CERT-In Advisory
CIAD-2023-0046
Multiple Vulnerabilities in Schneider Electric Products
Original Issue Date: December 14, 2023
Severity Rating: High
Software Affected
- Trio Q-Series Ethernet Data Radio
- Trio E-Series Ethernet Data Radio
- Trio J-Series Ethernet Data Radio
- Easy UPS Online Monitoring Software
- ION8650, ION8800
- Plant iT/Brewmaxx
Overview
Multiple vulnerabilities have been reported in Schneider Electric Products which could allow an attacker to execute arbitrary code, bypass security restrictions, elevation of privileges, obtain sensitive information and perform cross-site scripting on the targeted system.
Description
Multiple vulnerabilities have been reported in various Schneider Electric Products:

Solution
Apply appropriate security updates as mentioned in :
https://www.se.com/ww/en/work/support/cybersecurity/security-notifications.jsp
Vendor Information
Schneider Electric
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-346-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-346-01.pdf
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-346-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-346-02.pdf
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-346-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-346-03.pdf
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-318-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-318-01.pdf
CVE Name
CVE-2023-5629
CVE-2023-5630
CVE-2023-6407
CVE-2023-5984
CVE-2023-5985
CVE-2022-0543
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|