Kwetsbaarheden worden geladen…
Kwetsbaarheden worden geladen…
CVE-2026-9650
CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenticated attacker accesses credentials stored within firmware or system files. With this credential an attacker could subsequently compromise the device if they have physical access to the device.
Dit record: live koppeling — laatst opgehaald: 25 juli 2026 om 01:36.
Leverancier
Schneider Electric
Product
EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller
Gepubliceerd
25 juli 2026
Laatst gewijzigd
25 juli 2026
CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenticated attacker accesses credentials stored within firmware or system files. With this credential an attacker could subsequently compromise the device if they have physical access to the device.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack vector
NETWORK
Privileges required
NONE
User interaction
NONE
Vertrouwelijkheid
Hoog
Integriteit
Geen
Beschikbaarheid
Geen
Beperkte impact op beschikbaarheid; risico ligt vooral bij vertrouwelijkheid of integriteit van procesdata.
Beoordeeld als relevant voor de energiesector op basis van: Vermeld in een officiële CISA ICS Advisory, wat directe relevantie voor industriële besturingssystemen bevestigt. Productbeschrijving komt overeen met de categorie "RTU", een typisch OT/ICS-componenttype. Leverancier "Schneider Electric" is een bekende leverancier van apparatuur voor de energiesector.
Version 11.06.32 of EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller includes a fix for these vulnerabilities and is available:• Contact Schneider Electric’s Customer Care Center to download this firmware.• Reboot needed: Yes.
IACS Radar-duiding
Automatisch geclassificeerd als industrieel relevant op basis van CISA/NVD-signalen (zie redenen).
Geclassificeerd door IACS Radar-analysepijplijn (geautomatiseerd) op 25 juli 2026.
IACS Radar-duiding
IEC 62443-mapping
Automatische IACS Radar-duiding op basis van de gerapporteerde CWE-zwakteclassificatie; geen officiële certificeringsuitspraak.