These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-81861 is a CWE-522 Insufficiently Protected Credentials vulnerability. The vulnerability could result in exposure of authentication information and unauthorized access to RTU functionality. Defenders and security teams responsible for RTU functionality and authentication information protection should assess exposure and prioritize verification of authentication information protection in RTU funct [truncated]
An out-of-bounds write vulnerability exists in the IGSS Definition module that could cause loss of data or potentially risk arbitrary code execution when a malicious CGF file is imported. The vulnerability has a CVSS v4.0 Base Score of 8.4, indicating a High severity. This issue arises from inadequate input validation during the import process, allowing attackers to manipulate data and potentially execute [truncated]
CVE-2026-9718 is a medium-severity vulnerability in Schneider Electric's Powerogic P7 firmware. An authenticated attacker could trigger a denial-of-service (DoS) condition by sending a specially crafted request to a vulnerable network-exposed service, impacting system availability. This vulnerability, classified as CWE-617 (Reachable Assertion), was published on June 25, 2026, and has a CVSS score of 6.9. [truncated]
CVE-2026-9716 is a high-severity vulnerability in Schneider Electric's PowerLogic P7 device. A NULL pointer dereference could allow an attacker to cause a denial-of-service condition, rendering the device's HMI and configuration functionality unavailable when malformed requests are received over exposed network interfaces. The vulnerability has a CVSS score of 8.7 and is considered HIGH severity. Schneide [truncated]
CVE-2026-6866 is a CWE-1188 Initialization of a Resource with an Insecure Default vulnerability in Schneider Electric's EcoStruxure Panel Server. The vulnerability has a CVSS v4.0 Base Score of 7.5 and could cause unauthorized disclosure of sensitive information when credentials revert to initial settings. This vulnerability exists in multiple versions of the EcoStruxure Panel Server, including PAS800, PA [truncated]
The CWE-532 Insertion of Sensitive Information into Log File vulnerability exists in PowerChute Serial Shutdown. This vulnerability could cause confidential information to be exposed when a Web Admin user executes a malicious file provided by an attacker. The CVSS v4.0 Base Score is 2.4, indicating a Low severity. Organizations should be aware of this vulnerability and take steps to mitigate it. PowerChut [truncated]
The CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists in PowerChute Serial Shutdown, which could cause application user credentials to reset when a Web Admin user alters the POST /setPCBEDesc request payload. The CVSS v4.0 Base Score is 5.3, Medium severity. This vulnerability affects organizations using PowerChute Serial Shutdown, particularly those with exposed web [truncated]
The CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in PowerChute Serial Shutdown, which could cause critical files to be overwritten with text data when a Web Admin user alters the POST /REST/upssleep request payload. The CVSS v4.0 Base Score is 6.9, indicating a Medium severity. Schneider Electric has released version 1.5 of PowerChute Serial Sh [truncated]
CVE-2026-2273 is a Schneider Electric EcoStruxure Automation Expert code-injection issue that can run untrusted commands on an engineering workstation when an authenticated user opens a malicious project file. The vendor says this can cause a limited compromise of the workstation and downstream confidentiality, integrity, and availability impact on connected systems. Schneider Electric states that version [truncated]
CVE-2026-1286 is a deserialization of untrusted data issue in Schneider Electric EcoStruxure Foxboro DCS. According to the advisory, a malicious project file can trigger the flaw when an authenticated admin user opens it, creating risk to confidentiality, integrity, and potentially remote code execution on the workstation.
Schneider Electric disclosed CVE-2025-13957 on 2026-03-10, with a CISA republication update on 2026-03-17. The issue affects EcoStruxure IT Data Center Expert versions through 9.0, while v9.1 includes the fix. According to the advisory, the risk is tied to hard-coded credentials and becomes more serious when SOCKS Proxy is enabled and an attacker also knows administrator and PostgreSQL database credential [truncated]
CVE-2025-13902 is a cross-site scripting issue in Schneider Electric Modicon controller web interfaces. According to the advisory, an authenticated attacker can plant a malicious element so that a victim’s browser runs arbitrary JavaScript when hovering over it. Schneider Electric states that firmware 5.4.13.12, delivered with EcoStruxure Machine Expert v2.5.0.1, includes the fix for M241 and M251; the ad [truncated]
CVE-2025-13901 is an unauthenticated, network-reachable denial-of-service issue in Schneider Electric Modicon M241, M251, and M262 systems. According to the advisory, a malicious payload can occupy active communication channels in the Machine Expert protocol, leading to partial loss of availability. Schneider Electric and CISA list fixed firmware builds and recommend both software updates and network hard [truncated]
CVE-2025-11739 is a high-severity unsafe deserialization issue in Schneider Electric EcoStruxure Power Monitoring Expert (PME) and related EcoStruxure Power Operation (EPO) reporting/dashboard components. A locally authenticated attacker who can send a crafted data stream may trigger arbitrary code execution with administrative privileges. The advisory was published on 2026-03-10 and republished by CISA o [truncated]
CVE-2026-1227 is a high-severity XML external entity (XXE) issue in Schneider Electric EcoStruxure Building Operation (EBO) Workstation and WebStation. According to the advisory, a local user who uploads a maliciously crafted TGML graphics file to the EBO server from Workstation could trigger unauthorized disclosure of local files, unauthorized interaction with the EBO system, or denial-of-service conditi [truncated]
CVE-2026-1226 is a high-severity Schneider Electric EcoStruxure Building Operation issue where maliciously crafted TGML graphics content can cause the application to execute untrusted or unintended code. The advisory identifies vendor fixes for specific Workstation and WebStation releases and recommends access controls, MFA for EBO 7.0 or later, network segmentation, and monitoring if patching is delayed.
