The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Easergy T300 <2.8.2
- Schneider Electric PACiS GTW <5.2
- Schneider Electric Saitel DP <=11.06.21
- Schneider Electric Saitel DR <=11.06.12
- Schneider Electric Talus T4e RTU <A18
- Schneider Electric Talus T4c RTU <A19.08
- Schneider Electric SCADAPack E <8.18.1
- Schneider Electric SCADAPack Workbench <6.6.8
- Schneider Electric SAGE RTU - C3414 CPU <C3414-500-S02K5_P5
- Schneider Electric SAGE RTU - C3413 CPU C3412 CPU All Firmware Versions
- Schneider Electric SCD2200 <=10024
- Rockwell Automation ISaGRAF Runtime Versions 5.2 and prior default component of Schneider Electric Easergy C5 Versions up to 1.0.x
- Summary
- ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communication protocol provides various file system operations, as well as the uploading of applications. Data is transferred over this protocol unencrypted, which could allow a remote unauthenticated attacker to upload, read, and delete files.
- Remediation
- Customers should upgrade to the firmware V9.1.0 or later (14942), which incorporates ISaGRAF Workbench V6.6.9. Notification of firmware release can be found here: https://secommunities.force.com/PAkb/s/article/CCN000244525 A reboot is required when upgrading to new firmware. No user actions are required to apply the remediation beyond upgrading the firmware in the RTU.
