QID 590763

Date Published: 2022-12-09

QID 590763: Schneider Electric EcoStruxure Machine Expert Multiple Vulnerabilities (SEVD-2022-011-06)

Affected Products
Eurotherm E+PLC100 All Versions
Eurotherm E+PLC400 1.3.0.1 and prior
Eurotherm E+PLC tools 1.3.0.1 and prior
M241/M251Version prior to 5.1.9.34

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successfully exploited these vulnerabilities could result in denial of service or in some cases remote code execution.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to refer to Schneider Electric section SEVD-2022-011-06 for affected packages and patching details.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    SEVD-2022-011-06 URL Logo download.schneider-electric.com/files?p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-011-06_CODESYSV3_Runtime_Development_System_and_Gateway_Security_Notification.pdf