['CSAFPID-0002', 'CSAFPID-0006', 'CSAFPID-0010', 'CSAFPID-0014', 'CSAFPID-0018', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0029']}}, {'cve': 'CVE-2022-23129', 'cwe': {'id': 'CWE-256', 'name': 'Plaintext Storage of a Password'}, 'notes': [{'text': 'Information disclosure vulnerability due to Plaintext Storage of a Password (CWE-256) exists in Mitsubishi Electric Iconics Digital Solutions GENESIS64 and ICONICS Suite and Mitsubishi Electric GENESIS64, ICONICS Suite, and MC Works64.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/T:T/2026-02-10T00:00:00.000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H'}, 'products': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-23129', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://iconics.com/About/Security/CERT', 'details': 'Mitsubishi Electric Iconics Digital Solutions is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric Iconics Digital Solutions whitepaper on security vulnerabilities, the most recent version of which can be found here. https://iconics.com/About/Security/CERT', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019']}, {'url': 'https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-027_en.pdf', 'details': 'Mitsubishi Electric is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric security advisory, the most recent version of which can be found here. https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-027_en.pdf', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend deleting the authentication information (password) of the SQL database in the CSV file, after exporting the configuration information of GridWorX to the CSV file, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend deleting the authentication information (password) of the SQL database, before exporting the configuration information of GridWorX to the CSV file, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend changing the configuration of the security function so that users other than administrator is not authorized to export the configuration information of GridWorX to a CSV file, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend locating control system networks and remote devices behind firewalls and isolating them from the business network, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend restricting the connection of all control system devices and systems to the network so that they can only be accessed from trusted networks and hosts, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}], 'product_status': {'known_affected': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}}, {'cve': 'CVE-2022-23130', 'cwe': {'id': 'CWE-126', 'name': 'Buffer Over-read'}, 'notes': [{'text': ' Denial-of-Service (DoS) vulnerability due to Buffer Over-read (CWE-126) exists in database server of Mitsubishi Electric Iconics Digital Solutions GENESIS64, ICONICS, and GENESIS32 Suite and Mitsubishi Electric GENESIS64, ICONICS Suite, GENESIS32, and MC Works64.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/T:P/2026-02-10T00:00:00.000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:H'}, 'products': ['CSAFPID-0004', 'CSAFPID-0008', 'CSAFPID-0012', 'CSAFPID-0016', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0029']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-23130', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://iconics.com/About/Security/CERT', 'details': 'Mitsubishi Electric Iconics Digital Solutions is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric Iconics Digital Solutions whitepaper on security vulnerabilities, the most recent version of which can be found here. https://iconics.com/About/Security/CERT', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004', 'CSAFPID-0008', 'CSAFPID-0012', 'CSAFPID-0016', 'CSAFPID-0020']}, {'url': 'https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-028_en.pdf', 'details': 'Mitsubishi Electric is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric security advisory, the most recent version of which can be found here. https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-028_en.pdf', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0029']}, {'details': 'There are no plans to release a security update for GENESIS32. To minimize the risk of exploitation of this vulnerability, please consider replacing to GENESIS64 or ICONICS Suite.', 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0021', 'CSAFPID-0027']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend locating control system networks and remote devices behind firewalls and isolating them from the business network, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004', 'CSAFPID-0008', 'CSAFPID-0012', 'CSAFPID-0016', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0029']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend restricting the connection of all control system devices and systems to the network so that they can only be accessed from trusted networks and hosts, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004', 'CSAFPID-0008', 'CSAFPID-0012', 'CSAFPID-0016', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0029']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend avoiding clicking on web links in emails etc. from untrusted sources, and avoiding opening files attached to untrusted emails, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004', 'CSAFPID-0008', 'CSAFPID-0012', 'CSAFPID-0016', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0029']}], 'product_status': {'known_affected': ['CSAFPID-0004', 'CSAFPID-0008', 'CSAFPID-0012', 'CSAFPID-0016', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0029']}}]} | |
ot | ICSA-22-020-01 | CVE-2022-23130 | Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric HMI SCADA (Update B) | 2022-01-20 10:00:00+03:00 | 2026-03-05 10:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2022/icsa-22-020-01.json | 2adf922aaaec49dfa9658f7e300497a2befd777c419a77d416e5e1ae900af988 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could result in unauthorized access to information or to GENESIS64 and MC Works64 functionality, or the disabling of SQL Server in GENESIS64, ICONICS Suite, MC Works64, or GENESIS32.', 'title': 'Risk evaluation', 'category': 'summary'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States (Mitsubishi Electric Iconics Digital Solutions), Japan (Mitsubishi Electric)', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric HMI SCADA (Update B)', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-22-020-01', 'status': 'draft', 'version': '3', 'generator': {'date': '2026-03-05T00:05:34.123002Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2022-01-20T07:00:00.000000Z', 'number': '1', 'summary': 'IInitial Publication', 'legacy_version': 'Initial'}, {'date': '2026-01-08T00:00:00.000000Z', 'number': '2', 'summary': 'Update A - Added GENESIS32.', 'legacy_version': 'Update A'}, {'date': '2026-03-05T00:00:00.000000Z', 'number': '3', 'summary': 'Update B - Fixes for affected versions and typographical errors', 'legacy_version': 'Update B'}], 'current_release_date': '2026-03-05T07:00:00.000000Z', 'initial_release_date': '2022-01-20T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2022/icsa-22-020-01.json', 'summary': 'ICS Advisory ICSA-22-020-01 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-22-020-01', 'summary': 'ICSA Advisory ICSA-22-020-01 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to CISA', 'organization': 'Mitsubishi Electric Iconics Digital Solutions'}, {'summary': 'reported these vulnerabilities to CISA', 'organization': 'Mitsubishi Electric'}]}, 'product_tree': {'branches': [{'name': 'Mitsubishi Electric Iconics Digital Solutions', 'branches': [{'name': 'ICONICS Suite', 'branches': [{'name': '<=10.96.2', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions ICONICS Suite: <=10.96.2', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'ICONICS Suite', 'branches': [{'name': '>=10.95.3 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions ICONICS Suite: >=10.95.3 | <=10.97', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'ICONICS Suite', 'branches': [{'name': '>=10.90 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions ICONICS Suite: >=10.90 | <=10.97', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'ICONICS Suite', 'branches': [{'name': '<=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions ICONICS Suite: <=10.97', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'GENESIS64', 'branches': [{'name': '<=10.96.2', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions GENESIS64: <=10.96.2', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'GENESIS64', 'branches': [{'name': '>=10.95.3 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions GENESIS64: >=10.95.3 | <=10.97', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'GENESIS64', 'branches': [{'name': '>=10.90 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions GENESIS64: >=10.90 | <=10.97', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'GENESIS64', 'branches': [{'name': '<=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions GENESIS64: <=10.97', 'product_id': 'CSAFPID-0008'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Hyper Historian', 'branches': [{'name': '<=10.96.2', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions Hyper Historian: <=10.96.2', 'product_id': 'CSAFPID-0009'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Hyper Historian', 'branches': [{'name': '>=10.95.3 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions Hyper Historian: >=10.95.3 | <=10.97', 'product_id': 'CSAFPID-0010'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Hyper Historian', 'branches': [{'name': '>=10.90 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions Hyper Historian: >=10.90 | <=10.97', 'product_id': 'CSAFPID-0011'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Hyper Historian', 'branches': [{'name': '<=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions Hyper Historian: <=10.97', 'product_id': 'CSAFPID-0012'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'AnalytiX', 'branches': [{'name': '<=10.96.2', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions AnalytiX: <=10.96.2', 'product_id': 'CSAFPID-0013'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'AnalytiX', 'branches': [{'name': '>=10.95.3 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions AnalytiX: >=10.95.3 | <=10.97', 'product_id': 'CSAFPID-0014'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'AnalytiX', 'branches': [{'name': '>=10.90 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions AnalytiX: >=10.90 | <=10.97', 'product_id': 'CSAFPID-0015'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'AnalytiX', 'branches': [{'name': '<=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions AnalytiX: <=10.97', 'product_id': 'CSAFPID-0016'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'MobileHMI', 'branches': [{'name': '<=10.96.2', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions MobileHMI: <=10.96.2', 'product_id': 'CSAFPID-0017'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'MobileHMI', 'branches': [{'name': '>=10.95.3 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions MobileHMI: >=10.95.3 | <=10.97', 'product_id': 'CSAFPID-0018'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'MobileHMI', 'branches': [{'name': '>=10.90 | <=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions MobileHMI: >=10.90 | <=10.97', 'product_id': 'CSAFPID-0019'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'MobileHMI', 'branches': [{'name': '<=10.97', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions MobileHMI: <=10.97', 'product_id': 'CSAFPID-0020'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'GENESIS32', 'branches': [{'name': '<=9.7', 'product': {'name': 'Mitsubishi Electric Iconics Digital Solutions GENESIS32: <=9.7', 'product_id': 'CSAFPID-0021'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}, {'name': 'Mitsubishi Electric', 'branches': [{'name': 'ICONICS Suite', 'branches': [{'name': '10.97', 'product': {'name': 'Mitsubishi Electric ICONICS Suite: 10.97', 'product_id': 'CSAFPID-0022'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'GENESIS64', 'branches': [{'name': '10.97', 'product': {'name': 'Mitsubishi Electric GENESIS64: 10.97', 'product_id': 'CSAFPID-0023'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Hyper Historian', 'branches': [{'name': '10.97', 'product': {'name': 'Mitsubishi Electric Hyper Historian: 10.97', 'product_id': 'CSAFPID-0024'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'AnalytiX', 'branches': [{'name': '10.97', 'product': {'name': 'Mitsubishi Electric AnalytiX: 10.97', 'product_id': 'CSAFPID-0025'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'MobileHMI', 'branches': [{'name': '10.97', 'product': {'name': 'Mitsubishi Electric MobileHMI: 10.97', 'product_id': 'CSAFPID-0026'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'GENESIS32', 'branches': [{'name': '<=9.7', 'product': {'name': 'Mitsubishi Electric GENESIS32: <=9.7', 'product_id': 'CSAFPID-0027'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'MC Works64', 'branches': [{'name': '<=4.04E', 'product': {'name': 'Mitsubishi Electric MC Works64: <=4.04E', 'product_id': 'CSAFPID-0028'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'MC Works64', 'branches': [{'name': '>=4.00A | <=4.04E', 'product': {'name': 'Mitsubishi Electric MC Works64: >=4.00A | <=4.04E', 'product_id': 'CSAFPID-0029'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2022-23127', 'cwe': {'id': 'CWE-79', 'name': "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"}, 'notes': [{'text': 'Information disclosure vulnerability due to Improper Neutralization of Input During Web Page Generation (CWE-79) caused by the lack of proper input verification exists in Mitsubishi Electric Iconics Digital Solutions GENESIS64 and ICONICS Suite and Mitsubishi Electric MC Works64.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/T:P/2026-02-10T00:00:00.000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 4.2, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0005', 'CSAFPID-0009', 'CSAFPID-0013', 'CSAFPID-0017', 'CSAFPID-0028']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-23127', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://iconics.com/About/Security/CERT', 'details': 'Mitsubishi Electric Iconics Digital Solutions is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric Iconics Digital Solutions whitepaper on security vulnerabilities, the most recent version of which can be found here. https://iconics.com/About/Security/CERT', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0005', 'CSAFPID-0009', 'CSAFPID-0013', 'CSAFPID-0017']}, {'url': 'https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-025_en.pdf', 'details': ' Mitsubishi Electric is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric security advisory, the most recent version of which can be found here. https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-025_en.pdf', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend locating control system networks and remote devices behind firewalls and isolating them from the business network, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0005', 'CSAFPID-0009', 'CSAFPID-0013', 'CSAFPID-0017', 'CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend restricting the connection of all control system devices and systems to the network so that they can only be accessed from trusted networks and hosts, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0005', 'CSAFPID-0009', 'CSAFPID-0013', 'CSAFPID-0017', 'CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend restricting the connection of all control system devices and systems to the network so that they can only be accessed from trusted networks and hosts, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0005', 'CSAFPID-0009', 'CSAFPID-0013', 'CSAFPID-0017', 'CSAFPID-0028']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0005', 'CSAFPID-0009', 'CSAFPID-0013', 'CSAFPID-0017', 'CSAFPID-0028']}}, {'cve': 'CVE-2022-23128', 'cwe': {'id': 'CWE-184', 'name': 'Incomplete List of Disallowed Inputs'}, 'notes': [{'text': ' Authentication bypass vulnerability due to Incomplete List of Disallowed Inputs (CWE-184) exists in Mitsubishi Electric Iconics Digital Solutions GENESIS64 and ICONICS Suite Mitsubishi Electric GENESIS64, ICONICS Suite, and MC Works64.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/T:T/2026-02-10T00:00:00.000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0002', 'CSAFPID-0006', 'CSAFPID-0010', 'CSAFPID-0014', 'CSAFPID-0018', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0029']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-23128', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://iconics.com/About/Security/CERT', 'details': 'Mitsubishi Electric Iconics Digital Solutions is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric Iconics Digital Solutions whitepaper on security vulnerabilities, the most recent version of which can be found here. https://iconics.com/About/Security/CERT', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0002', 'CSAFPID-0006', 'CSAFPID-0010', 'CSAFPID-0014', 'CSAFPID-0018']}, {'url': 'https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-026_en.pdf', 'details': 'Mitsubishi Electric is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric security advisory, the most recent version of which can be found here. https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-026_en.pdf', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0029']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend switching the communication method of FrameWorX server from WebSocket communication to WCF communication and setting "WebSocketTransport" element to "false" in "FwxServer.Network.config" file located in the installation folder of the products, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002', 'CSAFPID-0006', 'CSAFPID-0010', 'CSAFPID-0014', 'CSAFPID-0018', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0029']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend locating control system networks and remote devices behind firewalls and isolating them from the business network, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002', 'CSAFPID-0006', 'CSAFPID-0010', 'CSAFPID-0014', 'CSAFPID-0018', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0029']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend restricting the connection of all control system devices and systems to the network so that they can only be accessed from trusted networks and hosts, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0002', 'CSAFPID-0006', 'CSAFPID-0010', 'CSAFPID-0014', 'CSAFPID-0018', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0029']}], 'product_status': {'known_affected': ['CSAFPID-0002', 'CSAFPID-0006', 'CSAFPID-0010', 'CSAFPID-0014', 'CSAFPID-0018', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0029']}}, {'cve': 'CVE-2022-23129', 'cwe': {'id': 'CWE-256', 'name': 'Plaintext Storage of a Password'}, 'notes': [{'text': 'Information disclosure vulnerability due to Plaintext Storage of a Password (CWE-256) exists in Mitsubishi Electric Iconics Digital Solutions GENESIS64 and ICONICS Suite and Mitsubishi Electric GENESIS64, ICONICS Suite, and MC Works64.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/T:T/2026-02-10T00:00:00.000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.7, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H'}, 'products': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-23129', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://iconics.com/About/Security/CERT', 'details': 'Mitsubishi Electric Iconics Digital Solutions is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric Iconics Digital Solutions whitepaper on security vulnerabilities, the most recent version of which can be found here. https://iconics.com/About/Security/CERT', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019']}, {'url': 'https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-027_en.pdf', 'details': 'Mitsubishi Electric is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric security advisory, the most recent version of which can be found here. https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-027_en.pdf', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend deleting the authentication information (password) of the SQL database in the CSV file, after exporting the configuration information of GridWorX to the CSV file, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend deleting the authentication information (password) of the SQL database, before exporting the configuration information of GridWorX to the CSV file, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend changing the configuration of the security function so that users other than administrator is not authorized to export the configuration information of GridWorX to a CSV file, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend locating control system networks and remote devices behind firewalls and isolating them from the business network, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend restricting the connection of all control system devices and systems to the network so that they can only be accessed from trusted networks and hosts, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}], 'product_status': {'known_affected': ['CSAFPID-0003', 'CSAFPID-0007', 'CSAFPID-0011', 'CSAFPID-0015', 'CSAFPID-0019', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0028']}}, {'cve': 'CVE-2022-23130', 'cwe': {'id': 'CWE-126', 'name': 'Buffer Over-read'}, 'notes': [{'text': ' Denial-of-Service (DoS) vulnerability due to Buffer Over-read (CWE-126) exists in database server of Mitsubishi Electric Iconics Digital Solutions GENESIS64, ICONICS, and GENESIS32 Suite and Mitsubishi Electric GENESIS64, ICONICS Suite, GENESIS32, and MC Works64.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/T:P/2026-02-10T00:00:00.000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.9, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:H'}, 'products': ['CSAFPID-0004', 'CSAFPID-0008', 'CSAFPID-0012', 'CSAFPID-0016', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0029']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-23130', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://iconics.com/About/Security/CERT', 'details': 'Mitsubishi Electric Iconics Digital Solutions is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric Iconics Digital Solutions whitepaper on security vulnerabilities, the most recent version of which can be found here. https://iconics.com/About/Security/CERT', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004', 'CSAFPID-0008', 'CSAFPID-0012', 'CSAFPID-0016', 'CSAFPID-0020']}, {'url': 'https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-028_en.pdf', 'details': 'Mitsubishi Electric is releasing security updates for the affected products as critical fixes/rollup releases. For more information on the security updates, refer to the Mitsubishi Electric security advisory, the most recent version of which can be found here. https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2021-028_en.pdf', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0029']}, {'details': 'There are no plans to release a security update for GENESIS32. To minimize the risk of exploitation of this vulnerability, please consider replacing to GENESIS64 or ICONICS Suite.', 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0021', 'CSAFPID-0027']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend locating control system networks and remote devices behind firewalls and isolating them from the business network, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004', 'CSAFPID-0008', 'CSAFPID-0012', 'CSAFPID-0016', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0029']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend restricting the connection of all control system devices and systems to the network so that they can only be accessed from trusted networks and hosts, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004', 'CSAFPID-0008', 'CSAFPID-0012', 'CSAFPID-0016', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0029']}, {'details': 'For customers who cannot immediately update the product, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric recommend avoiding clicking on web links in emails etc. from untrusted sources, and avoiding opening files attached to untrusted emails, to minimize the risk of exploiting this vulnerability.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0004', 'CSAFPID-0008', 'CSAFPID-0012', 'CSAFPID-0016', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0029']}], 'product_status': {'known_affected': ['CSAFPID-0004', 'CSAFPID-0008', 'CSAFPID-0012', 'CSAFPID-0016', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0029']}}]} | |
ot | ICSA-26-057-03 | CVE-2026-27652 | CloudCharge cloudcharge.se | 2026-02-26 10:00:00+03:00 | 2026-02-26 10:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-057-03.json | d5376ea7f2e1bfd645491393b28e41cff7e95739bef5740082e92d5d9e73ff71 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could allow attackers to impersonate charging stations, hijack sessions, suppress or misroute legitimate traffic to cause large-scale denial of service, and manipulate data sent to the backend.', 'title': 'Risk evaluation', 'category': 'summary'}, {'text': 'Energy, Transportation Systems', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Sweden', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'CloudCharge cloudcharge.se', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-057-03', 'status': 'final', 'version': '1', 'generator': {'date': '2026-02-25T21:17:50.139107Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-02-26T07:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}], 'current_release_date': '2026-02-26T07:00:00.000000Z', 'initial_release_date': '2026-02-26T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-057-03.json', 'summary': 'ICS Advisory ICSA-26-057-03 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-057-03', 'summary': 'ICSA Advisory ICSA-26-057-03 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Khaled Sarieddine', 'Mohammad Ali Sayed'], 'summary': 'reported these vulnerabilities to CISA'}]}, 'product_tree': {'branches': [{'name': 'CloudCharge', 'branches': [{'name': 'cloudcharge.se', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'CloudCharge cloudcharge.se: vers:all/*', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-20781', 'cwe': {'id': 'CWE-306', 'name': 'Missing Authentication for Critical Function'}, 'notes': [{'text': 'WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then issue or receive OCPP commands as a legitimate charger. Given that no authentication is required, this can lead to privilege escalation, unauthorized control of charging infrastructure, and corruption of charging network data reported to the backend.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-02-25T07:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.4, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/306.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-20781', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://cloudcharge.tech/support/contact/', 'details': "CloudCharge did not respond to CISA's request for coordination. Contact CloudCharge using their contact page here: https://cloudcharge.tech/support/contact/ for more information.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25114', 'cwe': {'id': 'CWE-307', 'name': 'Improper Restriction of Excessive Authentication Attempts'}, 'notes': [{'text': 'The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct brute-force attacks to gain unauthorized access.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-02-25T07:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/307.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25114', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://cloudcharge.tech/support/contact/', 'details': "CloudCharge did not respond to CISA's request for coordination. Contact CloudCharge using their contact page here: https://cloudcharge.tech/support/contact/ for more information.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-27652', 'cwe': {'id': 'CWE-613', 'name': 'Insufficient Session Expiration'}, 'notes': [{'text': 'The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the most recent connection displaces the legitimate charging station and receives backend commands intended for that station. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-02-25T07:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/613.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-27652', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://cloudcharge.tech/support/contact/', 'details': "CloudCharge did not respond to CISA's request for coordination. Contact CloudCharge using their contact page here: https://cloudcharge.tech/support/contact/ for more information.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-20733', 'cwe': {'id': 'CWE-522', 'name': 'Insufficiently Protected Credentials'}, 'notes': [{'text': 'Charging station authentication identifiers are publicly accessible via web-based mapping platforms.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-02-25T07:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/522.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-20733', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://cloudcharge.tech/support/contact/', 'details': "CloudCharge did not respond to CISA's request for coordination. Contact CloudCharge using their contact page here: https://cloudcharge.tech/support/contact/ for more information.