Description
CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when communicating over the Modbus TCP protocol.
Published: 2026-07-29
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Schneider Electric's RemoteConnect and SCADAPack devices allows an attacker to send specially crafted Modbus TCP frames that bypass a critical safety check, enabling arbitrary code execution, denial of service, and the loss of confidentiality and integrity of data. The weakness is classified as CWE‑754, an Improper Check for Unusual or Exceptional Conditions flaw. When exploited, an adversary could potentially take control of the affected devices or disrupt their operation.

Affected Systems

The vulnerability affects Schneider Electric RemoteConnect, SCADAPack 47x, SCADAPack 47xi, and SCADAPack 57x. No specific software or firmware version information is provided in the advisory.

Risk and Exploitability

The CVSS score of 9.3 indicates a critical level of risk, while the EPSS score of less than 1 % suggests a very low but non-zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote over the Modbus TCP protocol, implying that any network exposed to Modbus traffic could be targets if safeguards are not in place.

Generated by OpenCVE AI on August 4, 2026 at 12:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor-published patch or firmware upgrade for RemoteConnect and SCADAPack 47x, 47xi, and 57x devices.
  • If a patch is not immediately available, block or restrict Modbus TCP traffic to the affected devices using firewalls or network segmentation.
  • Enable and monitor security logging on the devices to detect anomalous Modbus activity and investigate any suspicious events.

Generated by OpenCVE AI on August 4, 2026 at 12:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Title High‑Severity Vulnerability in Schneider Electric RemoteConnect and SCADAPack Devices Allowing Arbitrary Code Execution via Modbus TCP

Sat, 01 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title High‑Severity Vulnerability in Schneider Electric RemoteConnect and SCADAPack Devices Allowing Arbitrary Code Execution via Modbus TCP

Thu, 30 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Schneider-electric
Schneider-electric remoteconnect
Schneider-electric scadapack 470
Schneider-electric scadapack 570
Vendors & Products Schneider-electric
Schneider-electric remoteconnect
Schneider-electric scadapack 470
Schneider-electric scadapack 570

Wed, 29 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Description CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when communicating over the Modbus TCP protocol.
Weaknesses CWE-754
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Schneider-electric Remoteconnect Scadapack 470 Scadapack 570
cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published:

Updated: 2026-07-29T14:20:14.876Z

Reserved: 2026-01-07T15:42:11.892Z

Link: CVE-2026-0667

cve-icon Vulnrichment

Updated: 2026-07-29T14:20:07.701Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-29T13:17:29.180

Modified: 2026-07-30T16:43:03.817

Link: CVE-2026-0667

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T12:45:05Z

Weaknesses
  • CWE-754

    Improper Check for Unusual or Exceptional Conditions