You are here

Schneider Electric InduSoft Web Studio and InTouch Machine Edition (ICSA-17-313-02) – Product Used in the Water and Wastewater and Energy Sectors

Schneider Electric InduSoft Web Studio and InTouch Machine Edition (ICSA-17-313-02) – Product Used in the Water and Wastewater and Energy Sectors

Created: Friday, November 10, 2017 - 10:32
Categories:
Cybersecurity

ICS-CERT has released an advisory on a Schneider Electric InduSoft Web Studio and InTouch Machine Edition vulnerability. For InduSoft Web Studio, v8.0 SP2 Patch 1 and prior versions are affected; for InTouch Machine Edition, v8.0 SP2 Patch 1 and prior versions are affected. Successful exploitation of this vulnerability could allow a remote un-authenticated attacker to remotely execute code with high privileges. For both products, Schneider Electric recommends users upgrade to v8.1 as soon as possible. Additionally, ICS-CERT recommends a series of defensive measures to minimize the risk of exploitation of the vulnerability. ICS-CERT.