Insufficiently Protected Credentials Vulnerability (CVE‑2026‑81861) in Schneider Electric SCADAPack x70 RTUs Risks Unauthorized Access
What It Is – Schneider Electric disclosed CVE‑2026‑81861, a vulnerability in the SCADAPack x70 family of Remote Terminal Units (RTU) that stores authentication data without adequate protection. An attacker who obtains the credentials could modify RTU configuration or read telemetry.
Exploitability – CVSS v3 6.5 (Medium). No public exploit has been observed, but the flaw is exploitable remotely once credentials are compromised.
Affected Products – SCADAPack 47x, 47xi, 47xd, 470R, 57x, 3xx, 32 (all firmware versions).
Why It Matters for Trust & Control Assurance
- Demonstrates the need for robust access‑control processes that protect credential storage on OT devices.
- Continuous monitoring of configuration changes and credential usage provides defensible evidence for auditors and enterprise buyers.
- Mitigating this flaw aligns with the control objective of “protecting authentication information” that underpins many frameworks (e.g., NIST CSF 2.0 Identify & Protect).
Recommended Actions – Apply Schneider’s mitigation guidance immediately, rotate all RTU credentials, enforce strong authentication (e.g., MFA or certificate‑based), segment OT networks, enable logging of credential‑related events, and document the remediation in your control‑evidence repository. Source: CISA Advisory