Junglewise Threat Intelligence

CVE-2026-81861: Schneider Electric SCADAPack x70 insufficiently protected credentials

CVE-2026-81861 · Severity: high · CVSS 6.5 · Published 2026-09-15

Executive brief

Schneider Electric SCADAPack Remote Terminal Units (RTUs) are industrial devices used in critical infrastructure sectors like manufacturing and energy to enable remote monitoring and control of critical systems. A weakness in the Secure Lock security feature fails to adequately protect credentials, potentially allowing attackers to bypass authentication and gain unauthorized access to RTU configuration. This could lead to exposure of sensitive authentication data and unauthorized control over industrial systems, impacting operational safety and confidentiality.

Technical details

This vulnerability is classified as CWE-522 (Insufficiently Protected Credentials), affecting the legacy Secure Lock functionality in Schneider Electric SCADAPack x70 products. The vulnerability allows exposure of authentication information and unauthorized access to RTU functionality through inadequate credential protection mechanisms. The attack vector is network-based with no authentication required but does require user interaction (PR:N, UI:R), as indicated by the CVSS v3.1 vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N. The impact is limited to confidentiality (high) with no integrity or availability impact. Schneider Electric recommends implementing Role-Based Access Control (RBAC) as a replacement for the legacy Secure Lock feature, and applying network segmentation and RTU firewall controls to restrict access and reduce attack surface. No patch is available; mitigation relies on configuration changes and architectural controls.

Affected products

  • Schneider Electric SCADAPack 47x all versions
  • Schneider Electric SCADAPack 47xi all versions
  • Schneider Electric SCADAPack 47xd all versions
  • Schneider Electric SCADAPack 470R all versions
  • Schneider Electric SCADAPack 57x all versions
  • Schneider Electric SCADAPack 3xx all versions
  • Schneider Electric SCADAPack 32 all versions

Timeline

  • 2026-09-15: disclosed: CISA ICS Advisory ICSA-26-258-04 published

References

Related threats