The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric EcoStruxure™ Control Expert <15.1 HF001
- Schneider Electric EcoStruxure™ Process Expert <2021
- Schneider Electric SCADAPack RemoteConnect™ for x70 <R2.7.3
- Summary
- The vulnerabilities reported on XDemill and XMilI are triggered through the execution of a malicious script on the engineering workstation, or when loading a specially crafted project file into the engineering tool. The successful exploitation of these vulnerabilities may lead to code execution with elevated privileges on the engineering workstation.
- Remediation
- V15.1 HF001 of EcoStruxure™ Control Expert includes a fix for these vulnerabilities and is available for download here: https://www.se.com/ww/en/download/document/ControlExpert_V151_HF001/ If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: • Store the project files in a secure storage and restrict the access to only trusted users • When exchanging files over the network, use secure communication channels • Only open project files received from a trusted source • Compute a hash of the project files and regularly check the consistency of this hash to verify the integrity before usage • Harden the workstation running EcoStruxure Control Expert or Unity Pro • Customers using Unity Pro should strongly consider migrating to EcoStruxure Control Expert.