Schneider Electric and CISA describe CVE-2026-0667 as a critical CWE-754 improper-check flaw affecting SCADAPack 47x/47xi and RemoteConnect when communicating over Modbus TCP. The vendor says the issue could lead to arbitrary code execution, denial of service, and loss of confidentiality and integrity, and recommends upgrading to the fixed releases or applying OT segmentation, RTU firewall restrictions, a [truncated]
CVE-2025-13845 is a use-after-free vulnerability in Schneider Electric EcoStruxure Power Build Rapsody software. The advisory says a malicious SSD project file can trigger remote code execution when an end user imports it into Rapsody. The original advisory was published on 2026-01-13 and later updated on 2026-03-17, with vendor fixes available for multiple regional builds.
CVE-2025-13844 is a user-assisted double-free vulnerability in Schneider Electric EcoStruxure Power Build Rapsody that may lead to heap memory corruption when an end user imports a malicious SSD project file shared by an attacker. Schneider Electric and CISA rate the issue as Medium, and the advisory provides fixed releases plus temporary handling guidance for environments that cannot patch immediately.
CVE-2025-49844 is a critical advisory for Schneider Electric ProLeiT Plant iT/Brewmaxx. The source material ties the issue to a patch that disables Redis eval commands across several ProLeiT components, indicating a high-impact flaw that can be addressed through vendor-provided remediation. The published CVSS vector is 10.0/CRITICAL, reflecting network attackability, no privileges required, no user intera [truncated]
CVE-2025-46819 is a Schneider Electric ProLeiT Plant iT/Brewmaxx issue scored CVSS 3.1 6.3 (Medium). CISA and Schneider Electric say Patch ProLeiT-2025-001 reduces risk by disabling Redis eval commands in key components and by enforcing secure Redis configuration templates. Because the weakness is locally accessible and can affect confidentiality and availability, affected OT deployments should patch promptly.
CVE-2025-46818 is a medium-severity issue affecting Schneider Electric ProLeiT Plant iT/Brewmaxx in the advisory published by CISA on 2026-01-13. Schneider Electric’s fix, ProLeiT-2025-001, is intended to reduce risk by disabling Redis eval commands on affected components and enforcing secure Redis configuration templates. The advisory applies to Application Server, VisuHub, Engineering Workstations, and [truncated]
CVE-2025-46817 is a high-severity Schneider Electric issue affecting ProLeiT Plant iT/Brewmaxx. The supplied CVSS vector (AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H) indicates a local attack path with low privileges and no user interaction, but with high impact if exploited. Schneider Electric's Patch ProLeiT-2025-001 reduces risk by disabling Redis eval commands on affected components, enforcing secure Redis te [truncated]
CVE-2025-13905 is a high-severity incorrect default permissions issue in Schneider Electric EcoStruxure™ Process Expert. According to the advisory, a local user with normal privileges may modify one or more executable service binaries in the installation folder, and upon service restart this can lead to privilege escalation through the reverse shell.
CVE-2024-7322 is a medium-severity availability issue in Schneider Electric’s Wiser Zigbee product line. The CISA CSAF advisory (ICSA-26-027-03) describes a CWE-400 uncontrolled resource consumption condition that could lead to denial of service when a malicious device joins the network. The source item names Wiser iTRV2 and also lists additional Wiser/connected devices in scope. The published CVSS vector [truncated]
CVE-2024-6352 is a Schneider Electric Zigbee product issue that can let a malicious device joining the network trigger a buffer overflow and cause denial of service. The advisory was published on 2026-01-13 and later republished on 2026-01-27, with CISA’s CSAF notice linking the issue to multiple Schneider Electric Zigbee products, including Wiser iTRV2. The reported CVSS v3.1 score is 4.3 (Medium), refle [truncated]
CVE-2024-6351 is a medium-severity Schneider Electric Zigbee advisory issue published by CISA on 2026-01-13. The disclosed weakness is a CWE-120 buffer overflow that can cause a denial of service when a malicious device joins the network. The published CVSS vector (4.3, AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L) indicates adjacent-network conditions and availability-only impact.
CVE-2024-6350 is a medium-severity buffer overflow issue in Schneider Electric Zigbee products, including Wiser iTRV2. According to the advisory, a malicious device joining the network could trigger a denial of service. The published mitigations focus on tightening Zigbee pairing and access controls rather than on exploit details.
CVE-2024-10106 is a low-severity availability issue in Schneider Electric Wiser Zigbee products. The advisory says a CWE-120 buffer overflow can cause denial of service if a malicious device joins the network. The published CVSS vector (AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L) indicates network reachability, no privileges, and limited availability impact, with no confidentiality or integrity impact identified [truncated]
CVE-2025-9317 affects Schneider Electric software tied to AVEVA components, including EcoStruxure Machine SCADA Expert and Pro-face BLUE Open Studio. The disclosed issue centers on passwords being stored as MD5 hashes, which could let an attacker with read access to Edge Project files or Edge Offline Cache files recover app-native or Active Directory passwords through computational brute-force attacks aga [truncated]