Flaw in Unity Pro Poses Major Headaches for Industrial Control Networks
ID: 45499442-f2c1-5021-92c4-9910d31b2586
STIX ID: report--45499442-f2c1-5021-92c4-9910d31b2586
Feed Name: Security Ledger
Threat Score
A remotely exploitable vulnerability in Schneider Electric's Unity Pro engineering software allows malicious APX project files to execute arbitrary code on engineering workstations and potentially affect any process controlled by Schneider PLCs; Indegy disclosed the flaw, explained the attack mechanics (malformed APX, checksum bypass, remote delivery over a default TCP port), and Schneider released a patch to mitigate the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
