How can we help you today?

Guideline on the Redis vulnerability SEVD-2026-013-01 in the Plant iT/bewmaxx products

https://www.se.com/us/en/download/document/SEVD-2026-013-01/

The Plant iT/brewmaxx patch for mitigation of Redis vulnerability (mentioned in SEVD-2023-346, SEVD-2026-013-01) is already integrated into the following product releases:

- Plant iT/brewmaxx V9.91 all CUs
- Plant iT/brewmaxx V9.90 CU2 or higher
- Plant iT/brewmaxx V9.80 CU3.1 or higher
- Plant iT/brewmaxx V9.70 CU4.2 or higher
- Plant iT/brewmaxx V9.60 CU5

Affected product versions and mitigation options:

Plant iT ReleaseRelease dateCompatibility Matrix Redis Patch
Plant_IT_V9.90:
Plant_IT_V0990_SYSTEM_RTM_20230908.ISO9/8/2023X
Plant_IT_V0990_CU1_SYSTEM_202310038.ISO10/3/2023X
Plant_IT_V0990_CU2 or newer2/8/2024Redis Patch included
Plant_IT_V9.80:
Plant_IT_V0980_CU1_SYSTEM_20220728.ISO7/28/2022no patch available
Plant_IT_V0980_CU1_1_SYSTEM_20221116.ISO11/16/2022no patch available
Plant_IT_V0980_CU2_SYSTEM_20230213.ISO2/13/2023X
Plant_IT_V0980_CU2_1_SYSTEM_20230325.ISO3/25/2023X
Plant_IT_V0980_CU2_2_SYSTEM_20230516.ISO5/16/2023X
Plant_IT_V0980_CU3_SYSTEM_20231207.ISO12/7/2023X
Plant_IT_V0980_CU3.1 or newer5/27/2024Redis Patch included
Plant_IT_V9.70:
Plant_IT_V0970_SYSTEM_RTM_20200421.ISO4/21/2020no patch available
Plant_IT_V0970_CU1_SYSTEM_20201204.ISO12/4/2020no patch available
Plant_IT_V0970_CU2_SYSTEM_20210210.ISO (Siemens)3/10/2021no patch available
Plant_IT_V0970_CU2_1__SYSTEM_20210319.ISO (Rockwell3/19/2021no patch available
Plant_IT_V0970_CU3_1_SYSTEM_20210607.ISO6/7/2021no patch available
Plant_IT_V0970_CU4_SYSTEM_20220920.ISO9/20/2022X
Plant_IT_V0970_CU4.2 or newer6/26/2024Redis Patch included
Plant_IT_V9.60:
V0960__CU01_20180706.ZIP7/6/2018no patch available
V0960__CU02_20181120.ZIP11/20/2018no patch available
V0960__CU02_20181128.ZIP11/28/2018no patch available
V0960__CU02_20190314.ZIP3/14/2019no patch available
V0960__CU03_20190704.ZIP7/4/2019not tested
V0960__CU03_1_20190809.ZIP8/9/2019not tested
V0960__CU04_20200207.ZIP2/7/2020not tested
V0960__CU04_1_20200327.ZIP3/27/2020not tested
V0960__CU5_20220123.ZIP1/23/2022X

What mitigation measures does ProLeiT recommend for affected systems?

As early as 2023, ProLeiT published effective mitigation measures for the vulnerability now known as CVE-2025-49844 in the Security Advisory SEVD-2023-346
LINK: https://www.se.com/au/en/download/document/SEVD-2023-346-02/

If these measures have already been implemented (Plant iT patch installed and activated) or if a version from V9.91 onwards is used and the system settings are configured accordingly,
no further action is currently required to mitigate the risk.

REDIS Settings in the ProLeiT System Functionality

Verification: 'Secure' Redis system settings with installed and activated Plant iT patch.


Important:
The recommendations published online and by Redis regarding updating the Redis software are NOT applicable,
as the ProLeiT PCS products brewmaxx and Plant iT have been developed and tested exclusively with a specific Redis version.


Schneider Electric Saudi Arabia

Explore more
Range:
Users group

Discuss this topic with experts

Visit our Community for first-hand insights from experts and peers on this topic and more.
Explore more
Range:
  • Product Documentation
  • Software Downloads
  • Product Selector
  • Product Substitution and Replacement
  • Help and Contact Centre
  • Find our Offices
  • Get a Quote
  • Where to buy
  • Schneider Electric Community
  • Careers
  • Company Profile
  • Report a misconduct
  • Accessibility
  • Newsroom
  • Investors
  • EcoStruxure
  • Job Search
  • Blog
  • Privacy Policy
  • Cookie Notice
  • Terms of use
  • Change your cookie settings