<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_se</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 22:22:41 +0000</lastBuildDate>
    <item>
      <title>SEVD-2026-251-04 — Incorrect Implementation of Authentication Algorithm vulnerability on Modicon M580 and Modicon M580 Safety</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2026-251-04</link>
      <description>&lt;p&gt;Schneider Electric is aware of a vulnerability in its Modicon M580 and Modicon M580 Safety controllers. &#13;
The Modicon M580 is an Ethernet-based Programmable Automation Controller (ePAC) designed for industrial digital transformation.&#13;
Failure to apply the remediations provided below may risk establishing an unauthenticated connection to Modicon M580 or M580 Safety controllers which could result in loss of confidentiality, integrity and availability of the PLC.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of a vulnerability in its Modicon M580 and Modicon M580 Safety controllers. &#13;
The Modicon M580 is an Ethernet-based Programmable Automation Controller (ePAC) designed for industrial digital transformation.&#13;
Failure to apply the remediations provided below may risk establishing an unauthenticated connection to Modicon M580 or M580 Safety controllers which could result in loss of confidentiality, integrity and availability of the PLC.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2026-251-04</guid>
      <pubDate>Tue, 08 Sep 2026 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SEVD-2026-251-03 — Insufficiently Protected Credentials vulnerability on SCADAPack x70 Products</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2026-251-03</link>
      <description>&lt;p&gt;Schneider Electric is aware of a vulnerability in its SCADAPack x70 products. The SCADAPack 47x, SCADAPack 47xi, SCADAPack 47xd, SCADAPack 470R and SCADAPack 57x products are Remote Terminal Units that provide communication capabilities for remote monitoring and control. Failure to apply the mitigations provided below may increase the risk of unauthorized access to RTU configuration through the Secure Lock functionality, potentially resulting in a loss of confidentiality.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of a vulnerability in its SCADAPack x70 products. The SCADAPack 47x, SCADAPack 47xi, SCADAPack 47xd, SCADAPack 470R and SCADAPack 57x products are Remote Terminal Units that provide communication capabilities for remote monitoring and control. Failure to apply the mitigations provided below may increase the risk of unauthorized access to RTU configuration through the Secure Lock functionality, potentially resulting in a loss of confidentiality.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2026-251-03</guid>
      <pubDate>Tue, 08 Sep 2026 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SEVD-2026-251-02 — Improper Neutralization of Special Elements used in an OS Command vulnerability on PowerLogic T300</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2026-251-02</link>
      <description>&lt;p&gt;Schneider Electric is aware of a vulnerability in the Head Unit (HU250) for the PowerLogic T300 RTU (Remote &#13;
Terminal Unit) (formerly Easergy T300 RTU).  &#13;
The [PowerLogic T300 RTU](https://www.se.com/ww/en/product-range/62399-easergy-t300) is a modular platform for medium voltage and low voltage public distribution &#13;
network management.  &#13;
Failure to apply the remediation provided below may risk privilege escalation, which could result in &#13;
unauthorized takeover of the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of a vulnerability in the Head Unit (HU250) for the PowerLogic T300 RTU (Remote &#13;
Terminal Unit) (formerly Easergy T300 RTU).  &#13;
The [PowerLogic T300 RTU](https://www.se.com/ww/en/product-range/62399-easergy-t300) is a modular platform for medium voltage and low voltage public distribution &#13;
network management.  &#13;
Failure to apply the remediation provided below may risk privilege escalation, which could result in &#13;
unauthorized takeover of the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2026-251-02</guid>
      <pubDate>Tue, 08 Sep 2026 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SEVD-2026-251-01 — Multiple Vulnerabilities on EcoStruxure IT Data Center Expert</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2026-251-01</link>
      <description>&lt;p&gt;Schneider Electric is aware of its vulnerability in its EcoStruxure IT Data Center Expert product &#13;
The EcoStruxure IT Data Center Expert product is a scalable monitoring software that collects, organizes,and distributes critical device information providing a comprehensive view of equipment. &#13;
Failure to apply the remediation provided below may risk information disclosure and remote compromise of the offer which could result in disruption of operations and access to system data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of its vulnerability in its EcoStruxure IT Data Center Expert product &#13;
