QID 590667
Date Published: 2022-02-14
QID 590667: Schneider Electric NMC cards and Embedded Devices Multiple Vulnerabilities (ICSA-21-313-01)
AFFECTED PRODUCTS
1-Phase Uninterruptible Power Supply (UPS) using NMC2, including Smart-UPS, Symmetra, and Galaxy 3500 with Network Management Card 2 (NMC2): NMC2 AOS v6.9.8 and prior
3-Phase Uninterruptible Power Supply (UPS) using NMC2, including Symmetra PX 250/500 (SYPX) Network Management Card 2 (NMC2): NMC2 AOS v6.9.6 and prior
3-Phase Uninterruptible Power Supply (UPS) using NMC2 including Symmetra PX 48/96/100/160 kW UPS (PX2), Symmetra PX 20/40 kW UPS (SY3P), Gutor (SXW, GVX), and Galaxy (GVMTS, GVMSA, GVXTS, GVXSA, G7K, GFC, G9KCHU): NMC2 AOS v6.9.6 and prior
1-Phase Uninterruptible Power Supply (UPS) using NMC3 including Smart-UPS, Symmetra, and Galaxy 3500 with Network Management Card 3 (NMC3): NMC3 AOS v1.4.2.1 and prior
APC Rack Power Distribution Units (PDU) using NMC2: NMC2 AOS v6.9.6 and prior
APC Rack Power Distribution Units (PDU) using NMC3: NMC3 AOS v1.4.0 and prior
APC 3-Phase Power Distribution Products using NMC2: NMC2 AOS v6.9.6 and prior
Network Management Card 2 (NMC2) for InfraStruxure 150 kVA PDU with 84 Poles (X84P): NMC2 AOS v6.9.6 and prior
Network Management Card 2 for InfraStruxure 40/60kVA PDU (XPDU): NMC2 AOS v6.9.6 and prior
Network Management Card 2 for Modular 150/175kVA PDU (XRDP): NMC2 AOS v6.9.6 and prior
Network Management Card 2 for 400 and 500 kVA (PMM): NMC2 AOS v6.9.6 and prior
Network Management Card 2 for Modular PDU (XRDP2G): NMC2 AOS v6.9.6 and prior
Rack Automatic Transfer Switches (ATS): NMC2 AOS v6.9.6 and prior
Environmental Monitoring Unit with embedded NMC2 (NB250) NetBotz NBRK0250: NMC2 AOS v6.9.6 and prior
Network Management Card 2 (NMC2) Cooling Products: NMC2 AOS v6.9.6 and prior
Network Management Card 2 (NMC2) AP9922 Battery Management System (BM4): NMC2 AOS v6.9.6 and prior
QID Detection Logic (Authenticated):
The QID checks for the Vulnerable version of using passive scanning
Successful exploitation of these vulnerabilities may allow data disclosure or cross-site scripting, which could result in an execution of malicious web code or a loss of device functionality.
Customers are advised to refer to CERT MITIGATIONS section ICSA-21-313-01 for affected packages and patching details.
- ICSA-21-313-01 -
www.us-cert.gov/ics/advisories/ICSA-21-313-01
CVEs related to QID 590667
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-21-313-01 |
|