CVE-2026-81861: CWE-522: Insufficiently Protected Credentials in Schneider Electric SCADAPack 47x
CVE-2026-81861 is a medium severity vulnerability in Schneider Electric SCADAPack 47x devices involving insufficient protection of credentials. This weakness could lead to exposure of authentication information, potentially allowing unauthorized access to the remote terminal unit (RTU) functionality. No specific affected versions or patches are currently identified.
AI Analysis
Technical Summary
This vulnerability, classified as CWE-522 (Insufficiently Protected Credentials), affects Schneider Electric SCADAPack 47x devices. It involves inadequate protection of authentication credentials, which could result in their exposure and unauthorized access to RTU functions. The CVSS 4.0 base score is 5.9, indicating a medium severity level. There is no information on affected versions or available patches, and no known exploits in the wild have been reported.
Potential Impact
If exploited, this vulnerability could allow attackers to obtain authentication credentials and gain unauthorized access to the SCADAPack 47x RTU functionality. This could compromise the integrity and availability of the affected devices. However, no active exploitation has been reported to date.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until official fixes are available, monitor Schneider Electric advisories for updates and apply recommended security controls specific to credential protection as advised by the vendor.
CVE-2026-81861: CWE-522: Insufficiently Protected Credentials in Schneider Electric SCADAPack 47x
Description
CVE-2026-81861 is a medium severity vulnerability in Schneider Electric SCADAPack 47x devices involving insufficient protection of credentials. This weakness could lead to exposure of authentication information, potentially allowing unauthorized access to the remote terminal unit (RTU) functionality. No specific affected versions or patches are currently identified.
CVSS v4.0
Score 5.9medium
Affected software
Schneider Electric
SCADAPack 47x
Schneider Electric
SCADAPack 47xi
Schneider Electric
SCADAPack 47xd
Schneider Electric
SCADAPack 470R
Schneider Electric
SCADAPack 57x
Schneider Electric
SCADAPack 3xx
Schneider Electric
SCADAPack 32
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability, classified as CWE-522 (Insufficiently Protected Credentials), affects Schneider Electric SCADAPack 47x devices. It involves inadequate protection of authentication credentials, which could result in their exposure and unauthorized access to RTU functions. The CVSS 4.0 base score is 5.9, indicating a medium severity level. There is no information on affected versions or available patches, and no known exploits in the wild have been reported.
Potential Impact
If exploited, this vulnerability could allow attackers to obtain authentication credentials and gain unauthorized access to the SCADAPack 47x RTU functionality. This could compromise the integrity and availability of the affected devices. However, no active exploitation has been reported to date.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until official fixes are available, monitor Schneider Electric advisories for updates and apply recommended security controls specific to credential protection as advised by the vendor.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- schneider
- Date Reserved
- 2026-08-27T16:49:45.578Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aa41f3091cc7f384856d456
Added to database: 09/11/2026, 15:33:04 UTC
Last enriched: 09/11/2026, 15:47:52 UTC
Last updated: 09/11/2026, 16:41:51 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.