CVE-2013-0655
published 2013-01-21CVE-2013-0655: The client in Schneider Electric Software Update (SESU) Utility 1.0.x and 1.1.x does not ensure that updates have a valid origin, which allows…
PriorityP344critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
2.91%
85.3th percentile
The client in Schneider Electric Software Update (SESU) Utility 1.0.x and 1.1.x does not ensure that updates have a valid origin, which allows man-in-the-middle attackers to spoof updates, and consequently execute arbitrary code, by modifying the data stream on TCP port 80.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | software_update_utility | — | — |
| schneider-electric | software_update_utility | — | — |
| schneider-electric | software_update_utility | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8q56-7r9c-2j9q: The client in Schneider Electric Software Update (SESU) Utility 1
ghsa_unreviewed·2022-05-17
CVE-2013-0655 [HIGH] CWE-20 GHSA-8q56-7r9c-2j9q: The client in Schneider Electric Software Update (SESU) Utility 1
The client in Schneider Electric Software Update (SESU) Utility 1.0.x and 1.1.x does not ensure that updates have a valid origin, which allows man-in-the-middle attackers to spoof updates, and consequently execute arbitrary code, by modifying the data stream on TCP port 80.
CISA ICS
Schneider Electric Authenticated Communication Risk Vulnerability
cisa_ics·2018-09-06
Schneider Electric Authenticated Communication Risk Vulnerability
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Schneider Electric Authenticated Communication Risk Vulnerability
Last RevisedSeptember 06, 2018
Alert CodeICSA-13-016-01
## OVERVIEW
ICS-CERT received a report from Schneider Electric concerning an Authenticated Communication Risk vulnerability in the Schneider Electric Software Update (SESU) utility. This vulnerability was reported to Schneider Electric by security researcher Arthur Gervais.
The SESU is a centralized update mechanism for updating Schneider Electric software on Windows PC. Schneider Electric has updated the SESU client as of January 2013, which adds the use of
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.schneider-electric.com/download/ww/en/details/29960967-SE-Software-Update-Utility-Vulnerability-Disclosure/?reference=SEVD-2013-009-01http://www.us-cert.gov/control_systems/pdf/ICSA-13-016-01.pdfhttp://www2.schneider-electric.com/corporate/en/support/cybersecurity/viewer-news.page?c_filepath=/templatedata/Content/News/data/en/local/cybersecurity/general_information/2013/01/20130109_advisory_of_vulnerability_affecting_schneider_electric_s_software_upda.xmlhttp://www.schneider-electric.com/download/ww/en/details/29960967-SE-Software-Update-Utility-Vulnerability-Disclosure/?reference=SEVD-2013-009-01http://www.us-cert.gov/control_systems/pdf/ICSA-13-016-01.pdfhttp://www2.schneider-electric.com/corporate/en/support/cybersecurity/viewer-news.page?c_filepath=/templatedata/Content/News/data/en/local/cybersecurity/general_information/2013/01/20130109_advisory_of_vulnerability_affecting_schneider_electric_s_software_upda.xml
2013-01-21
Published