SAGE RTU'S
  • Home
  • Products
  • Downloads
  • Support
    • Contacts
    • Services
  • Brochures
  • Updates
  • About

Updates and News

Monthly Security Updates, Product News, and more

October 2019 SECURITY UPDATE

10/30/2019

0 Comments

 

​SAGE Monthly Security / Firmware Update Notice

Update Summary:
We have posted a firmware release to address the VxWorks Urgent/11 issues the first week of October 2019.   Click the links below for more information regarding the vulnerabilities and our patches.
 VxWorks Urgent/11 
C3414-500-S02K4 Firmware Release
October_2019_Security_Update.pdf
File Size: 83 kb
File Type: pdf
Download File

0 Comments

C3414-500-S02K4 Firmware Release

10/4/2019

0 Comments

 
Reposting in case the original post didn't show up in some of your Security Updates Feeds.  Forgot to tag it with the Security Updates category the first time.
​
The SAGE Team is proud to announce the release of our latest firmware release for the SAGE RTU product family.  There are many important security enhancements and exciting features included in this release. See below for more details. 
​The C3414-500-S02K4 firmware can be downloaded from our Downloads -> Firmware Tab or by clicking here.  ​

Firmware Highlights
  • ​​VxWorks Urgent/11 Ethernet Communications Vulnerability Fix - Click the link for more details.
  • RADIUS Authentication - Security improvement which enables user authentication and authorization via an enterprise system.  This facilitates NERC CIP compliance for those of you with network access to your RTU's. See our Secure Software Users Guide for instructions on configuration and usage.
  • FTP Push Application - This application is designed to automatically push files to one or more servers to facilitate quick analysis of events generated by SEL relays connected to the RTU and from log files created by the RTU.  See our Config@web Applications Manual for more information. 
  • SEL Tunnel Enhancements - Users can now tunnel through the RTU to connected relays via the SEL 5030 Quickset software.  
  • Data Trap Enhancements - The Data Trap application now supports up to 5 simultaneous capture sessions.  These can be launched from the Applications Menu Block now. 
  • Syslog Client Enhancements - Logging of critical RTU information can be sent to an enterprise Syslog Server so the right person can be notified immediately. This includes all of the Command Log, System Log, and User Log entries. 
  • Annunciator Panel Enhancements - Annunciator and Alarming pages can be viewed without logging into the RTU. Now up to 60 (from 30) cells with up to 60 points per cell (from 16) can be configured.  Black background and Alarm Sound can be configured. 
  • DNP Protocol Fixes and enhancements. See Release Notes for details.
  • SEL Protocol Enhancements to improve compatibility with newer relay models. 
If you have any questions or comments, feel free to contact me or anyone on the SAGE team for more info.
C3414_Release_Notes_K4.pdf
File Size: 448 kb
File Type: pdf
Download File

0 Comments

VxWorks Urgent/11 Update

10/3/2019

0 Comments

 
Update:  The SAGE Team is proud to announce the release of our latest firmware release for the SAGE RTU product family.  There are many important security enhancements, including this VxWorks Urgent/11 fix,  and exciting features included in this release.  For more details about the release, see our post here.

Schneider Electric is aware of recently disclosed vulnerabilities in Wind River’s VxWorks TCP/IP Stack. These vulnerabilities have wide-ranging impact across multiple IT and industrial applications. We are working closely with Wind River to understand and assess how these vulnerabilities impact Schneider Electric offers and our customers’ operations.
​
We downloaded Wind River’s patches as soon as they were made available to us, and we have quickly instituted a remediation plan to evolve all current and future products that rely on the Wind River platform to embed these fixes. We will continue to monitor and will respond further if new information becomes available.

In the meantime, customers should immediately make sure they have implemented cybersecurity best practices across their operations to protect themselves from these vulnerabilities. Where appropriate this includes locating your industrial systems and remotely accessible devices behind firewalls; installing physical controls to prevent unauthorized access; and preventing mission-critical systems and devices from being accessed from outside networks.

Please subscribe to the Schneider Electric security notification service to be informed of updates to this disclosure, including details on affected products and remediation plans, as well as other important security notifications:
https://www.schneider-electric.com/en/work/support/cybersecurity/security-notifications.jsp www.schneider-electric.com/en/work/support/cybersecurity/security-notifications.jsp
For additional information and support, please contact your Schneider Electric sales or service representative or Schneider Electric’s Customer Care Center. 


An update for our customers regarding the recently announced Urgent/11 VxWorks vulnerabilities.

