Executive brief
Schneider Electric SCADAPack controllers and RemoteConnect software are affected by a critical vulnerability in their handling of Modbus TCP communications. These devices are typically used in industrial environments to monitor and control critical infrastructure like water or power systems. A successful exploit could allow an attacker to remotely shut down the equipment, steal sensitive operational data, or take full control of the device's operations.
Technical details
A vulnerability classified as CWE-754 (Improper Check for Unusual or Exceptional Conditions) exists within the Modbus TCP protocol implementation of Schneider Electric SCADAPack 47x/57x series and RemoteConnect software. The flaw is triggered during the processing of Modbus TCP communications, where the system fails to properly handle specific exceptional conditions. A remote, unauthenticated attacker can exploit this over the network to achieve arbitrary code execution, cause a denial of service (DoS) condition, or compromise the confidentiality and integrity of the system. Schneider Electric has released firmware updates (R3.4.2 / 9.12.2) to address the issue for most affected models.
Affected products
- Schneider Electric SCADAPack 47x Prior to R3.4.2 (Firmware prior to 9.12.2)
- Schneider Electric SCADAPack 47xi Prior to R3.4.2 (Firmware prior to 9.12.2)
- Schneider Electric SCADAPack 57x All versions
- Schneider Electric RemoteConnect Prior to R3.4.2
Timeline
- 2026-07-29: disclosed
- 2026-07-29: advisory