Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY2 SECURITY RECORDS

Schneider Electric

SmartConnect

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

Official registry publication history is available at SmartConnect, but registry activity is not a publisher support boundary.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2022-22806 9 Mar 2022 SMT Series; SMC Series; SMTL Series; SCL Series; SMX Series Firmware Version UPS 04.6 (SMT series), Version UPS 15.0 (SMTL, SCL, SMX series) and Version UPS 04.3 (SMC series) includes a partial remediation for CVE-2022-0715, which will reduce the risk of successful exploitation, for the Smart-UPS SMT and SMC series and a fix for CVE-2022-22805 and CVE-2022-22806 for the SmartConnect UPS SMT, SMTL, SCL, SMX series and SMC series.There are three ways to apply this remediation: 1. For units connected to the SmartConnect Portal, new firmware will become available automatically. Follow prompts via the portal or display to install new firmware. 2. For units not connected to the SmartConnect Portal, use the Firmware Upgrade Wizard to install the new firmware. 3. For those devices which include a NMC, it can be used to remotely update the firmware of the UPS. When downloading updates, only download from the official Schneider Electric sources above and ensure that hashes are verified before installation.Note: After the firmware is installed, the unit will lose the capability to install future firmware via the NMC. All other methods of firmware update will continue to be available. A future firmware update will be released to re-enable this feature. To verify new firmware version post-installation: Go to the About screen on local display, the SmartConnect portal, or on the NMC and confirm that the UPS firmware Revision is UPS 04.6 (SMT series) and UPS 04.3 (SMC series)In addition to the remediations above, customers should immediately apply the General Security Recommendations provided below to reduce the risk of exploit. Update reference ↗
CVE-2022-22805 9 Mar 2022 SMT Series; SMC Series; SMTL Series; SCL Series; SMX Series Firmware Version UPS 04.6 (SMT series), Version UPS 15.0 (SMTL, SCL, SMX series) and Version UPS 04.3 (SMC series) includes a partial remediation for CVE-2022-0715, which will reduce the risk of successful exploitation, for the Smart-UPS SMT and SMC series and a fix for CVE-2022-22805 and CVE-2022-22806 for the SmartConnect UPS SMT, SMTL, SCL, SMX series and SMC series.There are three ways to apply this remediation: 1. For units connected to the SmartConnect Portal, new firmware will become available automatically. Follow prompts via the portal or display to install new firmware. 2. For units not connected to the SmartConnect Portal, use the Firmware Upgrade Wizard to install the new firmware. 3. For those devices which include a NMC, it can be used to remotely update the firmware of the UPS. When downloading updates, only download from the official Schneider Electric sources above and ensure that hashes are verified before installation.Note: After the firmware is installed, the unit will lose the capability to install future firmware via the NMC. All other methods of firmware update will continue to be available. A future firmware update will be released to re-enable this feature. To verify new firmware version post-installation: Go to the About screen on local display, the SmartConnect portal, or on the NMC and confirm that the UPS firmware Revision is UPS 04.6 (SMT series) and UPS 04.3 (SMC series)In addition to the remediations above, customers should immediately apply the General Security Recommendations provided below to reduce the risk of exploit. Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.