QID 591430
Date Published: 2024-04-03
QID 591430: Schneider Electric EcoStruxure IT Gateway Multiple Vulnerabilities (SEVD-2024-044-03)
AFFECTED PRODUCTS
Schneider Electric reports the vulnerability affects the following EcoStruxure IT Gateway versions:
versions 1.20.x and prior
CISA will update this document as more mitigations are identified by affected vendors.
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning.
Successful exploitation of this vulnerability by using the hard-coded credentials vulnerability exists that could cause local privilege escalation when logged in as a non-administrative user.
Solution
Customers are advised to refer to CERT MITIGATIONS section SEVD-2024-044-03 for affected packages and patching details.
Vendor References
- SEVD-2024-044-03 -
download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-044-03
CVEs related to QID 591430
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SEVD-2024-044-03 |
|