50% (81) 451 views 7 pages

SEVD-2022-221-01: EcoStruxure Control Expert and Modicon Controller Vulnerability

AI-enhanced description

This document details a critical vulnerability (CVE-2022-37300) in Schneider Electric's EcoStruxure Control Expert, Process Expert, and Modicon M580/M340 controllers, which could allow unauthorized access and arbitrary code execution via a weak password recovery mechanism. It provides specific firmware and software remediation versions for affected products, along with mitigations such as network segmentation, application passwords, and IPSEC configuration for customers who cannot immediately patch.

Uploaded by Charlotte_744
Download
/ 7
Loading document…