Summary
- CVE-2026-81861 (CVSS 3.1 score: 6.5) affects all versions of SCADAPack 47x, 47xi, 47xd, 470R, 57x, 3xx, and 32 series remote terminal units.
- The vulnerability sits in the legacy Secure Lock feature, which insufficiently protects credentials and can expose RTU authentication information to an unauthenticated remote attacker requiring only user interaction.
- No patched firmware is referenced in the advisory; mitigation relies on configuration changes, specifically migrating from Secure Lock to Role-Based Access Control (RBAC).
- Affected devices are deployed worldwide in critical manufacturing and energy sector environments.
- Network segmentation and the RTU firewall service are the key compensating controls recommended by both Schneider Electric and CISA.
What Has Been Disclosed
Schneider Electric and CISA have jointly published an advisory covering a credential protection weakness in the SCADAPack x70 product family. The vulnerability, tracked as CVE-2026-81861, is classified under CWE-522 (Insufficiently Protected Credentials) and carries a CVSS 3.1 base score of 6.5, rated medium severity. The flaw resides in the Secure Lock functionality used to restrict RTU configuration access.
Scope of Affected Products
Every version of the following products is listed as affected: SCADAPack 47x, 47xi, 47xd, 470R, 57x, 3xx, and 32. The advisory uses a wildcard version notation, indicating no currently released firmware version is exempt. These RTUs are used for remote monitoring and control across critical manufacturing and energy infrastructure globally.
Nature of the Vulnerability
The attack vector is network-based, requires no special privileges, and carries a high confidentiality impact with no integrity or availability impact assessed. User interaction is required, which marginally reduces the attack complexity rating. Successful exploitation could expose authentication credentials and allow unauthorised access to RTU configuration through the Secure Lock mechanism. The vulnerability was reported to CISA by researcher Abhinav Agarwal.
Why Secure Lock Is the Problem
The advisory is candid about the nature of Secure Lock: it is described as legacy functionality retained for backward compatibility with existing deployments. Schneider Electric’s position is that Role-Based Access Control is the recommended access control mechanism for SCADAPack 47x devices and should be used in place of Secure Lock wherever operationally possible. Organisations still relying on Secure Lock are advised to treat that as a risk acceptance decision rather than a supported security posture.
No Firmware Patch; Mitigation Is Configuration-Driven
The advisory does not identify a remediated firmware version. Mitigation is entirely configuration and architecture-based. The primary recommendation is to implement RBAC per the SCADAPack documentation, specifically the Security Guidelines for Administrators and the Working with Role-Based Access Control sections. Organisations should also consult the SCADAPack Cybersecurity Guide, including its hardening and secured communication sections, available through Schneider Electric’s RemoteConnect documentation portal.
Network Controls as Compensating Measures
Both Schneider Electric and CISA recommend network segmentation to isolate RTUs from untrusted networks, and enabling the RTU firewall service to restrict access to device services. Standard OT security guidance also applies: control system networks should sit behind firewalls, be isolated from corporate business networks, and remote access should only be permitted via VPN solutions that are kept current. Physical access controls and restrictions on mobile media are also referenced.
Why it matters
SCADAPack RTUs are embedded in energy and manufacturing operations worldwide, and any exposure of RTU authentication credentials represents a credible pathway to operational disruption or manipulation of physical processes. The fact that all versions are affected and no firmware patch exists means the risk cannot be closed through a simple update cycle. CISOs overseeing OT environments need to assess whether Secure Lock is active in their deployments, treat its continued use as an elevated risk, and prioritise the RBAC migration as a formal remediation task rather than a deferred hardening item. The medium CVSS score should not create complacency: in OT environments, confidentiality losses at the RTU layer can precede integrity and availability impacts that don’t register in IT-centric risk models.
What to do now
- Audit all SCADAPack x70 deployments to determine whether Secure Lock is currently enabled and document any operational dependencies on that feature.
- Implement Role-Based Access Control (RBAC) in place of Secure Lock on all SCADAPack 47x devices, following the Security Guidelines for Administrators and Working with Role-Based Access Control sections of the SCADAPack documentation.
- Where Secure Lock cannot be immediately replaced, document the risk acceptance rationale and apply all available compensating controls.
- Configure network segmentation to restrict access between trusted and untrusted networks for all affected RTUs.
- Enable the RTU firewall service on affected devices to reduce the attack surface and restrict unauthorised access to device services.
- Review and apply guidance in the SCADAPack Cybersecurity Guide, including the Hardening and Secured Communication sections.
- Ensure RTUs are not directly accessible from the internet, and that any required remote access routes through a current, maintained VPN solution.
- Contact Schneider Electric Industrial Cybersecurity Services or your local Schneider Electric representative for site-specific remediation support.
- Monitor Schneider Electric’s security advisory portal (SEVD-2026-251-03) for updates, including any future firmware remediation release.
