QID 590820

Date Published: 2022-07-18

QID 590820: Schneider Electric Wind River VxWorks (URGENT/11) Vulnerability (SESB-2019-214-01)

ConneXium Industrial Firewall/ Router TCSEFEC2CF3F21 (MM/TX) TCSEFEC23FCF21 (TX/MM) TCSEFEC23F3F21 (TX/TX)V5.33 and prior ConneXium Industrial Firewall TCSEFEC2CF3F20 (MM/TX) TCSEFEC23FCF20 (TX/MM) TCSEFEC23F3F20 (TX/TX) V5.24 and prior
E+PLC100 Combination PLC 1.2.0.4 firmware version and prior
E+PLC400 Combination PLC 1.2.0.4 firmware version and prior
HMIGXU V1.1.0.32 and prior
Magelis HMI - HMIGTO Series, HMISCU Series, HMIGTUX Series, and HMIGTU Series (Except Open BOX)Vijeo Designer V6.2SP9 and prior
Modicon X80 I/O modules: Modicon X80 BMEAHI0812 HART Analog Input Module Modicon X80 BMEAHO0412 HART Analog Output Module Modicon Network Option Switch BMENOS0300 (C)I/O Drop Adapters BMXCRA31200,BMXCRA31210(C),BMECRA31210(C)
Modicon LMC078 Controller V1.51.15.05 and prior
Modicon M241 Micro PLC Firmware versions prior to V5.1.9.14
Modicon M251 Micro PLC Firmware versions prior to V5.1.9.14
Modicon M262 Logic/Motion ControllerFirmware V5.0.3.2 and prior
Modicon M580 Ethernet Communications Modules Modicon M580 Ethernet Communications Modules: BMENOC0301 BMENOC0311 BMENOC0321
Modicon M580 Ethernet communications ModulesModicon M580 IEC 61850 - BMENOP0300 (C)V2.1 and prior
Modicon M580 ePAC CPUs including Safety CPUs M580 V2.90 and prior
Modicon MC80 Programmable Logic Controller V1.4 and prior
Modicon Momentum Unity V2.01 and prior
Modicon Quantum Ethernet DIO network module - 140NOC78x00 (C) All versions
Modicon Quantum 140 CRA V2.40 and prior
Modicon Quantum Head 140 CRP module - 140CRP31200 (C)All versions
Modicon Quantum 140 NOP Communications Module All versions
Nanodac Recorder / Controller V8.14 and prior
PacDrive 3 Eco/Pro/Pro2 Motion Controllers V1.62.5.6 and prior
Pro-face HMI -GP4000H/R/E Series, GP4100 Compact Series, LT4000M Modular Series, GP4000E Series, IoT Gateway, SP5000 Series, and SP5000X Series GP-ProEX V4.09.100 and prior (HMI version is dependent on using GP-Pro EX version)
SCADAPack 53xE RTUs V8.14.7 and prior
SCADAPack 57x RTUs V9.2.3 and earlier
SCD6000 Industrial RTUV7.0.34 SY1101207G17 and prior
Tricon Communication Modules TCM/TCM2 V11.1 V11.4
Trident Communication Integration Module V3.0
versadac Scalable Data RecorderV2.37 firmware version and prior
Easergy MiCOM C264
Easergy MiCOM P30
Easergy MiCOM Px40
Easergy P5
Easergy T300 (SC150 and LV150)
ION7400
ION7400 MID(METSEION74001)
ION9000
PM8000
PM8000 MID (METSEPM82401)
SAGE RTU
Saitel DR with HU_A CPU
TeSys island

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Wind River VxWorks TCP/IP Stack vulnerabilities have wide-ranging impact across multiple IT and industrial applications. We are working closely with Wind River to understand and assess how these vulnerabilities impact Schneider Electric offers and our customers operations. We downloaded Wind Rivers patches as soon as they were made available to us, and we have quickly instituted a remediation plan to evolve all current and future products that rely on the Wind River platform to embed these fixes

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 4.4 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section SESB-2019-214-01 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590820

    Software Advisories
    Advisory ID Software Component Link
    SESB-2019-214-01 URL Logo www.se.com/ww/en/download/document/SESB-2019-214-01/

    © CVE.report 2026

    Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

    CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

    Free CVE JSON API cve.report/api

    CVE.report and Source URL Uptime Status status.cve.report