Release date:
Updated on:
Affected Systems:
Schneider Electric SCADAPack 35x
Schneider Electric SCADAPack 33x
Description:
--------------------------------------------------------------------------------
Schneider Electric Group provides products and services for energy and infrastructure, industry, data centers and networks, buildings and residential areas.
Because Schneider Electric SCADAPack 330,334,350,357 has a security vulnerability that enables the VxWorks debugging proxy, remote attackers can exploit this vulnerability to control affected devices by sending specially crafted requests to UDP port 17185.
<* Source: vendor
Link: http://secunia.com/advisories/56811/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Schneider Electric
------------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.schneider-electric.com/sites/corporate/en/support/cybersecurity/cyber-security-vulnerabil
Http://download.schneider-electric.com/files? P_Doc_Ref = SEVD % 202013-345-01