Executive brief
Schneider Electric industrial controllers contain a security flaw where sensitive login credentials are not properly protected within the device's internal files. An attacker could potentially discover these credentials and use them to gain unauthorized access to the equipment. If an attacker also has physical access to the device, they could use this information to fully compromise the controller, potentially disrupting industrial operations or accessing sensitive data.
Technical details
A CWE-522 (Insufficiently Protected Credentials) vulnerability exists in the firmware and system files of Schneider Electric EasyLogic T150 and Saitel DP Remote Terminal Units (RTUs). An unauthenticated attacker can access credentials stored within these files over the network. While the initial exposure provides sensitive information, full device compromise requires the attacker to have physical access to the hardware to utilize the recovered credentials. The vulnerability affects EasyLogic T150 versions 11.06.30 and prior, and Saitel DP versions 11.06.35 and prior.
Affected products
- Schneider Electric EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller Version 11.06.30 and prior
- Schneider Electric Saitel DP Remote Terminal Unit & Controller Version 11.06.35 and prior
Timeline
- 2026-06-25: disclosed: Initial disclosure by Schneider Electric and NVD publication.