Impact
A flaw in Schneider Electric's RemoteConnect and SCADAPack devices allows an attacker to send specially crafted Modbus TCP frames that bypass a critical safety check, enabling arbitrary code execution, denial of service, and the loss of confidentiality and integrity of data. The weakness is classified as CWE‑754, an Improper Check for Unusual or Exceptional Conditions flaw. When exploited, an adversary could potentially take control of the affected devices or disrupt their operation.
Affected Systems
The vulnerability affects Schneider Electric RemoteConnect, SCADAPack 47x, SCADAPack 47xi, and SCADAPack 57x. No specific software or firmware version information is provided in the advisory.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical level of risk, while the EPSS score of less than 1 % suggests a very low but non-zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote over the Modbus TCP protocol, implying that any network exposed to Modbus traffic could be targets if safeguards are not in place.
OpenCVE Enrichment