How can we help you today?

Treck TCP/IP Ripple 20 Vulnerabilities Affecting Schneider Devices

Issue:

What Schneider Electric devices were affected by the Treck Inc. Ripple20 cyber vulnerabilities?

Product:

Schneider Electric Devices

Environment:

Cybersecurity

Cause:

Treck Inc. publicly disclosed 19 vulnerabilities in its embedded TCP/IP stack, collectively known as Ripple20.
These vulnerabilities vary in severity, with several capable of enabling remote code execution. Other possible impacts include:

  • Privilege escalation
  • Denial of service
  • Information leakage

These issues arise from flaws such as improper length handling, improper input validation, out‑of‑bounds read/write, integer overflows, double free, and others, as identified in federal advisories.

Resolution:

A list of Schneider Electric devices affected by the Ripple20 vulnerabilities is available in theattached document found under the Related tab.



Recommendation:

If you are using an older version of PME, consider upgrading to the latest version for improved protocol support and security. For assistance with integration or upgrades, contact Schneider Electric Technical Support at: pmo-psup@se.com


support details




Schneider Electric USA

Attachment(s)
SEVD-2020-175-01_Treck_Vulnerabilities_Ripple20_Security_Notification_V1.1.pdf [219.24 KB]
Explore more
Range:
Users group

Discuss this topic with experts

Visit our community and get advice from experts and peers on this topic and more
Explore more
Range:

Need help?

Need help?

Product Selector

Product Selector

Quickly and easily find the right products and accessories for your applications.

Get a Quote

Get a Quote

Start your sales inquiry online and an expert will connect with you.

Where to buy?

Where to buy?

Easily find the nearest Schneider Electric distributor in your location.

Help Center

Help Center

Find support resources for all your needs, in one place.

  • Help and Contact Center
  • Contact Sales
  • Find our Offices
  • Where to Buy
  • Tech Support: 877-342-5173
  • Careers
  • Company Profile
  • Investors
  • Newsroom
  • Report a Misconduct
  • Product Documentation
  • Software and Firmware
  • Product Selector
  • Product Replacement
  • DigestPLUS Online Catalogue
  • Blog
  • Events
  • Schneider Electric Community
  • Sustainability
  • Privacy Policy
  • Cookie Notice
  • Terms of use
  • Change your cookie settings