Schneider Electric CitectSCADA Products Exception Handler Vulnerability (Update A)
An unhandled exception vulnerability exists in the exception handler of Schneider Electric CitectSCADA and related SCADA products. The vulnerability affects multiple versions of Vijeo Citect, CitectSCADA, StruxureWare PowerSCADA Expert, PowerLogic SCADA, and StruxureWare SCADA Expert. CWE-248 (Uncaught Exception) indicates that the application fails to properly handle exceptions, which could allow an attacker to trigger crashes or potentially achieve code execution. No fix is available for any of the affected product versions.
- Network access to CitectSCADA application server or engineering workstation
- CitectSCADA application must be running and accepting network connections
Patching may require device reboot — plan for process interruption
/api/v1/advisories/e70f63e6-f329-41d9-9196-b37a2b7e0ac3Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.