The EcoStruxure IT Data Center Expert product is a scalable monitoring software that collects, organizes,and distributes critical device information providing a comprehensive view of equipment. &#13;
Failure to apply the remediation provided below may risk information disclosure and remote compromise of the offer which could result in disruption of operations and access to system data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2026-251-01</guid>
      <pubDate>Tue, 08 Sep 2026 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SEVD-2026-223-02 — Multiple Vulnerabilities on NetBotz 5 750/755 Products</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2026-223-02</link>
      <description>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in its NetBotz 5 – 750/755 products.The NetBotz 5 – 750/755 products are security and environmental monitors providing temperature, humidity, leak, smoke, vibration, door contact, and video monitoring capabilities.Failure to apply the remediation provided below may risk arbitrary or remote code execution over the local network, which could result in device manipulation and unauthorized data access.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in its NetBotz 5 – 750/755 products.The NetBotz 5 – 750/755 products are security and environmental monitors providing temperature, humidity, leak, smoke, vibration, door contact, and video monitoring capabilities.Failure to apply the remediation provided below may risk arbitrary or remote code execution over the local network, which could result in device manipulation and unauthorized data access.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2026-223-02</guid>
      <pubDate>Tue, 11 Aug 2026 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SEVD-2026-223-01 — Improper Restriction of Excessive Authentication Attempts vulnerability on PowerChute Serial Shutdown</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2026-223-01</link>
      <description>&lt;p&gt;Schneider Electric is aware of vulnerabilities in its PowerChute™ Serial Shutdown product. &#13;
The PowerChute Serial Shutdown product is a UPS management software enabling graceful system shutdown and energy management capabilities for desktops, servers and workstations. &#13;
Failure to apply the remediation provided below may risk improper authentication validation which could result in disruption of operations and access to system data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of vulnerabilities in its PowerChute™ Serial Shutdown product. &#13;
The PowerChute Serial Shutdown product is a UPS management software enabling graceful system shutdown and energy management capabilities for desktops, servers and workstations. &#13;
Failure to apply the remediation provided below may risk improper authentication validation which could result in disruption of operations and access to system data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2026-223-01</guid>
      <pubDate>Tue, 11 Aug 2026 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SEVD-2026-195-02 — Insufficiently Protected Credentials vulnerability on EcoStruxure™ Cybersecurity Admin Expert</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2026-195-02</link>
      <description>&lt;p&gt;Schneider Electric is aware of a vulnerability in its EcoStruxure™ Cybersecurity Admin Expert  product (CAE).  &#13;
The [EcoStruxure™ Cybersecurity Admin Expert](https://www.se.com/ww/en/product-country-selector/?pageType=product-range&amp;amp;sourceId=63515) product is a configurator for managing cybersecurity in your &#13;
electrical network’s operational technology (OT). It is an intuitive, software-based tool used for multiple &#13;
administration purposes. &#13;
Failure to apply the remediation provided below may risk an authentication bypass and privilege escalation &#13;
attack, which could result in unauthorized access to application accounts, manipulation of credentials, and &#13;
potential compromise of managed devices.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of a vulnerability in its EcoStruxure™ Cybersecurity Admin Expert  product (CAE).  &#13;
The [EcoStruxure™ Cybersecurity Admin Expert](https://www.se.com/ww/en/product-country-selector/?pageType=product-range&amp;amp;sourceId=63515) product is a configurator for managing cybersecurity in your &#13;
electrical network’s operational technology (OT). It is an intuitive, software-based tool used for multiple &#13;
administration purposes. &#13;
Failure to apply the remediation provided below may risk an authentication bypass and privilege escalation &#13;
attack, which could result in unauthorized access to application accounts, manipulation of credentials, and &#13;
potential compromise of managed devices.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2026-195-02</guid>
      <pubDate>Tue, 14 Jul 2026 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SEVD-2026-195-01 — Out-of-Bounds Write vulnerability in IGSS</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2026-195-01</link>
      <description>&lt;p&gt;Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical &#13;
SCADA System) product.  &#13;
