The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Lexium ILE ILA ILS communication drive version 01.110 and prior
- Schneider Electric Altivar 32/320/340/600/900 Profinet communication module (VW3A3627)
- Schneider Electric Altivar 32/320 and Lexium 32 Ethernet TCP/IP communication module (VW3A3616) versions prior to V1.20IE01
- Schneider Electric Altivar 61/71 Profinet communication card (VW3A3327) All versions
- Summary
- Five of the 14 vulnerabilities disclosed by researchers in the NicheStack TCP/IP component impact Schneider Electric’s Lexium ILE, ILA, ILS, Altivar Profinet Communication Module (VW3A3627), Altivar and Lexium Ethernet TCP/IP Communication Module (VW3A3616), and Altivar Profinet - Communication Card (VW3A3327). Additional information vulnerability details can be found at https://us-cert.cisa.gov/ics/advisories/icsa-21-217-01.
- Remediation
- V01.111 of Lexium ILE, ILA, ILS communication module includes a fix for these vulnerabilities. Reboot is needed. Please contact your local Schneider Electric technical support for more information on how to get the firmware and how to upgrade the communication firmware module.
