SB2021071414 - Multiple vulnerabilities in Schneider Electric SCADApack RTU, Modicon Controllers and Software



SB2021071414 - Multiple vulnerabilities in Schneider Electric SCADApack RTU, Modicon Controllers and Software

Published: July 14, 2021 Updated: June 2, 2022

Security Bulletin ID SB2021071414
Severity
High
Patch available
YES
Number of vulnerabilities 4
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 25% Medium 75%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 4 secuirty vulnerabilities.


1) Insufficiently protected credentials (CVE-ID: CVE-2021-22778)

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to insufficiently protected credentials. A remote attacker can use a specially crafted project file and read protected derived function blocks.


2) Insufficiently protected credentials (CVE-ID: CVE-2021-22780)

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to insufficiently protected credentials. A remote authenticated attacker can gain unauthorized access to a project file protected by a password when this file is shared with untrusted sources and view and modify a project file.


3) Insufficiently protected credentials (CVE-ID: CVE-2021-22781)

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to insufficiently protected credentials. A remote attacker can access a project file and cause a leak of SMTP credentials.


4) Missing Encryption of Sensitive Data (CVE-ID: CVE-2021-22782)

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to a missing encryption of sensitive data issue. A remote attacker can access a project file and cause an information leak allowing disclosure of network and process information, credentials, or intellectual property.


Remediation

Install update from vendor's website.