CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenticated attacker accesses credentials stored within firmware or system files. With this credential an attacker could subsequently compromise the device if they have physical access to the device.
Metrics
Affected Vendors & Products
References
History
Fri, 26 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Schneider Electric
Schneider Electric easylogic T150 (formerly Saitel Dr) Remote Terminal Unit & Controller Schneider Electric saitel Dp Remote Terminal Unit & Controller |
|
| Vendors & Products |
Schneider Electric
Schneider Electric easylogic T150 (formerly Saitel Dr) Remote Terminal Unit & Controller Schneider Electric saitel Dp Remote Terminal Unit & Controller |
Thu, 25 Jun 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthorized access via exposed firmware credentials in Schneider Electric remote terminals |
Thu, 25 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 25 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenticated attacker accesses credentials stored within firmware or system files. With this credential an attacker could subsequently compromise the device if they have physical access to the device. | |
| Weaknesses | CWE-522 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: schneider
Published: 2026-06-25T14:44:30.419Z
Updated: 2026-06-25T15:49:18.212Z
Reserved: 2026-05-26T19:45:16.940Z
Link: CVE-2026-9650
Updated: 2026-06-25T15:49:14.392Z
No data.
No data.