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-057-03 | CVE-2026-20733 | CloudCharge cloudcharge.se | 2026-02-26 10:00:00+03:00 | 2026-02-26 10:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-057-03.json | 91908f8f2eb9522196aae2a5bae1515c753a84bb5af3b4929f9f7d3812972da9 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could allow attackers to impersonate charging stations, hijack sessions, suppress or misroute legitimate traffic to cause large-scale denial of service, and manipulate data sent to the backend.', 'title': 'Risk evaluation', 'category': 'summary'}, {'text': 'Energy, Transportation Systems', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Sweden', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'CloudCharge cloudcharge.se', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-057-03', 'status': 'final', 'version': '1', 'generator': {'date': '2026-02-25T21:17:50.139107Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-02-26T07:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}], 'current_release_date': '2026-02-26T07:00:00.000000Z', 'initial_release_date': '2026-02-26T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-057-03.json', 'summary': 'ICS Advisory ICSA-26-057-03 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-057-03', 'summary': 'ICSA Advisory ICSA-26-057-03 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Khaled Sarieddine', 'Mohammad Ali Sayed'], 'summary': 'reported these vulnerabilities to CISA'}]}, 'product_tree': {'branches': [{'name': 'CloudCharge', 'branches': [{'name': 'cloudcharge.se', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'CloudCharge cloudcharge.se: vers:all/*', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-20781', 'cwe': {'id': 'CWE-306', 'name': 'Missing Authentication for Critical Function'}, 'notes': [{'text': 'WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then issue or receive OCPP commands as a legitimate charger. Given that no authentication is required, this can lead to privilege escalation, unauthorized control of charging infrastructure, and corruption of charging network data reported to the backend.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-02-25T07:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.4, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/306.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-20781', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://cloudcharge.tech/support/contact/', 'details': "CloudCharge did not respond to CISA's request for coordination. Contact CloudCharge using their contact page here: https://cloudcharge.tech/support/contact/ for more information.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-25114', 'cwe': {'id': 'CWE-307', 'name': 'Improper Restriction of Excessive Authentication Attempts'}, 'notes': [{'text': 'The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct brute-force attacks to gain unauthorized access.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-02-25T07:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/307.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25114', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://cloudcharge.tech/support/contact/', 'details': "CloudCharge did not respond to CISA's request for coordination. Contact CloudCharge using their contact page here: https://cloudcharge.tech/support/contact/ for more information.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-27652', 'cwe': {'id': 'CWE-613', 'name': 'Insufficient Session Expiration'}, 'notes': [{'text': 'The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the most recent connection displaces the legitimate charging station and receives backend commands intended for that station. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-02-25T07:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.3, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/613.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-27652', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://cloudcharge.tech/support/contact/', 'details': "CloudCharge did not respond to CISA's request for coordination. Contact CloudCharge using their contact page here: https://cloudcharge.tech/support/contact/ for more information.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-20733', 'cwe': {'id': 'CWE-522', 'name': 'Insufficiently Protected Credentials'}, 'notes': [{'text': 'Charging station authentication identifiers are publicly accessible via web-based mapping platforms.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-02-25T07:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 6.5, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/522.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-20733', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://cloudcharge.tech/support/contact/', 'details': "CloudCharge did not respond to CISA's request for coordination. Contact CloudCharge using their contact page here: https://cloudcharge.tech/support/contact/ for more information.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-055-01 | CVE-2026-21410 | InSAT MasterSCADA BUK-TS | 2026-02-24 10:00:00+03:00 | 2026-02-24 10:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-055-01.json | 5d1e88c5ee77f932e638da5bda40fbc2d9d0fc01e3365c008b94e67837dff6a3 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities may allow remote code execution.', 'title': 'Risk evaluation', 'category': 'summary'}, {'text': 'Critical Manufacturing, Energy, Water and Wastewater', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Russia', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'InSAT MasterSCADA BUK-TS', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-055-01', 'status': 'final', 'version': '1', 'generator': {'date': '2026-02-23T18:58:15.622238Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-02-24T07:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}], 'current_release_date': '2026-02-24T07:00:00.000000Z', 'initial_release_date': '2026-02-24T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-055-01.json', 'summary': 'ICS Advisory ICSA-26-055-01 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-055-01', 'summary': 'ICSA Advisory ICSA-26-055-01 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Adem El Adeb'], 'summary': 'reported these vulnerabilities to CISA'}]}, 'product_tree': {'branches': [{'name': 'InSAT', 'branches': [{'name': 'MasterSCADA BUK-TS', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'InSAT MasterSCADA BUK-TS: vers:all/*', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-21410', 'cwe': {'id': 'CWE-89', 'name': "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"}, 'notes': [{'text': 'InSAT MasterSCADA BUK-TS is susceptible to SQL Injection through its main web interface. Malicious users that use the vulnerable endpoint are potentially able to cause remote code execution.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-02-23T07:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/89.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-21410', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'mailto:info@insat.ru', 'details': 'InSAT has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of the affected products are encouraged to contact info@insat.ru or scada@insat.ru for additional information.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'mailto:scada@insat.ru', 'details': 'InSAT has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of the affected products are encouraged to contact info@insat.ru or scada@insat.ru for additional information.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-22553', 'cwe': {'id': 'CWE-78', 'name': "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}, 'notes': [{'text': 'All versions of InSAT MasterSCADA BUK-TS are susceptible to OS command injection through a field in its MMadmServ web interface. Malicious users that use the vulnerable endpoint are potentially able to cause remote code execution.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-02-23T07:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/78.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-22553', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'mailto:info@insat.ru', 'details': 'InSAT has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of the affected products are encouraged to contact info@insat.ru or scada@insat.ru for additional information.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'mailto:scada@insat.ru', 'details': 'InSAT has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of the affected products are encouraged to contact info@insat.ru or scada@insat.ru for additional information.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-050-03 | CVE-2026-24455 | Jinan USR IOT Technology Limited (PUSR) USR-W610 | 2026-02-19 10:00:00+03:00 | 2026-02-19 10:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-050-03.json | 7a4e48a2fbb2ec0484ad18d400f3452e29cc7d0ec90bf91408e6b4f1d34133a0 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could result in authentication being disabled, a denial-of-service condition, or an attacker stealing valid user credentials, including administrator credentials.', 'title': 'Risk evaluation', 'category': 'summary'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'China', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Jinan USR IOT Technology Limited (PUSR) USR-W610', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-050-03', 'status': 'final', 'version': '1', 'generator': {'date': '2026-02-18T15:41:58.419343Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-02-19T07:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}], 'current_release_date': '2026-02-19T07:00:00.000000Z', 'initial_release_date': '2026-02-19T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-050-03.json', 'summary': 'ICS Advisory ICSA-26-050-03 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-050-03', 'summary': 'ICSA Advisory ICSA-26-050-03 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Abhishek Pandey'], 'summary': 'reported CVE-2026-25715, CVE-2026-24455, and CVE-2026-26049 to CISA', 'organization': 'Payatu Security Consulting'}, {'names': ['Abhishek Pandey', 'Ranit Pradhan'], 'summary': 'reported CVE-2026-26048 to CISA', 'organization': 'Payatu Security Consulting'}]}, 'product_tree': {'branches': [{'name': 'Jinan USR IOT Technology Limited (PUSR)', 'branches': [{'name': 'USR-W610', 'branches': [{'name': '<=3.1.1.0', 'product': {'name': 'Jinan USR IOT Technology Limited (PUSR) USR-W610: <=3.1.1.0', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-25715', 'cwe': {'id': 'CWE-521', 'name': 'Weak Password Requirements'}, 'notes': [{'text': 'The web management interface of the device allows the administrator username and password to be set to blank values. Once applied, the device permits authentication with empty credentials over the web management interface and Telnet service. This effectively disables authentication across all critical management channels, allowing any network-adjacent attacker to gain full administrative control without credentials.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-02-18T07:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/521.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-25715', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'mailto:inquiry@usriot.com', 'details': 'Jinan USR IOT Technology Limited (PUSR) has stated that the product is end-of-life, and there are no plans to patch. Users of PUSR USR-W610 devices are encouraged to contact PUSR and keep their systems up to date.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-24455', 'cwe': {'id': 'CWE-319', 'name': 'Cleartext Transmission of Sensitive Information'}, 'notes': [{'text': 'The embedded web interface of the device does not support HTTPS/TLS for authentication and uses HTTP Basic Authentication. Traffic is encoded but not encrypted, exposing user credentials to passive interception by attackers on the same network.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-02-18T07:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/319.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-24455', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'mailto:inquiry@usriot.com', 'details': 'Jinan USR IOT Technology Limited (PUSR) has stated that the product is end-of-life, and there are no plans to patch. Users of PUSR USR-W610 devices are encouraged to contact PUSR and keep their systems up to date.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-26049', 'cwe': {'id': 'CWE-522', 'name': 'Insufficiently Protected Credentials'}, 'notes': [{'text': 'The web management interface of the device renders the passwords in a plaintext input field. The current password is directly visible to anyone with access to the UI, potentially exposing administrator credentials to unauthorized observation via shoulder surfing, screenshots, or browser form caching.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-02-18T07:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.7, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/522.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-26049', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'mailto:inquiry@usriot.com', 'details': 'Jinan USR IOT Technology Limited (PUSR) has stated that the product is end-of-life, and there are no plans to patch. Users of PUSR USR-W610 devices are encouraged to contact PUSR and keep their systems up to date.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2026-26048', 'cwe': {'id': 'CWE-306', 'name': 'Missing Authentication for Critical Function'}, 'notes': [{'text': 'The Wi-Fi router is vulnerable to de-authentication attacks due to the absence of Management Frame Protection, allowing forged deauthentication and disassociation frames to be broadcast without authentication or encryption. An attacker can use this to cause unauthorized disruptions and create a denial-of-service condition.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:Y/2026-02-18T07:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/306.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-26048', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'mailto:inquiry@usriot.com', 'details': 'Jinan USR IOT Technology Limited (PUSR) has stated that the product is end-of-life, and there are no plans to patch. Users of PUSR USR-W610 devices are encouraged to contact PUSR and keep their systems up to date.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-12-349-01 | CVE-2012-4691 | Siemens Automation License Manager Uncontrolled Resource Consumption | 2012-12-12 04:00:00+04:00 | 2026-02-12 10:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2012/icsa-12-349-01.json | 660a483230906fdfeab06a78e5552bad06e94af3fa179402a35459f28f41c8a1 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en', 'notes': [{'text': 'A vulnerability was identified in the Automation License Manager software before V5.2 that could be triggered by sending specially crafted packets to port 4410/tcp of an affected system. This could cause a denial of service preventing legitimate users from using the system.\n\nSiemens has released a new version for Automation License Manager and recommends to update to the latest version.', 'title': 'Summary', 'category': 'summary'}, {'text': "As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and to follow the recommendations in the product manuals.\nAdditional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity", 'title': 'General Recommendations', 'category': 'general'}, {'text': 'For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories', 'title': 'Additional Resources', 'category': 'general'}, {'text': 'The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use.', 'title': 'Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of Siemens ProductCERT SSA-783261 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Germany', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Siemens Automation License Manager Uncontrolled Resource Consumption', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-12-349-01', 'status': 'final', 'version': '5', 'generator': {'date': '2026-02-11T22:36:08.464936Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2012-09-17T06:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}, {'date': '2012-12-12T00:00:00.000000Z', 'number': '2', 'summary': 'Publication Date', 'legacy_version': 'Additional Release 1'}, {'date': '2025-06-06T22:38:35.719268Z', 'number': '3', 'summary': 'Advisory converted into a CSAF', 'legacy_version': 'Additional Release 2'}, {'date': '2026-02-10T00:00:00.000000Z', 'number': '4', 'summary': 'Used CVE ID (CVE-2012-4691) instead of the deprecated SVE ID (SVE-2012-0001); Corrected CVSS vector; Updated SSA to current data model and support of csaf', 'legacy_version': 'Additional Release 3'}, {'date': '2026-02-12T07:00:00.000000Z', 'number': '5', 'summary': 'CISA Republication update based on Siemens ProductCERT SSA-783261 advisory', 'legacy_version': 'Latest Updated CISA Republication'}], 'current_release_date': '2026-02-12T07:00:00.000000Z', 'initial_release_date': '2012-12-12T00:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://cert-portal.siemens.com/productcert/csaf/ssa-783261.json', 'summary': 'SSA-783261: Denial of Service Vulnerability in Automation License Manager (ALM) Before V5.2 - CSAF Version', 'category': 'self'}, {'url': 'https://cert-portal.siemens.com/productcert/html/ssa-783261.html', 'summary': 'SSA-783261: Denial of Service Vulnerability in Automation License Manager (ALM) Before V5.2 - HTML Version', 'category': 'self'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2012/icsa-12-349-01.json', 'summary': 'ICS Advisory ICSA-12-349-01 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-12-349-01', 'summary': 'ICS Advisory ICSA-12-349-01 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported this vulnerability to CISA.', 'organization': 'Siemens ProductCERT'}]}, 'product_tree': {'branches': [{'name': 'Siemens', 'branches': [{'name': 'Automation License Manager', 'branches': [{'name': 'vers:intdot/>=4.0|<5.2', 'product': {'name': 'Automation License Manager', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2012-4691', 'cwe': {'id': 'CWE-400', 'name': 'Uncontrolled Resource Consumption'}, 'notes': [{'text': 'Specially crafted packets sent to port 4410/tcp cause memory leaks within the application. This could allow a remote unauthenticated attacker to crash the application due to insufficient resources. This denial of service condition could prevent legitimate users from using subsequent products that rely on the affected application for license verification.', 'title': 'Summary', 'category': 'summary'}], 'title': 'CVE-2012-4691', 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.6, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2012-4691', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/400.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'If remote connections are needed, limit remote access to port 4410/tcp to trusted systems only', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'On the Automation License Manager settings menu disable "Allow Remote Connections"', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://support.industry.siemens.com/cs/ww/en/view/114358/', 'details': 'Update to V5.2 or later version', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-036-01 | CVE-2026-0629 | TP-Link Systems Inc. VIGI Series IP Camera | 2026-02-05 09:00:00+03:00 | 2026-02-11 09:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-036-01.json | ae23e2888eb45312307b83b74503a1033e3474ce4a569e6cf5889fb9508c9f09 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of this vulnerability could result in unauthorized users gaining administrative access to affected closed circuit television cameras.', 'title': 'Risk evaluation', 'category': 'summary'}, {'text': 'Commercial Facilities', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability, such as:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the Internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'TP-Link Systems Inc. VIGI Series IP Camera', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-036-01', 'status': 'final', 'version': '2', 'generator': {'date': '2026-02-04T20:02:24.548178Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-02-05T06:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}, {'date': '2026-02-11T06:00:00.000000Z', 'number': '2', 'summary': 'Updated Headquarters Country to US and corrected reference to TP-Link Systems Inc.', 'legacy_version': 'Additional Release 1'}], 'current_release_date': '2026-02-11T06:00:00.000000Z', 'initial_release_date': '2026-02-05T06:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-036-01.json', 'summary': 'ICS Advisory ICSA-26-036-01 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-036-01', 'summary': 'ICSA Advisory ICSA-26-036-01 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Arko Dhar'], 'summary': 'reported this vulnerability to CISA', 'organization': 'Redinent Innovations'}]}, 'product_tree': {'branches': [{'name': 'TP-Link Systems Inc.', 'branches': [{'name': 'VIGI Cx45 Series Models C345, C445', 'branches': [{'name': '<=3.1.0_Build_250820_Rel.57668n', 'product': {'name': 'TP-Link Systems Inc. VIGI Cx45 Series Models C345, C445: <=3.1.0_Build_250820_Rel.57668n', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VIGI Cx55 Series Models C355, C455', 'branches': [{'name': '<=3.1.0_Build_250820_Rel.58873n', 'product': {'name': 'TP-Link Systems Inc. VIGI Cx55 Series Models C355, C455: <=3.1.0_Build_250820_Rel.58873n', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VIGI Cx85 Series Models C385, C485', 'branches': [{'name': '<=3.0.2_Build_250630_Rel.71279n', 'product': {'name': 'TP-Link Systems Inc. VIGI Cx85 Series Models C385, C485: <=3.0.2_Build_250630_Rel.71279n', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VIGI C340S Series', 'branches': [{'name': '<=3.1.0_Build_250625_Rel.65381n', 'product': {'name': 'TP-Link Systems Inc. VIGI C340S Series: <=3.1.0_Build_250625_Rel.65381n', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VIGI C540S Series Models C540S, EasyCam C540S', 'branches': [{'name': '<=3.1.0_Build_250625_Rel.66601n', 'product': {'name': 'TP-Link Systems Inc. VIGI C540S Series Models C540S, EasyCam C540S: <=3.1.0_Build_250625_Rel.66601n', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VIGI C540V Series', 'branches': [{'name': '<=2.1.0_Build_250702_Rel.54300n', 'product': {'name': 'TP-Link Systems Inc. VIGI C540V Series: <=2.1.0_Build_250702_Rel.54300n', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VIGI C250 Series', 'branches': [{'name': '<=2.1.0_Build_250702_Rel.54301n', 'product': {'name': 'TP-Link Systems Inc. VIGI C250 Series: <=2.1.0_Build_250702_Rel.54301n', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VIGI Cx50 Series Models C350, C450', 'branches': [{'name': '<=2.1.0_Build_250702_Rel.54294n', 'product': {'name': 'TP-Link Systems Inc. VIGI Cx50 Series Models C350, C450: <=2.1.0_Build_250702_Rel.54294n', 'product_id': 'CSAFPID-0008'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VIGI Cx20I (1.0) Series Models C220I 1.0, C320I 1.0, C420I 1.0', 'branches': [{'name': '<=2.1.0_Build_251014_Rel.58331n', 'product': {'name': 'TP-Link Systems Inc. VIGI Cx20I (1.0) Series Models C220I 1.0, C320I 1.0, C420I 1.0: <=2.1.0_Build_251014_Rel.58331n', 'product_id': 'CSAFPID-0009'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VIGI Cx20I (1.20) Series Models C220I 1.20, C320I 1.20, C420I 1.20', 'branches': [{'name': '<=2.1.0_Build_250701_Rel.44071n', 'product': {'name': 'TP-Link Systems Inc. VIGI Cx20I (1.20) Series Models C220I 1.20, C320I 1.20, C420I 1.20: <=2.1.0_Build_250701_Rel.44071n', 'product_id': 'CSAFPID-0010'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VIGI Cx30I (1.0) Series Models C230I 1.0, C330I 1.0, C430I 1.0', 'branches': [{'name': '<=2.1.0_Build_250701_Rel.45506n', 'product': {'name': 'TP-Link Systems Inc. VIGI Cx30I (1.0) Series Models C230I 1.0, C330I 1.0, C430I 1.0: <=2.1.0_Build_250701_Rel.45506n', 'product_id': 'CSAFPID-0011'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VIGI Cx30I (1.20) Series Models C230I 1.20, C330I 1.20, C430I 1.20', 'branches': [{'name': '<=2.1.0_Build_250701_Rel.44555n', 'product': {'name': 'TP-Link Systems Inc. VIGI Cx30I (1.20) Series Models C230I 1.20, C330I 1.20, C430I 1.20: <=2.1.0_Build_250701_Rel.44555n', 'product_id': 'CSAFPID-0012'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VIGI Cx30 (1.0) Series Models C230 1.0, C330 1.0, C430 1.0', 'branches': [{'name': '<=2.1.0_Build_250701_Rel.46796n', 'product': {'name': 'TP-Link Systems Inc. VIGI Cx30 (1.0) Series Models C230 1.0, C330 1.0, C430 1.0: <=2.1.0_Build_250701_Rel.46796n', 'product_id': 'CSAFPID-0013'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VIGI Cx30 (1.20) Series Models C230 1.20, C330 1.20, C430 1.20', 'branches': [{'name': '<=2.1.0_Build_250701_Rel.46796n', 'product': {'name': 'TP-Link Systems Inc. VIGI Cx30 (1.20) Series Models C230 1.20, C330 1.20, C430 1.20: <=2.1.0_Build_250701_Rel.46796n', 'product_id': 'CSAFPID-0014'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VIGI Cx40I (1.0) Series Models C240I 1.0, C340I 1.0, C440I 1.0', 'branches': [{'name': '<=2.1.0_Build_250701_Rel.46003n', 'product': {'name': 'TP-Link Systems Inc. VIGI Cx40I (1.0) Series Models C240I 1.0, C340I 1.0, C440I 1.0: <=2.1.0_Build_250701_Rel.46003n', 'product_id': 'CSAFPID-0015'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VIGI Cx40I (1.20) Series Models C240I 1.20, C340I 1.20, C440I 1.20', 'branches': [{'name': '<=2.1.0_Build_250701_Rel.45041n', 'product': {'name': 'TP-Link Systems Inc. VIGI Cx40I (1.20) Series Models C240I 1.20, C340I 1.20, C440I 1.20: <=2.1.0_Build_250701_Rel.45041n', 'product_id': 'CSAFPID-0016'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VIGI C230I Mini Series', 'branches': [{'name': '<=2.1.0_Build_250701_Rel.47570n', 'product': {'name': 'TP-Link Systems Inc. VIGI C230I Mini Series: <=2.1.0_Build_250701_Rel.47570n', 'product_id': 'CSAFPID-0017'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VIGI C240 1.0 Series', 'branches': [{'name': '<=2.1.0_Build_250701_Rel.48425n', 'product': {'name': 'TP-Link Systems Inc. VIGI C240 1.0 Series: <=2.1.0_Build_250701_Rel.48425n', 'product_id': 'CSAFPID-0018'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VIGI C340 2.0 Series', 'branches': [{'name': '<=2.1.0_Build_250701_Rel.49304n', 'product': {'name': 'TP-Link Systems Inc. VIGI C340 2.0 Series: <=2.1.0_Build_250701_Rel.49304n', 'product_id': 'CSAFPID-0019'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VIGI C440 2.0 Series', 'branches': [{'name': '<=2.1.0_Build_250701_Rel.49778n', 'product': {'name': 'TP-Link Systems Inc. VIGI C440 2.0 Series: <=2.1.0_Build_250701_Rel.49778n', 'product_id': 'CSAFPID-0020'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VIGI C540 2.0 Series', 'branches': [{'name': '<=2.1.0_Build_250701_Rel.50397n', 'product': {'name': 'TP-Link Systems Inc. VIGI C540 2.0 Series: <=2.1.0_Build_250701_Rel.50397n', 'product_id': 'CSAFPID-0021'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VIGI C540‑4G Series', 'branches': [{'name': '<=2.2.0_Build_250826_Rel.56808n', 'product': {'name': 'TP-Link Systems Inc. VIGI C540‑4G Series: <=2.2.0_Build_250826_Rel.56808n', 'product_id': 'CSAFPID-0022'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VIGI Cx40‑W Series Models C340‑W 2.0/2.20, C440‑W 2.0, C540‑W 2.0', 'branches': [{'name': '<=2.1.1_Build_250717', 'product': {'name': 'TP-Link Systems Inc. VIGI Cx40‑W Series Models C340‑W 2.0/2.20, C440‑W 2.0, C540‑W 2.0: <=2.1.1_Build_250717', 'product_id': 'CSAFPID-0023'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VIGI Cx20 Series Models C320, C420', 'branches': [{'name': '<=2.1.0_Build_250701_Rel.39597n', 'product': {'name': 'TP-Link Systems Inc. VIGI Cx20 Series Models C320, C420: <=2.1.0_Build_250701_Rel.39597n', 'product_id': 'CSAFPID-0024'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VIGI InSight Sx45 Series Models S245, S345, S445', 'branches': [{'name': '<=3.1.0_Build_250820_Rel.57668n', 'product': {'name': 'TP-Link Systems Inc. VIGI InSight Sx45 Series Models S245, S345, S445: <=3.1.0_Build_250820_Rel.57668n', 'product_id': 'CSAFPID-0025'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VIGI InSight Sx55 Series Models S355, S455', 'branches': [{'name': '<=3.1.0_Build_250820_Rel.58873n', 'product': {'name': 'TP-Link Systems Inc. VIGI InSight Sx55 Series Models S355, S455: <=3.1.0_Build_250820_Rel.58873n', 'product_id': 'CSAFPID-0026'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VIGI InSight Sx85 Series Models S285, S385', 'branches': [{'name': '<=3.0.2_Build_250630_Rel.71279n', 'product': {'name': 'TP-Link Systems Inc. VIGI InSight Sx85 Series Models S285, S385: <=3.0.2_Build_250630_Rel.71279n', 'product_id': 'CSAFPID-0027'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VIGI InSight Sx45ZI Series Models S245ZI, S345ZI, S445ZI', 'branches': [{'name': '<=1.2.0_Build_250820_Rel.60930n', 'product': {'name': 'TP-Link Systems Inc. VIGI InSight Sx45ZI Series Models S245ZI, S345ZI, S445ZI: <=1.2.0_Build_250820_Rel.60930n', 'product_id': 'CSAFPID-0028'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VIGI InSight Sx85PI Series Models S385PI, S485PI', 'branches': [{'name': '<=1.2.0_Build_250827_Rel.66817n', 'product': {'name': 'TP-Link Systems Inc. VIGI InSight Sx85PI Series Models S385PI, S485PI: <=1.2.0_Build_250827_Rel.66817n', 'product_id': 'CSAFPID-0029'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VIGI InSight S655I Series', 'branches': [{'name': '<=1.1.1_Build_250625_Rel.64224n', 'product': {'name': 'TP-Link Systems Inc. VIGI InSight S655I Series: <=1.1.1_Build_250625_Rel.64224n', 'product_id': 'CSAFPID-0030'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VIGI InSight S345‑4G Series', 'branches': [{'name': '<=2.1.0_Build_250725_Rel.36867n', 'product': {'name': 'TP-Link Systems Inc. VIGI InSight S345‑4G Series: <=2.1.0_Build_250725_Rel.36867n', 'product_id': 'CSAFPID-0031'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'VIGI InSight Sx25 Series Models S225, S325, S425', 'branches': [{'name': '<=1.1.0_Build_250630_Rel.39597n', 'product': {'name': 'TP-Link Systems Inc. VIGI InSight Sx25 Series Models S225, S325, S425: <=1.1.0_Build_250630_Rel.39597n', 'product_id': 'CSAFPID-0032'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2026-0629', 'cwe': {'id': 'CWE-287', 'name': 'Improper Authentication'}, 'notes': [{'text': 'An authentication bypass in the password recovery feature of the local web interface across multiple VIGI camera models allows an attacker on the LAN to reset the admin password without verification by manipulating client-side state. Attackers can gain full administrative access to the device, compromising configuration and network security.', 'title': 'Vulnerability Summary', 'category': 'summary'}, {'text': 'SSVCv2/E:N/A:N/2026-02-04T06:00:00.000000Z', 'title': 'SSVC', 'category': 'details'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0028', 'CSAFPID-0029', 'CSAFPID-0030', 'CSAFPID-0031', 'CSAFPID-0032']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/287.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2026-0629', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'TP-Link Systems Inc. strongly recommends that users with affected devices take the following actions:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0028', 'CSAFPID-0029', 'CSAFPID-0030', 'CSAFPID-0031', 'CSAFPID-0032']}, {'details': 'Download and update to the latest firmware version to fix the vulnerability from the following links.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0028', 'CSAFPID-0029', 'CSAFPID-0030', 'CSAFPID-0031', 'CSAFPID-0032']}, {'url': 'https://www.vigi.com/us/support/download/', 'details': 'United States users should visit the TP-Link US Download Center here: https://www.vigi.com/us/support/download/.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0028', 'CSAFPID-0029', 'CSAFPID-0030', 'CSAFPID-0031', 'CSAFPID-0032']}, {'url': 'https://www.vigi.com/es/support/download/', 'details': 'Global English users should visit the TP-Link EN Download Center:https://www.vigi.com/es/support/download/.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0028', 'CSAFPID-0029', 'CSAFPID-0030', 'CSAFPID-0031', 'CSAFPID-0032']}, {'url': 'https://www.vigi.com/in/support/download/', 'details': 'India users should visit the TP-Link India Download Center:https://www.vigi.com/in/support/download/.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0028', 'CSAFPID-0029', 'CSAFPID-0030', 'CSAFPID-0031', 'CSAFPID-0032']}, {'url': 'https://www.tp-link.com/us/support/faq/4906/', 'details': 'Please visit https://www.tp-link.com/us/support/faq/4906/ for the TP-Link advisory.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0028', 'CSAFPID-0029', 'CSAFPID-0030', 'CSAFPID-0031', 'CSAFPID-0032']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0023', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0026', 'CSAFPID-0027', 'CSAFPID-0028', 'CSAFPID-0029', 'CSAFPID-0030', 'CSAFPID-0031', 'CSAFPID-0032']}}]} | |
