Executive brief
Schneider Electric EcoStruxure Panel Servers, which are used to manage and monitor electrical distribution systems, contain a vulnerability that can cause security credentials to revert to their factory default settings. This could allow an unauthorized person to log into the device using well-known default passwords. Successful exploitation could lead to the exposure of sensitive operational data and unauthorized access to the management interface.
Technical details
A CWE-1188 (Initialization of a Resource with an Insecure Default) vulnerability exists in Schneider Electric EcoStruxure Panel Server firmware. Under specific rare circumstances, the device may revert its authentication credentials to initial factory settings. An unauthenticated attacker with network access to the device can exploit this by using known default credentials to gain unauthorized access. This can lead to the disclosure of sensitive information stored on or managed by the panel server. The issue is addressed in firmware version 002.006.000 and later.
Affected products
- Schneider Electric EcoStruxure Panel Server PAS400 Versions prior to 002.006.000
- Schneider Electric EcoStruxure Panel Server PAS600 Versions prior to 002.006.000
- Schneider Electric EcoStruxure Panel Server PAS600V2 Versions prior to 002.006.000
- Schneider Electric EcoStruxure Panel Server PAS800 Versions prior to 002.006.000
- Schneider Electric EcoStruxure Panel Server PAS800V2 Versions prior to 002.006.000
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory