{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/scadapack-32/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-81861"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SCADAPack 47x","SCADAPack 47xi","SCADAPack 47xd","SCADAPack 470R","SCADAPack 57x","SCADAPack 3xx","SCADAPack 32"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","industrial-control-systems","critical-infrastructure"],"_cs_type":"advisory","_cs_vendors":["Schneider Electric"],"content_html":"\u003cp\u003eSchneider Electric has identified an insufficiently protected credentials vulnerability, tracked as CVE-2026-81861, affecting multiple models in the SCADAPack x70 series of Remote Terminal Units (RTUs). This flaw resides within the legacy 'Secure Lock' feature, which was designed for backward compatibility with older deployments. If an attacker leverages this weakness, they could potentially gain unauthorized access to RTU configuration information, resulting in a loss of confidentiality. The vulnerability affects a wide range of devices, including the SCADAPack 47x, 47xi, 47xd, 470R, 57x, 3xx, and 32 models. Schneider Electric advises users to prioritize the transition to Role-Based Access Control (RBAC) mechanisms, which provide more robust security, and to restrict access to these devices through network segmentation and firewall implementation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a risk to critical infrastructure sectors, specifically Energy and Critical Manufacturing. Successful exploitation allows unauthorized parties to bypass intended access controls for RTU configuration, potentially leading to unauthorized visibility into sensitive operational control parameters. The impact is primarily categorized as a loss of confidentiality regarding the device configuration and authentication artifacts.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePrioritize migrating from the 'Secure Lock' feature to Role-Based Access Control (RBAC) as described in the SCADAPack Cybersecurity Guide.\u003c/li\u003e\n\u003cli\u003eImplement strict network segmentation to isolate control system networks from untrusted business networks.\u003c/li\u003e\n\u003cli\u003eEnable and configure the built-in RTU firewall service to minimize the attack surface of the affected devices.\u003c/li\u003e\n\u003cli\u003eEnsure all SCADAPack devices are stored in physically secure, locked cabinets to prevent unauthorized local or peripheral access.\u003c/li\u003e\n\u003cli\u003eReview the Schneider Electric security advisory SEVD-2026-251-03 for detailed hardening procedures and administrative security guidelines.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-15T16:31:30Z","date_published":"2026-09-15T16:31:30Z","id":"https://feed.craftedsignal.io/briefs/2026-09-schneider-scadapack-vuln/","summary":"Schneider Electric SCADAPack x70 series RTUs contain a vulnerability (CVE-2026-81861) in the legacy 'Secure Lock' functionality that could lead to unauthorized exposure of authentication information.","title":"Insufficiently Protected Credentials Vulnerability in Schneider Electric SCADAPack x70","url":"https://feed.craftedsignal.io/briefs/2026-09-schneider-scadapack-vuln/"}],"language":"en","title":"CraftedSignal Threat Feed - SCADAPack 32","version":"https://jsonfeed.org/version/1.1"}