news.mlab.sh
Back to the feed
vulnerability

Schneider Electric SCADAPack x70 Products

MediumCVSS 5.9
Summary

Schneider Electric has identified a critical vulnerability (CVE-2026-81861) in its SCADAPack x70 products, specifically the SCADAPack 47x, 47xi, 47xd, 470R, and 57x families. This vulnerability, an insufficiently protected credentials issue, could allow unauthorized access to RTU configuration through the Secure Lock functionality. Mitigation involves implementing Role-Based Access Control (RBAC) and utilizing the RTU firewall service, replacing the legacy Secure Lock feature. Schneider Electric strongly recommends implementing industry best practices for industrial control systems security, including network segmentation and minimizing exposure to the internet.

Schneider Electric is aware of a critical vulnerability in its SCADAPack x70 products, specifically the SCADAPack 47x, 47xi, 47xd, 470R, and 57x families. The vulnerability, identified as CVE-2026-81861, is an insufficiently protected credentials issue that could lead to exposure of authentication information and unauthorized access to RTU (Remote Terminal Unit) functionality. This vulnerability can be exploited through the Secure Lock functionality, a legacy feature retained for backward compatibility.

Affected Products: Schneider Electric SCADAPack x70 Products (SCADAPack 47x, SCADAPack 47xi, SCADAPack 47xd, SCADAPack 470R, SCADAPack 57x, SCADAPack 3xx, SCADAPack 32).

Schneider Electric recommends implementing the Role-Based Access Control (RBAC) feature as the primary access control mechanism for SCADAPack 47x devices, replacing the Secure Lock feature. The Secure Lock feature should only be used where required to support legacy system requirements.

To mitigate this vulnerability, Schneider Electric advises the following:

  • Implement RBAC.
  • Utilize the RTU firewall service to restrict unauthorized access to device services.
  • Configure network segmentation to isolate control systems from business networks.
  • Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.
  • When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing that VPNs may have vulnerabilities and should be updated to the most recent version available.
  • Locate control system networks and remote devices behind firewalls.
  • Never leave controllers in the “Program” mode.
  • Never connect programming software to any network other than the network intended for that device.
  • Scan all methods of mobile data exchange with the isolated network before use.
  • Never allow mobile devices that have connected to any other network to connect to safety or control networks without proper sanitation.

Schneider Electric strongly recommends implementing industry cybersecurity best practices, as detailed in the Schneider Electric Recommended Cybersecurity Best Practices document, and can be found at: https://www.se.com/ww/en/work/solutions/cybersecurity/.

For more information and assistance, contact your local Schneider Electric representative or Schneider Electric Industrial Cybersecurity Services: https://www.se.com/ww/en/work/solutions/cybersecurity/. A vendor advisory (SEVD-2026-251-03) is available at: https://www.cisa.gov/notification.

CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Read the full article at CISA Advisories