Schneider Electric announced critical vulnerability in InduSoft Web Studio and InTouch Machine Edition

Document created by Shlomi Feldman Employee on May 13, 2018
Version 1Show Document
  • View in full screen mode

Background
InduSoft Web Studio is a powerful collection of tools that provide all the automation building blocks to develop HMIs, SCADA systems and embedded instrumentation solutions. InTouch Machine Edition is a highly scalable, flexible HMI designed to provide everything from advanced HMI applications to small-footprint embedded devices. InduSoft Web Studio and InTouch Machine Edition are used in many industries worldwide, including Manufacturing, Oil and Gas, Water and Wastewater, Building Automation, Automotive, Wind and Solar Power.

 

Vulnerability Details
InduSoft Web Studio and InTouch Machine Edition provide the capability for an HMI client to read, write tags and monitor alarms and events. A remote malicious entity could send a carefully crafted packet to exploit a stack-based buffer overflow vulnerability during tag, alarm, or event related actions such as read and write, with potential for code to be executed. The code would be executed under high privileges and could lead to a complete compromise of the InduSoft Web Studio or InTouch Machine Edition server machine.

 

Recommendations
Customers using InduSoft Web Studio v8.1 or prior versions are affected and should upgrade and apply InduSoft Web Studio v8.1 SP1 as soon as possible.
Customers using InTouch Machine Edition 2017 v8.1 or prior versions are affected and should upgrade and apply InTouch Machine Edition 2017 v8.1 SP1 as soon as possible

Outcomes