<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>SCADAPack 3xx - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/scadapack-3xx/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 15 Sep 2026 16:31:30 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/scadapack-3xx/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Insufficiently Protected Credentials Vulnerability in Schneider Electric SCADAPack x70</title><link>https://feed.craftedsignal.io/briefs/2026-09-schneider-scadapack-vuln/</link><pubDate>Tue, 15 Sep 2026 16:31:30 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-schneider-scadapack-vuln/</guid><description>Schneider Electric SCADAPack x70 series RTUs contain a vulnerability (CVE-2026-81861) in the legacy 'Secure Lock' functionality that could lead to unauthorized exposure of authentication information.</description><content:encoded><![CDATA[<p>Schneider Electric has identified an insufficiently protected credentials vulnerability, tracked as CVE-2026-81861, affecting multiple models in the SCADAPack x70 series of Remote Terminal Units (RTUs). This flaw resides within the legacy 'Secure Lock' feature, which was designed for backward compatibility with older deployments. If an attacker leverages this weakness, they could potentially gain unauthorized access to RTU configuration information, resulting in a loss of confidentiality. The vulnerability affects a wide range of devices, including the SCADAPack 47x, 47xi, 47xd, 470R, 57x, 3xx, and 32 models. Schneider Electric advises users to prioritize the transition to Role-Based Access Control (RBAC) mechanisms, which provide more robust security, and to restrict access to these devices through network segmentation and firewall implementation.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability poses a risk to critical infrastructure sectors, specifically Energy and Critical Manufacturing. Successful exploitation allows unauthorized parties to bypass intended access controls for RTU configuration, potentially leading to unauthorized visibility into sensitive operational control parameters. The impact is primarily categorized as a loss of confidentiality regarding the device configuration and authentication artifacts.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Prioritize migrating from the 'Secure Lock' feature to Role-Based Access Control (RBAC) as described in the SCADAPack Cybersecurity Guide.</li>
<li>Implement strict network segmentation to isolate control system networks from untrusted business networks.</li>
<li>Enable and configure the built-in RTU firewall service to minimize the attack surface of the affected devices.</li>
<li>Ensure all SCADAPack devices are stored in physically secure, locked cabinets to prevent unauthorized local or peripheral access.</li>
<li>Review the Schneider Electric security advisory SEVD-2026-251-03 for detailed hardening procedures and administrative security guidelines.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>vulnerability</category><category>industrial-control-systems</category><category>critical-infrastructure</category></item></channel></rss>