Executive brief
Schneider Electric EcoStruxure™ Cybersecurity Admin Expert, a tool used to manage security settings across industrial devices, contains a vulnerability in how it stores and protects sensitive credentials. A local attacker with high-level system privileges could exploit this weakness to bypass authentication or modify credentials. This could lead to a total loss of control over the managed industrial devices, potentially impacting operational safety and availability.
Technical details
A CWE-522 (Insufficiently Protected Credentials) vulnerability exists in Schneider Electric EcoStruxure™ Cybersecurity Admin Expert v4.2.0 and prior. The flaw stems from weaknesses in the handling and protection of stored credentials within the application database or configuration files. A local attacker who already possesses high privileges on the host system can leverage these weaknesses to bypass authentication mechanisms or perform unauthorized credential modifications. Successful exploitation grants the attacker the ability to compromise devices managed by the software. The vulnerability is tracked under Schneider Electric advisory SEVD-2026-195-02.
Affected products
- Schneider Electric EcoStruxure™ Cybersecurity Admin Expert v4.2.0 and prior
Timeline
- 2026-07-29: disclosed: Initial disclosure by Schneider Electric
- 2026-07-29: advisory: NVD publication date