Schneider Electric security advisory (AV26-912)
Schneider Electric's industrial control systems, used in power plants, factories, and data centers, have flaws that could let attackers take control of equipment or cause crashes. These flaws affect older versions of EcoStruxure IT Data Center Expert and PowerLogic T300.
- Severity
- Not scoredNo CVSS score recorded
- Fix
- Fixed in 9.1.3
- Exploited
- Not confirmedNo confirmation recorded
How it works
- Attackers can send specially crafted requests to Schneider Electric's EcoStruxure IT Data Center Expert (versions 9.1.2 and earlier) or PowerLogic T300 (versions 2.9.8-5620 and earlier).
- These requests can crash the software or let attackers run commands on the system they control.
- The flaws happen when the software does not properly check or handle certain inputs sent over the network.
What to do
If you run Schneider Electric's EcoStruxure IT Data Center Expert version 9.1.2 or earlier, check your installed version by opening the software and looking for the About or Version menu. If you run PowerLogic T300 version 2.9.8-5620 or earlier, check the software's settings or version screen for the version number. Compare it against the advisory to see if you need to update.
Update EcoStruxure IT Data Center Expert to version 9.1.3 or later, and update PowerLogic T300 to version 2.9.9 or later. Check Schneider Electric's official advisory for detailed update instructions. After updating, verify the new version number to confirm the fix is applied.
Technical details
Schneider Electric disclosed two critical vulnerabilities affecting their industrial control systems. In EcoStruxure IT Data Center Expert (formerly StruxureWare Data Center Expert), versions 9.1.2 and earlier contain unspecified flaws that could allow remote attackers to execute arbitrary code or gain elevated privileges, potentially compromising system integrity. The PowerLogic T300 firmware, versions 2.9.8-5620 and earlier, suffers from a similar issue where attackers may bypass authentication or manipulate device configurations, leading to unauthorized access or operational disruption.
No CVSS score or CVE ID was assigned in this advisory. The vendor advises immediate updates to mitigate risks.
References
- download.se.com · files CCCS Canada
- se.com · security-notifications.jsp CCCS Canada