ot | ICSA-26-036-04 | CVE-2025-34183 | Ilevia EVE X1 Server | 2026-02-05 10:00:00+03:00 | 2026-02-05 10:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-036-04.json | 34b7871e88c57282efa07815228e5d9c46e9ab812d0419e0459c9d6ab0211154 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary shell commands and the disclosure of sensitive system information.', 'title': 'Risk evaluation', 'category': 'summary'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Italy', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also recommends users take the following measures to protect themselves from social engineering attacks:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Do not click web links or open attachments in unsolicited email messages.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Ilevia EVE X1 Server', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-036-04', 'status': 'final', 'version': '1', 'generator': {'date': '2026-02-04T23:11:56.724837Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-02-05T07:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}], 'current_release_date': '2026-02-05T07:00:00.000000Z', 'initial_release_date': '2026-02-05T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-036-04.json', 'summary': 'ICS Advisory ICSA-26-036-04 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-036-04', 'summary': 'ICSA Advisory ICSA-26-036-04 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/ncas/tips/ST04-014', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Gjoko Krstic'], 'summary': 'reported these vulnerabilities to CISA', 'organization': 'Zero Science Lab'}]}, 'product_tree': {'branches': [{'name': 'Ilevia', 'branches': [{'name': 'EVE X1', 'branches': [{'name': '<=4.7.18.0', 'product': {'name': 'Ilevia EVE X1: <=4.7.18.0', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-34185', 'cwe': {'id': 'CWE-22', 'name': "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"}, 'notes': [{'text': "Ilevia EVE X1 Server contains a pre-authentication file disclosure vulnerability via the 'db_log' POST parameter. Remote attackers can retrieve arbitrary files from the server, exposing sensitive system information and credentials.", 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/22.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-34185', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Ilevia recommends that users perform the following mitigation steps: Update to the newest version of Ilevia Manager at https://www.ilevia.com/downloads/. Verify port 8080 is closed on all devices and routers and enable access only through the secure option provided in the updated Ilevia Manager. Change all default passwords on active systems to strong, unique credentials to prevent unauthorized access and automated attacks. Review firewall configurations to confirm that internal protections are functioning as intended and external exposure is minimized. Monitor for unauthorized access attempts and apply network segmentation where possible to reduce attack surfaces.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-34184', 'cwe': {'id': 'CWE-78', 'name': "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}, 'notes': [{'text': "Ilevia EVE X1 Server contains an unauthenticated OS command injection vulnerability in the /ajax/php/login.php script. Remote attackers can execute arbitrary system commands by injecting payloads into the 'passwd' HTTP POST parameter, leading to full system compromise or denial of service.", 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/78.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-34184', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Ilevia recommends that users perform the following mitigation steps: Update to the newest version of Ilevia Manager at https://www.ilevia.com/downloads/. Verify port 8080 is closed on all devices and routers and enable access only through the secure option provided in the updated Ilevia Manager. Change all default passwords on active systems to strong, unique credentials to prevent unauthorized access and automated attacks. Review firewall configurations to confirm that internal protections are functioning as intended and external exposure is minimized. Monitor for unauthorized access attempts and apply network segmentation where possible to reduce attack surfaces.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-34183', 'cwe': {'id': 'CWE-532', 'name': 'Insertion of Sensitive Information into Log File'}, 'notes': [{'text': 'Ilevia EVE X1 Server contains a vulnerability in its server-side logging mechanism that allows unauthenticated remote attackers to retrieve plaintext credentials from exposed .log files. This flaw enables full authentication bypass and system compromise through credential reuse.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/532.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-34183', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Ilevia recommends that users perform the following mitigation steps: Update to the newest version of Ilevia Manager at https://www.ilevia.com/downloads/. Verify port 8080 is closed on all devices and routers and enable access only through the secure option provided in the updated Ilevia Manager. Change all default passwords on active systems to strong, unique credentials to prevent unauthorized access and automated attacks. Review firewall configurations to confirm that internal protections are functioning as intended and external exposure is minimized. Monitor for unauthorized access attempts and apply network segmentation where possible to reduce attack surfaces.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-34186', 'cwe': {'id': 'CWE-78', 'name': "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}, 'notes': [{'text': "Ilevia EVE X1/X5 Server contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() call for authentication, allowing attackers to inject special characters and manipulate command parsing. Due to the binary's interpretation of non-zero exit codes as successful authentication, remote attackers can bypass authentication and gain full access to the system.", 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/78.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-34186', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Ilevia recommends that users perform the following mitigation steps: Update to the newest version of Ilevia Manager at https://www.ilevia.com/downloads/. Verify port 8080 is closed on all devices and routers and enable access only through the secure option provided in the updated Ilevia Manager. Change all default passwords on active systems to strong, unique credentials to prevent unauthorized access and automated attacks. Review firewall configurations to confirm that internal protections are functioning as intended and external exposure is minimized. Monitor for unauthorized access attempts and apply network segmentation where possible to reduce attack surfaces.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-34187', 'cwe': {'id': 'CWE-78', 'name': "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}, 'notes': [{'text': 'Ilevia EVE X1/X5 Server contains a misconfiguration in the sudoers file that allows passwordless execution of certain Bash scripts. If these scripts are writable by web-facing users or accessible via command injection, attackers can replace them with malicious payloads. Execution with sudo grants full root access, resulting in remote privilege escalation and potential system compromise.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/78.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-34187', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Ilevia recommends that users perform the following mitigation steps: Update to the newest version of Ilevia Manager at https://www.ilevia.com/downloads/. Verify port 8080 is closed on all devices and routers and enable access only through the secure option provided in the updated Ilevia Manager. Change all default passwords on active systems to strong, unique credentials to prevent unauthorized access and automated attacks. Review firewall configurations to confirm that internal protections are functioning as intended and external exposure is minimized. Monitor for unauthorized access attempts and apply network segmentation where possible to reduce attack surfaces.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-34517', 'cwe': {'id': 'CWE-22', 'name': "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"}, 'notes': [{'text': 'Ilevia EVE X1 Server firmware contains an absolute path traversal vulnerability in get_file_content.php that allows an attacker to read arbitrary files. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/22.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-34517', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Ilevia recommends that users perform the following mitigation steps: Update to the newest version of Ilevia Manager at https://www.ilevia.com/downloads/. Verify port 8080 is closed on all devices and routers and enable access only through the secure option provided in the updated Ilevia Manager. Change all default passwords on active systems to strong, unique credentials to prevent unauthorized access and automated attacks. Review firewall configurations to confirm that internal protections are functioning as intended and external exposure is minimized. Monitor for unauthorized access attempts and apply network segmentation where possible to reduce attack surfaces.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-34518', 'cwe': {'id': 'CWE-22', 'name': "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"}, 'notes': [{'text': 'Ilevia EVE X1 Server firmware contains a relative path traversal vulnerability in get_file_content.php that allows an attacker to read arbitrary files. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/22.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-34518', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Ilevia recommends that users perform the following mitigation steps: Update to the newest version of Ilevia Manager at https://www.ilevia.com/downloads/. Verify port 8080 is closed on all devices and routers and enable access only through the secure option provided in the updated Ilevia Manager. Change all default passwords on active systems to strong, unique credentials to prevent unauthorized access and automated attacks. Review firewall configurations to confirm that internal protections are functioning as intended and external exposure is minimized. Monitor for unauthorized access attempts and apply network segmentation where possible to reduce attack surfaces.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-34512', 'cwe': {'id': 'CWE-79', 'name': "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"}, 'notes': [{'text': 'Ilevia EVE X1 Server firmware contains a reflected cross-site scripting (XSS) vulnerability in index.php that allows an unauthenticated attacker to execute arbitrary code. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/79.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-34512', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Ilevia recommends that users perform the following mitigation steps: Update to the newest version of Ilevia Manager at https://www.ilevia.com/downloads/. Verify port 8080 is closed on all devices and routers and enable access only through the secure option provided in the updated Ilevia Manager. Change all default passwords on active systems to strong, unique credentials to prevent unauthorized access and automated attacks. Review firewall configurations to confirm that internal protections are functioning as intended and external exposure is minimized. Monitor for unauthorized access attempts and apply network segmentation where possible to reduce attack surfaces.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-34513', 'cwe': {'id': 'CWE-78', 'name': "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}, 'notes': [{'text': 'Ilevia EVE X1 Server firmware contains an OS command injection vulnerability in mbus_build_from_csv.php that allows an unauthenticated attacker to execute arbitrary code. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/78.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-34513', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Ilevia recommends that users perform the following mitigation steps: Update to the newest version of Ilevia Manager at https://www.ilevia.com/downloads/. Verify port 8080 is closed on all devices and routers and enable access only through the secure option provided in the updated Ilevia Manager. Change all default passwords on active systems to strong, unique credentials to prevent unauthorized access and automated attacks. Review firewall configurations to confirm that internal protections are functioning as intended and external exposure is minimized. Monitor for unauthorized access attempts and apply network segmentation where possible to reduce attack surfaces.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-036-04 | CVE-2025-34186 | Ilevia EVE X1 Server | 2026-02-05 10:00:00+03:00 | 2026-02-05 10:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-036-04.json | 51f33c713fca4f3d16727a3fcb0eb597ab1b51f107d8f260358fdadc8e3e4811 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary shell commands and the disclosure of sensitive system information.', 'title': 'Risk evaluation', 'category': 'summary'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'Italy', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also recommends users take the following measures to protect themselves from social engineering attacks:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Do not click web links or open attachments in unsolicited email messages.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Ilevia EVE X1 Server', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-036-04', 'status': 'final', 'version': '1', 'generator': {'date': '2026-02-04T23:11:56.724837Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-02-05T07:00:00.000000Z', 'number': '1', 'summary': 'Initial Publication', 'legacy_version': 'Initial'}], 'current_release_date': '2026-02-05T07:00:00.000000Z', 'initial_release_date': '2026-02-05T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-036-04.json', 'summary': 'ICS Advisory ICSA-26-036-04 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-036-04', 'summary': 'ICSA Advisory ICSA-26-036-04 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/ncas/tips/ST04-014', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Gjoko Krstic'], 'summary': 'reported these vulnerabilities to CISA', 'organization': 'Zero Science Lab'}]}, 'product_tree': {'branches': [{'name': 'Ilevia', 'branches': [{'name': 'EVE X1', 'branches': [{'name': '<=4.7.18.0', 'product': {'name': 'Ilevia EVE X1: <=4.7.18.0', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-34185', 'cwe': {'id': 'CWE-22', 'name': "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"}, 'notes': [{'text': "Ilevia EVE X1 Server contains a pre-authentication file disclosure vulnerability via the 'db_log' POST parameter. Remote attackers can retrieve arbitrary files from the server, exposing sensitive system information and credentials.", 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/22.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-34185', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Ilevia recommends that users perform the following mitigation steps: Update to the newest version of Ilevia Manager at https://www.ilevia.com/downloads/. Verify port 8080 is closed on all devices and routers and enable access only through the secure option provided in the updated Ilevia Manager. Change all default passwords on active systems to strong, unique credentials to prevent unauthorized access and automated attacks. Review firewall configurations to confirm that internal protections are functioning as intended and external exposure is minimized. Monitor for unauthorized access attempts and apply network segmentation where possible to reduce attack surfaces.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-34184', 'cwe': {'id': 'CWE-78', 'name': "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}, 'notes': [{'text': "Ilevia EVE X1 Server contains an unauthenticated OS command injection vulnerability in the /ajax/php/login.php script. Remote attackers can execute arbitrary system commands by injecting payloads into the 'passwd' HTTP POST parameter, leading to full system compromise or denial of service.", 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/78.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-34184', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Ilevia recommends that users perform the following mitigation steps: Update to the newest version of Ilevia Manager at https://www.ilevia.com/downloads/. Verify port 8080 is closed on all devices and routers and enable access only through the secure option provided in the updated Ilevia Manager. Change all default passwords on active systems to strong, unique credentials to prevent unauthorized access and automated attacks. Review firewall configurations to confirm that internal protections are functioning as intended and external exposure is minimized. Monitor for unauthorized access attempts and apply network segmentation where possible to reduce attack surfaces.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-34183', 'cwe': {'id': 'CWE-532', 'name': 'Insertion of Sensitive Information into Log File'}, 'notes': [{'text': 'Ilevia EVE X1 Server contains a vulnerability in its server-side logging mechanism that allows unauthenticated remote attackers to retrieve plaintext credentials from exposed .log files. This flaw enables full authentication bypass and system compromise through credential reuse.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/532.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-34183', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Ilevia recommends that users perform the following mitigation steps: Update to the newest version of Ilevia Manager at https://www.ilevia.com/downloads/. Verify port 8080 is closed on all devices and routers and enable access only through the secure option provided in the updated Ilevia Manager. Change all default passwords on active systems to strong, unique credentials to prevent unauthorized access and automated attacks. Review firewall configurations to confirm that internal protections are functioning as intended and external exposure is minimized. Monitor for unauthorized access attempts and apply network segmentation where possible to reduce attack surfaces.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-34186', 'cwe': {'id': 'CWE-78', 'name': "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}, 'notes': [{'text': "Ilevia EVE X1/X5 Server contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() call for authentication, allowing attackers to inject special characters and manipulate command parsing. Due to the binary's interpretation of non-zero exit codes as successful authentication, remote attackers can bypass authentication and gain full access to the system.", 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/78.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-34186', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Ilevia recommends that users perform the following mitigation steps: Update to the newest version of Ilevia Manager at https://www.ilevia.com/downloads/. Verify port 8080 is closed on all devices and routers and enable access only through the secure option provided in the updated Ilevia Manager. Change all default passwords on active systems to strong, unique credentials to prevent unauthorized access and automated attacks. Review firewall configurations to confirm that internal protections are functioning as intended and external exposure is minimized. Monitor for unauthorized access attempts and apply network segmentation where possible to reduce attack surfaces.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-34187', 'cwe': {'id': 'CWE-78', 'name': "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}, 'notes': [{'text': 'Ilevia EVE X1/X5 Server contains a misconfiguration in the sudoers file that allows passwordless execution of certain Bash scripts. If these scripts are writable by web-facing users or accessible via command injection, attackers can replace them with malicious payloads. Execution with sudo grants full root access, resulting in remote privilege escalation and potential system compromise.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/78.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-34187', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Ilevia recommends that users perform the following mitigation steps: Update to the newest version of Ilevia Manager at https://www.ilevia.com/downloads/. Verify port 8080 is closed on all devices and routers and enable access only through the secure option provided in the updated Ilevia Manager. Change all default passwords on active systems to strong, unique credentials to prevent unauthorized access and automated attacks. Review firewall configurations to confirm that internal protections are functioning as intended and external exposure is minimized. Monitor for unauthorized access attempts and apply network segmentation where possible to reduce attack surfaces.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-34517', 'cwe': {'id': 'CWE-22', 'name': "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"}, 'notes': [{'text': 'Ilevia EVE X1 Server firmware contains an absolute path traversal vulnerability in get_file_content.php that allows an attacker to read arbitrary files. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/22.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-34517', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Ilevia recommends that users perform the following mitigation steps: Update to the newest version of Ilevia Manager at https://www.ilevia.com/downloads/. Verify port 8080 is closed on all devices and routers and enable access only through the secure option provided in the updated Ilevia Manager. Change all default passwords on active systems to strong, unique credentials to prevent unauthorized access and automated attacks. Review firewall configurations to confirm that internal protections are functioning as intended and external exposure is minimized. Monitor for unauthorized access attempts and apply network segmentation where possible to reduce attack surfaces.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-34518', 'cwe': {'id': 'CWE-22', 'name': "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"}, 'notes': [{'text': 'Ilevia EVE X1 Server firmware contains a relative path traversal vulnerability in get_file_content.php that allows an attacker to read arbitrary files. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.5, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/22.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-34518', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Ilevia recommends that users perform the following mitigation steps: Update to the newest version of Ilevia Manager at https://www.ilevia.com/downloads/. Verify port 8080 is closed on all devices and routers and enable access only through the secure option provided in the updated Ilevia Manager. Change all default passwords on active systems to strong, unique credentials to prevent unauthorized access and automated attacks. Review firewall configurations to confirm that internal protections are functioning as intended and external exposure is minimized. Monitor for unauthorized access attempts and apply network segmentation where possible to reduce attack surfaces.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-34512', 'cwe': {'id': 'CWE-79', 'name': "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"}, 'notes': [{'text': 'Ilevia EVE X1 Server firmware contains a reflected cross-site scripting (XSS) vulnerability in index.php that allows an unauthenticated attacker to execute arbitrary code. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 5.4, 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/79.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-34512', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Ilevia recommends that users perform the following mitigation steps: Update to the newest version of Ilevia Manager at https://www.ilevia.com/downloads/. Verify port 8080 is closed on all devices and routers and enable access only through the secure option provided in the updated Ilevia Manager. Change all default passwords on active systems to strong, unique credentials to prevent unauthorized access and automated attacks. Review firewall configurations to confirm that internal protections are functioning as intended and external exposure is minimized. Monitor for unauthorized access attempts and apply network segmentation where possible to reduce attack surfaces.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-34513', 'cwe': {'id': 'CWE-78', 'name': "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}, 'notes': [{'text': 'Ilevia EVE X1 Server firmware contains an OS command injection vulnerability in mbus_build_from_csv.php that allows an unauthenticated attacker to execute arbitrary code. Ilevia has declined to service this vulnerability, and recommends that customers not expose port 8080 to the internet.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 9.8, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/78.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-34513', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Ilevia recommends that users perform the following mitigation steps: Update to the newest version of Ilevia Manager at https://www.ilevia.com/downloads/. Verify port 8080 is closed on all devices and routers and enable access only through the secure option provided in the updated Ilevia Manager. Change all default passwords on active systems to strong, unique credentials to prevent unauthorized access and automated attacks. Review firewall configurations to confirm that internal protections are functioning as intended and external exposure is minimized. Monitor for unauthorized access attempts and apply network segmentation where possible to reduce attack surfaces.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-020-02 | CVE-2023-3663 | Schneider Electric devices using CODESYS Runtime | 2023-07-11 10:15:18+03:00 | 2026-01-20 18:49:51.778731+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-020-02.json | b8dab9d11166ca644b61e733fce6eb7b12575583dd8ce652c7a60455def3f3f2 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'We strongly recommend the following industry cybersecurity best practices.\n\nhttps://www.se.com/us/en/download/document/7EN52-0390/\n* Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.\n* Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.\n* Place all controllers in locked cabinets and never leave them in the “Program” mode.\n* Never connect programming software to any network other than the network intended for that device.\n* Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.\n* Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.\n* Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.\n* When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.\nFor more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document. \n', 'title': 'General Security Recommendations', 'category': 'general'}, {'text': 'This document provides an overview of the identified vulnerability or vulnerabilities and actions required to mitigate. For more details and assistance on how to protect your installation, contact your local Schneider Electric representative or Schneider Electric Industrial Cybersecurity Services: https://www.se.com/ww/en/work/solutions/cybersecurity/. These organizations will be fully aware of this situation and can support you through the process.