Schneider Electric Enerlin'X IFE and eIFE Improper Input Validation Vulnerability Leading to Denial-of-Service
Vulnerability
A denial-of-service vulnerability has been identified in Schneider Electric's Enerlin'X IFE and eIFE products, all versions. This vulnerability arises from improper input validation, allowing malicious ICMPv6 packets to be sent to the device. The attack disrupts the availability of the IEC61850 services on the affected products, requiring a manual reboot to restore functionality.
Impact
Exploitation of this vulnerability causes a denial-of-service condition, disrupting the IEC61850 services of the Enerlin'X IFE and eIFE products and requiring a manual reboot to restore normal operation.
Remediation
Users can upgrade to version 004.010.000 of Enerlin'X IFE and eIFE, which includes a fix for this vulnerability. The latest version can be downloaded using the EcoStruxure Power Commission tool. For those who cannot apply the update, it is recommended to use the devices only in a protected environment, minimize network exposure, and implement network segmentation and firewall rules to block unauthorized access. Consult the Cybersecurity Guide for Access Control List recommendations.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
