Ask the Community
Ask questions, get advice from experts and peers on Digital Automation & Energy Management.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2023-11-13 07:12 PM
Easergy Pro makes use of third party software components of which some have existing security vulnerabilities. Winpcap is also not supported anymore.
Easergy Pro third party software Components with vulnerabilities / not supported for security patches:
Software component | Version | Release date | Latest version | Latest version release date | Notes | Security vulnerabilities |
Winpcap driver | 4.1.3 | 2013 | 4.1.3 | 2013 | Industry recommendation is to migrate to a supported version of Npcap | No patches or support provided |
Apache log4net for .NET 4.5 | 2.0.8 | 2017 | 2.0.15 | 2022 | Industry recommendation to migrate to supported version. | |
|
|
|
|
| ||
JSON.Net | 12.0.3.23909 | 2019 | 13.0.3 | 2023 | The installed version has a high severity security vulnerability | |
SharpCompress | 0.25.1 | 2020 | 0.34.1 | 2023 | The installed version has a medium severity security vulnerability | |
SSH.NET .NET4.0 | 2016.1.0 | 2017 | 2020.0.2 | 2020 | The installed version has a medium severity security vulnerability |
May I ask if it would be possible to confirm the following:
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2023-11-14 10:55 PM
@ControlSystemSoftware I suggest that you contact your local Schneider Electric Customer Care center to get assistance with this query. It doesn't sound like something that should be discussed in a semi open forum such as this.
https://www.se.com/au/en/work/support/customer-care/contact-schneider-electric.jsp
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2023-11-14 11:10 PM
I see that you have made a request to Customer Care previously that seems to have been miss-assigned by the system. I have hopefully added enough information to the case so that the correct team in Australia will pick it up and respond to you.
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2023-11-14 11:18 PM
Alternatively you may want to go to Cybersecurity support portal where you can find known vulnerabilities and mitigations, or report a vulnerability.
https://www.se.com/ww/en/work/support/cybersecurity/security-notifications.jsp
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2023-11-15 09:10 PM
@ControlSystemSoftware I took a look at your case in our Customer Care system and it seems to have gained some traction following my changes. It has progressed to the Expert Support team responsible for the product and hopefully you'll get an answer soon.
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2023-11-23 12:38 AM
Thank you - much appreciated.
Link copied. Please paste this link to share this article on your social media post.
Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.