WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home H2OSecCon 2026 Schneider Electric IIoT Monitor (Update A) (ICSA-19-008-02) – Product Used in the Energy Sector
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Schneider Electric IIoT Monitor (Update A) (ICSA-19-008-02) – Product Used in the Energy Sector

Author: Charles Egli

Created: Tuesday, January 15, 2019 - 21:15

Categories: Cybersecurity

January 15, 2019

The NCCIC has updated this advisory with information on the nature of the vulnerabilities. Read the full advisory at NCCIC/ICS-CERT.

January 8, 2019

The NCCIC has published an advisory on path traversal, unrestricted upload of file with dangerous type, and XXE vulnerabilities in Schneider Electric IIoT Monitor. Versions 3.1.38 and prior are affected. Successful exploitation of these vulnerabilities could allow a remote attacker to access files available to system users, arbitrarily upload and execute malicious files, and embed incorrect documents into the system output to expose restricted information. Schneider Electric recommends that affected users contact Schneider Electric customer support for assistance in migrating to the latest software to resolve the issues and has released a security notification. The NCCIC also advises on a series of mitigating measures for these vulnerabilities. NCCIC/ICS-CERT.

Related Resources

Members Only

(TLP:AMBER) DHS Office of Intelligence and Analysis Reports (May 21, 2026)

May 21, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) Weekly Vulnerabilities to Prioritize – May 21, 2026

May 21, 2026 in Cybersecurity, Security Preparedness
Members Only

(TLP:GREEN) PEAR Ransomware Claims U.S. Drinking Water Utility as Victim

May 21, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar