我们今天能为您提供什么帮助?

Treck TCP/IP Ripple 20 Vulnerabilities Affecting Schneider Devices

Issue:

What Schneider Electric devices were affected by the Treck Inc. Ripple20 cyber vulnerabilities?

Product:

Industrial Automation Products

Energy Management Products

Uninterruptible Power Supply

Power Distribution Units

Battery Management

Automatic Transfer Switches

Environmental Monitoring Products

Cooling Products

*complete detailed list of products in the attachment

Environment:

Cybersecurity

Cause:

Treck Inc. publicly disclosed 19 vulnerabilities in its embedded TCP/IP stack, collectively known as Ripple20.
These vulnerabilities vary in severity, with several capable of enabling remote code execution. Other possible impacts include:

  • Privilege escalation
  • Denial of service
  • Information leakage

These issues arise from flaws such as improper length handling, improper input validation, out‑of‑bounds read/write, integer overflows, double free, and others, as identified in federal advisories.

Resolution:

A list of Schneider Electric devices affected by the Ripple20 vulnerabilities is available in theattached document found under the Related tab.



Recommendation:

If you are using an older version of PME, consider upgrading to the latest version for improved protocol support and security. For assistance with integration or upgrades, contact Schneider Electric Technical Support at: pmo.support@se.com

PME Version History





施耐德電機Taiwan

附件
SEVD-2020-175-01_Treck_Vulnerabilities_Ripple20_Security_Notification_V1.1.pdf [219.24 KB]
探索更多
系列:
探索更多
系列:
  • 產品文檔
  • 軟體下載
  • 產品選型工具
  • 產品替代和替換
  • 幫助和聯絡中心
  • 尋找我們的辦公室
  • 取得報價
  • 施耐德電機社群
  • 人才招募
  • 公司簡介
  • 舉報不當行為
  • 無障礙
  • 新聞中心
  • 投資者
  • 專業洞察
  • 台灣施耐德電機學院
  • 綠色影響力落差調查
  • Schneider Go Green 2025
  • 隱私政策
  • Cookie通告
  • 使用條款
  • Change your cookie settings