SEVD-2022-221-01: EcoStruxure Control Expert and Modicon Controller Vulnerability
This document details a critical vulnerability (CVE-2022-37300) in Schneider Electric's EcoStruxure Control Expert, Process Expert, and Modicon M580/M340 controllers, which could allow unauthorized access and arbitrary code execution via a weak password recovery mechanism. It provides specific firmware and software remediation versions for affected products, along with mitigations such as network segmentation, application passwords, and IPSEC configuration for customers who cannot immediately patch.
Failed to load PDF
Download insteadYou might also like
Modicon TM3 Digital I/O Modules Hardware Guide
164 pages
Galaxy VM Battery Cabinet Runtime Tables
5 pages
H11D-S6 Over-Current and Under-Current Monitor Manual
5 pages
SpaceLogic AS-P Automation Server Introduction and Feature Overview
11 pages
Condensation Protection for Electrical Control Panels Technical Guide
12 pages
PowerLogic ION8800 Series Revenue and Power Quality Meter Datasheet
10 pages
STT900 Series Mechanical Frost Thermostat Specification Sheet
3 pages
Acti9 iID B-SI RCCB for Industrial Speed Drive Protection Customer Story
2 pages
APC Charge Mobile Power Supply for Surface Hub 2 Safety Data Sheet
16 pages
BVA Series V-Shaped Control Ball Valve Specification Sheet
6 pages