我們的品牌

Impact-Company-Logo-English Black-01-177x54

歡迎造訪施耐德電機全球網站

歡迎訪問我們的網站
		
我们今天能为您提供什么帮助?
PowerSCADA Expert Security Notification (Wonderware ArchestrA Logger multiple vulnerabilities)
Issue
Schneider Electric has become aware of a vulnerability in the Wonderware ArchestrA Logger component used within the PowerSCADA Expert 8.2 product.

Product Line
PowerSCADA Expert 8.2

Environment
Wonderware ArchestrA Logger component

Cause
The Wonderware ArchestrA Logger component exposes a Remote Procedure Call (RPC) interface for remote management. Some of the methods on this interface are susceptible to:

•    Remote Code Execution, which could allow an attacker to run arbitrary code in the context of a highly privileged account.
•    Memory Leaks, which could allow an attacker to exhaust the memory of the target machine and cause Denial of Service for applications running on the target machine.
•    Null Pointer Dereferences, which could allow an attacker to crash the logger process causing Denial of Service for logging and log-viewing operations.

Resolution


Schneider Electric has developed a patch which addresses these vulnerabilities.
Download, unzip and install the patch from the following location: (A new location must be provided before putting online)

Schneider Electric recommends ALL customers using the affected software packages to download and apply the relevant patch.
Notes on applying the patch:
•    Customers are recommended to close System Management Console (SMC) and Log Viewer applications prior to applying this patch. If the applications are open customers may receive an error. To resolve this error please restart the System Management Console (SMC) or refresh the Log Viewer applications.
•    If PowerSCADA Expert 8.2 is reinstalled after this patch is applied, then the patch needs to be reinstalled after the PowerSCADA Expert 8.2 is reinstalled.

For more information
This document is intended to help provide an overview of the identified vulnerability and actions required to mitigate it. To obtain full details on the issues and assistance on how to protect your installation, please contact your local Schneider Electric representative. These organizations will be fully aware of the situation and can support you through the process.
For further information on vulnerabilities in Schneider Electric's products, please visit Schneider Electric's cybersecurity web page at http://www2.schneider-electric.com/sites/corporate/en/support/cybersecurity/cybersecurity.page

施耐德電機Taiwan

探索更多
系列:
探索更多
系列:

需要協助?

  • 產品選型工具

    快速輕鬆地為您的應用找到合適的產品和附件。

  • 取得報價

    立即線上提交您的銷售需求,專業團隊將主動聯繫您。

  • 購買地點

    輕鬆在您所在地區找到最近的施耐德電機經銷商。

  • 支援中心

    在同一位置找到滿足您所有需求的支援資源。

  • 產品文檔
  • 軟體下載
  • 產品選型工具
  • 產品替代和替換
  • 幫助和聯絡中心
  • 尋找我們的辦公室
  • 取得報價
  • 人才招募
  • 公司簡介
  • 舉報不當行為
  • 無障礙
  • 新聞中心
  • 投資者
  • 專業洞察
  • 台灣施耐德電機學院
  • 綠色影響力落差調查
  • Schneider Go Green 2025
  • 隱私政策
  • Cookie通告
  • 使用條款
  • Change your cookie settings