Vulnerabilities
Schneider Electric SCADAPack x70 RTU Vulnerability (CVE‑2026‑81861) – Urgent RBAC Migration Needed
Schneider Electric’s SCADAPack x70 series – including the 47x, 47xi, 47xd, 470R, 57x, 3xx, and 32 models – is affected by CVE‑2026‑81861. The flaw stems from insufficiently protected credentials that allow attackers to hijack the Secure Lock feature and gain unauthorized access to RTU configuration. The vulnerability carries a CVSS score of 6.5 and threatens critical manufacturing and energy infrastructures worldwide. Immediate remediation requires disabling legacy Secure Lock, enabling Role‑Based Access Control (RBAC), and applying standard hardening measures such as network segmentation and
Schneider Electric has identified a credential‑management flaw in its SCADAPack x70 Remote Terminal Units (RTUs). The issue, catalogued as CVE‑2026‑81861, allows an attacker to exploit the legacy Secure Lock function and gain unauthorized control over RTU settings. The vulnerability is present in all firmware versions of the following models: 47x, 47xi, 47xd, 470R, 57x, 3xx, and 32.
Impact
- Unauthorized modification of RTU configuration
- Potential loss of confidentiality and integrity for critical infrastructure
- Risk to manufacturing, energy, and other sectors that rely on SCADA systems
Remediation Guidance
- Immediately replace the Secure Lock feature with the recommended Role‑Based Access Control (RBAC) mechanism. Follow Schneider Electric’s SCADAPack documentation on “Security Guidelines for Administrators” and “Working with Role‑Based Access Control.”
- Disable or remove the Secure Lock functionality unless legacy compatibility absolutely requires it.
- Apply the SCADAPack Cybersecurity Guide, focusing on the “Hardening” and “Secured Communication” sections.
- Implement network segmentation to isolate RTUs from untrusted networks.
- Enable and enforce secure communication protocols for all RTU traffic.
“The Secure Lock feature is legacy functionality retained for backward compatibility and should only be used where required to support legacy system requirements.”
Given the CVSS score of 6.5 and the widespread deployment of these devices, operators must act swiftly to mitigate the risk. Failure to apply these controls could expose sensitive operational data and disrupt critical industrial processes.