Schneider Electric SCADAPack x70 Products

Summary

Schneider Electric has identified a vulnerability, CVE-2026-81861, affecting its SCADAPack x70 line of Remote Terminal Units. This vulnerability could lead to unauthorized access to RTU configuration and a loss of confidentiality due to insufficiently protected credentials. Mitigation involves implementing the Role-Based Access Control (RBAC) feature.

IFF Assessment

FOE

This vulnerability allows for unauthorized access to critical industrial control system configurations, posing a significant risk to operational integrity.

Severity

6.5 Medium

The CVSS score of 6.5 is attributed to the 'Insufficiently Protected Credentials' vulnerability, which allows for unauthorized access and potential loss of confidentiality, impacting availability and integrity.

Defender Context

This alert highlights a critical vulnerability in industrial control systems (ICS) used in energy and manufacturing sectors. Defenders should prioritize patching or applying mitigations for SCADAPack x70 products to prevent unauthorized access and potential disruption of essential services.

Read Full Story →