The [IGSS](https://igss.schneider-electric.com/) product is a state-of-the-art SCADA system used for monitoring and controlling industrial processes. &#13;
The IGSS Definition module is a design-time component used by system integrators to create mimic diagrams &#13;
for plant personnel, enabling them to monitor and control the SCADA system. &#13;
Failure to apply the remediation provided below may risk loss of data or arbitrary code execution, which could &#13;
result in the loss of control of the system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical &#13;
SCADA System) product.  &#13;
The [IGSS](https://igss.schneider-electric.com/) product is a state-of-the-art SCADA system used for monitoring and controlling industrial processes. &#13;
The IGSS Definition module is a design-time component used by system integrators to create mimic diagrams &#13;
for plant personnel, enabling them to monitor and control the SCADA system. &#13;
Failure to apply the remediation provided below may risk loss of data or arbitrary code execution, which could &#13;
result in the loss of control of the system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2026-195-01</guid>
      <pubDate>Tue, 14 Jul 2026 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SEVD-2026-160-03 — Multiple Vulnerabilities on PowerLogic™ P7</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2026-160-03</link>
      <description>&lt;p&gt;Schneider Electric is aware of a vulnerability in its PowerLogic™ P7 product. &#13;
The PowerLogic™ P7 is a protection and control platform designed for complex and advanced electrical &#13;
network applications.&#13;
Failure to apply the remediation provided below may risk unauthorized execution of privileged commands or &#13;
loss of HMI operability and configuration functionality, which could result in loss of control over system &#13;
operations and disruption of critical services.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of a vulnerability in its PowerLogic™ P7 product. &#13;
The PowerLogic™ P7 is a protection and control platform designed for complex and advanced electrical &#13;
network applications.&#13;
Failure to apply the remediation provided below may risk unauthorized execution of privileged commands or &#13;
loss of HMI operability and configuration functionality, which could result in loss of control over system &#13;
operations and disruption of critical services.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2026-160-03</guid>
      <pubDate>Tue, 09 Jun 2026 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SEVD-2026-160-02 — Multiple Vulnerabilities on EasyLogic T150 and Saitel DP RTU</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2026-160-02</link>
      <description>&lt;p&gt;Schneider Electric is aware of a vulnerability in its EasyLogic T150 (formerly known as Saitel DR) and Saitel &#13;
DP Remote Terminal Unit &amp;amp; Controller products.   &#13;
The [EasyLogic T150 (formerly known as Saitel DR RTU)](https://www.se.com/ww/en/product-country-selector/?pageType=product-range&amp;amp;sourceId=62685#overview) is a field device, offering a solid and powerful &#13;
modular platform for data acquisition, communication, automation and IED integration for distribution and &#13;
transmission networks, generation sector and railway.    &#13;
The [Saitel DP RTU](https://www.se.com/ww/en/product-country-selector/?pageType=product-range&amp;amp;sourceId=61747) is a modular platform for medium voltage and high voltage public distribution and &#13;
transmission substation control. &#13;
 &#13;
Failure to apply the mitigations provided below may risk credential harvesting and unauthorized access &#13;
attacks, which could result in exposure of sensitive information and compromise of device integrity and &#13;
operations when an attacker has subsequent physical access to the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of a vulnerability in its EasyLogic T150 (formerly known as Saitel DR) and Saitel &#13;
DP Remote Terminal Unit &amp;amp; Controller products.   &#13;
The [EasyLogic T150 (formerly known as Saitel DR RTU)](https://www.se.com/ww/en/product-country-selector/?pageType=product-range&amp;amp;sourceId=62685#overview) is a field device, offering a solid and powerful &#13;
modular platform for data acquisition, communication, automation and IED integration for distribution and &#13;
transmission networks, generation sector and railway.    &#13;
The [Saitel DP RTU](https://www.se.com/ww/en/product-country-selector/?pageType=product-range&amp;amp;sourceId=61747) is a modular platform for medium voltage and high voltage public distribution and &#13;
transmission substation control. &#13;
 &#13;
Failure to apply the mitigations provided below may risk credential harvesting and unauthorized access &#13;
attacks, which could result in exposure of sensitive information and compromise of device integrity and &#13;
operations when an attacker has subsequent physical access to the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2026-160-02</guid>
      <pubDate>Tue, 09 Jun 2026 07:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
