Multiple vulnerabilities found on Schneider Quantum Ethernet module
Multiple vulnerabilities found on Schneider Quantum Ethernet module
The Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) has reported multiple vulnerabilities on Schneider Electric’s Quantum Ethernet module. The module is primarily used in Schneider Quantum PLCs (programmable controllers), but is also used in Premium PLC, M340 PLC and STB I/O products.
According to the report (ICS-ALERT-11-346-01), independent researcher Rubén Santamarta publicly announced details of the vulnerabilities, and Schneider has produced a fix for two of the reported vulnerabilities and is continuing to develop additional mitigations.