news.mlab.sh
Back to the feed
vulnerability

Schneider Electric EcoStruxure Panel Server

High
Summary

Schneider Electric has identified a vulnerability in its EcoStruxure Panel Server product line, specifically versions prior to 002.006.000. This vulnerability, classified as CWE-1188, allows for potential unauthorized authentication and disclosure of sensitive information if default settings are utilized. Schneider Electric has released a firmware update to address this issue, requiring a reboot of affected systems.

This security advisory details a critical vulnerability affecting Schneider Electric’s EcoStruxure Panel Server, a gateway used in commercial facilities, critical manufacturing, and energy sectors. The vulnerability, identified as CWE-1188 – Initialization of a Resource with an Insecure Default – stems from the potential for unauthorized access if default credentials are used. This could allow an attacker to gain control of the server and access sensitive data. Schneider Electric has released a firmware update (version 002.006.000) to mitigate this risk, and immediate action is advised.

Read the full article at CISA Advisories