SEVD-2022-221-01: EcoStruxure Control Expert and Modicon Controller Vulnerability
This document details a critical vulnerability (CVE-2022-37300) in Schneider Electric's EcoStruxure Control Expert, Process Expert, and Modicon M580/M340 controllers, which could allow unauthorized access and arbitrary code execution via a weak password recovery mechanism. It provides specific firmware and software remediation versions for affected products, along with mitigations such as network segmentation, application passwords, and IPSEC configuration for customers who cannot immediately patch.
Failed to load PDF
Download insteadYou might also like
DEGB Electronic Light Transmitter Installation Guide
2 pages
SpaceLogic SLP Series Multisensor Platform Specification Sheet
4 pages
SecurityExpert–KONE Elevator Integration Guide
2 pages
EcoFit Life Extension Advanced for Sepam 2000 Protection Relays
2 pages
Modena 800 Series Double Metal Mounting Brackets Datasheet
1 pages
SpaceLogic VB601R Valve and MB10 Actuator Specification Sheet
4 pages
TAC I/A Series MicroNet MN 800 Controller Specifications
4 pages
Satchwell UNC 296 Universal Network Controller Specification
4 pages
SP-ACX Security Purpose ACX Controller Datasheet
5 pages
EcoStruxure OPC UA Server Expert and Modicon Communication Server XXE Vulnerability Security Notification
4 pages