Our takeSchneider Electric disclosed a vulnerability in the IGSS Definition module. If you run IGSS, review the CISA advisory and apply the update.Cyber Resilience desk
Sources (1)
- cisa_ics · cisa_ics
What this means for you — Security leader:Apply the Schneider Electric IGSS patch (ICSA-26-211-04) to all IGSS Definition servers. If you cannot patch immediately, restrict network access to the IGSS Definition module to only authorized engineering workstations.
What this means for you — Lean IT orgs:If you or your vendor use Schneider Electric IGSS to monitor or control equipment, ask them today whether the IGSS Definition module is patched to the latest version and whether it can be reached from the internet.
What this means for you — MSP:Audit every client running Schneider Electric IGSS; confirm the Definition module is updated per ICSA-26-211-04 and that it is not exposed to the internet. Document the version and exposure status for each.
What this means for you — Researcher:Review the CSAF and advisory for the IGSS Definition module vulnerability details, affected versions, and available mitigations.