We are aware of the vulnerabilities and working to include the patches for these vulnerabilities in our SAGE RTU operating system. We are committed to the security of your equipment and will release a patch as soon as possible. 

​These vulnerabilities are all related to the TCP/IP network stack.  If your RTU is not connected to one of the ethernet ports, which could possibly be accessed from a network, there is no additional risk associated to these devices.  Only network connected devices are affected by these vulnerabilities. Serial connections are not affected.  

These patches will be included in our next firmware release, C3414-500-S02K4, which will include this and other exciting features like RADIUS authentication, and some excellent improvements to our SEL Relay interoperability.  Keep an eye out for the firmware release here.  

​If you have any questions, feel free to contact me.  

See the official announcement for all Schneider Electric products here.
https://www.schneider-electric.com/ww/en/download/document/SESB-2019-214-01
SESB-2019-214-01-Wind_River_VxWorks_Security_Bulletin.pdf
File Size: 259 kb
File Type: pdf
Download File

0 Comments

C3414-500-S02K4 Firmware Release

10/3/2019

0 Comments

 
The SAGE Team is proud to announce the release of our latest firmware release for the SAGE RTU product family.  There are many important security enhancements and exciting features included in this release. See below for more details. 
​The C3414-500-S02K4 firmware can be downloaded from our Downloads -> Firmware Tab or by clicking here.  

Firmware Highlights

  • ​​VxWorks Urgent/11 Ethernet Communications Vulnerability Fix - Click the link for more details.
  • RADIUS Authentication - Security improvement which enables user authentication and authorization via an enterprise system.  This facilitates NERC CIP compliance for those of you with network access to your RTU's. See our Secure Software Users Guide for instructions on configuration and usage.
  • FTP Push Application - This application is designed to automatically push files to one or more servers to facilitate quick analysis of events generated by SEL relays connected to the RTU and from log files created by the RTU.  See our Config@web Applications Manual for more information. 
  • SEL Tunnel Enhancements - Users can now tunnel through the RTU to connected relays via the SEL 5030 Quickset software.  
  • Data Trap Enhancements - The Data Trap application now supports up to 5 simultaneous capture sessions.  These can be launched from the Applications Menu Block now. 
  • Syslog Client Enhancements - Logging of critical RTU information can be sent to an enterprise Syslog Server so the right person can be notified immediately. This includes all of the Command Log, System Log, and User Log entries. 
  • Annunciator Panel Enhancements - Annunciator and Alarming pages can be viewed without logging into the RTU. Now up to 60 (from 30) cells with up to 60 points per cell (from 16) can be configured.  Black background and Alarm Sound can be configured. 
  • DNP Protocol Fixes and enhancements. See Release Notes for details.
  • SEL Protocol Enhancements to improve compatibility with newer relay models. 
If you have any questions or comments, feel free to contact me or anyone on the SAGE team for more info.

C3414_Release_Notes_K4.pdf
File Size: 448 kb
File Type: pdf
Download File

0 Comments

September 2019 Security Update

10/2/2019

0 Comments

 

SAGE Monthly Security / Firmware Update Notice

Update Summary:
No security related items in firmware release(s) for September 2019. 
We will post a firmware release to address the VxWorks Urgent/11 issues the first week of October 2019.  
​
September_2019_Security_Update.pdf
File Size: 98 kb
File Type: pdf
Download File

0 Comments

    Categories

    All
    Bulletins
    Security Updates

    Archives

    November 2022
    October 2022
    September 2022
    August 2022
    July 2022
    June 2022
    May 2022
    April 2022
    March 2022
    February 2022
    January 2022
    December 2021
    November 2021
    October 2021
    September 2021
    July 2021
    June 2021
    April 2021
    March 2021
    February 2021
    January 2021
    November 2020
    October 2020
    August 2020
    July 2020
    June 2020
    April 2020
    March 2020
    February 2020
    January 2020
    November 2019
    October 2019
    September 2019
    August 2019
    July 2019
    June 2019
    April 2019
    March 2019
    February 2019
    January 2019
    December 2018
    November 2018
    October 2018
    August 2018
    July 2018
    June 2018
    May 2018

    RSS Feed

Services

RTU System Consulting
Project Management
Design and Install
NERC/CIP Security Support
Complete RTU SUpport
RIG for ISO

​

Company

About
​
​

Support

Contact
​
© COPYRIGHT 2018. ALL RIGHTS RESERVED.
  • Home
  • Products
  • Downloads
  • Support
    • Contacts
    • Services
  • Brochures
  • Updates
  • About