CVE Tools

CVE-2026-0667

Уязвимость микропрограммного обеспечения промышленных контроллеров SCADAPack 47xi, SCADAPack 47x и SCADAPack 57x и программного средства конфигурирования SCADAPack RemoteConnect, связанная с недостаточной проверкой необычных или исключительных состояний, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

Published: Feb 18, 2026Updated: Feb 18, 2026 Sources: BDU csafCWE-754Improper Check for Unusual or Exceptional Conditions
9.8CVSSCRITICAL

Description

We strongly recommend the following industry cybersecurity best practices. * Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network. * Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks. * Place all controllers in locked cabinets and never leave them in the “Program” mode. * Never connect programming software to any network other than the network intended for that device. * Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks. * Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation. * Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet. * When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices. For more information refer to the Schneider Electric [Recommended Cybersecurity Best Practices](https://www.se.com/us/en/download/document/7EN52-0390/) document.

CVSS Vector Breakdown

AV:NAC:LC:HI:HA:H
Exploitability
AV:NAccess Vector
Network
AC:LAccess Complexity
Low
Impact
C:HConfidentiality
H
I:HIntegrity
H
A:HAvailability
H

Weaknesses

Affected Products

schneider electriccommercialFRICS / OT / IoTaka schneider-electric

Exploitability

Official Patch Available

References

and 13 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-0667 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows