Guideline on the Redis vulnerability SEVD-2026-013-01 in the Plant iT/bewmaxx products
https://www.se.com/us/en/download/document/SEVD-2026-013-01/
The Plant iT/brewmaxx patch for mitigation of Redis vulnerability (mentioned in SEVD-2023-346, SEVD-2026-013-01) is already integrated into the following product releases:
- Plant iT/brewmaxx V9.91 all CUs
- Plant iT/brewmaxx V9.90 CU2 or higher
- Plant iT/brewmaxx V9.80 CU3.1 or higher
- Plant iT/brewmaxx V9.70 CU4.2 or higher
- Plant iT/brewmaxx V9.60 CU5
Affected product versions and mitigation options:
| Plant iT Release | Release date | Compatibility Matrix Redis Patch |
| Plant_IT_V9.90: | ||
| Plant_IT_V0990_SYSTEM_RTM_20230908.ISO | 9/8/2023 | X |
| Plant_IT_V0990_CU1_SYSTEM_202310038.ISO | 10/3/2023 | X |
| Plant_IT_V0990_CU2 or newer | 2/8/2024 | Redis Patch included |
| Plant_IT_V9.80: | ||
| Plant_IT_V0980_CU1_SYSTEM_20220728.ISO | 7/28/2022 | no patch available |
| Plant_IT_V0980_CU1_1_SYSTEM_20221116.ISO | 11/16/2022 | no patch available |
| Plant_IT_V0980_CU2_SYSTEM_20230213.ISO | 2/13/2023 | X |
| Plant_IT_V0980_CU2_1_SYSTEM_20230325.ISO | 3/25/2023 | X |
| Plant_IT_V0980_CU2_2_SYSTEM_20230516.ISO | 5/16/2023 | X |
| Plant_IT_V0980_CU3_SYSTEM_20231207.ISO | 12/7/2023 | X |
| Plant_IT_V0980_CU3.1 or newer | 5/27/2024 | Redis Patch included |
| Plant_IT_V9.70: | ||
| Plant_IT_V0970_SYSTEM_RTM_20200421.ISO | 4/21/2020 | no patch available |
| Plant_IT_V0970_CU1_SYSTEM_20201204.ISO | 12/4/2020 | no patch available |
| Plant_IT_V0970_CU2_SYSTEM_20210210.ISO (Siemens) | 3/10/2021 | no patch available |
| Plant_IT_V0970_CU2_1__SYSTEM_20210319.ISO (Rockwell | 3/19/2021 | no patch available |
| Plant_IT_V0970_CU3_1_SYSTEM_20210607.ISO | 6/7/2021 | no patch available |
| Plant_IT_V0970_CU4_SYSTEM_20220920.ISO | 9/20/2022 | X |
| Plant_IT_V0970_CU4.2 or newer | 6/26/2024 | Redis Patch included |
| Plant_IT_V9.60: | ||
| V0960__CU01_20180706.ZIP | 7/6/2018 | no patch available |
| V0960__CU02_20181120.ZIP | 11/20/2018 | no patch available |
| V0960__CU02_20181128.ZIP | 11/28/2018 | no patch available |
| V0960__CU02_20190314.ZIP | 3/14/2019 | no patch available |
| V0960__CU03_20190704.ZIP | 7/4/2019 | not tested |
| V0960__CU03_1_20190809.ZIP | 8/9/2019 | not tested |
| V0960__CU04_20200207.ZIP | 2/7/2020 | not tested |
| V0960__CU04_1_20200327.ZIP | 3/27/2020 | not tested |
| V0960__CU5_20220123.ZIP | 1/23/2022 | X |
What mitigation measures does ProLeiT recommend for affected systems?
As early as 2023, ProLeiT published effective mitigation measures for the vulnerability now known as CVE-2025-49844 in the Security Advisory SEVD-2023-346
LINK: https://www.se.com/au/en/download/document/SEVD-2023-346-02/
If these measures have already been implemented (Plant iT patch installed and activated) or if a version from V9.91 onwards is used and the system settings are configured accordingly,
no further action is currently required to mitigate the risk.
Verification: 'Secure' Redis system settings with installed and activated Plant iT patch.
Important: The recommendations published online and by Redis regarding updating the Redis software are NOT applicable,
as the ProLeiT PCS products brewmaxx and Plant iT have been developed and tested exclusively with a specific Redis version.