\nFor further information related to cybersecurity in Schneider Electric’s products, visit the company’s cybersecurity support portal page: https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp', 'title': 'For More Information', 'category': 'general'}, {'text': 'THIS NOTIFICATION DOCUMENT, THE INFORMATION CONTAINED HEREIN, AND ANY MATERIALS LINKED FROM IT (COLLECTIVELY, THIS “NOTIFICATION”) ARE INTENDED TO HELP PROVIDE AN OVERVIEW OF THE IDENTIFIED SITUATION AND SUGGESTED MITIGATION ACTIONS, REMEDIATION, FIX, AND/OR GENERAL SECURITY RECOMMENDATIONS AND IS PROVIDED ON AN “AS-IS” BASIS WITHOUT WARRANTY OR GUARANTEE OF ANY KIND. SCHNEIDER ELECTRIC DISCLAIMS ALL WARRANTIES RELATING TO THIS NOTIFICATION, EITHER EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SCHNEIDER ELECTRIC MAKES NO WARRANTY THAT THE NOTIFICATION WILL RESOLVE THE IDENTIFIED SITUATION. IN NO EVENT SHALL SCHNEIDER ELECTRIC BE LIABLE FOR ANY DAMAGES OR LOSSES WHATSOEVER IN CONNECTION WITH THIS NOTIFICATION, INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF SCHNEIDER ELECTRIC HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. YOUR USE OF THIS NOTIFICATION IS AT YOUR OWN RISK, AND YOU ARE SOLELY LIABLE FOR ANY DAMAGES TO YOUR SYSTEMS OR ASSETS OR OTHER LOSSES THAT MAY RESULT FROM YOUR USE OF THIS NOTIFICATION. SCHNEIDER ELECTRIC RESERVES THE RIGHT TO UPDATE OR CHANGE THIS NOTIFICATION AT ANY TIME AND IN ITS SOLE DISCRETION', 'title': 'LEGAL DISCLAIMER', 'category': 'legal_disclaimer'}, {'text': 'Schneider’s purpose is to create Impact by empowering all to make the most of our energy and resources, bridging progress and\r\nsustainability for all. We call this Life Is On.\n\nOur mission is to be the trusted partner in Sustainability and Efficiency.\n\nWe are a global industrial technology leader bringing world-leading expertise in electrification, automation and digitization to smart\r\nindustries, resilient infrastructure, future-proof data centers, intelligent buildings, and intuitive homes. Anchored by our deep\r\ndomain expertise, we provide integrated end-to-end lifecycle AI enabled Industrial IoT solutions with connected products, automation,\r\nsoftware and services, delivering digital twins to enable profitable growth for our customers.\n\nWe are a people company with an ecosystem of 150,000 colleagues and more than a million partners operating in over 100 countries\r\nto ensure proximity to our customers and stakeholders. We embrace diversity and inclusion in everything we do, guided by our\r\nmeaningful purpose of a sustainable future for all.', 'title': 'About Schneider Electric', 'category': 'general'}, {'text': 'Schneider Electric is aware of multiple vulnerabilities disclosed on CODESYS runtime system V3 communication server. Many vendors, including Schneider Electric, embed CODESYS in their offers. \r\n\r\nIf successfully exploited, these vulnerabilities could result in a denial of service or, in some cases, in remote code execution on PacDrive controllers, Modicon Controllers M241 / M251 / M262 / M258 / LMC058 / LMC078 / M218 , HMISCU, the Simulation Runtime SoftSPS from EcoStruxure Machine Expert and EcoStruxure Microgrid Operation products. \r\n\r\nFailure to apply the mitigations provided below may result in denial of service and/or arbitrary remote code execution. ', 'title': 'Overview', 'category': 'summary'}, {'text': 'Vulnerabilities disclosed by CODESYSTM group in the CODESYS Runtime and Simulation Runtime impact Schneider Electric controller products and software. \n\nAdditional information about the vulnerabilities can be found in the CODESYSTM Advisories at: \n Advisory 2023-02 • Advisory 2023-03\n • Advisory 2023-04\n • Advisory 2023-05\n • Advisory 2023-06\n • Advisory 2023-07\n • Advisory 2023-08 \n • Advisory 2023-09 ', 'title': 'Details', 'category': 'details'}, {'text': 'Customers should use appropriate patching methodologies when applying these patches to their systems. We strongly recommend the use of back-ups and evaluating the impact of these patches in a Test and Development environment or on an offline infrastructure. Contact Schneider Electric’s Customer Care Center https://www.se.com/us/en/work/support/contacts.jsp if you need assistance removing a patch. ', 'category': 'other'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of Schneider Electric CPCERT SEVD-2023-192-04 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Schneider Electric CPCERT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'Commercial Facilities, Critical Manufacturing, Energy', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'France', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Schneider Electric devices using CODESYS Runtime', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-020-02', 'status': 'final', 'version': '10', 'generator': {'date': '2026-01-20T15:49:51.777331Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2023-07-11T07:15:18.000000Z', 'number': '1', 'summary': 'Original Release', 'legacy_version': 'Initial'}, {'date': '2023-08-08T15:41:00.000000Z', 'number': '2', 'summary': 'New CODESYS advisories 2023-04 to 2023-09 added. Additional impacted product: Harmony and Easy Harmony, Vijeo Designer embedded in EcoStruxure Machine Expert.', 'legacy_version': 'Revision 1'}, {'date': '2024-01-09T00:00:00.000000Z', 'number': '3', 'summary': 'Remediations added for different products.', 'legacy_version': 'Revision 2'}, {'date': '2024-03-12T00:00:00.000000Z', 'number': '4', 'summary': 'A remediation is now available for HMIGK/HMIGTO/HMIGTU/HMIGTUX/HMISTU series', 'legacy_version': 'Revision 3'}, {'date': '2024-04-09T00:00:00.000000Z', 'number': '5', 'summary': 'A remediation is now available for Easy Harmony HMIET6/HMIFT6, and Magelis HMIGXU series', 'legacy_version': 'Revision 4'}, {'date': '2024-06-11T00:00:00.000000Z', 'number': '6', 'summary': 'Easy Modicon M310 is added to the list of products impacted', 'legacy_version': 'Revision 5'}, {'date': '2025-08-12T04:00:00.000000Z', 'number': '7', 'summary': 'Remediations are available for Harmony iPC series and Harmony P6 series with Vijeo Designer.', 'legacy_version': 'Revision 6'}, {'date': '2025-11-11T08:00:00.000000Z', 'number': '8', 'summary': 'Remediation is available for Easy Modicon M310.', 'legacy_version': 'Revision 7'}, {'date': '2025-12-09T08:00:00.000000Z', 'number': '9', 'summary': 'Replaced advisory IDs with CVE IDs. Added vulnerability details, including CVE descriptions, CWE identifiers, CVSS scores, and vector strings. Corrected mappings of affected and fixed products for each CVE.', 'legacy_version': 'Revision 8'}, {'date': '2026-01-20T15:49:51.778731Z', 'number': '10', 'summary': 'Initial Republication of Schneider Electric CPCERT SEVD-2023-192-04 advisory', 'legacy_version': 'CISA Republication'}], 'current_release_date': '2026-01-20T15:49:51.778731Z', 'initial_release_date': '2023-07-11T07:15:18.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-192-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2023-192-04.json', 'summary': 'CODESYS Runtime Vulnerabilities - SEVD-2023-192-04 CSAF Version', 'category': 'self'}, {'url': 'https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-192-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-192-04.pdf', 'summary': 'CODESYS Runtime Vulnerabilities - SEVD-2023-192-04 PDF Version', 'category': 'self'}, {'url': 'https://www.se.com/us/en/download/document/7EN52-0390/', 'summary': 'Recommended Cybersecurity Best Practices', 'category': 'external'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-020-02.json', 'summary': 'ICS Advisory ICSA-26-020-02 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-020-02', 'summary': 'ICS Advisory ICSA-26-020-02 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to CISA.', 'organization': 'Schneider Electric CPCERT'}]}, 'product_tree': {'branches': [{'name': 'Schneider Electric', 'branches': [{'name': 'HMISCU Controller', 'branches': [{'name': '<6.3.1', 'product': {'name': 'Schneider Electric HMISCU Controller All versions prior to v6.3.1', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Modicon Controller LMC078', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Schneider Electric Modicon Controller LMC078 All Versions', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Modicon Controller M241', 'branches': [{'name': '<5.2.11.18', 'product': {'name': 'Schneider Electric Modicon Controller M241 All versions prior to v5.2.11.18', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Modicon Controller M251', 'branches': [{'name': '<5.2.11.18', 'product': {'name': 'Schneider Electric Modicon Controller M251 All Versions prior to v5.2.11.18', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Modicon Controller M262', 'branches': [{'name': '<5.2.8.12', 'product': {'name': 'Schneider Electric Modicon Controller M262 All versions prior to v5.2.8.12', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Modicon Controller M258', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Schneider Electric Modicon Controller M258 All Versions', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Modicon Controller LMC058', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Schneider Electric Modicon Controller LMC058 All Versions', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Modicon Controller M218', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Schneider Electric Modicon Controller M218 All Versions', 'product_id': 'CSAFPID-0008'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'PacDrive 3 Controllers: LMC Eco/Pro/Pro2 ', 'branches': [{'name': '<1.76.14.1', 'product': {'name': 'Schneider Electric PacDrive 3 Controllers: LMC Eco/Pro/Pro2 All versions prior to v1.76.14.1', 'product_id': 'CSAFPID-0009'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SoftSPS embedded in EcoStruxure Machine Expert ', 'branches': [{'name': '<2.2', 'product': {'name': 'Schneider Electric SoftSPS embedded in EcoStruxure Machine Expert All Versions prior to Machine Expert v2.2', 'product_id': 'CSAFPID-0010'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Vijeo Designer embedded in EcoStruxure Machine Expert ', 'branches': [{'name': '<6.3.1', 'product': {'name': 'Schneider Electric Vijeo Designer embedded in EcoStruxure Machine Expert All versions prior to v6.3.1', 'product_id': 'CSAFPID-0011'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Harmony (Formerly Magelis) HMIGK/HMIGTO/HMIGTU/HMIGTUX/HMISTU series', 'branches': [{'name': '<6.3_HF3', 'product': {'name': 'Schneider Electric Harmony (Formerly Magelis) HMIGK/HMIGTO/HMIGTU/HMIGTUX/HMISTU series All Versions prior to V6.3 HF3', 'product_id': 'CSAFPID-0012'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Easy Harmony HMIET6/HMIFT6 Magelis HMIGXU series', 'branches': [{'name': '<2.0_HF2', 'product': {'name': 'Schneider Electric Easy Harmony HMIET6/HMIFT6 Magelis HMIGXU all versions prior to v2.0 HF2', 'product_id': 'CSAFPID-0013'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'HMISCU Controller', 'branches': [{'name': '6.3.1', 'product': {'name': 'Schneider Electric HMISCU Controller 6.3.1', 'product_id': 'CSAFPID-0014'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Modicon Controller M241', 'branches': [{'name': '5.2.11.18', 'product': {'name': 'Schneider Electric Modicon Controller M241 5.2.11.18', 'product_id': 'CSAFPID-0015'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Modicon Controller M251', 'branches': [{'name': '5.2.11.18', 'product': {'name': 'Schneider Electric Modicon Controller M251 5.2.11.18', 'product_id': 'CSAFPID-0016'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Modicon Controller M262', 'branches': [{'name': '5.2.8.12', 'product': {'name': 'Schneider Electric Modicon Controller M262 5.2.8.12', 'product_id': 'CSAFPID-0017'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'PacDrive 3 Controllers: LMC Eco/Pro/Pro2 ', 'branches': [{'name': '1.76.14.1', 'product': {'name': 'Schneider Electric PacDrive 3 Controllers: LMC Eco/Pro/Pro2 1.76.14.1', 'product_id': 'CSAFPID-0018'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'SoftSPS embedded in EcoStruxure Machine Expert ', 'branches': [{'name': '2.2', 'product': {'name': 'Schneider Electric SoftSPS embedded in EcoStruxure Machine Expert 2.2', 'product_id': 'CSAFPID-0019'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Vijeo Designer embedded in EcoStruxure Machine Expert ', 'branches': [{'name': '6.3.1', 'product': {'name': 'Schneider Electric Vijeo Designer embedded in EcoStruxure Machine Expert 6.3.1', 'product_id': 'CSAFPID-0020'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Harmony (Formerly Magelis) HMIGK/HMIGTO/HMIGTU/HMIGTUX/HMISTU series iPC series with Vijeo Designer runtime', 'branches': [{'name': '6.3_HF3', 'product': {'name': 'Schneider Electric Harmony (Formerly Magelis) HMIGK/HMIGTO/HMIGTU/HMIGTUX/HMISTU series iPC series with Vijeo Designer runtime V6.3 HF3', 'product_id': 'CSAFPID-0021'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Vijeo Designer Basic', 'branches': [{'name': '2.0_HotFix_2', 'product': {'name': 'Vijeo Designer Basic v2.0 HF2', 'product_id': 'CSAFPID-0022'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Harmony iPC series', 'product': {'name': 'Schneider Electric Harmony iPC series', 'product_id': 'CSAFPID-0023'}, 'category': 'product_name'}, {'name': 'Magelis XBT series', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Schneider Electric Magelis XBT series All Versions', 'product_id': 'CSAFPID-0024'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Easy Modicon M310', 'branches': [{'name': '<3.1.5.82', 'product': {'name': 'Schneider Electric Easy Modicon M310 All versions prior to v3.1.5.82', 'product_id': 'CSAFPID-0025'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Harmony P6 series', 'product': {'name': 'Schneider Electric Harmony P6 series', 'product_id': 'CSAFPID-0026'}, 'category': 'product_name'}, {'name': 'Vijeo Designer runtime', 'branches': [{'name': '<6.3_SP2', 'product': {'name': 'Schneider Electric Vijeo Designer runtime <6.3 SP2', 'product_id': 'CSAFPID-0027'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Vijeo Designer runtime', 'branches': [{'name': '6.3_SP2', 'product': {'name': 'Schneider Electric Vijeo Designer runtime 6.3 SP2', 'product_id': 'CSAFPID-0028'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Easy Modicon M310', 'branches': [{'name': '3.1.5.82', 'product': {'name': 'Schneider Electric Easy Modicon M310 version v3.1.5.82', 'product_id': 'CSAFPID-0029'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Schneider Electric Vijeo Designer runtime Versions Prior to 6.3 SP2 installed on Schneider Electric Harmony iPC series', 'product_id': 'CSAFPID-0030'}, 'product_reference': 'CSAFPID-0027', 'relates_to_product_reference': 'CSAFPID-0023'}, {'category': 'installed_on', 'full_product_name': {'name': 'Schneider Electric Vijeo Designer runtime Version 6.3 SP2 installed on Schneider Electric Harmony iPC series', 'product_id': 'CSAFPID-0031'}, 'product_reference': 'CSAFPID-0028', 'relates_to_product_reference': 'CSAFPID-0023'}, {'category': 'installed_on', 'full_product_name': {'name': 'Schneider Electric Vijeo Designer runtime Versions Prior to 6.3 SP2 installed on Schneider Electric Harmony P6 series', 'product_id': 'CSAFPID-0032'}, 'product_reference': 'CSAFPID-0027', 'relates_to_product_reference': 'CSAFPID-0026'}, {'category': 'installed_on', 'full_product_name': {'name': 'Schneider Electric Vijeo Designer runtime Version 6.3 SP2 installed on Schneider Electric Harmony P6 series', 'product_id': 'CSAFPID-0033'}, 'product_reference': 'CSAFPID-0028', 'relates_to_product_reference': 'CSAFPID-0026'}]}, 'vulnerabilities': [{'cve': 'CVE-2022-4046', 'cwe': {'id': 'CWE-119', 'name': 'Improper Restriction of Operations within the Bounds of a Memory Buffer'}, 'notes': [{'text': 'In addition to the functionality described above, there are memory access functions that allow the PLC application code to read or write memory. These are not limited to the data memories that are assigned to it or allocated by it. For this reason, the PLC application code can potentially access the entire RAM memory of the CODESYS Control runtime process surrounding it. This could allow PLC programmers who have successfully authenticated themselves at the controller to execute PLC application code that can modify itself or read or write sensitive data of the CODESYS Control runtime process.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-4046', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-4046', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/119.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': 'Schneider Electric´s Modicon LMC078 controllers have reached end of their life and are no longer commercially available. They have been replaced by the Modicon M262 controllers. We recommend our customers to migrate to the latest offer. Please contact your local Schneider Electric technical support for more information.', 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0002']}, {'details': 'Schneider Electric’s Modicon M218 controllers have reached their end of life and are no longer commercially available. They have been replaced by the Modicon Easy M200 and Modicon M241 controllers. We recommend our customers to migrate to the latest offer. Please contact your local Schneider Electric technical support for more information.', 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0008']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-28355', 'cwe': {'id': 'CWE-354', 'name': 'Improper Validation of Integrity Check Value'}, 'notes': [{'text': 'The PLC application code executed by the CODESYS Control Runtime contains a checksum. This enables the CODESYS development system to check at login whether its loaded project matches the PLC application code executed on the controller. This checksum is not sufficient to reliably detect PLC application code that has been modified in memory or boot application files that have been manipulated.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-28355', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-28355', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/354.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': 'Schneider Electric´s Modicon LMC078 controllers have reached end of their life and are no longer commercially available. They have been replaced by the Modicon M262 controllers. We recommend our customers to migrate to the latest offer. Please contact your local Schneider Electric technical support for more information.', 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0002']}, {'details': 'Schneider Electric’s Modicon M218 controllers have reached their end of life and are no longer commercially available. They have been replaced by the Modicon Easy M200 and Modicon M241 controllers. We recommend our customers to migrate to the latest offer. Please contact your local Schneider Electric technical support for more information.', 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0008']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47378', 'cwe': {'id': 'CWE-1288', 'name': 'Improper Validation of Consistency within Input'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests with inconsistent content can cause the CmpFiletransfer component to read internally from an invalid address, potentially leading to a denial-of-service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47378', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47378', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/1288.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47379', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpApp component to write attacker-controlled data to memory, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47379', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47379', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47380', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpApp component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47380', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47380', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47381', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpApp component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47381', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47381', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47382', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpTraceMgr component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47382', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47382', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47383', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpTraceMgr component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47383', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47383', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47384', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpTraceMgr component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47384', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47384', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47386', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpTraceMgr component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47386', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47386', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47387', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpTraceMgr component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47387', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47387', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47388', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpTraceMgr component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47388', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47388', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47389', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpTraceMgr component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47389', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47389', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47390', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpTraceMgr component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47390', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47390', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47385', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpAppForce component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47385', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47385', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47392', 'cwe': {'id': 'CWE-1288', 'name': 'Improper Validation of Consistency within Input'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests with inconsistent content can cause the CmpApp/CmpAppBP/CmpAppForce components to read internally from an invalid address, potentially leading to a denial-of-service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47392', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47392', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/1288.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47393', 'cwe': {'id': 'CWE-822', 'name': 'Untrusted Pointer Dereference'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpFiletransfer component to dereference addresses provided by the request for internal read access, which can lead to a denial-of-service situation.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47393', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47393', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/822.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47391', 'cwe': {'id': 'CWE-1288', 'name': 'Improper Validation of Consistency within Input'}, 'notes': [{'text': 'Crafted communication requests can cause the affected products to read internally from an invalid address, potentially leading to a denial-of-service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47391', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47391', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/1288.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37545', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-ofservice condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37545', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37545', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37546', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-ofservice condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37546', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37546', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37547', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-ofservice condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37547', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37547', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37548', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-ofservice condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37548', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37548', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37549', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-ofservice condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37549', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37549', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37550', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-ofservice condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37550', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37550', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37551', 'cwe': {'id': 'CWE-552', 'name': 'Files or Directories Accessible to External Parties'}, 'notes': [{'text': 'After successful authentication as a user, specially crafted communication requests can utilize the CmpApp component to download files with any file extensions to the controller. In contrast to the regular file download via CmpFileTransfer, no filtering of certain file types is performed here. As a result, the integrity of the CODESYS control runtime system may be compromised by the files loaded onto the controller.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37551', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37551', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/552.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37552', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37552', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37552', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37553', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37553', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37553', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37554', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37554', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37554', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37555', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37555', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37555', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37556', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37556', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37556', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37557', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests can cause the CmpAppBP component to overwrite a heap-based buffer, which can lead to a denial-of-service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37557', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37557', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37558', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37558', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37558', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37559', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37559', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37559', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-3662', 'cwe': {'id': 'CWE-427', 'name': 'Uncontrolled Search Path Element'}, 'notes': [{'text': 'The CODESYS Development System is vulnerable to the execution of malicious binaries from the current working directory.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-3662', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-3662', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/427.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-3663', 'cwe': {'id': 'CWE-924', 'name': 'Improper Enforcement of Message Integrity During Transmission in a Communication Channel'}, 'notes': [{'text': 'The Notification Center of the CODESYS Development System receives messages without ensuring that the message was not modified during transmission. This finally enables MITMs code execution when the user clicks the Learn More button.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-3663', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-3663', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/924.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-3669', 'cwe': {'id': 'CWE-307', 'name': 'Improper Restriction of Excessive Authentication Attempts'}, 'notes': [{'text': 'The Notification Center of the CODESYS Development System receives messages without ensuring that the message was not modified during transmission. This finally enables MITMs code execution when the user clicks the Learn More button.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-3669', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 3.3, 'attackVector': 'LOCAL', 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'LOW'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-3669', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/307.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-3670', 'cwe': {'id': 'CWE-668', 'name': 'Exposure of Resource to Wrong Sphere'}, 'notes': [{'text': 'CODESYS Scripting executes potentially malicious scripts saved by another user.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-3670', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-3670', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/668.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}]} | |
