HomeSecuritySchneider Electric released a patch for its digital programs

Schneider Electric releases patch for its digital programs

Schneider Electric

Various ICS digital application software products from Schneider Electric have been updated by the company for a buffer overflow vulnerability.

Initially, the problem was reported in the SoMove Lite software package, but after a closer examination of the issue, it was found that all versions of Unity Pro software (software development for control, debugging and application management), SoMachine (software environment for developing, configuring and operating automation) and SoMove (software for controlling motorized devices) are affected in the same way.

The issue was found in a DLL file that is in a DTM (Device Type Manager). When the DTM is set up and configured, the problematic DLL is also included in the management system, making it vulnerable.

According to the report from ICS-CERT (Industrial Control Systems Cyber ​​Emergency Response Team), an attacker could exploit this vulnerability and execute a script on the system. This could also be done from a remote machine.

The bug, discovered by Ariele Caltabiano, is designated CVE-2014-9200. It has a severity rating of 7.5, given that it can be remotely affected and does not require special skills from someone who would want to exploit the problem.

ICS-CERT says that at this time, there is no evidence that the flaw has been exploited by anyone to damage a project. Schneider Electric has been quick to fix the problem and has immediately released a patch update so that the company's customers are not at risk.

 

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS