logo

Critical 9.8 CVSS Schneider Electric Flaw Exposes SCADA and Data Center Systems

ID: 2e9465b1-5426-5f05-bc4e-e832b5a290a7

STIX ID: report--2e9465b1-5426-5f05-bc4e-e832b5a290a7

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-03-18

Date Updated: 2026-04-23

Author: Ddos

...
...

Schneider Electric disclosed two significant vulnerabilities: CVE-2026-0667 (CVSS 9.8) affecting SCADAPack x70 RTUs that may allow denial of service or remote code execution over Modbus TCP, and CVE-2025-13957 (CVSS 7.2) in EcoStruxure IT Data Center Expert involving hard-coded credentials exploitable under specific conditions; vendor patches and configuration mitigations are available (Firmware R3.4.2 / Version 9.1, RTU firewall, disable logic debug, keep SOCKS Proxy disabled).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.