ot | ICSA-26-020-02 | CVE-2023-3669 | Schneider Electric devices using CODESYS Runtime | 2023-07-11 10:15:18+03:00 | 2026-01-20 18:49:51.778731+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-020-02.json | 022eb24fbb873be9c8a5aefe179ffdd79c19bb0e82ed811ce73cde62c00bf8ff | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'We strongly recommend the following industry cybersecurity best practices.\n\nhttps://www.se.com/us/en/download/document/7EN52-0390/\n* Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.\n* Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.\n* Place all controllers in locked cabinets and never leave them in the “Program” mode.\n* Never connect programming software to any network other than the network intended for that device.\n* Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.\n* Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.\n* Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.\n* When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.\nFor more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document. \n', 'title': 'General Security Recommendations', 'category': 'general'}, {'text': 'This document provides an overview of the identified vulnerability or vulnerabilities and actions required to mitigate. For more details and assistance on how to protect your installation, contact your local Schneider Electric representative or Schneider Electric Industrial Cybersecurity Services: https://www.se.com/ww/en/work/solutions/cybersecurity/. These organizations will be fully aware of this situation and can support you through the process.\nFor further information related to cybersecurity in Schneider Electric’s products, visit the company’s cybersecurity support portal page: https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp', 'title': 'For More Information', 'category': 'general'}, {'text': 'THIS NOTIFICATION DOCUMENT, THE INFORMATION CONTAINED HEREIN, AND ANY MATERIALS LINKED FROM IT (COLLECTIVELY, THIS “NOTIFICATION”) ARE INTENDED TO HELP PROVIDE AN OVERVIEW OF THE IDENTIFIED SITUATION AND SUGGESTED MITIGATION ACTIONS, REMEDIATION, FIX, AND/OR GENERAL SECURITY RECOMMENDATIONS AND IS PROVIDED ON AN “AS-IS” BASIS WITHOUT WARRANTY OR GUARANTEE OF ANY KIND. SCHNEIDER ELECTRIC DISCLAIMS ALL WARRANTIES RELATING TO THIS NOTIFICATION, EITHER EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SCHNEIDER ELECTRIC MAKES NO WARRANTY THAT THE NOTIFICATION WILL RESOLVE THE IDENTIFIED SITUATION. IN NO EVENT SHALL SCHNEIDER ELECTRIC BE LIABLE FOR ANY DAMAGES OR LOSSES WHATSOEVER IN CONNECTION WITH THIS NOTIFICATION, INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF SCHNEIDER ELECTRIC HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. YOUR USE OF THIS NOTIFICATION IS AT YOUR OWN RISK, AND YOU ARE SOLELY LIABLE FOR ANY DAMAGES TO YOUR SYSTEMS OR ASSETS OR OTHER LOSSES THAT MAY RESULT FROM YOUR USE OF THIS NOTIFICATION. SCHNEIDER ELECTRIC RESERVES THE RIGHT TO UPDATE OR CHANGE THIS NOTIFICATION AT ANY TIME AND IN ITS SOLE DISCRETION', 'title': 'LEGAL DISCLAIMER', 'category': 'legal_disclaimer'}, {'text': 'Schneider’s purpose is to create Impact by empowering all to make the most of our energy and resources, bridging progress and\r\nsustainability for all. We call this Life Is On.\n\nOur mission is to be the trusted partner in Sustainability and Efficiency.\n\nWe are a global industrial technology leader bringing world-leading expertise in electrification, automation and digitization to smart\r\nindustries, resilient infrastructure, future-proof data centers, intelligent buildings, and intuitive homes. Anchored by our deep\r\ndomain expertise, we provide integrated end-to-end lifecycle AI enabled Industrial IoT solutions with connected products, automation,\r\nsoftware and services, delivering digital twins to enable profitable growth for our customers.\n\nWe are a people company with an ecosystem of 150,000 colleagues and more than a million partners operating in over 100 countries\r\nto ensure proximity to our customers and stakeholders. We embrace diversity and inclusion in everything we do, guided by our\r\nmeaningful purpose of a sustainable future for all.', 'title': 'About Schneider Electric', 'category': 'general'}, {'text': 'Schneider Electric is aware of multiple vulnerabilities disclosed on CODESYS runtime system V3 communication server. Many vendors, including Schneider Electric, embed CODESYS in their offers. \r\n\r\nIf successfully exploited, these vulnerabilities could result in a denial of service or, in some cases, in remote code execution on PacDrive controllers, Modicon Controllers M241 / M251 / M262 / M258 / LMC058 / LMC078 / M218 , HMISCU, the Simulation Runtime SoftSPS from EcoStruxure Machine Expert and EcoStruxure Microgrid Operation products. \r\n\r\nFailure to apply the mitigations provided below may result in denial of service and/or arbitrary remote code execution. ', 'title': 'Overview', 'category': 'summary'}, {'text': 'Vulnerabilities disclosed by CODESYSTM group in the CODESYS Runtime and Simulation Runtime impact Schneider Electric controller products and software. \n\nAdditional information about the vulnerabilities can be found in the CODESYSTM Advisories at: \n Advisory 2023-02 • Advisory 2023-03\n • Advisory 2023-04\n • Advisory 2023-05\n • Advisory 2023-06\n • Advisory 2023-07\n • Advisory 2023-08 \n • Advisory 2023-09 ', 'title': 'Details', 'category': 'details'}, {'text': 'Customers should use appropriate patching methodologies when applying these patches to their systems. We strongly recommend the use of back-ups and evaluating the impact of these patches in a Test and Development environment or on an offline infrastructure. Contact Schneider Electric’s Customer Care Center https://www.se.com/us/en/work/support/contacts.jsp if you need assistance removing a patch. ', 'category': 'other'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of Schneider Electric CPCERT SEVD-2023-192-04 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Schneider Electric CPCERT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'Commercial Facilities, Critical Manufacturing, Energy', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'France', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Schneider Electric devices using CODESYS Runtime', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-020-02', 'status': 'final', 'version': '10', 'generator': {'date': '2026-01-20T15:49:51.777331Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2023-07-11T07:15:18.000000Z', 'number': '1', 'summary': 'Original Release', 'legacy_version': 'Initial'}, {'date': '2023-08-08T15:41:00.000000Z', 'number': '2', 'summary': 'New CODESYS advisories 2023-04 to 2023-09 added. Additional impacted product: Harmony and Easy Harmony, Vijeo Designer embedded in EcoStruxure Machine Expert.', 'legacy_version': 'Revision 1'}, {'date': '2024-01-09T00:00:00.000000Z', 'number': '3', 'summary': 'Remediations added for different products.', 'legacy_version': 'Revision 2'}, {'date': '2024-03-12T00:00:00.000000Z', 'number': '4', 'summary': 'A remediation is now available for HMIGK/HMIGTO/HMIGTU/HMIGTUX/HMISTU series', 'legacy_version': 'Revision 3'}, {'date': '2024-04-09T00:00:00.000000Z', 'number': '5', 'summary': 'A remediation is now available for Easy Harmony HMIET6/HMIFT6, and Magelis HMIGXU series', 'legacy_version': 'Revision 4'}, {'date': '2024-06-11T00:00:00.000000Z', 'number': '6', 'summary': 'Easy Modicon M310 is added to the list of products impacted', 'legacy_version': 'Revision 5'}, {'date': '2025-08-12T04:00:00.000000Z', 'number': '7', 'summary': 'Remediations are available for Harmony iPC series and Harmony P6 series with Vijeo Designer.', 'legacy_version': 'Revision 6'}, {'date': '2025-11-11T08:00:00.000000Z', 'number': '8', 'summary': 'Remediation is available for Easy Modicon M310.', 'legacy_version': 'Revision 7'}, {'date': '2025-12-09T08:00:00.000000Z', 'number': '9', 'summary': 'Replaced advisory IDs with CVE IDs. Added vulnerability details, including CVE descriptions, CWE identifiers, CVSS scores, and vector strings. Corrected mappings of affected and fixed products for each CVE.', 'legacy_version': 'Revision 8'}, {'date': '2026-01-20T15:49:51.778731Z', 'number': '10', 'summary': 'Initial Republication of Schneider Electric CPCERT SEVD-2023-192-04 advisory', 'legacy_version': 'CISA Republication'}], 'current_release_date': '2026-01-20T15:49:51.778731Z', 'initial_release_date': '2023-07-11T07:15:18.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-192-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2023-192-04.json', 'summary': 'CODESYS Runtime Vulnerabilities - SEVD-2023-192-04 CSAF Version', 'category': 'self'}, {'url': 'https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-192-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-192-04.pdf', 'summary': 'CODESYS Runtime Vulnerabilities - SEVD-2023-192-04 PDF Version', 'category': 'self'}, {'url': 'https://www.se.com/us/en/download/document/7EN52-0390/', 'summary': 'Recommended Cybersecurity Best Practices', 'category': 'external'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-020-02.json', 'summary': 'ICS Advisory ICSA-26-020-02 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-020-02', 'summary': 'ICS Advisory ICSA-26-020-02 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to CISA.', 'organization': 'Schneider Electric CPCERT'}]}, 'product_tree': {'branches': [{'name': 'Schneider Electric', 'branches': [{'name': 'HMISCU Controller', 'branches': [{'name': '<6.3.1', 'product': {'name': 'Schneider Electric HMISCU Controller All versions prior to v6.3.1', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Modicon Controller LMC078', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Schneider Electric Modicon Controller LMC078 All Versions', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Modicon Controller M241', 'branches': [{'name': '<5.2.11.18', 'product': {'name': 'Schneider Electric Modicon Controller M241 All versions prior to v5.2.11.18', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Modicon Controller M251', 'branches': [{'name': '<5.2.11.18', 'product': {'name': 'Schneider Electric Modicon Controller M251 All Versions prior to v5.2.11.18', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Modicon Controller M262', 'branches': [{'name': '<5.2.8.12', 'product': {'name': 'Schneider Electric Modicon Controller M262 All versions prior to v5.2.8.12', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Modicon Controller M258', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Schneider Electric Modicon Controller M258 All Versions', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Modicon Controller LMC058', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Schneider Electric Modicon Controller LMC058 All Versions', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Modicon Controller M218', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Schneider Electric Modicon Controller M218 All Versions', 'product_id': 'CSAFPID-0008'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'PacDrive 3 Controllers: LMC Eco/Pro/Pro2 ', 'branches': [{'name': '<1.76.14.1', 'product': {'name': 'Schneider Electric PacDrive 3 Controllers: LMC Eco/Pro/Pro2 All versions prior to v1.76.14.1', 'product_id': 'CSAFPID-0009'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SoftSPS embedded in EcoStruxure Machine Expert ', 'branches': [{'name': '<2.2', 'product': {'name': 'Schneider Electric SoftSPS embedded in EcoStruxure Machine Expert All Versions prior to Machine Expert v2.2', 'product_id': 'CSAFPID-0010'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Vijeo Designer embedded in EcoStruxure Machine Expert ', 'branches': [{'name': '<6.3.1', 'product': {'name': 'Schneider Electric Vijeo Designer embedded in EcoStruxure Machine Expert All versions prior to v6.3.1', 'product_id': 'CSAFPID-0011'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Harmony (Formerly Magelis) HMIGK/HMIGTO/HMIGTU/HMIGTUX/HMISTU series', 'branches': [{'name': '<6.3_HF3', 'product': {'name': 'Schneider Electric Harmony (Formerly Magelis) HMIGK/HMIGTO/HMIGTU/HMIGTUX/HMISTU series All Versions prior to V6.3 HF3', 'product_id': 'CSAFPID-0012'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Easy Harmony HMIET6/HMIFT6 Magelis HMIGXU series', 'branches': [{'name': '<2.0_HF2', 'product': {'name': 'Schneider Electric Easy Harmony HMIET6/HMIFT6 Magelis HMIGXU all versions prior to v2.0 HF2', 'product_id': 'CSAFPID-0013'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'HMISCU Controller', 'branches': [{'name': '6.3.1', 'product': {'name': 'Schneider Electric HMISCU Controller 6.3.1', 'product_id': 'CSAFPID-0014'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Modicon Controller M241', 'branches': [{'name': '5.2.11.18', 'product': {'name': 'Schneider Electric Modicon Controller M241 5.2.11.18', 'product_id': 'CSAFPID-0015'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Modicon Controller M251', 'branches': [{'name': '5.2.11.18', 'product': {'name': 'Schneider Electric Modicon Controller M251 5.2.11.18', 'product_id': 'CSAFPID-0016'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Modicon Controller M262', 'branches': [{'name': '5.2.8.12', 'product': {'name': 'Schneider Electric Modicon Controller M262 5.2.8.12', 'product_id': 'CSAFPID-0017'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'PacDrive 3 Controllers: LMC Eco/Pro/Pro2 ', 'branches': [{'name': '1.76.14.1', 'product': {'name': 'Schneider Electric PacDrive 3 Controllers: LMC Eco/Pro/Pro2 1.76.14.1', 'product_id': 'CSAFPID-0018'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'SoftSPS embedded in EcoStruxure Machine Expert ', 'branches': [{'name': '2.2', 'product': {'name': 'Schneider Electric SoftSPS embedded in EcoStruxure Machine Expert 2.2', 'product_id': 'CSAFPID-0019'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Vijeo Designer embedded in EcoStruxure Machine Expert ', 'branches': [{'name': '6.3.1', 'product': {'name': 'Schneider Electric Vijeo Designer embedded in EcoStruxure Machine Expert 6.3.1', 'product_id': 'CSAFPID-0020'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Harmony (Formerly Magelis) HMIGK/HMIGTO/HMIGTU/HMIGTUX/HMISTU series iPC series with Vijeo Designer runtime', 'branches': [{'name': '6.3_HF3', 'product': {'name': 'Schneider Electric Harmony (Formerly Magelis) HMIGK/HMIGTO/HMIGTU/HMIGTUX/HMISTU series iPC series with Vijeo Designer runtime V6.3 HF3', 'product_id': 'CSAFPID-0021'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Vijeo Designer Basic', 'branches': [{'name': '2.0_HotFix_2', 'product': {'name': 'Vijeo Designer Basic v2.0 HF2', 'product_id': 'CSAFPID-0022'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Harmony iPC series', 'product': {'name': 'Schneider Electric Harmony iPC series', 'product_id': 'CSAFPID-0023'}, 'category': 'product_name'}, {'name': 'Magelis XBT series', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Schneider Electric Magelis XBT series All Versions', 'product_id': 'CSAFPID-0024'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Easy Modicon M310', 'branches': [{'name': '<3.1.5.82', 'product': {'name': 'Schneider Electric Easy Modicon M310 All versions prior to v3.1.5.82', 'product_id': 'CSAFPID-0025'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Harmony P6 series', 'product': {'name': 'Schneider Electric Harmony P6 series', 'product_id': 'CSAFPID-0026'}, 'category': 'product_name'}, {'name': 'Vijeo Designer runtime', 'branches': [{'name': '<6.3_SP2', 'product': {'name': 'Schneider Electric Vijeo Designer runtime <6.3 SP2', 'product_id': 'CSAFPID-0027'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Vijeo Designer runtime', 'branches': [{'name': '6.3_SP2', 'product': {'name': 'Schneider Electric Vijeo Designer runtime 6.3 SP2', 'product_id': 'CSAFPID-0028'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Easy Modicon M310', 'branches': [{'name': '3.1.5.82', 'product': {'name': 'Schneider Electric Easy Modicon M310 version v3.1.5.82', 'product_id': 'CSAFPID-0029'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Schneider Electric Vijeo Designer runtime Versions Prior to 6.3 SP2 installed on Schneider Electric Harmony iPC series', 'product_id': 'CSAFPID-0030'}, 'product_reference': 'CSAFPID-0027', 'relates_to_product_reference': 'CSAFPID-0023'}, {'category': 'installed_on', 'full_product_name': {'name': 'Schneider Electric Vijeo Designer runtime Version 6.3 SP2 installed on Schneider Electric Harmony iPC series', 'product_id': 'CSAFPID-0031'}, 'product_reference': 'CSAFPID-0028', 'relates_to_product_reference': 'CSAFPID-0023'}, {'category': 'installed_on', 'full_product_name': {'name': 'Schneider Electric Vijeo Designer runtime Versions Prior to 6.3 SP2 installed on Schneider Electric Harmony P6 series', 'product_id': 'CSAFPID-0032'}, 'product_reference': 'CSAFPID-0027', 'relates_to_product_reference': 'CSAFPID-0026'}, {'category': 'installed_on', 'full_product_name': {'name': 'Schneider Electric Vijeo Designer runtime Version 6.3 SP2 installed on Schneider Electric Harmony P6 series', 'product_id': 'CSAFPID-0033'}, 'product_reference': 'CSAFPID-0028', 'relates_to_product_reference': 'CSAFPID-0026'}]}, 'vulnerabilities': [{'cve': 'CVE-2022-4046', 'cwe': {'id': 'CWE-119', 'name': 'Improper Restriction of Operations within the Bounds of a Memory Buffer'}, 'notes': [{'text': 'In addition to the functionality described above, there are memory access functions that allow the PLC application code to read or write memory. These are not limited to the data memories that are assigned to it or allocated by it. For this reason, the PLC application code can potentially access the entire RAM memory of the CODESYS Control runtime process surrounding it. This could allow PLC programmers who have successfully authenticated themselves at the controller to execute PLC application code that can modify itself or read or write sensitive data of the CODESYS Control runtime process.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-4046', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-4046', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/119.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': 'Schneider Electric´s Modicon LMC078 controllers have reached end of their life and are no longer commercially available. They have been replaced by the Modicon M262 controllers. We recommend our customers to migrate to the latest offer. Please contact your local Schneider Electric technical support for more information.', 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0002']}, {'details': 'Schneider Electric’s Modicon M218 controllers have reached their end of life and are no longer commercially available. They have been replaced by the Modicon Easy M200 and Modicon M241 controllers. We recommend our customers to migrate to the latest offer. Please contact your local Schneider Electric technical support for more information.', 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0008']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-28355', 'cwe': {'id': 'CWE-354', 'name': 'Improper Validation of Integrity Check Value'}, 'notes': [{'text': 'The PLC application code executed by the CODESYS Control Runtime contains a checksum. This enables the CODESYS development system to check at login whether its loaded project matches the PLC application code executed on the controller. This checksum is not sufficient to reliably detect PLC application code that has been modified in memory or boot application files that have been manipulated.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-28355', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-28355', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/354.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': 'Schneider Electric´s Modicon LMC078 controllers have reached end of their life and are no longer commercially available. They have been replaced by the Modicon M262 controllers. We recommend our customers to migrate to the latest offer. Please contact your local Schneider Electric technical support for more information.', 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0002']}, {'details': 'Schneider Electric’s Modicon M218 controllers have reached their end of life and are no longer commercially available. They have been replaced by the Modicon Easy M200 and Modicon M241 controllers. We recommend our customers to migrate to the latest offer. Please contact your local Schneider Electric technical support for more information.', 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0008']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47378', 'cwe': {'id': 'CWE-1288', 'name': 'Improper Validation of Consistency within Input'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests with inconsistent content can cause the CmpFiletransfer component to read internally from an invalid address, potentially leading to a denial-of-service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47378', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47378', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/1288.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47379', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpApp component to write attacker-controlled data to memory, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47379', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47379', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47380', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpApp component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47380', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47380', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47381', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpApp component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47381', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47381', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47382', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpTraceMgr component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47382', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47382', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47383', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpTraceMgr component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47383', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47383', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47384', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpTraceMgr component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47384', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47384', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47386', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpTraceMgr component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47386', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47386', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47387', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpTraceMgr component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47387', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47387', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47388', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpTraceMgr component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47388', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47388', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47389', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpTraceMgr component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47389', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47389', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47390', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpTraceMgr component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47390', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47390', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47385', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpAppForce component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47385', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47385', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47392', 'cwe': {'id': 'CWE-1288', 'name': 'Improper Validation of Consistency within Input'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests with inconsistent content can cause the CmpApp/CmpAppBP/CmpAppForce components to read internally from an invalid address, potentially leading to a denial-of-service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47392', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47392', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/1288.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47393', 'cwe': {'id': 'CWE-822', 'name': 'Untrusted Pointer Dereference'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpFiletransfer component to dereference addresses provided by the request for internal read access, which can lead to a denial-of-service situation.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47393', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47393', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/822.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47391', 'cwe': {'id': 'CWE-1288', 'name': 'Improper Validation of Consistency within Input'}, 'notes': [{'text': 'Crafted communication requests can cause the affected products to read internally from an invalid address, potentially leading to a denial-of-service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47391', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47391', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/1288.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37545', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-ofservice condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37545', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37545', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37546', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-ofservice condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37546', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37546', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37547', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-ofservice condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37547', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37547', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37548', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-ofservice condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37548', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37548', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37549', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-ofservice condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37549', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37549', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37550', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-ofservice condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37550', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37550', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37551', 'cwe': {'id': 'CWE-552', 'name': 'Files or Directories Accessible to External Parties'}, 'notes': [{'text': 'After successful authentication as a user, specially crafted communication requests can utilize the CmpApp component to download files with any file extensions to the controller. In contrast to the regular file download via CmpFileTransfer, no filtering of certain file types is performed here. As a result, the integrity of the CODESYS control runtime system may be compromised by the files loaded onto the controller.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37551', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37551', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/552.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37552', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37552', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37552', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37553', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37553', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37553', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37554', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37554', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37554', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37555', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37555', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37555', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37556', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37556', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37556', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37557', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests can cause the CmpAppBP component to overwrite a heap-based buffer, which can lead to a denial-of-service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37557', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37557', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37558', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37558', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37558', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37559', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37559', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37559', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-3662', 'cwe': {'id': 'CWE-427', 'name': 'Uncontrolled Search Path Element'}, 'notes': [{'text': 'The CODESYS Development System is vulnerable to the execution of malicious binaries from the current working directory.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-3662', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-3662', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/427.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-3663', 'cwe': {'id': 'CWE-924', 'name': 'Improper Enforcement of Message Integrity During Transmission in a Communication Channel'}, 'notes': [{'text': 'The Notification Center of the CODESYS Development System receives messages without ensuring that the message was not modified during transmission. This finally enables MITMs code execution when the user clicks the Learn More button.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-3663', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-3663', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/924.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-3669', 'cwe': {'id': 'CWE-307', 'name': 'Improper Restriction of Excessive Authentication Attempts'}, 'notes': [{'text': 'The Notification Center of the CODESYS Development System receives messages without ensuring that the message was not modified during transmission. This finally enables MITMs code execution when the user clicks the Learn More button.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-3669', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 3.3, 'attackVector': 'LOCAL', 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'LOW'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-3669', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/307.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-3670', 'cwe': {'id': 'CWE-668', 'name': 'Exposure of Resource to Wrong Sphere'}, 'notes': [{'text': 'CODESYS Scripting executes potentially malicious scripts saved by another user.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-3670', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-3670', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/668.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}]} | |
