Executive brief
A Schneider Electric product contains an argument injection vulnerability in its backup configuration feature. An attacker with administrative privileges can inject malicious arguments to execute arbitrary code on the system, potentially compromising operational technology infrastructure and connected systems.
Technical details
The vulnerability is a CWE-88 argument injection flaw in backup configuration parameter handling. An authenticated attacker with elevated privileges can supply specially crafted arguments to the backup configuration functionality to inject commands. The vulnerability requires a privileged account to exploit, limiting the attack surface to insider threats or scenarios where admin credentials have been compromised. Successful exploitation allows arbitrary remote code execution on the affected system.
Affected products
- Schneider Electric <UNKNOWN>
Timeline
- 2026-09-09: disclosed