Skip navigation
1 2 3 Previous Next

SAGE

42 posts

Hi All,

 

As part of your NERC compliance, some of you are required to check for relevant security advisories and firmware updates periodically.

We have had several requests regarding this recently and I wanted to share the best way to keep automatically updated in your email inbox.

You should be signed up for an account on this site which links your username to your email address.

 

First, you should follow the spaces and people in the link below.

 

This space is public and is where new Security Advirories, Manuals, and other Important Information will be posted.

SAGE

 

This space requires permission to be accessible.  This post explains how to become a member.  Getting the latest SAGE firmware guide

The latest firmware and firmware archives will be posted here.

RTU Downloads

 

I will generally be the person to post information to this site regarding SAGE RTU's so you can follow me too, but the two spaces above should be sufficient.

Chris Kerr

 

To follow, hover over the links above and look for the button that looks like this.

2016-05-11 10_58_33-Space_ SAGE _ exchange.png

Then be sure to check the "Inbox" option to get emailed when new information is available.

2016-05-11 11_00_04-Space_ SAGE _ exchange.png

 

I hope this info makes your lives easier.  Let me know if you have questions.

RTU Downloads Group on Exchange - Requesting Access.pdf

 

We have created a guide to help with the process of getting access to the RTU Downloads group so you can get the latest SAGE firmware.

Check out the link to the document above for that information.

Schneider Electric has become aware of a VxWorks TCP Initial Sequence Vulnerability in the SAGE RTU product line which could result in remote man-in-the-middle or denial-of-service exploitation.


Please browse the following link to learn the details of this vulnerability in the Schneider Electric SAGE RTU product line.


http://www.schneider-electric.com/ww/en/download/document/SEVD-2015-162-01


Further information about the vulnerability in VxWorks is available here:


https://ics-cert.us-cert.gov/advisories/ICSA-15-169-01

Did you recently get a new PC?

 

Have you recently had to replace the Windows XP machine running Internet Explorer 8 or 9 32 bit version used to configure the SAGE RTUs with one running a newer versions of Windows or Internet Explorer?

 

If so, updates and instructions on how to configure your existing or new PC and RTUs to work with the new versions of the Microsoft programs are available.

 

If you still have your old Windows XP machine, hang on to it if you can until you update the firmware or GUI in your RTUs before giving it up. If you do not have the firmware or GUI updates in the RTU before switching to the newer versions of Internet Explorer, the Up/Download function of the firmware may not function reliably and you will have to use FTP to move files on and off the RTU.

 

Don't wait to do this in the field, as it may require some help from your IT folks to configure your PC.

 

Hook up your spare RTU in a convenient place, connect to the web and download the following updates and documents to get started:

 

If you have any of these RTU models running C3413-500-001YZ firmware, SAGE 1310, 1330, 1350, 2300, 3030, 3103, get the following file from the SAGE RTU Downloads page:

 

C3413-500-001F0_PB_Update_Files.zip - contains updates to the GUI web pages for this version of application.

 

If you have any of these RTU models running C3414-500-001YZ firmware, SAGE 1410, 1430, 1450, 2400, 3030M, LANDAC II, get the following file from the SAGE RTU Downloads page:

 

C3414-500-001G3_P6_Update_Files.zip - contains updates to GUI web pages for this version of application.

 

If you have any of these RTU models running C3414-500-S02YZ firmware, SAGE 1410, 1430, 1450, 2400, 3030M, LANDAC II, there are no firmware updates, just browser configuration.

 

You will need the following document: from the SAGE page FAQ section of this web site (put the following string in the search box to find it quickly):

 

SAGE Firmware & Internet Explorer Config

 

You will need one of the following documents depending on the version of Internet Explorer you are using from the SAGE page FAQ section of this web site. The version number in the name may change if the documents are revised.

 

Config@web_IE8_settings_V1.1.pdf

Config@web_IE9_settings_V1.1.pdf

Config@web_IE10_settings_V1.1.pdf

Config@web_IE11_settings_V1.2.pdf

 

If you follow the directions in these manuals, you will be able to browse and Up/Download the configurations for the RTU as you have in the past using your old Windows XP machine.

Heartbleed

Posted by duaneg Apr 29, 2014

 

The Sage RTUs are not affected by the Heartbleed bug.

 

Our RTU does not use OpenSSL v 1.01-1.01f.

 

We also tested our RTU with latest Nessus add-ons to detect this vulnerability and passed.

 

ICS-CERT and DNP

Posted by duaneg Feb 11, 2014

Many of you may have seen the ICS-CERT notifications regarding DNP issues and how they can result in a "Denial of Service" attack. The Secure Firmware available for download on this site fixes the currently known vulnerabilities with DNP as well as providing the latest secure functionality for the SAGE product line.

The latest version of the data trap analyzer program is available in the download access. Fixes some minor bugs found in the last version.

ISaGRAF on Windows 7

Posted by duaneg Oct 21, 2013

Moving onto Window 7 and having trouble installing ISaGRAF? See the new document in the White Papers link. (right hand side under "Must Reads"

Active X issues

Posted by duaneg Oct 21, 2013

If you are having issues with ActiveX controls, check out the Active X document published in the FAQ (Left hand side under "Information")

Check out the RSS feed function

Posted by duaneg Oct 18, 2013

The RSS feed is a feature that lets you know when something on the web site has been added. If you have ever visited our site only to find that there is nothing new of interest or missed notice of a feature or function that could have been helpful, subscribe to the RSS Feed. It lets you know when something is new so that you can check it out when you have some spare time. Give it a try!

Off-line Configuration Tool

Posted by duaneg Sep 6, 2013

If you have ever wished there was a tool for viewing a configuration or making modifications to the SAGE units without having to be physically connected to one, your wish has come true! The SAGE Off-Line Configuration Tool is now available. The tool requires only a USB dongle to give you the same capabilities for viewing and changing an RTU's configuration that you have when connected to a SAGE unit. Contact your local Rep or Debbie Gierman at 713-920-6897 debbie.gierman@schneider-electric.com for more information.

Here you will find helpful information, manuals, drawings, white papers and the latest Firmware for all the SAGE products. Additionally you can ask questions and dialog with other users about anything. We hope you will find this new interactive forum useful and informative. Dive in!

RTU Training

Posted by duaneg Aug 14, 2013

If you are interesting in getting SAGE RTU training, it's not too late! The next class will be held the week of November 11th. This will be a three day training on the SAGE units held in Houston and is open to all users. The cost is $1625 per person. If you are interested and would like more details, contact Giselle Doss at 713-920-6886.

Blog Site Updates

Posted by duaneg Aug 14, 2013

Looking for a way to get notified whenever there is a new post on this site? Subscribe to the RSS Feed and you will be able to see that there is a new post whenever you open your browser and view your "Favorites" links. RSS will "bold" the link signifying there is a new post available. Check it out!

Boolean Status App

Posted by duaneg Aug 14, 2013

Want to “OR” alarm points to create a higher level alarm? Boolean Status is an application available in all SAGE RTUs that allows the user to create “And, Or, Nor, Nand, and Xor” gates without using the (IEC 61131 RLL) Ladder Logic Engine. This easy to use application makes it easy to build logic gates.