Junglewise Threat Intelligence

CVE-2026-0667: Schneider Electric SCADAPack code execution in Modbus TCP protocol handling

CVE-2026-0667 · Severity: info · CVSS 9.3 · Published 2026-07-29

Executive brief

Schneider Electric SCADAPack controllers and RemoteConnect software are affected by a critical vulnerability in their handling of Modbus TCP communications. These devices are typically used in industrial environments to monitor and control critical infrastructure like water or power systems. A successful exploit could allow an attacker to remotely shut down the equipment, steal sensitive operational data, or take full control of the device's operations.

Technical details

A vulnerability classified as CWE-754 (Improper Check for Unusual or Exceptional Conditions) exists within the Modbus TCP protocol implementation of Schneider Electric SCADAPack 47x/57x series and RemoteConnect software. The flaw is triggered during the processing of Modbus TCP communications, where the system fails to properly handle specific exceptional conditions. A remote, unauthenticated attacker can exploit this over the network to achieve arbitrary code execution, cause a denial of service (DoS) condition, or compromise the confidentiality and integrity of the system. Schneider Electric has released firmware updates (R3.4.2 / 9.12.2) to address the issue for most affected models.

Affected products

  • Schneider Electric SCADAPack 47x Prior to R3.4.2 (Firmware prior to 9.12.2)
  • Schneider Electric SCADAPack 47xi Prior to R3.4.2 (Firmware prior to 9.12.2)
  • Schneider Electric SCADAPack 57x All versions
  • Schneider Electric RemoteConnect Prior to R3.4.2

Timeline

  • 2026-07-29: disclosed
  • 2026-07-29: advisory

References

Related threats