Publisher not identified
EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Control Expert V15.0 SP1, EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), SCADAPack RemoteConnect for x70 (all versions), Modicon M580 CPU (all versions - part numbers BMEP* and BMEH*), Modicon M340 CPU (all versions - part numbers BMXP34*)
Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.
This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.
A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.
CVE-observed version history
| CVE | Published | Affected versions | Fixed version information | Publisher evidence |
|---|---|---|---|---|
| CVE-2021-22779 | 14 Jul 2021 | EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Control Expert V15.0 SP1, EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), SCADAPack RemoteConnect for x70 (all versions), Modicon M580 CPU (all versions - part numbers BMEP* and BMEH*), Modicon M340 CPU (all versions - part numbers BMXP34*) | EcoStruxure™ Control Expert V15.1*, available for download below, includes a fix for CVE-2021-22778, CVE-2021-22780, CVE-2021-22781, CVE-2021-22782, CVE-2020-12525, and CVE-2021-22779: https://www.se.com/ww/en/download/document/EcoStruxureControlExpert_V15.1/ * Upgrading to EcoStruxure™ Control Expert V15.1 is the first step in a two steps process to fully address CVE-2021-22779. The second step is to update the firmware of the Modicon Controllers referenced. Important Note: • The fix is provided through the additional feature “file encryption”, for further information on the feature and how to set it up please refers to the chapter “file encryption” of the help file available in the EcoStruxure™ Control Expert v15.0 SP1. • This feature is proposed by default when creating a new project. • This feature is also available, after selecting “project” in structural view, in the “Edit/ Properties/ Project & Controller Protection” menu. • For new projects: Customers are recommended to apply this feature to all new projects. • For existing projects: Customers are recommended to apply this feature to the existing projects coming from trusted source. For sta project files, as a reminder, project modification can be done in connected mode to prevent desynchronization and keep the controller in RUN state. • It is possible to set a security level specific to the Derived Function Blocks (DFB) in addition to the file encryption feature. Please refer to the chapter "How to protect a DFB type" in the EcoStruxure™ Control Expert help file for further information. • Customers are recommended to share project files only when configured with the encryption feature described above. If customers choose not to apply the remediation provided above, they should immediately apply the following mitigations to reduce the risk of exploit. These mitigations also reduce the risk of exploit for CVE-2021-22779 on all versions of EcoStruxure™ Control Expert, including V15.1: • Store the project files in a secure storage and restrict the access to only trusted users • When exchanging files over the network, use secure communication protocols • Encrypt project files when stored • Only open project files received from trusted source • Compute a hash of the project files and regularly check the consistency of this hash to verify the integrity before usage • Harden the workstation running EcoStruxure™ Control Expert or Unity Pro Customers using Unity Pro should strongly consider migrating to EcoStruxure™ Control Expert. Please contact your local Schneider Electric technical support for more information. | Update reference ↗ |
How this record is maintained
The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.