EcoStruxure IT forum
Schneider Electric support forum about installation and configuration for DCIM including EcoStruxure IT Expert, IT Advisor, Data Center Expert, and NetBotz
Link copied. Please paste this link to share this article on your social media post.
Posted: 2023-09-28 12:08 PM
Please advise if the Data Centre Expert and IT Advisor Software are at risk by the most recent vulnerability called: Critical Zero-Day Vulnerability 2023-09-28
Summary:
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2023-09-29 10:06 AM
Following...
Link copied. Please paste this link to share this article on your social media post.
Link copied. Please paste this link to share this article on your social media post.
Posted: 2023-10-02 04:32 AM
Hello Peter. I had sent you a note via the email you had forwarded to me pertaining to this topic. Pasting comments from the email below to this post.
From a Schneider standpoint, the authority regarding vulnerabilities for all Schneider products is the Schneider cyber portal page at https://www.se.com/ww/en/work/support/cybersecurity/security-notifications.jsp
The Schneider Cyber portal mentioned above should be considered the source of truth.
If ITA and DCE are not listed as being vulnerable to this specific zero-day vulnerability, then you should consider them as not impacted. Given this vulnerability is still quite recent, I'd suggest you subscribe to be notified on the Cyber portal in case the status changes. As of today (Oct 2, 2023) neither DCE nor ITA is identified as being impacted by this vulnerability.
I did check where Redhat has responded to this threat. Redhat has responded to CVE-2023-5217 on this page https://access.redhat.com/security/cve/cve-2023-5217 . The zero day vulnerability does apply to Redhat 8x operating systems when the thunderbird, libwebp modules or libvpx library are present. These modules appear to be installed as dependencies when/if browser like chrome or firefox are installed in the OS.
I checked online and offline ITA servers. These rpm’s/modules are not part of the ITA online or offline iso’s. When I installed firefox on one of my ITA servers I did indeed see the libvpx and libwebp libraries were also installed. This would lead me to believe your ITA server is safe as long as your team did not install a browser on the server.
Regards
Greg Sterling
Link copied. Please paste this link to share this article on your social media post.
Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.