<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_se/10</id>
  <title>Most recent entries from csaf_se</title>
  <updated>2026-10-03T03:51:14.452297+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2026-251-04</id>
    <title>SEVD-2026-251-04 — Incorrect Implementation of Authentication Algorithm vulnerability on Modicon M580 and Modicon M580 Safety</title>
    <updated>2026-09-08T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of a vulnerability in its Modicon M580 and Modicon M580 Safety controllers. 
The Modicon M580 is an Ethernet-based Programmable Automation Controller (ePAC) designed for industrial digital transformation.
Failure to apply the remediations provided below may risk establishing an unauthenticated connection to Modicon M580 or M580 Safety controllers which could result in loss of confidentiality, integrity and availability of the PLC.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2026-251-04"/>
    <published>2026-09-08T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2026-251-03</id>
    <title>SEVD-2026-251-03 — Insufficiently Protected Credentials vulnerability on SCADAPack x70 Products</title>
    <updated>2026-09-08T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of a vulnerability in its SCADAPack x70 products. The SCADAPack 47x, SCADAPack 47xi, SCADAPack 47xd, SCADAPack 470R and SCADAPack 57x products are Remote Terminal Units that provide communication capabilities for remote monitoring and control. Failure to apply the mitigations provided below may increase the risk of unauthorized access to RTU configuration through the Secure Lock functionality, potentially resulting in a loss of confidentiality.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2026-251-03"/>
    <published>2026-09-08T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2026-251-02</id>
    <title>SEVD-2026-251-02 — Improper Neutralization of Special Elements used in an OS Command vulnerability on PowerLogic T300</title>
    <updated>2026-09-08T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of a vulnerability in the Head Unit (HU250) for the PowerLogic T300 RTU (Remote 
Terminal Unit) (formerly Easergy T300 RTU).  
The [PowerLogic T300 RTU](https://www.se.com/ww/en/product-range/62399-easergy-t300) is a modular platform for medium voltage and low voltage public distribution 
network management.  
Failure to apply the remediation provided below may risk privilege escalation, which could result in 
unauthorized takeover of the device.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2026-251-02"/>
    <published>2026-09-08T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2026-251-01</id>
    <title>SEVD-2026-251-01 — Multiple Vulnerabilities on EcoStruxure IT Data Center Expert</title>
    <updated>2026-09-08T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of its vulnerability in its EcoStruxure IT Data Center Expert product 
The EcoStruxure IT Data Center Expert product is a scalable monitoring software that collects, organizes,and distributes critical device information providing a comprehensive view of equipment. 
Failure to apply the remediation provided below may risk information disclosure and remote compromise of the offer which could result in disruption of operations and access to system data.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2026-251-01"/>
    <published>2026-09-08T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2026-223-02</id>
    <title>SEVD-2026-223-02 — Multiple Vulnerabilities on NetBotz 5 750/755 Products</title>
    <updated>2026-08-11T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of multiple vulnerabilities in its NetBotz 5 – 750/755 products.The NetBotz 5 – 750/755 products are security and environmental monitors providing temperature, humidity, leak, smoke, vibration, door contact, and video monitoring capabilities.Failure to apply the remediation provided below may risk arbitrary or remote code execution over the local network, which could result in device manipulation and unauthorized data access.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2026-223-02"/>
    <published>2026-08-11T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2026-223-01</id>
    <title>SEVD-2026-223-01 — Improper Restriction of Excessive Authentication Attempts vulnerability on PowerChute Serial Shutdown</title>
    <updated>2026-08-11T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of vulnerabilities in its PowerChute™ Serial Shutdown product. 
The PowerChute Serial Shutdown product is a UPS management software enabling graceful system shutdown and energy management capabilities for desktops, servers and workstations. 
Failure to apply the remediation provided below may risk improper authentication validation which could result in disruption of operations and access to system data.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2026-223-01"/>
    <published>2026-08-11T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2026-195-02</id>
    <title>SEVD-2026-195-02 — Insufficiently Protected Credentials vulnerability on EcoStruxure™ Cybersecurity Admin Expert</title>
    <updated>2026-07-14T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of a vulnerability in its EcoStruxure™ Cybersecurity Admin Expert  product (CAE).  
The [EcoStruxure™ Cybersecurity Admin Expert](https://www.se.com/ww/en/product-country-selector/?pageType=product-range&amp;sourceId=63515) product is a configurator for managing cybersecurity in your 
electrical network’s operational technology (OT). It is an intuitive, software-based tool used for multiple 
administration purposes. 
Failure to apply the remediation provided below may risk an authentication bypass and privilege escalation 
attack, which could result in unauthorized access to application accounts, manipulation of credentials, and 
potential compromise of managed devices.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2026-195-02"/>
    <published>2026-07-14T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2026-195-01</id>
    <title>SEVD-2026-195-01 — Out-of-Bounds Write vulnerability in IGSS</title>
    <updated>2026-07-14T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical 
SCADA System) product.  
The [IGSS](https://igss.schneider-electric.com/) product is a state-of-the-art SCADA system used for monitoring and controlling industrial processes. 
The IGSS Definition module is a design-time component used by system integrators to create mimic diagrams 
for plant personnel, enabling them to monitor and control the SCADA system. 
Failure to apply the remediation provided below may risk loss of data or arbitrary code execution, which could 
result in the loss of control of the system.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2026-195-01"/>
    <published>2026-07-14T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2026-160-03</id>
    <title>SEVD-2026-160-03 — Multiple Vulnerabilities on PowerLogic™ P7</title>
    <updated>2026-06-09T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of a vulnerability in its PowerLogic™ P7 product. 
The PowerLogic™ P7 is a protection and control platform designed for complex and advanced electrical 
network applications.
Failure to apply the remediation provided below may risk unauthorized execution of privileged commands or 
loss of HMI operability and configuration functionality, which could result in loss of control over system 
operations and disruption of critical services.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2026-160-03"/>
    <published>2026-06-09T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2026-160-02</id>
    <title>SEVD-2026-160-02 — Multiple Vulnerabilities on EasyLogic T150 and Saitel DP RTU</title>
    <updated>2026-06-09T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of a vulnerability in its EasyLogic T150 (formerly known as Saitel DR) and Saitel 
DP Remote Terminal Unit &amp; Controller products.   
The [EasyLogic T150 (formerly known as Saitel DR RTU)](https://www.se.com/ww/en/product-country-selector/?pageType=product-range&amp;sourceId=62685#overview) is a field device, offering a solid and powerful 
modular platform for data acquisition, communication, automation and IED integration for distribution and 
transmission networks, generation sector and railway.    
The [Saitel DP RTU](https://www.se.com/ww/en/product-country-selector/?pageType=product-range&amp;sourceId=61747) is a modular platform for medium voltage and high voltage public distribution and 
transmission substation control. 
 
Failure to apply the mitigations provided below may risk credential harvesting and unauthorized access 
attacks, which could result in exposure of sensitive information and compromise of device integrity and 
operations when an attacker has subsequent physical access to the device.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2026-160-02"/>
    <published>2026-06-09T07:00:00+00:00</published>
  </entry>
</feed>