ot | ICSA-26-020-02 | CVE-2023-3670 | Schneider Electric devices using CODESYS Runtime | 2023-07-11 10:15:18+03:00 | 2026-01-20 18:49:51.778731+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-020-02.json | a12c588bca5652420a9e7aeb74211e523fa79e30fae605b08dd2ce51c8a29b31 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'We strongly recommend the following industry cybersecurity best practices.\n\nhttps://www.se.com/us/en/download/document/7EN52-0390/\n* Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.\n* Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.\n* Place all controllers in locked cabinets and never leave them in the “Program” mode.\n* Never connect programming software to any network other than the network intended for that device.\n* Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.\n* Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.\n* Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet.\n* When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices.\nFor more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document. \n', 'title': 'General Security Recommendations', 'category': 'general'}, {'text': 'This document provides an overview of the identified vulnerability or vulnerabilities and actions required to mitigate. For more details and assistance on how to protect your installation, contact your local Schneider Electric representative or Schneider Electric Industrial Cybersecurity Services: https://www.se.com/ww/en/work/solutions/cybersecurity/. These organizations will be fully aware of this situation and can support you through the process.\nFor further information related to cybersecurity in Schneider Electric’s products, visit the company’s cybersecurity support portal page: https://www.se.com/ww/en/work/support/cybersecurity/overview.jsp', 'title': 'For More Information', 'category': 'general'}, {'text': 'THIS NOTIFICATION DOCUMENT, THE INFORMATION CONTAINED HEREIN, AND ANY MATERIALS LINKED FROM IT (COLLECTIVELY, THIS “NOTIFICATION”) ARE INTENDED TO HELP PROVIDE AN OVERVIEW OF THE IDENTIFIED SITUATION AND SUGGESTED MITIGATION ACTIONS, REMEDIATION, FIX, AND/OR GENERAL SECURITY RECOMMENDATIONS AND IS PROVIDED ON AN “AS-IS” BASIS WITHOUT WARRANTY OR GUARANTEE OF ANY KIND. SCHNEIDER ELECTRIC DISCLAIMS ALL WARRANTIES RELATING TO THIS NOTIFICATION, EITHER EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. SCHNEIDER ELECTRIC MAKES NO WARRANTY THAT THE NOTIFICATION WILL RESOLVE THE IDENTIFIED SITUATION. IN NO EVENT SHALL SCHNEIDER ELECTRIC BE LIABLE FOR ANY DAMAGES OR LOSSES WHATSOEVER IN CONNECTION WITH THIS NOTIFICATION, INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF SCHNEIDER ELECTRIC HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. YOUR USE OF THIS NOTIFICATION IS AT YOUR OWN RISK, AND YOU ARE SOLELY LIABLE FOR ANY DAMAGES TO YOUR SYSTEMS OR ASSETS OR OTHER LOSSES THAT MAY RESULT FROM YOUR USE OF THIS NOTIFICATION. SCHNEIDER ELECTRIC RESERVES THE RIGHT TO UPDATE OR CHANGE THIS NOTIFICATION AT ANY TIME AND IN ITS SOLE DISCRETION', 'title': 'LEGAL DISCLAIMER', 'category': 'legal_disclaimer'}, {'text': 'Schneider’s purpose is to create Impact by empowering all to make the most of our energy and resources, bridging progress and\r\nsustainability for all. We call this Life Is On.\n\nOur mission is to be the trusted partner in Sustainability and Efficiency.\n\nWe are a global industrial technology leader bringing world-leading expertise in electrification, automation and digitization to smart\r\nindustries, resilient infrastructure, future-proof data centers, intelligent buildings, and intuitive homes. Anchored by our deep\r\ndomain expertise, we provide integrated end-to-end lifecycle AI enabled Industrial IoT solutions with connected products, automation,\r\nsoftware and services, delivering digital twins to enable profitable growth for our customers.\n\nWe are a people company with an ecosystem of 150,000 colleagues and more than a million partners operating in over 100 countries\r\nto ensure proximity to our customers and stakeholders. We embrace diversity and inclusion in everything we do, guided by our\r\nmeaningful purpose of a sustainable future for all.', 'title': 'About Schneider Electric', 'category': 'general'}, {'text': 'Schneider Electric is aware of multiple vulnerabilities disclosed on CODESYS runtime system V3 communication server. Many vendors, including Schneider Electric, embed CODESYS in their offers. \r\n\r\nIf successfully exploited, these vulnerabilities could result in a denial of service or, in some cases, in remote code execution on PacDrive controllers, Modicon Controllers M241 / M251 / M262 / M258 / LMC058 / LMC078 / M218 , HMISCU, the Simulation Runtime SoftSPS from EcoStruxure Machine Expert and EcoStruxure Microgrid Operation products. \r\n\r\nFailure to apply the mitigations provided below may result in denial of service and/or arbitrary remote code execution. ', 'title': 'Overview', 'category': 'summary'}, {'text': 'Vulnerabilities disclosed by CODESYSTM group in the CODESYS Runtime and Simulation Runtime impact Schneider Electric controller products and software. \n\nAdditional information about the vulnerabilities can be found in the CODESYSTM Advisories at: \n Advisory 2023-02 • Advisory 2023-03\n • Advisory 2023-04\n • Advisory 2023-05\n • Advisory 2023-06\n • Advisory 2023-07\n • Advisory 2023-08 \n • Advisory 2023-09 ', 'title': 'Details', 'category': 'details'}, {'text': 'Customers should use appropriate patching methodologies when applying these patches to their systems. We strongly recommend the use of back-ups and evaluating the impact of these patches in a Test and Development environment or on an offline infrastructure. Contact Schneider Electric’s Customer Care Center https://www.se.com/us/en/work/support/contacts.jsp if you need assistance removing a patch. ', 'category': 'other'}, {'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'This ICSA is a verbatim republication of Schneider Electric CPCERT SEVD-2023-192-04 from a direct conversion of the vendor\'s Common Security Advisory Framework (CSAF) advisory. This is republished to CISA\'s website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Schneider Electric CPCERT directly for any questions regarding this advisory.', 'title': 'Advisory Conversion Disclaimer', 'category': 'other'}, {'text': 'Commercial Facilities, Critical Manufacturing, Energy', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'France', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolate them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Schneider Electric devices using CODESYS Runtime', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-020-02', 'status': 'final', 'version': '10', 'generator': {'date': '2026-01-20T15:49:51.777331Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.5.0'}}, 'revision_history': [{'date': '2023-07-11T07:15:18.000000Z', 'number': '1', 'summary': 'Original Release', 'legacy_version': 'Initial'}, {'date': '2023-08-08T15:41:00.000000Z', 'number': '2', 'summary': 'New CODESYS advisories 2023-04 to 2023-09 added. Additional impacted product: Harmony and Easy Harmony, Vijeo Designer embedded in EcoStruxure Machine Expert.', 'legacy_version': 'Revision 1'}, {'date': '2024-01-09T00:00:00.000000Z', 'number': '3', 'summary': 'Remediations added for different products.', 'legacy_version': 'Revision 2'}, {'date': '2024-03-12T00:00:00.000000Z', 'number': '4', 'summary': 'A remediation is now available for HMIGK/HMIGTO/HMIGTU/HMIGTUX/HMISTU series', 'legacy_version': 'Revision 3'}, {'date': '2024-04-09T00:00:00.000000Z', 'number': '5', 'summary': 'A remediation is now available for Easy Harmony HMIET6/HMIFT6, and Magelis HMIGXU series', 'legacy_version': 'Revision 4'}, {'date': '2024-06-11T00:00:00.000000Z', 'number': '6', 'summary': 'Easy Modicon M310 is added to the list of products impacted', 'legacy_version': 'Revision 5'}, {'date': '2025-08-12T04:00:00.000000Z', 'number': '7', 'summary': 'Remediations are available for Harmony iPC series and Harmony P6 series with Vijeo Designer.', 'legacy_version': 'Revision 6'}, {'date': '2025-11-11T08:00:00.000000Z', 'number': '8', 'summary': 'Remediation is available for Easy Modicon M310.', 'legacy_version': 'Revision 7'}, {'date': '2025-12-09T08:00:00.000000Z', 'number': '9', 'summary': 'Replaced advisory IDs with CVE IDs. Added vulnerability details, including CVE descriptions, CWE identifiers, CVSS scores, and vector strings. Corrected mappings of affected and fixed products for each CVE.', 'legacy_version': 'Revision 8'}, {'date': '2026-01-20T15:49:51.778731Z', 'number': '10', 'summary': 'Initial Republication of Schneider Electric CPCERT SEVD-2023-192-04 advisory', 'legacy_version': 'CISA Republication'}], 'current_release_date': '2026-01-20T15:49:51.778731Z', 'initial_release_date': '2023-07-11T07:15:18.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'other', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-192-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=sevd-2023-192-04.json', 'summary': 'CODESYS Runtime Vulnerabilities - SEVD-2023-192-04 CSAF Version', 'category': 'self'}, {'url': 'https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-192-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-192-04.pdf', 'summary': 'CODESYS Runtime Vulnerabilities - SEVD-2023-192-04 PDF Version', 'category': 'self'}, {'url': 'https://www.se.com/us/en/download/document/7EN52-0390/', 'summary': 'Recommended Cybersecurity Best Practices', 'category': 'external'}, {'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-020-02.json', 'summary': 'ICS Advisory ICSA-26-020-02 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-020-02', 'summary': 'ICS Advisory ICSA-26-020-02 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to CISA.', 'organization': 'Schneider Electric CPCERT'}]}, 'product_tree': {'branches': [{'name': 'Schneider Electric', 'branches': [{'name': 'HMISCU Controller', 'branches': [{'name': '<6.3.1', 'product': {'name': 'Schneider Electric HMISCU Controller All versions prior to v6.3.1', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Modicon Controller LMC078', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Schneider Electric Modicon Controller LMC078 All Versions', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Modicon Controller M241', 'branches': [{'name': '<5.2.11.18', 'product': {'name': 'Schneider Electric Modicon Controller M241 All versions prior to v5.2.11.18', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Modicon Controller M251', 'branches': [{'name': '<5.2.11.18', 'product': {'name': 'Schneider Electric Modicon Controller M251 All Versions prior to v5.2.11.18', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Modicon Controller M262', 'branches': [{'name': '<5.2.8.12', 'product': {'name': 'Schneider Electric Modicon Controller M262 All versions prior to v5.2.8.12', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Modicon Controller M258', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Schneider Electric Modicon Controller M258 All Versions', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Modicon Controller LMC058', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Schneider Electric Modicon Controller LMC058 All Versions', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Modicon Controller M218', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Schneider Electric Modicon Controller M218 All Versions', 'product_id': 'CSAFPID-0008'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'PacDrive 3 Controllers: LMC Eco/Pro/Pro2 ', 'branches': [{'name': '<1.76.14.1', 'product': {'name': 'Schneider Electric PacDrive 3 Controllers: LMC Eco/Pro/Pro2 All versions prior to v1.76.14.1', 'product_id': 'CSAFPID-0009'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'SoftSPS embedded in EcoStruxure Machine Expert ', 'branches': [{'name': '<2.2', 'product': {'name': 'Schneider Electric SoftSPS embedded in EcoStruxure Machine Expert All Versions prior to Machine Expert v2.2', 'product_id': 'CSAFPID-0010'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Vijeo Designer embedded in EcoStruxure Machine Expert ', 'branches': [{'name': '<6.3.1', 'product': {'name': 'Schneider Electric Vijeo Designer embedded in EcoStruxure Machine Expert All versions prior to v6.3.1', 'product_id': 'CSAFPID-0011'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Harmony (Formerly Magelis) HMIGK/HMIGTO/HMIGTU/HMIGTUX/HMISTU series', 'branches': [{'name': '<6.3_HF3', 'product': {'name': 'Schneider Electric Harmony (Formerly Magelis) HMIGK/HMIGTO/HMIGTU/HMIGTUX/HMISTU series All Versions prior to V6.3 HF3', 'product_id': 'CSAFPID-0012'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Easy Harmony HMIET6/HMIFT6 Magelis HMIGXU series', 'branches': [{'name': '<2.0_HF2', 'product': {'name': 'Schneider Electric Easy Harmony HMIET6/HMIFT6 Magelis HMIGXU all versions prior to v2.0 HF2', 'product_id': 'CSAFPID-0013'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'HMISCU Controller', 'branches': [{'name': '6.3.1', 'product': {'name': 'Schneider Electric HMISCU Controller 6.3.1', 'product_id': 'CSAFPID-0014'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Modicon Controller M241', 'branches': [{'name': '5.2.11.18', 'product': {'name': 'Schneider Electric Modicon Controller M241 5.2.11.18', 'product_id': 'CSAFPID-0015'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Modicon Controller M251', 'branches': [{'name': '5.2.11.18', 'product': {'name': 'Schneider Electric Modicon Controller M251 5.2.11.18', 'product_id': 'CSAFPID-0016'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Modicon Controller M262', 'branches': [{'name': '5.2.8.12', 'product': {'name': 'Schneider Electric Modicon Controller M262 5.2.8.12', 'product_id': 'CSAFPID-0017'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'PacDrive 3 Controllers: LMC Eco/Pro/Pro2 ', 'branches': [{'name': '1.76.14.1', 'product': {'name': 'Schneider Electric PacDrive 3 Controllers: LMC Eco/Pro/Pro2 1.76.14.1', 'product_id': 'CSAFPID-0018'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'SoftSPS embedded in EcoStruxure Machine Expert ', 'branches': [{'name': '2.2', 'product': {'name': 'Schneider Electric SoftSPS embedded in EcoStruxure Machine Expert 2.2', 'product_id': 'CSAFPID-0019'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Vijeo Designer embedded in EcoStruxure Machine Expert ', 'branches': [{'name': '6.3.1', 'product': {'name': 'Schneider Electric Vijeo Designer embedded in EcoStruxure Machine Expert 6.3.1', 'product_id': 'CSAFPID-0020'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Harmony (Formerly Magelis) HMIGK/HMIGTO/HMIGTU/HMIGTUX/HMISTU series iPC series with Vijeo Designer runtime', 'branches': [{'name': '6.3_HF3', 'product': {'name': 'Schneider Electric Harmony (Formerly Magelis) HMIGK/HMIGTO/HMIGTU/HMIGTUX/HMISTU series iPC series with Vijeo Designer runtime V6.3 HF3', 'product_id': 'CSAFPID-0021'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Vijeo Designer Basic', 'branches': [{'name': '2.0_HotFix_2', 'product': {'name': 'Vijeo Designer Basic v2.0 HF2', 'product_id': 'CSAFPID-0022'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Harmony iPC series', 'product': {'name': 'Schneider Electric Harmony iPC series', 'product_id': 'CSAFPID-0023'}, 'category': 'product_name'}, {'name': 'Magelis XBT series', 'branches': [{'name': 'vers:all/*', 'product': {'name': 'Schneider Electric Magelis XBT series All Versions', 'product_id': 'CSAFPID-0024'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Easy Modicon M310', 'branches': [{'name': '<3.1.5.82', 'product': {'name': 'Schneider Electric Easy Modicon M310 All versions prior to v3.1.5.82', 'product_id': 'CSAFPID-0025'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Harmony P6 series', 'product': {'name': 'Schneider Electric Harmony P6 series', 'product_id': 'CSAFPID-0026'}, 'category': 'product_name'}, {'name': 'Vijeo Designer runtime', 'branches': [{'name': '<6.3_SP2', 'product': {'name': 'Schneider Electric Vijeo Designer runtime <6.3 SP2', 'product_id': 'CSAFPID-0027'}, 'category': 'product_version_range'}], 'category': 'product_name'}, {'name': 'Vijeo Designer runtime', 'branches': [{'name': '6.3_SP2', 'product': {'name': 'Schneider Electric Vijeo Designer runtime 6.3 SP2', 'product_id': 'CSAFPID-0028'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Easy Modicon M310', 'branches': [{'name': '3.1.5.82', 'product': {'name': 'Schneider Electric Easy Modicon M310 version v3.1.5.82', 'product_id': 'CSAFPID-0029'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}], 'relationships': [{'category': 'installed_on', 'full_product_name': {'name': 'Schneider Electric Vijeo Designer runtime Versions Prior to 6.3 SP2 installed on Schneider Electric Harmony iPC series', 'product_id': 'CSAFPID-0030'}, 'product_reference': 'CSAFPID-0027', 'relates_to_product_reference': 'CSAFPID-0023'}, {'category': 'installed_on', 'full_product_name': {'name': 'Schneider Electric Vijeo Designer runtime Version 6.3 SP2 installed on Schneider Electric Harmony iPC series', 'product_id': 'CSAFPID-0031'}, 'product_reference': 'CSAFPID-0028', 'relates_to_product_reference': 'CSAFPID-0023'}, {'category': 'installed_on', 'full_product_name': {'name': 'Schneider Electric Vijeo Designer runtime Versions Prior to 6.3 SP2 installed on Schneider Electric Harmony P6 series', 'product_id': 'CSAFPID-0032'}, 'product_reference': 'CSAFPID-0027', 'relates_to_product_reference': 'CSAFPID-0026'}, {'category': 'installed_on', 'full_product_name': {'name': 'Schneider Electric Vijeo Designer runtime Version 6.3 SP2 installed on Schneider Electric Harmony P6 series', 'product_id': 'CSAFPID-0033'}, 'product_reference': 'CSAFPID-0028', 'relates_to_product_reference': 'CSAFPID-0026'}]}, 'vulnerabilities': [{'cve': 'CVE-2022-4046', 'cwe': {'id': 'CWE-119', 'name': 'Improper Restriction of Operations within the Bounds of a Memory Buffer'}, 'notes': [{'text': 'In addition to the functionality described above, there are memory access functions that allow the PLC application code to read or write memory. These are not limited to the data memories that are assigned to it or allocated by it. For this reason, the PLC application code can potentially access the entire RAM memory of the CODESYS Control runtime process surrounding it. This could allow PLC programmers who have successfully authenticated themselves at the controller to execute PLC application code that can modify itself or read or write sensitive data of the CODESYS Control runtime process.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-4046', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-4046', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/119.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': 'Schneider Electric´s Modicon LMC078 controllers have reached end of their life and are no longer commercially available. They have been replaced by the Modicon M262 controllers. We recommend our customers to migrate to the latest offer. Please contact your local Schneider Electric technical support for more information.', 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0002']}, {'details': 'Schneider Electric’s Modicon M218 controllers have reached their end of life and are no longer commercially available. They have been replaced by the Modicon Easy M200 and Modicon M241 controllers. We recommend our customers to migrate to the latest offer. Please contact your local Schneider Electric technical support for more information.', 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0008']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-28355', 'cwe': {'id': 'CWE-354', 'name': 'Improper Validation of Integrity Check Value'}, 'notes': [{'text': 'The PLC application code executed by the CODESYS Control Runtime contains a checksum. This enables the CODESYS development system to check at login whether its loaded project matches the PLC application code executed on the controller. This checksum is not sufficient to reliably detect PLC application code that has been modified in memory or boot application files that have been manipulated.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-28355', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-28355', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/354.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': 'Schneider Electric´s Modicon LMC078 controllers have reached end of their life and are no longer commercially available. They have been replaced by the Modicon M262 controllers. We recommend our customers to migrate to the latest offer. Please contact your local Schneider Electric technical support for more information.', 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0002']}, {'details': 'Schneider Electric’s Modicon M218 controllers have reached their end of life and are no longer commercially available. They have been replaced by the Modicon Easy M200 and Modicon M241 controllers. We recommend our customers to migrate to the latest offer. Please contact your local Schneider Electric technical support for more information.', 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0008']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47378', 'cwe': {'id': 'CWE-1288', 'name': 'Improper Validation of Consistency within Input'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests with inconsistent content can cause the CmpFiletransfer component to read internally from an invalid address, potentially leading to a denial-of-service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47378', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47378', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/1288.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47379', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpApp component to write attacker-controlled data to memory, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47379', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47379', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47380', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpApp component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47380', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47380', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47381', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpApp component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47381', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47381', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47382', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpTraceMgr component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47382', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47382', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47383', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpTraceMgr component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47383', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47383', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47384', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpTraceMgr component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47384', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47384', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47386', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpTraceMgr component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47386', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47386', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47387', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpTraceMgr component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47387', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47387', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47388', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpTraceMgr component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47388', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47388', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47389', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpTraceMgr component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47389', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47389', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47390', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpTraceMgr component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47390', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47390', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47385', 'cwe': {'id': 'CWE-121', 'name': 'Stack-based Buffer Overflow'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpAppForce component to write attacker-controlled data to stack, which can lead to a denial-of-service condition, memory overwriting, or remote code execution.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47385', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47385', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/121.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47392', 'cwe': {'id': 'CWE-1288', 'name': 'Improper Validation of Consistency within Input'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests with inconsistent content can cause the CmpApp/CmpAppBP/CmpAppForce components to read internally from an invalid address, potentially leading to a denial-of-service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47392', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47392', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/1288.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47393', 'cwe': {'id': 'CWE-822', 'name': 'Untrusted Pointer Dereference'}, 'notes': [{'text': 'After successful authentication, specific crafted communication requests can cause the CmpFiletransfer component to dereference addresses provided by the request for internal read access, which can lead to a denial-of-service situation.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47393', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47393', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/822.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2022-47391', 'cwe': {'id': 'CWE-1288', 'name': 'Improper Validation of Consistency within Input'}, 'notes': [{'text': 'Crafted communication requests can cause the affected products to read internally from an invalid address, potentially leading to a denial-of-service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2022-47391', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.5, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2022-47391', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/1288.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37545', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-ofservice condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37545', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37545', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37546', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-ofservice condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37546', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37546', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37547', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-ofservice condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37547', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37547', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37548', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-ofservice condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37548', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37548', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37549', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-ofservice condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37549', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37549', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37550', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-ofservice condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37550', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37550', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37551', 'cwe': {'id': 'CWE-552', 'name': 'Files or Directories Accessible to External Parties'}, 'notes': [{'text': 'After successful authentication as a user, specially crafted communication requests can utilize the CmpApp component to download files with any file extensions to the controller. In contrast to the regular file download via CmpFileTransfer, no filtering of certain file types is performed here. As a result, the integrity of the CODESYS control runtime system may be compromised by the files loaded onto the controller.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37551', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N', 'integrityImpact': 'HIGH', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37551', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/552.