CVE-2026-0667

Summary

CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when communicating over the Modbus TCP protocol.

Affected Software

VendorProductVersion RangeStatus
Schneider ElectricSCADAPack 47xVersions prior to R3.4.2 (Firmware version prior to 9.12.2)affected
Schneider ElectricSCADAPack 47xiVersions prior to R3.4.2 (Firmware version prior to 9.12.2)affected
Schneider ElectricSCADAPack 57xAll Versionsaffected
Schneider ElectricRemoteConnectVersions prior to R3.4.2affected

Weaknesses

  • CWE-754: CWE-754: Improper Check for Unusual or Exceptional Conditions

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References