QID 591059

Date Published: 2022-09-27

QID 591059: Emerson Proficy Machine Edition Multiple Vulnerabilities (ICSA-22-228-06)

AFFECTED PRODUCTS
The following versions of Proficy Machine Edition, an engineering workstation that is part of the PACSystems control system software platform, are affected: Proficy Machine Edition Version 9.80 and prior

QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys

Successful exploitation of these vulnerabilities could allow for remote hidden code execution on the connected programmable logic controller (PLC) and for malicious files to be uploaded from the PLC to connected workstations.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Low - 0 severity.
  • Solution

    Customers are advised to refer to Schneider Electric MITIGATIONS section icsa-22-228-06 for affected packages and patching details.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link