Schneider Electric is aware of a vulnerability in its SCADAPack x70 products. The SCADAPack 47x, SCADAPack 47xi, SCADAPack 47xd, SCADAPack 470R and SCADAPack 57x products are Remote Terminal Units that provide communication capabilities for remote monitoring and control. Failure to apply the mitigations provided below may increase the risk of unauthorized access to RTU configuration through the Secure Lock functionality, potentially resulting in a loss of confidentiality.
The following versions of Schneider Electric SCADAPack x70 Products are affected:
- SCADAPack 47x vers:all/* (CVE-2026-81861)
- SCADAPack 47xi vers:all/* (CVE-2026-81861)
- SCADAPack 47xd vers:all/* (CVE-2026-81861)
- SCADAPack 470R vers:all/* (CVE-2026-81861)
- SCADAPack 57x vers:all/* (CVE-2026-81861)
- SCADAPack 3xx vers:all/* (CVE-2026-81861)
- SCADAPack 32 vers:all/* (CVE-2026-81861)
The vulnerability is classified as an insufficiently protected credentials issue (CWE-522). A successful exploit could result in exposure of authentication information and unauthorized access to RTU functionality. Schneider Electric has assigned a CVSS v3.1 base score of 6.5, rating the severity as MEDIUM.
The CVSS vector string is: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Schneider Electric recommends the following mitigations:
- Implement the Role-Based Access Control (RBAC) feature and follow the SCADAPack documentation sections Security Guidelines for Administrators and Working with Role-Based Access Control. RBAC is the recommended access control mechanism for SCADAPack 47x devices and should be used in place of the Secure Lock feature.
- Configure network segmentation to restrict access between trusted and untrusted networks.
- Enable and implement the RTU firewall service to restrict unauthorized access to device services and reduce the attack surface.
- Consult the SCADAPack Cybersecurity Guide, including the SCADAPack Hardening and Secured Communication sections.
Relevant CWE: CWE-522 Insufficiently Protected Credentials
Schneider Electric strongly recommends the following industry cybersecurity best practices:
- Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network.
- Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks.
- Place all controllers in locked cabinets and never leave them in the "Program" mode.
- Never connect programming software to any network other than the network intended for that device.
- Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks.
- Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation.
For more information, see the associated Schneider Electric security advisory SEVD-2026-251-03.