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37552', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37552', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37552', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37553', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37553', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37553', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37554', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37554', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37554', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37555', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37555', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37555', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37556', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37556', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37556', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37557', 'cwe': {'id': 'CWE-787', 'name': 'Out-of-bounds Write'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests can cause the CmpAppBP component to overwrite a heap-based buffer, which can lead to a denial-of-service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37557', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37557', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/787.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37558', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37558', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37558', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-37559', 'cwe': {'id': 'CWE-20', 'name': 'Improper Input Validation'}, 'notes': [{'text': 'After successful authentication as a user, specific crafted communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of service condition.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-37559', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 6.5, 'attackVector': 'NETWORK', 'baseSeverity': 'MEDIUM', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'NONE'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-37559', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/20.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-3662', 'cwe': {'id': 'CWE-427', 'name': 'Uncontrolled Search Path Element'}, 'notes': [{'text': 'The CODESYS Development System is vulnerable to the execution of malicious binaries from the current working directory.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-3662', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-3662', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/427.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-3663', 'cwe': {'id': 'CWE-924', 'name': 'Improper Enforcement of Message Integrity During Transmission in a Communication Channel'}, 'notes': [{'text': 'The Notification Center of the CODESYS Development System receives messages without ensuring that the message was not modified during transmission. This finally enables MITMs code execution when the user clicks the Learn More button.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-3663', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 8.8, 'attackVector': 'NETWORK', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'NONE', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-3663', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/924.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-3669', 'cwe': {'id': 'CWE-307', 'name': 'Improper Restriction of Excessive Authentication Attempts'}, 'notes': [{'text': 'The Notification Center of the CODESYS Development System receives messages without ensuring that the message was not modified during transmission. This finally enables MITMs code execution when the user clicks the Learn More button.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-3669', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 3.3, 'attackVector': 'LOCAL', 'baseSeverity': 'LOW', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N', 'integrityImpact': 'NONE', 'userInteraction': 'NONE', 'attackComplexity': 'LOW', 'availabilityImpact': 'NONE', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'LOW'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-3669', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/307.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}, {'cve': 'CVE-2023-3670', 'cwe': {'id': 'CWE-668', 'name': 'Exposure of Resource to Wrong Sphere'}, 'notes': [{'text': 'CODESYS Scripting executes potentially malicious scripts saved by another user.', 'title': 'Overview', 'category': 'description'}], 'title': 'CVE-2023-3670', 'scores': [{'cvss_v3': {'scope': 'UNCHANGED', 'version': '3.1', 'baseScore': 7.3, 'attackVector': 'LOCAL', 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H', 'integrityImpact': 'HIGH', 'userInteraction': 'REQUIRED', 'attackComplexity': 'LOW', 'availabilityImpact': 'HIGH', 'privilegesRequired': 'LOW', 'confidentialityImpact': 'HIGH'}, 'products': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2023-3670', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://cwe.mitre.org/data/definitions/668.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer. In order to complete the update, connect to Harmony HMI and download the project file using Vijeo Designer v6.3.1.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M241 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M241 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0003']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M251 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M251 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0004']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'Modicon Controller M262 Firmware delivered with Machine Expert v2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to v2.2 of Machine Expert. Update Modicon Controller M262 to the latest firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0005']}, {'details': "Schneider Electric’s Magelis XBT series have reached their end of commercialization. Magelis XBTGT/XBTGK offers have been replaced by HMIGTO/HMIGTU/HMIGK. We recommend our customers to migrate to the latest offers. For Magelis XBT series that haven't been replaced, please contact your local Schneider Electric technical support for more information.", 'category': 'no_fix_planned', 'product_ids': ['CSAFPID-0024']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'PacDrive 3 Controllers LMC Eco/Pro/Pro2 Firmware delivered with Machine Expert V2.2 includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/ On the engineering workstation, update to V2.2 of Machine Expert. Update PacDrive 3 Controllers: LMC Eco/Pro/Pro2 to the latest Firmware and preform reboot.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0009']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware', 'details': 'Version 6.3.1 of Vijeo Designer includes a fix for this vulnerability and can be updated through the Schneider Electric Software Update (SESU) application. https://www.se.com/ww/en/product-range/1054-vijeodesigner-hmi-software/#software-and-firmware On the engineering workstation, update to v6.3.1 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0011']}, {'url': 'https://www.se.com/ww/en/product-range/2226-ecostruxure-machine-expert-software/', 'details': 'SoftSPS component has been removed from Machine Expert V2.2. Machine Expert can be updated through the Schneider Electric Software Update (SESU) application. ', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0010']}, {'details': '• Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use. • Use encrypted communication links. • The “Cybersecurity Guidelines for EcoStruxure Machine Expert, Modicon and PacDrive Controllers and Associated Equipment” provide mitigations through the activation of project encryption in the Enhanced Security Settings, chapter https://download.schneiderelectric.com/files?p_enDocType=User+guide&p_File_Name=EIO0000004242.00.pdf&p_Doc_Ref=EIO0000004242. • Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/1105.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009']}, {'details': '• Enable the optional ‘Implicit Checks’ on logic applications. • Avoid use of the POINTER data type and MEMMOVE instructions, especially on untrusted inputs. • Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside. • Use firewalls to protect and separate the control system network from other networks. • Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection. To ensure you are informed of all updates, including details on affected products and remediation plans, subscribe to Schneider Electric’s security notification service here: https://www.se.com/en/work/support/cybersecurity/securitynotifications.jsp', 'category': 'mitigation', 'product_ids': ['CSAFPID-0010']}, {'url': 'https://www.se.com/ww/en/product-range/268959560-easy-modicon-m310', 'details': 'Version 3.1.5.82 includes a fix for this vulnerability\r\nand can be download here: \r\nhttps://www.se.com/ww/en/product-range/268959560-easy-modicon-m310 \r\nAs an alternative, contact your Schneider Electric \r\nCustomer Care Center to obtain the firmware. \r\nTo complete the update, connect to M310 and \r\ndownload the firmware using EcoStruxureTM Motion \r\nExpert.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0025']}, {'details': 'Version 6.3 HF3 of Vijeo Designer includes a fix for \n this vulnerability and can be updated through the \nSchneider Electric Software Update (SESU) \napplication.\nAs an alternative, please contact your Schneider \nElectric Customer Care Center to obtain the Hot Fix. \nFor additional detail please refer to the supplied help \nfile in Hot Fix.\nOn the engineering workstation, update to v6.3 HF3 \nof Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0012']}, {'url': 'https://www.se.com/us/en/work/support/contacts.jsp', 'details': 'Vijeo Designer Basic v2.0 HotFix 2 includes a fix for \nthis vulnerability. Please contact your Schneider \nElectric Customer Care Center to obtain the installer. \nTo complete the update, connect to Harmony HMI \nand download the firmware using Vijeo Designer \nBasic.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0013']}, {'url': 'https://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware', 'details': 'Version 6.3 SP2 of Vijeo Designer includes a fix \r\nfor this vulnerability and can be updated through \r\nthe Schneider Electric Software Update (SESU) \r\napplication.\r\nhttps://www.se.com/ww/en/product-range/1054-vijeo-designer-hmi-software/#software-and-firmware\r\nAs an alternative, please contact your Schneider \r\nElectric Customer Care Center to obtain the Fix.\r\nFor additional details, please refer to the supplied \r\nhelp file in Hot Fix.\r\nOn the engineering workstation, update to v6.3 \r\nSP2 of Vijeo Designer.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0030', 'CSAFPID-0032']}, {'details': 'Customers should immediately apply the following mitigations to reduce the risk of exploitation: • Ensure usage of user management and password features. User rights are enabled by default and forced to create a strong password at first use.• Restrict access to programming ports, typically UDP/1740, TCP/11740 and TCP/484.• Use controllers and devices only in a protected environment to minimize network exposure and ensure that they are not accessible from outside.• Use firewalls to protect and separate the control system network from other networks.• Use VPN (Virtual Private Networks) tunnels if remote access is required. • Limit the access to both development and control system by physical means, operating system features, etc. • Protect both development and control system by using up to date malware protection.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0025']}], 'product_status': {'fixed': ['CSAFPID-0014', 'CSAFPID-0015', 'CSAFPID-0016', 'CSAFPID-0017', 'CSAFPID-0018', 'CSAFPID-0019', 'CSAFPID-0020', 'CSAFPID-0021', 'CSAFPID-0022', 'CSAFPID-0031', 'CSAFPID-0033', 'CSAFPID-0029'], 'known_affected': ['CSAFPID-0001', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012', 'CSAFPID-0013', 'CSAFPID-0024', 'CSAFPID-0025', 'CSAFPID-0030', 'CSAFPID-0032']}}]} | |
ot | ICSA-26-020-03 | CVE-2025-14376 | Rockwell Automation Verve Asset Manager | 2026-01-20 10:00:00+03:00 | 2026-01-20 10:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-020-03.json | 7f38ca3e001fc37417ed5d0ba2a813e7879f904beabb2cd4207cab3f8f7a8600 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities may allow an attacker to access sensitive information stored in variables within the ADI server.', 'title': 'Risk evaluation', 'category': 'summary'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also recommends users take the following measures to protect themselves from social engineering attacks:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Do not click web links or open attachments in unsolicited email messages.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Rockwell Automation Verve Asset Manager', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-020-03', 'status': 'final', 'version': '1', 'generator': {'date': '2026-01-20T15:49:50.756600Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-01-20T07:00:00.000000Z', 'number': '1', 'summary': "Initial Republication of Rockwell Automation's security advisory", 'legacy_version': 'Initial'}], 'current_release_date': '2026-01-20T07:00:00.000000Z', 'initial_release_date': '2026-01-20T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-020-03.json', 'summary': 'ICS Advisory ICSA-26-020-03 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-020-03', 'summary': 'ICSA Advisory ICSA-26-020-03 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/ncas/tips/ST04-014', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to CISA', 'organization': 'Rockwell Automation'}]}, 'product_tree': {'branches': [{'name': 'Rockwell Automation', 'branches': [{'name': 'Verve Asset Manager', 'branches': [{'name': '1.33', 'product': {'name': 'Rockwell Automation Verve Asset Manager: 1.33', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Verve Asset Manager', 'branches': [{'name': '1.34', 'product': {'name': 'Rockwell Automation Verve Asset Manager: 1.34', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Verve Asset Manager', 'branches': [{'name': '1.35', 'product': {'name': 'Rockwell Automation Verve Asset Manager: 1.35', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Verve Asset Manager', 'branches': [{'name': '1.36', 'product': {'name': 'Rockwell Automation Verve Asset Manager: 1.36', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Verve Asset Manager', 'branches': [{'name': '1.37', 'product': {'name': 'Rockwell Automation Verve Asset Manager: 1.37', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Verve Asset Manager', 'branches': [{'name': '1.38', 'product': {'name': 'Rockwell Automation Verve Asset Manager: 1.38', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Verve Asset Manager', 'branches': [{'name': '1.39', 'product': {'name': 'Rockwell Automation Verve Asset Manager: 1.39', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Verve Asset Manager', 'branches': [{'name': '1.40', 'product': {'name': 'Rockwell Automation Verve Asset Manager: 1.40', 'product_id': 'CSAFPID-0008'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Verve Asset Manager', 'branches': [{'name': '1.41', 'product': {'name': 'Rockwell Automation Verve Asset Manager: 1.41', 'product_id': 'CSAFPID-0009'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Verve Asset Manager', 'branches': [{'name': '1.41.1', 'product': {'name': 'Rockwell Automation Verve Asset Manager: 1.41.1', 'product_id': 'CSAFPID-0010'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Verve Asset Manager', 'branches': [{'name': '1.41.2', 'product': {'name': 'Rockwell Automation Verve Asset Manager: 1.41.2', 'product_id': 'CSAFPID-0011'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Verve Asset Manager', 'branches': [{'name': '1.41.3', 'product': {'name': 'Rockwell Automation Verve Asset Manager: 1.41.3', 'product_id': 'CSAFPID-0012'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-14376', 'cwe': {'id': 'CWE-922', 'name': 'Insecure Storage of Sensitive Information'}, 'notes': [{'text': 'A security issue was discovered within the legacy ADI server component of Verve Asset Manager, where unencrypted sensitive data was stored in environment variables. This component was retired and became optional beginning with the 1.36 release in 2024.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/922.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-14376', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation reports that the issue was resolved in version 1.42, and the component has been optional since version 1.36. Rockwell Automation recommends updating to the latest available version.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html', 'details': 'For additional details, refer to the advisory on the Rockwell Automation security page.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012']}, {'url': 'https://www.rockwellautomation.com/en-us/company/about-us/contact-us.html', 'details': 'For further assistance, contact Rockwell Automation TechConnect for help.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012']}}, {'cve': 'CVE-2025-14377', 'cwe': {'id': 'CWE-312', 'name': 'Cleartext Storage of Sensitive Information'}, 'notes': [{'text': 'A security issue was discovered within the legacy Ansible playbook component of Verve Asset Manager. The issue occurred because unencrypted sensitive information was incorrectly stored during playbook execution. This component was retired and became optional starting with the 1.36 release in 2024.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.9, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:L'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/312.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-14377', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation reports that the issue was resolved in version 1.42, and the component has been optional since version 1.36. Rockwell Automation recommends updating to the latest available version.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html', 'details': 'For additional details, refer to the advisory on the Rockwell Automation security page.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012']}, {'url': 'https://www.rockwellautomation.com/en-us/company/about-us/contact-us.html', 'details': 'For further assistance, contact Rockwell Automation TechConnect for help.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012']}}]} | |
ot | ICSA-26-020-03 | CVE-2025-14377 | Rockwell Automation Verve Asset Manager | 2026-01-20 10:00:00+03:00 | 2026-01-20 10:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-020-03.json | 9dc731b12edc716d79f3d409cf1f2c002fe841be8c29177f89c4dfdee73431d8 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities may allow an attacker to access sensitive information stored in variables within the ADI server.', 'title': 'Risk evaluation', 'category': 'summary'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United States', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also recommends users take the following measures to protect themselves from social engineering attacks:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Do not click web links or open attachments in unsolicited email messages.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'Rockwell Automation Verve Asset Manager', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-020-03', 'status': 'final', 'version': '1', 'generator': {'date': '2026-01-20T15:49:50.756600Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-01-20T07:00:00.000000Z', 'number': '1', 'summary': "Initial Republication of Rockwell Automation's security advisory", 'legacy_version': 'Initial'}], 'current_release_date': '2026-01-20T07:00:00.000000Z', 'initial_release_date': '2026-01-20T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-020-03.json', 'summary': 'ICS Advisory ICSA-26-020-03 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-020-03', 'summary': 'ICSA Advisory ICSA-26-020-03 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/ncas/tips/ST04-014', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'summary': 'reported these vulnerabilities to CISA', 'organization': 'Rockwell Automation'}]}, 'product_tree': {'branches': [{'name': 'Rockwell Automation', 'branches': [{'name': 'Verve Asset Manager', 'branches': [{'name': '1.33', 'product': {'name': 'Rockwell Automation Verve Asset Manager: 1.33', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Verve Asset Manager', 'branches': [{'name': '1.34', 'product': {'name': 'Rockwell Automation Verve Asset Manager: 1.34', 'product_id': 'CSAFPID-0002'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Verve Asset Manager', 'branches': [{'name': '1.35', 'product': {'name': 'Rockwell Automation Verve Asset Manager: 1.35', 'product_id': 'CSAFPID-0003'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Verve Asset Manager', 'branches': [{'name': '1.36', 'product': {'name': 'Rockwell Automation Verve Asset Manager: 1.36', 'product_id': 'CSAFPID-0004'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Verve Asset Manager', 'branches': [{'name': '1.37', 'product': {'name': 'Rockwell Automation Verve Asset Manager: 1.37', 'product_id': 'CSAFPID-0005'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Verve Asset Manager', 'branches': [{'name': '1.38', 'product': {'name': 'Rockwell Automation Verve Asset Manager: 1.38', 'product_id': 'CSAFPID-0006'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Verve Asset Manager', 'branches': [{'name': '1.39', 'product': {'name': 'Rockwell Automation Verve Asset Manager: 1.39', 'product_id': 'CSAFPID-0007'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Verve Asset Manager', 'branches': [{'name': '1.40', 'product': {'name': 'Rockwell Automation Verve Asset Manager: 1.40', 'product_id': 'CSAFPID-0008'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Verve Asset Manager', 'branches': [{'name': '1.41', 'product': {'name': 'Rockwell Automation Verve Asset Manager: 1.41', 'product_id': 'CSAFPID-0009'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Verve Asset Manager', 'branches': [{'name': '1.41.1', 'product': {'name': 'Rockwell Automation Verve Asset Manager: 1.41.1', 'product_id': 'CSAFPID-0010'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Verve Asset Manager', 'branches': [{'name': '1.41.2', 'product': {'name': 'Rockwell Automation Verve Asset Manager: 1.41.2', 'product_id': 'CSAFPID-0011'}, 'category': 'product_version'}], 'category': 'product_name'}, {'name': 'Verve Asset Manager', 'branches': [{'name': '1.41.3', 'product': {'name': 'Rockwell Automation Verve Asset Manager: 1.41.3', 'product_id': 'CSAFPID-0012'}, 'category': 'product_version'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-14376', 'cwe': {'id': 'CWE-922', 'name': 'Insecure Storage of Sensitive Information'}, 'notes': [{'text': 'A security issue was discovered within the legacy ADI server component of Verve Asset Manager, where unencrypted sensitive data was stored in environment variables. This component was retired and became optional beginning with the 1.36 release in 2024.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.2, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/922.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-14376', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation reports that the issue was resolved in version 1.42, and the component has been optional since version 1.36. Rockwell Automation recommends updating to the latest available version.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html', 'details': 'For additional details, refer to the advisory on the Rockwell Automation security page.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012']}, {'url': 'https://www.rockwellautomation.com/en-us/company/about-us/contact-us.html', 'details': 'For further assistance, contact Rockwell Automation TechConnect for help.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012']}}, {'cve': 'CVE-2025-14377', 'cwe': {'id': 'CWE-312', 'name': 'Cleartext Storage of Sensitive Information'}, 'notes': [{'text': 'A security issue was discovered within the legacy Ansible playbook component of Verve Asset Manager. The issue occurred because unencrypted sensitive information was incorrectly stored during playbook execution. This component was retired and became optional starting with the 1.36 release in 2024.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.9, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:L'}, 'products': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012']}], 'references': [{'url': 'https://cwe.mitre.org/data/definitions/312.html', 'summary': 'cwe.mitre.org', 'category': 'external'}, {'url': 'https://www.cve.org/CVERecord?id=CVE-2025-14377', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4-0#CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'Rockwell Automation reports that the issue was resolved in version 1.42, and the component has been optional since version 1.36. Rockwell Automation recommends updating to the latest available version.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012']}, {'url': 'https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html', 'details': 'For additional details, refer to the advisory on the Rockwell Automation security page.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012']}, {'url': 'https://www.rockwellautomation.com/en-us/company/about-us/contact-us.html', 'details': 'For further assistance, contact Rockwell Automation TechConnect for help.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012']}], 'product_status': {'known_affected': ['CSAFPID-0001', 'CSAFPID-0002', 'CSAFPID-0003', 'CSAFPID-0004', 'CSAFPID-0005', 'CSAFPID-0006', 'CSAFPID-0007', 'CSAFPID-0008', 'CSAFPID-0009', 'CSAFPID-0010', 'CSAFPID-0011', 'CSAFPID-0012']}}]} | |
