QID 590829
Date Published: 2022-06-30
QID 590829: Schneider Electric SCADAPack 330, SCADAPack 334, SCADAPack 350, and SCADAPack 357 Firmware Vulnerability (SEVD 2013-345-01)
Details on Products Affected
The following product firmware versions are affected:
SCADAPack 33x firmware 1.71 or earlier
SCADAPack 35x firmware 1.71 or earlier
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
UDP port 17185 is open by default. This open debug port could be exploited by an attacker to facilitate a denial-of-service attack, or in some cases even fully compromise the device.There is no evidence that this vulnerability has been exploited.
Solution
Customers are advised to refer to CERT MITIGATIONS section SEVD-2013-345-01 for affected packages and patching details.
Vendor References
- SEVD-2013-345-01 -
www.se.com/in/en/download/document/SEVD%202013-345-01/
CVEs related to QID 590829
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SEVD-2013-345-01 |
|