我們的品牌

Impact-Company-Logo-English Black-01-177x54

歡迎造訪施耐德電機全球網站

歡迎訪問我們的網站
		
我们今天能为您提供什么帮助?
Does the Heartbleed OpenSSL vulnerability affect APC products?


Issue

On 07-APR-2014, the "Heartbleed" Vulnerability, also called the "Heartbeat" Vulnerability (CVE-2014-0160) was detected and published by several Cyber Security outlets.


Product Line
  • StruxureWare Data Center Expert
  • StruxureWare Data Center Operation
  • NetBotz
  • APC Network Management Cards
  • PowerChute Network Shutdown
  • PowerChute Business Edition
  • APC Remote Monitoring Service (RMS)
  • APC Digital IP KVM Switches (KVM1116P, KVM2116P, KVM2132P)/KVM Access Software
  • MGE Network Shutdown Module Software, v3.07.01

Environment
  • SSL authentication applications


Cause

Reported vulnerabilities in OpenSSL - CVE-2014-0160


Resolution

Detailed description of the issue and some FAQ's can be found here and here.

The Heartbleed bug allows anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software. This compromises the secret keys used to identify the service providers and to encrypt the traffic, the names and passwords of the users and the actual content. This allows attackers to eavesdrop on communications, steal data directly from the services and users and to impersonate services and users.

Schneider Electrics' Data Center Business has conducted a vulnerability assessment on the following platforms and found current shipping versions of each are not affected by the Heartbleed vulnerability.
  • Data Center Operations (DCO) is currently operating with OpenSSL v0.9.8 and is therefore not affected.
  • Data Center Expert (DCE) is currently operating with OpenSSL v1.0.0 and is therefore not affected.
  • NetBotz Appliances are currently operating with OpenSSL v0.9.8b and is therefore not affected.
  • All Network Management Card (NMC) Applications do not utilize OpenSSL and are therefore not affected.
  • PowerChute Network Shutdown is not affected. PowerChute Network Shutdown version 3.1 Appliance for VMware utilizes v0.9.8e.
  • PowerChute Business Edition is not affected. PowerChute Business Edition utilizes OpenSSL version 0.9.4.
  • APC Remote Monitoring Service (RMS) is not affected because it does not utilize OpenSSL.
  • APC Digital IP KVM Switches (KVM1116P, KVM2116P, KVM2132P) & the accompanying KVM Access Software utilize OpenSSL v0.9.7 and therefore are not affected.
  • MGE Network Shutdown Module v3.07.01 for Windows uses the OpenSSL v1.0.1e which is vulnerable to the Heartbleed bug. Network Shutdown Module v3.06.04 for Linux is not impacted.
    • To recover, upgrade all instances of Network Shutdown Module for Windows to v3.07.02 (available @ http://www.apc.com/tools/download/index.cfm and select "Software Upgrade - MGE Accessories" in the Software Filter and click submit.) and change your user credentials. Please read the Release Notes for further information.


Cyber Security is an important element of Schneider Electrics' commitment to software quality. Regular vulnerability assessment and further investigation is ongoing on other Schneider Electric platforms in addition to the above and will be detailed if discovered.

For customers or researchers to report a potential vulnerability incident, please check the following site:

https://www.se.com/ww/en/work/support/cybersecurity/security-notifications.jsp

施耐德電機Taiwan

探索更多
系列:
探索更多
系列:

需要協助?

  • 產品選型工具

    快速輕鬆地為您的應用找到合適的產品和附件。

  • 取得報價

    立即線上提交您的銷售需求,專業團隊將主動聯繫您。

  • 購買地點

    輕鬆在您所在地區找到最近的施耐德電機經銷商。

  • 支援中心

    在同一位置找到滿足您所有需求的支援資源。

  • 產品文檔
  • 軟體下載
  • 產品選型工具
  • 產品替代和替換
  • 幫助和聯絡中心
  • 尋找我們的辦公室
  • 取得報價
  • 人才招募
  • 公司簡介
  • 舉報不當行為
  • 無障礙
  • 新聞中心
  • 投資者
  • 專業洞察
  • 台灣施耐德電機學院
  • 綠色影響力落差調查
  • Schneider Go Green 2025
  • 隱私政策
  • Cookie通告
  • 使用條款
  • Change your cookie settings