Schneider Electric Wonderware System Platform Vulnerability
Schneider Electric Wonderware System Platform Vulnerability
Release date:
Updated on:
Affected Systems:
Schneider Electric Wonderware System Platform <= 2014 R2
Description:
CVE (CAN) ID: CVE-2015-3940
Wonderware System Platform is a System Platform applied in multiple fields.
Schneider Electric's Wonderware InTouch, Application Server, Historian, and SuiteLink applications have a fixed Search Path Vulnerability. Successful exploitation of this vulnerability allows attackers to install and execute malicious code.
<* Source: Ivan Sanchez
Link: https://ics-cert.us-cert.gov/advisories/ICSA-15-169-02
*>
Suggestion:
Vendor patch:
Schneider Electric
------------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://gcsresource.invensys.com/tracking/ConfirmDownload.aspx? Id = 21913
Http://software.schneider-electric.com/support/cyber-security-updates/
This article permanently updates the link address: