SEVD-2022-221-01: EcoStruxure Control Expert and Modicon Controller Vulnerability
This document details a critical vulnerability (CVE-2022-37300) in Schneider Electric's EcoStruxure Control Expert, Process Expert, and Modicon M580/M340 controllers, which could allow unauthorized access and arbitrary code execution via a weak password recovery mechanism. It provides specific firmware and software remediation versions for affected products, along with mitigations such as network segmentation, application passwords, and IPSEC configuration for customers who cannot immediately patch.
Failed to load PDF
Download insteadYou might also like
Easy UPS 3S Technical Specifications
70 pages
Intelligent Building Management Systems (iBMS) Overview
1 pages
644N and 644Z 4-Gang Horizontal Switched Socket Datasheet
2 pages
SmartStruxure WebStation User Guide
3 pages
PowerTag Control Wireless I/O Module Datasheet
5 pages
Phaseo to Modicon Optimized Power Supply Migration Guide
12 pages
Satchwell Keyboard 700 MPD Multi-point Display Module Data Sheet and Installation Guide
4 pages
TAC 2000 Air Handling Controllers Data Sheet
8 pages
Satchwell CXR Mark 4 Reset Controller Installation Guide
6 pages
Vigilohm Insulation Monitoring Devices Technical Datasheet
8 pages