QID 590893
Date Published: 2022-06-30
QID 590893: Schneider Electric Tricon Model MP3008 Vulnerability (SEVD-2017-347-01)
AFFECTED PRODUCTS
Tricon Model MP3008, versions 10.0 - 10.4
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
The malware requires unrestricted access to the safety network via remote network or physical access. Additionally, the malware requires the Tricon key switch to be in the PROGRAM mode to successfully deploy its payload. The malware has the capability to scan and map the industrial control system to provide reconnaissance and issue commands to Tricon controllers. Once deployed, this type of malware, known as a Remotely Accessible Trojan (RAT), controls a system via a remote network connection as if by physical access.
Customers are advised to refer to Vendor MITIGATIONS section SEVD-2017-347-01 for affected packages and patching details.
- SEVD-2017-347-01 -
www.se.com/ww/en/download/document/SEVD-2017-347-01/
CVEs related to QID 590893
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SEVD-2017-347-01 |
|