QID 590828
Date Published: 2022-06-23
QID 590828: Schneider Electric Trio J-Series Radio Encryption Key Vulnerability (SEVD-2013-143-01)
Product Affected
The following products are affected by the Trio J-Series Radio Encryption Key vulnerability:
TBURJR900-00002DH0,TBURJR900-01002DH0,TBURJR900-05002DH0,TBURJR900-06002DH0,TBURJR900-00002EH0,TBURJR900-01002EH0,TBURJR900-05002EH0,TBURJR900-06002EH0
Running Firmware Versions V3.6.0, V3.6.1, V3.6.2 and V3.6.3
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
Trio J-Series Radio Firmware Versions V3.6.0, V3.6.1, V3.6.2 and V3.6.3 do not correctly generate an AES encryption key when AES encryption is enabled in the device configuration.
Solution
Customers are advised to refer to CERT MITIGATIONS section SEVD-2013-143-01 for affected packages and patching details.
Vendor References
- SEVD 2013-143-01 -
www.se.com/in/en/download/document/SEVD%202013-143-01/
CVEs related to QID 590828
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SEVD-2013-143-01 |
|