Rewterz
Rewterz Threat Alert – Snake Keylogger’s Malware – Active IOCs
April 4, 2022
Rewterz
Rewterz Threat Alert – HawkEye Infostealer – Active IOCs
April 4, 2022

Rewterz Threat Alert – ICS: Schneider Electric SCADAPack Workbench Vulnerability

Severity

High

Analysis Summary

CVE-2022-0221

Schneider Electric SCADAPack Workbench could allow a remote attacker to obtain sensitive information, caused by an XML external entity (XXE) error when processing XML data by various functions. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to obtain sensitive information.

Impact

  • Information Disclosure

Indicator Of Compromise

CVE

  • CVE-2022-0221

Affected Vendors

  • Schneider Electric

Affected Products

  • Schneider Electric SCADAPack Workbench 6.6.8a

Remediation

Refer to CISA-CERT Advisory for the patch, upgrade, or suggested workaround information.

CISA-CERT