Executive brief
A security vulnerability has been identified in Schneider Electric products where the system uses weak or predictable session identifiers. This flaw could allow an unauthorized person on the network to guess or hijack a user's active session. If exploited, an attacker could gain unauthorized access to the device's management interface, potentially leading to unauthorized configuration changes or disruption of operations.
Technical details
An insufficient entropy vulnerability (CWE-331) exists within the session management protections of affected Schneider Electric products. The root cause is the generation of session identifiers or security tokens with low randomness, making them susceptible to prediction or brute-force attacks. A network-based attacker can exploit these weaknesses to bypass authentication and gain unauthorized access to the system. According to the CVSS 4.0 vector, the attack requires some user interaction (UI:P) but no prior privileges (PR:N). Successful exploitation could result in high impacts on confidentiality and integrity.
Affected products
- Schneider Electric Schneider Electric Products
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory