Building Automation Software Exposes Company Headquarters to Attacks

Building Automation Software Exposes Company Headquarters to Attacks

Building automation server comes with hard-coded credentials

  • Security
  • By Catalin Cimpanu
  • September 16th, 2015
Schneider Electric Fixes Security Bug in Its IoT Home Management System

Schneider Electric Fixes Security Bug in Its IoT Home Management System

Home management dashboard exposed credentials in clear text

Schneider Electric’s Wonderware Products Receive Security Patch

Schneider Electric’s Wonderware Products Receive Security Patch

Severity rating for the vulnerability is “high”

Schneider Electric Fixes Security Flaws in Multiple Products

Schneider Electric Fixes Security Flaws in Multiple Products

Vulnerability exists in DLL in DTM development kit

Schneider Electric HMI Gateway Comes with Hard-Coded FTP Credentials

Schneider Electric HMI Gateway Comes with Hard-Coded FTP Credentials

FTP server should be disabled for full risk mitigation

Buffer Overflow Glitch in Wonderware Server Gets Fix from Schneider Electric

Buffer Overflow Glitch in Wonderware Server Gets Fix from Schneider Electric

ICS-CERT warns of high severity of the vulnerability

Schneider Electric Patches 22 Products Against Remotely Exploitable Vulnerability

Schneider Electric Patches 22 Products Against Remotely Exploitable Vulnerability

Some products still have to receive firmware updates

Schneider Electric Patches Hard-Coded Credentials Flaw in Quantum Ethernet Module

Schneider Electric Patches Hard-Coded Credentials Flaw in Quantum Ethernet Module

Almost two years have passed since the issue was first discovered

Schneider Electric Starts Patching SCADA Vulnerabilities Discovered in 2011

Schneider Electric Starts Patching SCADA Vulnerabilities Discovered in 2011

Only a portion of the remotely-exploitable flaws have been addressed