The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric ATV340E Altivar Machine Drives prior to 3.2IE25
- Schneider Electric ATV630/650/660/680/6A0/6B0 Altivar Process Drives prior to 3.3IE33
- Schneider Electric ATV930/950/960/980/9A0/9B0 Altivar Process Drives prior to V3.3IE26
- Schneider Electric ATV6000 Medium Voltage Altivar Process Drives prior to V1.6IE01
- Schneider Electric SCADAPack 32 RTU prior to V2.25
- Schneider Electric TM3BC bus coupler module – EIP prior to V2.2.1.1
- Schneider Electric TM3BC bus coupler module - SL prior to V2.1.1.1
- Schneider Electric TM3BC bus coupler module - CANOpen prior to V2.1.1.1
- Schneider Electric VW3A3310 Altivar 61/71 Modbus TCP option version 2.1IE09 and prior
- Schneider Electric VW3A3310D Altivar 61/71 Ethernet daisy chain option Version 3.0IE11 and prior
- Schneider Electric VW3A3320 Altivar 61/71 Ethernet IP RSTP option version V1.1IE19 and prior
- Schneider Electric VW3A3320 Altivar 61/71 Ethernet IP option Version V1.2IE14 and prior
- Summary
- Additional details on these specific vulnerabilities can be found on the ICS-CERT Advisory at https://www.us-cert.gov/ics/advisories/ICSA-20-168-01.
- Remediation
- A fix is now available in product releases V3.2IE25 and above. For product release prior to V3.2IE25, apply the mitigations detailed in the Recommended Mitigations section and contact your local technical support for more information.
