CERT-In Advisory
CIAD-2024-0032
Multiple Vulnerabilities in Schneider Electric Products
Original Issue Date: June 17, 2024
Severity Rating: High
Software Affected
- APC Easy UPS Online Monitoring Software
- Schneider Electric Easy UPS Online Monitoring Software
- Sage 1410, Sage 1430,Sage 1450,Sage 2400,Sage 3030 Magnum and Sage 4400
- SpaceLogic AS-P and SpaceLogic AS-B
- EVlink Home Smart
- PowerLogic P5
- Modicon M340
- Network module, Modicon M340, Modbus/TCP BMXNOE0100
- Network module, Modicon M340, Ethernet TCP/IP BMXNOE0110
Overview
Multiple vulnerabilities have been identified in Schneider Electric products, which could allow an attacker to execute arbitrary code, gain elevated privileges, access sensitive information, or cause Denial-of-Service (DoS) condition on the targeted system.
Description
Multiple vulnerabilities have been reported in Schneider Electric products; details of which are provided below:

Solution
Apply appropriate security updates as mentioned in:
https://www.se.com/ww/en/work/support/cybersecurity/security-notifications.jsp
Vendor Information
Schneider Electric
https://www.se.com/ww/en/work/support/cybersecurity/security-notifications.jsp
References
Schneider Electric
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-101-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-101-04.pdf
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-163-05&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-163-05.pdf
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-163-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-163-04.pdf
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-163-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-163-03.pdf
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-163-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-163-02.pdf
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-163-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-163-01.pdf
CVE Name
CVE-2023-29411
CVE-2023-29412
CVE-2023-29413
CVE-2024-37036
CVE-2024-37037
CVE-2024-37038
CVE-2024-37039
CVE-2024-37040
CVE-2024-5560
CVE-2024-5559
CVE-2024-5558
CVE-2024-5557
CVE-2024-5313
CVE-2024-5056
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|