MARCH 1, 2022
Multiple security vulnerabilities have been identified affecting Easergy voltage protection relays developed by Schneider Electric. Voltage protection relays are devices designed to protect motors and systems against over or under-voltage, phase absence, and phase sequence error.
The identified security vulnerabilities are as follows;
Successfully exploiting security vulnerabilities can lead to device credential exposure, device shutdown, or reboot. As a result, the threat actor who takes complete control of the device can endanger the electrical grid’s security.
The vulnerabilities affecting all previous versions of Easergy P3 v30.205 and Easergy P5 v01.401.101 have been fixed with the released updates. To avoid being affected by attacks that can be carried out through vulnerabilities, it is recommended to minimize network exposure for all industrial control systems, prevent internet access, and use secure methods such as VPN when remote access is required.
Take control of your digital security with an exclusive demo of our powerful threat management platform.