Number: AV20-140
Date: 8 May 2020
On 14 April 2020 Schneider Electric published a security notification highlighting a DLL substitution vulnerability in the following products:
• SoMachine Basic (all versions)
• EcoStruxure Machine Expert – Basic (all versions)
• Modicon M100 Logic Controller (all versions)
• Modicon M200 Logic Controller (all versions)
• Modicon M221 Logic Controller (all versions)
Successful exploitation of this vulnerability may allow for malicious code to be transferred to vulnerable controllers.
The Cyber Centre encourages users and administrators to review the following for recommended mitigations and apply the necessary manufacturer software and firmware updates:
https://www.se.com/ww/en/download/document/SEVD-2020-105-01/
Note to Readers
The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada’s national authority on cyber security and we lead the government’s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure , Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.