Our takeSchneider Electric disclosed a vulnerability in the IGSS Definition module of its SCADA product. If you run IGSS, review the advisory and apply the update now.Cyber Resilience desk
Sources (1)
- cisa_advisories · cisa_advisories
What this means for you — Security leader:Apply the Schneider Electric IGSS patch (ICSA-26-211-04) to all affected Definition module instances. If you cannot patch immediately, restrict network access to IGSS servers and limit use of the Definition module to trusted, isolated workstations.
What this means for you — Lean IT orgs:Check whether you use Schneider Electric IGSS for monitoring equipment or processes. If you do, apply the vendor’s security update as soon as possible or ask your integrator to do it for you.
What this means for you — MSP:Audit all client environments for Schneider Electric IGSS installations and schedule the ICSA-26-211-04 patch. Prioritize clients running the Definition module on networks reachable from corporate or internet zones.
What this means for you — Researcher:Review the CSAF and advisory for the IGSS Definition module vulnerability details, affected versions, and any available exploit information.