ot | ICSA-26-015-01 | CVE-2025-61937 | AVEVA Process Optimization | 2026-01-15 10:00:00+03:00 | 2026-01-15 10:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-015-01.json | 3a9a80b0d45399d480bad926ee55775129a2ce3ea88dd818b7eba55978fb2e5e | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could enable an attacker to execute remote code, perform SQL injection, escalate privileges, or access sensitive information.', 'title': 'Risk evaluation', 'category': 'summary'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United Kingdom', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of this (these) vulnerability(ies), such as:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also recommends users take the following measures to protect themselves from social engineering attacks:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Do not click web links or open attachments in unsolicited email messages.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'AVEVA Process Optimization', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-015-01', 'status': 'final', 'version': '1', 'generator': {'date': '2026-01-14T22:05:05.319706Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-01-15T07:00:00.000000Z', 'number': '1', 'summary': 'Initial Republication of AVEVA-2026-001', 'legacy_version': 'Initial'}], 'current_release_date': '2026-01-15T07:00:00.000000Z', 'initial_release_date': '2026-01-15T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-015-01.json', 'summary': 'ICS Advisory ICSA-26-015-01 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-015-01', 'summary': 'ICSA Advisory ICSA-26-015-01 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/ncas/tips/ST04-014', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Christopher Wu'], 'summary': 'reported these vulnerabilities to AVEVA', 'organization': 'Veracode'}, {'summary': 'reported these vulnerabilities to CISA', 'organization': 'AVEVA'}]}, 'product_tree': {'branches': [{'name': 'AVEVA', 'branches': [{'name': 'Process Optimization', 'branches': [{'name': '<=2024.1', 'product': {'name': 'AVEVA Process Optimization: <=2024.1', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-61937', 'cwe': {'id': 'CWE-94', 'name': "Improper Control of Generation of Code ('Code Injection')"}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS System privileges of "taoimr" service, potentially resulting in complete compromise of the Model Application Server.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 10.0, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-61937', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-64691', 'cwe': {'id': 'CWE-94', 'name': "Improper Control of Generation of Code ('Code Injection')"}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with TCL Macro scripts and escalate privileges to OS System, potentially resulting in complete compromise of the Model Application Server.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-64691', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-61943', 'cwe': {'id': 'CWE-89', 'name': "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper with queries in Captive Historian and achieve code execution under SQL Server administrative privileges, potentially resulting in complete compromise of the SQL Server.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-61943', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-65118', 'cwe': {'id': 'CWE-427', 'name': 'Uncontrolled Search Path Element'}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to trick Process Optimization services into loading arbitrary code and escalate privileges to OS System, potentially resulting in complete compromise of the Model Application Server.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-65118', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-64729', 'cwe': {'id': 'CWE-862', 'name': 'Missing Authorization'}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Process Optimization project files, embed code, and escalate their privileges to the identity of a victim user who subsequently interacts with the project files.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-64729', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-65117', 'cwe': {'id': 'CWE-676', 'name': 'Use of Potentially Dangerous Function'}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Designer User) to embed OLE objects into graphics, and escalate their privileges to the identity of a victim user who subsequently interacts with the graphical elements.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-65117', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-64769', 'cwe': {'id': 'CWE-319', 'name': 'Cleartext Transmission of Sensitive Information'}, 'notes': [{'text': 'The Process Optimization application suite leverages connection channels/protocols that by-default are not encrypted and could become subject to hijacking or data leakage in certain man-in-the-Middle or passive inspection scenarios.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-64769', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-015-01 | CVE-2025-64691 | AVEVA Process Optimization | 2026-01-15 10:00:00+03:00 | 2026-01-15 10:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-015-01.json | e983aba5d7fa8e89ecf0bfb3be80042dfa56d7e59bf3b49fc7b214edc57f4c0d | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could enable an attacker to execute remote code, perform SQL injection, escalate privileges, or access sensitive information.', 'title': 'Risk evaluation', 'category': 'summary'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United Kingdom', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of this (these) vulnerability(ies), such as:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also recommends users take the following measures to protect themselves from social engineering attacks:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Do not click web links or open attachments in unsolicited email messages.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'AVEVA Process Optimization', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-015-01', 'status': 'final', 'version': '1', 'generator': {'date': '2026-01-14T22:05:05.319706Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-01-15T07:00:00.000000Z', 'number': '1', 'summary': 'Initial Republication of AVEVA-2026-001', 'legacy_version': 'Initial'}], 'current_release_date': '2026-01-15T07:00:00.000000Z', 'initial_release_date': '2026-01-15T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-015-01.json', 'summary': 'ICS Advisory ICSA-26-015-01 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-015-01', 'summary': 'ICSA Advisory ICSA-26-015-01 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/ncas/tips/ST04-014', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Christopher Wu'], 'summary': 'reported these vulnerabilities to AVEVA', 'organization': 'Veracode'}, {'summary': 'reported these vulnerabilities to CISA', 'organization': 'AVEVA'}]}, 'product_tree': {'branches': [{'name': 'AVEVA', 'branches': [{'name': 'Process Optimization', 'branches': [{'name': '<=2024.1', 'product': {'name': 'AVEVA Process Optimization: <=2024.1', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-61937', 'cwe': {'id': 'CWE-94', 'name': "Improper Control of Generation of Code ('Code Injection')"}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS System privileges of "taoimr" service, potentially resulting in complete compromise of the Model Application Server.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 10.0, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-61937', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-64691', 'cwe': {'id': 'CWE-94', 'name': "Improper Control of Generation of Code ('Code Injection')"}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with TCL Macro scripts and escalate privileges to OS System, potentially resulting in complete compromise of the Model Application Server.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-64691', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-61943', 'cwe': {'id': 'CWE-89', 'name': "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper with queries in Captive Historian and achieve code execution under SQL Server administrative privileges, potentially resulting in complete compromise of the SQL Server.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-61943', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-65118', 'cwe': {'id': 'CWE-427', 'name': 'Uncontrolled Search Path Element'}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to trick Process Optimization services into loading arbitrary code and escalate privileges to OS System, potentially resulting in complete compromise of the Model Application Server.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-65118', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-64729', 'cwe': {'id': 'CWE-862', 'name': 'Missing Authorization'}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Process Optimization project files, embed code, and escalate their privileges to the identity of a victim user who subsequently interacts with the project files.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-64729', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-65117', 'cwe': {'id': 'CWE-676', 'name': 'Use of Potentially Dangerous Function'}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Designer User) to embed OLE objects into graphics, and escalate their privileges to the identity of a victim user who subsequently interacts with the graphical elements.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-65117', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-64769', 'cwe': {'id': 'CWE-319', 'name': 'Cleartext Transmission of Sensitive Information'}, 'notes': [{'text': 'The Process Optimization application suite leverages connection channels/protocols that by-default are not encrypted and could become subject to hijacking or data leakage in certain man-in-the-Middle or passive inspection scenarios.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-64769', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-015-01 | CVE-2025-61943 | AVEVA Process Optimization | 2026-01-15 10:00:00+03:00 | 2026-01-15 10:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-015-01.json | 106e4d9641d4f167a6163e488413bf02bae3f32e9d49c4e459148b18c551d56b | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could enable an attacker to execute remote code, perform SQL injection, escalate privileges, or access sensitive information.', 'title': 'Risk evaluation', 'category': 'summary'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United Kingdom', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of this (these) vulnerability(ies), such as:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also recommends users take the following measures to protect themselves from social engineering attacks:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Do not click web links or open attachments in unsolicited email messages.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'AVEVA Process Optimization', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-015-01', 'status': 'final', 'version': '1', 'generator': {'date': '2026-01-14T22:05:05.319706Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-01-15T07:00:00.000000Z', 'number': '1', 'summary': 'Initial Republication of AVEVA-2026-001', 'legacy_version': 'Initial'}], 'current_release_date': '2026-01-15T07:00:00.000000Z', 'initial_release_date': '2026-01-15T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-015-01.json', 'summary': 'ICS Advisory ICSA-26-015-01 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-015-01', 'summary': 'ICSA Advisory ICSA-26-015-01 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/ncas/tips/ST04-014', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Christopher Wu'], 'summary': 'reported these vulnerabilities to AVEVA', 'organization': 'Veracode'}, {'summary': 'reported these vulnerabilities to CISA', 'organization': 'AVEVA'}]}, 'product_tree': {'branches': [{'name': 'AVEVA', 'branches': [{'name': 'Process Optimization', 'branches': [{'name': '<=2024.1', 'product': {'name': 'AVEVA Process Optimization: <=2024.1', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-61937', 'cwe': {'id': 'CWE-94', 'name': "Improper Control of Generation of Code ('Code Injection')"}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS System privileges of "taoimr" service, potentially resulting in complete compromise of the Model Application Server.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 10.0, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-61937', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-64691', 'cwe': {'id': 'CWE-94', 'name': "Improper Control of Generation of Code ('Code Injection')"}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with TCL Macro scripts and escalate privileges to OS System, potentially resulting in complete compromise of the Model Application Server.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-64691', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-61943', 'cwe': {'id': 'CWE-89', 'name': "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper with queries in Captive Historian and achieve code execution under SQL Server administrative privileges, potentially resulting in complete compromise of the SQL Server.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-61943', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-65118', 'cwe': {'id': 'CWE-427', 'name': 'Uncontrolled Search Path Element'}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to trick Process Optimization services into loading arbitrary code and escalate privileges to OS System, potentially resulting in complete compromise of the Model Application Server.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-65118', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-64729', 'cwe': {'id': 'CWE-862', 'name': 'Missing Authorization'}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Process Optimization project files, embed code, and escalate their privileges to the identity of a victim user who subsequently interacts with the project files.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-64729', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-65117', 'cwe': {'id': 'CWE-676', 'name': 'Use of Potentially Dangerous Function'}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Designer User) to embed OLE objects into graphics, and escalate their privileges to the identity of a victim user who subsequently interacts with the graphical elements.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-65117', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-64769', 'cwe': {'id': 'CWE-319', 'name': 'Cleartext Transmission of Sensitive Information'}, 'notes': [{'text': 'The Process Optimization application suite leverages connection channels/protocols that by-default are not encrypted and could become subject to hijacking or data leakage in certain man-in-the-Middle or passive inspection scenarios.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-64769', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-015-01 | CVE-2025-65118 | AVEVA Process Optimization | 2026-01-15 10:00:00+03:00 | 2026-01-15 10:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-015-01.json | 352ec209b54051fdaefce2dbad457407fae125835a2fa764b42f217676e979b9 | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could enable an attacker to execute remote code, perform SQL injection, escalate privileges, or access sensitive information.', 'title': 'Risk evaluation', 'category': 'summary'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United Kingdom', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of this (these) vulnerability(ies), such as:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also recommends users take the following measures to protect themselves from social engineering attacks:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Do not click web links or open attachments in unsolicited email messages.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'AVEVA Process Optimization', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-015-01', 'status': 'final', 'version': '1', 'generator': {'date': '2026-01-14T22:05:05.319706Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-01-15T07:00:00.000000Z', 'number': '1', 'summary': 'Initial Republication of AVEVA-2026-001', 'legacy_version': 'Initial'}], 'current_release_date': '2026-01-15T07:00:00.000000Z', 'initial_release_date': '2026-01-15T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-015-01.json', 'summary': 'ICS Advisory ICSA-26-015-01 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-015-01', 'summary': 'ICSA Advisory ICSA-26-015-01 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/ncas/tips/ST04-014', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Christopher Wu'], 'summary': 'reported these vulnerabilities to AVEVA', 'organization': 'Veracode'}, {'summary': 'reported these vulnerabilities to CISA', 'organization': 'AVEVA'}]}, 'product_tree': {'branches': [{'name': 'AVEVA', 'branches': [{'name': 'Process Optimization', 'branches': [{'name': '<=2024.1', 'product': {'name': 'AVEVA Process Optimization: <=2024.1', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-61937', 'cwe': {'id': 'CWE-94', 'name': "Improper Control of Generation of Code ('Code Injection')"}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS System privileges of "taoimr" service, potentially resulting in complete compromise of the Model Application Server.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 10.0, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-61937', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-64691', 'cwe': {'id': 'CWE-94', 'name': "Improper Control of Generation of Code ('Code Injection')"}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with TCL Macro scripts and escalate privileges to OS System, potentially resulting in complete compromise of the Model Application Server.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-64691', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-61943', 'cwe': {'id': 'CWE-89', 'name': "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper with queries in Captive Historian and achieve code execution under SQL Server administrative privileges, potentially resulting in complete compromise of the SQL Server.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-61943', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-65118', 'cwe': {'id': 'CWE-427', 'name': 'Uncontrolled Search Path Element'}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to trick Process Optimization services into loading arbitrary code and escalate privileges to OS System, potentially resulting in complete compromise of the Model Application Server.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-65118', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-64729', 'cwe': {'id': 'CWE-862', 'name': 'Missing Authorization'}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Process Optimization project files, embed code, and escalate their privileges to the identity of a victim user who subsequently interacts with the project files.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-64729', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-65117', 'cwe': {'id': 'CWE-676', 'name': 'Use of Potentially Dangerous Function'}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Designer User) to embed OLE objects into graphics, and escalate their privileges to the identity of a victim user who subsequently interacts with the graphical elements.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-65117', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-64769', 'cwe': {'id': 'CWE-319', 'name': 'Cleartext Transmission of Sensitive Information'}, 'notes': [{'text': 'The Process Optimization application suite leverages connection channels/protocols that by-default are not encrypted and could become subject to hijacking or data leakage in certain man-in-the-Middle or passive inspection scenarios.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-64769', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-015-01 | CVE-2025-64729 | AVEVA Process Optimization | 2026-01-15 10:00:00+03:00 | 2026-01-15 10:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-015-01.json | e3268f8a00eb1071acca385163f5ae958179f050ba23beb7f059f2b10d03882e | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could enable an attacker to execute remote code, perform SQL injection, escalate privileges, or access sensitive information.', 'title': 'Risk evaluation', 'category': 'summary'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United Kingdom', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of this (these) vulnerability(ies), such as:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also recommends users take the following measures to protect themselves from social engineering attacks:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Do not click web links or open attachments in unsolicited email messages.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'AVEVA Process Optimization', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-015-01', 'status': 'final', 'version': '1', 'generator': {'date': '2026-01-14T22:05:05.319706Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-01-15T07:00:00.000000Z', 'number': '1', 'summary': 'Initial Republication of AVEVA-2026-001', 'legacy_version': 'Initial'}], 'current_release_date': '2026-01-15T07:00:00.000000Z', 'initial_release_date': '2026-01-15T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-015-01.json', 'summary': 'ICS Advisory ICSA-26-015-01 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-015-01', 'summary': 'ICSA Advisory ICSA-26-015-01 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/ncas/tips/ST04-014', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Christopher Wu'], 'summary': 'reported these vulnerabilities to AVEVA', 'organization': 'Veracode'}, {'summary': 'reported these vulnerabilities to CISA', 'organization': 'AVEVA'}]}, 'product_tree': {'branches': [{'name': 'AVEVA', 'branches': [{'name': 'Process Optimization', 'branches': [{'name': '<=2024.1', 'product': {'name': 'AVEVA Process Optimization: <=2024.1', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-61937', 'cwe': {'id': 'CWE-94', 'name': "Improper Control of Generation of Code ('Code Injection')"}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS System privileges of "taoimr" service, potentially resulting in complete compromise of the Model Application Server.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 10.0, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-61937', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-64691', 'cwe': {'id': 'CWE-94', 'name': "Improper Control of Generation of Code ('Code Injection')"}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with TCL Macro scripts and escalate privileges to OS System, potentially resulting in complete compromise of the Model Application Server.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-64691', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-61943', 'cwe': {'id': 'CWE-89', 'name': "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper with queries in Captive Historian and achieve code execution under SQL Server administrative privileges, potentially resulting in complete compromise of the SQL Server.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-61943', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-65118', 'cwe': {'id': 'CWE-427', 'name': 'Uncontrolled Search Path Element'}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to trick Process Optimization services into loading arbitrary code and escalate privileges to OS System, potentially resulting in complete compromise of the Model Application Server.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-65118', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-64729', 'cwe': {'id': 'CWE-862', 'name': 'Missing Authorization'}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Process Optimization project files, embed code, and escalate their privileges to the identity of a victim user who subsequently interacts with the project files.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-64729', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-65117', 'cwe': {'id': 'CWE-676', 'name': 'Use of Potentially Dangerous Function'}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Designer User) to embed OLE objects into graphics, and escalate their privileges to the identity of a victim user who subsequently interacts with the graphical elements.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-65117', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-64769', 'cwe': {'id': 'CWE-319', 'name': 'Cleartext Transmission of Sensitive Information'}, 'notes': [{'text': 'The Process Optimization application suite leverages connection channels/protocols that by-default are not encrypted and could become subject to hijacking or data leakage in certain man-in-the-Middle or passive inspection scenarios.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-64769', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} | |
ot | ICSA-26-015-01 | CVE-2025-65117 | AVEVA Process Optimization | 2026-01-15 10:00:00+03:00 | 2026-01-15 10:00:00+03:00 | https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-015-01.json | fd2b5b8ea11f7953c45b31e8b2db8012d18761d1a657d14bb06f427c82a76b7d | 2026-05-29 09:17:34.767089+03:00 | 2026-06-22 22:12:32.721319+03:00 | {'document': {'lang': 'en-US', 'notes': [{'text': 'This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).', 'title': 'Legal Notice and Terms of Use', 'category': 'legal_disclaimer'}, {'text': 'Successful exploitation of these vulnerabilities could enable an attacker to execute remote code, perform SQL injection, escalate privileges, or access sensitive information.', 'title': 'Risk evaluation', 'category': 'summary'}, {'text': 'Critical Manufacturing', 'title': 'Critical infrastructure sectors', 'category': 'other'}, {'text': 'Worldwide', 'title': 'Countries/areas deployed', 'category': 'other'}, {'text': 'United Kingdom', 'title': 'Company headquarters location', 'category': 'other'}, {'text': 'CISA recommends users take defensive measures to minimize the risk of exploitation of this (these) vulnerability(ies), such as:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Locate control system networks and remote devices behind firewalls and isolating them from business networks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'CISA also recommends users take the following measures to protect themselves from social engineering attacks:', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Do not click web links or open attachments in unsolicited email messages.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.', 'title': 'Recommended Practices', 'category': 'general'}, {'text': 'No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.', 'title': 'Recommended Practices', 'category': 'general'}], 'title': 'AVEVA Process Optimization', 'category': 'csaf_security_advisory', 'tracking': {'id': 'ICSA-26-015-01', 'status': 'final', 'version': '1', 'generator': {'date': '2026-01-14T22:05:05.319706Z', 'engine': {'name': 'CISA CSAF Generator', 'version': '1.0.0'}}, 'revision_history': [{'date': '2026-01-15T07:00:00.000000Z', 'number': '1', 'summary': 'Initial Republication of AVEVA-2026-001', 'legacy_version': 'Initial'}], 'current_release_date': '2026-01-15T07:00:00.000000Z', 'initial_release_date': '2026-01-15T07:00:00.000000Z'}, 'publisher': {'name': 'CISA', 'category': 'coordinator', 'namespace': 'https://www.cisa.gov/', 'contact_details': 'central@cisa.dhs.gov'}, 'references': [{'url': 'https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-015-01.json', 'summary': 'ICS Advisory ICSA-26-015-01 JSON', 'category': 'self'}, {'url': 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-015-01', 'summary': 'ICSA Advisory ICSA-26-015-01 - Web Version', 'category': 'self'}, {'url': 'https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/resources-tools/resources/ics-recommended-practices', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/topics/industrial-control-systems', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/uscert/ncas/tips/ST04-014', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/secure-our-world/teach-employees-avoid-phishing', 'summary': 'Recommended Practices', 'category': 'external'}, {'url': 'https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks', 'summary': 'Recommended Practices', 'category': 'external'}], 'csaf_version': '2.0', 'distribution': {'tlp': {'url': 'https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage', 'label': 'WHITE'}, 'text': 'Disclosure is not limited'}, 'acknowledgments': [{'names': ['Christopher Wu'], 'summary': 'reported these vulnerabilities to AVEVA', 'organization': 'Veracode'}, {'summary': 'reported these vulnerabilities to CISA', 'organization': 'AVEVA'}]}, 'product_tree': {'branches': [{'name': 'AVEVA', 'branches': [{'name': 'Process Optimization', 'branches': [{'name': '<=2024.1', 'product': {'name': 'AVEVA Process Optimization: <=2024.1', 'product_id': 'CSAFPID-0001'}, 'category': 'product_version_range'}], 'category': 'product_name'}], 'category': 'vendor'}]}, 'vulnerabilities': [{'cve': 'CVE-2025-61937', 'cwe': {'id': 'CWE-94', 'name': "Improper Control of Generation of Code ('Code Injection')"}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS System privileges of "taoimr" service, potentially resulting in complete compromise of the Model Application Server.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 10.0, 'baseSeverity': 'CRITICAL', 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-61937', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-64691', 'cwe': {'id': 'CWE-94', 'name': "Improper Control of Generation of Code ('Code Injection')"}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with TCL Macro scripts and escalate privileges to OS System, potentially resulting in complete compromise of the Model Application Server.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-64691', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-61943', 'cwe': {'id': 'CWE-89', 'name': "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper with queries in Captive Historian and achieve code execution under SQL Server administrative privileges, potentially resulting in complete compromise of the SQL Server.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-61943', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-65118', 'cwe': {'id': 'CWE-427', 'name': 'Uncontrolled Search Path Element'}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to trick Process Optimization services into loading arbitrary code and escalate privileges to OS System, potentially resulting in complete compromise of the Model Application Server.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.8, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-65118', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-64729', 'cwe': {'id': 'CWE-862', 'name': 'Missing Authorization'}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Process Optimization project files, embed code, and escalate their privileges to the identity of a victim user who subsequently interacts with the project files.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 8.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-64729', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-65117', 'cwe': {'id': 'CWE-676', 'name': 'Use of Potentially Dangerous Function'}, 'notes': [{'text': 'The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Designer User) to embed OLE objects into graphics, and escalate their privileges to the identity of a victim user who subsequently interacts with the graphical elements.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.4, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-65117', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}, {'cve': 'CVE-2025-64769', 'cwe': {'id': 'CWE-319', 'name': 'Cleartext Transmission of Sensitive Information'}, 'notes': [{'text': 'The Process Optimization application suite leverages connection channels/protocols that by-default are not encrypted and could become subject to hijacking or data leakage in certain man-in-the-Middle or passive inspection scenarios.', 'title': 'Vulnerability Summary', 'category': 'summary'}], 'scores': [{'cvss_v3': {'version': '3.1', 'baseScore': 7.1, 'baseSeverity': 'HIGH', 'vectorString': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L'}, 'products': ['CSAFPID-0001']}], 'references': [{'url': 'https://www.cve.org/CVERecord?id=CVE-2025-64769', 'summary': 'www.cve.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L', 'summary': 'www.first.org', 'category': 'external'}, {'url': 'https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N', 'summary': 'www.first.org', 'category': 'external'}], 'remediations': [{'details': 'AVEVA recommends users take the following action:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea', 'details': 'Update to AVEVA Process Optimization v2025', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'AVEVA alternatively recommends the following actions users can take to mitigate risk:', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply Host and/or Network firewall rules restricting the taoimr service to accept traffic only from trusted source(s). By default, AVEVA Process Optimization listens on port 8888/8889(TLS). Please refer to the AVEVA Process Optimization Installation Guide for additional details on ports configuration.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'details': 'Apply ACLs to the installation and data folders, limiting write-access to trusted users only.', 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}, {'details': 'Maintain a trusted chain-of-custody on Process Optimization project files during creation, modification, distribution, backups, and use.', 'category': 'vendor_fix', 'product_ids': ['CSAFPID-0001']}, {'url': 'https://www.aveva.com/en/support-and-success/cyber-security-updates/', 'details': "For more information, please Aveva's security bulletin AVEVA-2026-001.", 'category': 'mitigation', 'product_ids': ['CSAFPID-0001']}], 'product_status': {'known_affected': ['CSAFPID-0001']}}]} |