Critical 9.8 CVSS Schneider Electric Flaw Exposes SCADA and Data Center Systems
ID: 2e9465b1-5426-5f05-bc4e-e832b5a290a7
STIX ID: report--2e9465b1-5426-5f05-bc4e-e832b5a290a7
Feed Name: securityonline.info
Schneider Electric disclosed two significant vulnerabilities: CVE-2026-0667 (CVSS 9.8) affecting SCADAPack x70 RTUs that may allow denial of service or remote code execution over Modbus TCP, and CVE-2025-13957 (CVSS 7.2) in EcoStruxure IT Data Center Expert involving hard-coded credentials exploitable under specific conditions; vendor patches and configuration mitigations are available (Firmware R3.4.2 / Version 9.1, RTU firewall, disable logic debug, keep SOCKS Proxy disabled).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
