The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric EcoStruxure™ Control Expert <=V15.0 SP1
- Schneider Electric EcoStruxure™ Process Expert <V2021
- Schneider Electric SCADAPack RemoteConnect™ for x70 <R2.7.3
- Summary
- A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause a disruption of communication between the Modicon controller and the engineering software, when an attacker is able to intercept and manipulate specific Modbus response data.
- Remediation
- Version 15.1 of EcoStruxure™ Control Expert includes a fix for these vulnerabilities and is available for download here: https://www.se.com/ww/en/download/document/EcoStruxureControlExpert_V15.1/ Customers using Unity Pro should strongly consider migrating to EcoStruxure™ Control Expert. If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit: To mitigate the risks associated to Modbus weaknesses, users should immediately: • Setup network segmentation and implement a firewall to block all unauthorized access to port 502/TCP
