HomeSecurityNew patch for Schneider Electric's Wonderware System Platform

New patch for Schneider Electric's Wonderware System Platform

Schneider Electric

A vulnerability has been identified in certain versions of Wonderware System Platform, developed by Schneider Electric, and has been classified as high risk. Based on the initial report on the issue, an attacker could exploit the issue to execute malicious script on the affected computer.

Based on the CVSS (Common Vulnerability Scoring System), the severity score of the vulnerability is 7.2, with a maximum of 10. The vulnerability was also detected in all versions, except for the latest, 2014 R2 patch 01, which was recently released by Schneider Electric developers.

Wonderware System Platformis a software product intended for industrial environments. It is an operating system that combines functions and services aimed at creating a central unit for managing various processes, physical equipment and systems in facilities, as well as helping administrators diagnose and resolve problems that arise.

The glitch, which was found in InTouch, Application Server, Historian, and SuiteLink, has been described as DLL hijacking. It does not require authentication for access, and the impact on the system is total.

However, they cannot be exploited remotely, and as with DLL hijacking, user interaction is required, which helps reduce the severity of the issue. This means that the attacker must trick the system user into executing a file to replace the original DLL with the malicious one. This is not impossible to achieve, but the threat actor must carefully plan the attack and resort to social engineering tactics to deceive the victim without raising any suspicion. While this is not impossible to do, the attacker must use sophisticated social engineering tactics to deceive the victim and run the malicious script, as Schneider Electric informs.

The update for the operating system is distributed as an ISO that can be burned to a DVD or mounted as a virtual drive. Schneider Electric warns that installed Wonderware System Platform 2014 and earlier systems must first be updated with the 2014 R2 patch and then apply the new available update.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS