Improper Check for Exceptional Conditions in Modbus TCP Protocol by Schneider Electric
CVE-2026-0667

9.3CRITICAL

Key Information:

Vendor
CVE Published:
29 July 2026

What is CVE-2026-0667?

This vulnerability in Schneider Electric's Modbus TCP protocol arises from an improper check for unusual or exceptional conditions, which can lead to serious security implications. When exploited, this flaw could allow an attacker to execute arbitrary code, resulting in a denial of service, and jeopardizing the confidentiality and integrity of communications over the Modbus TCP protocol. It is crucial for users to assess their systems and apply necessary mitigations to address this vulnerability.

Affected Version(s)

RemoteConnect Versions prior to R3.4.2

SCADAPack 47x Versions prior to R3.4.2 (Firmware version prior to 9.12.2)

SCADAPack 47xi Versions prior to R3.4.2 (Firmware version prior to 9.12.2)

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.