Insufficiently Protected Credentials Vulnerability in Schneider Electric Product
CVE-2026-14354

8.7HIGH

What is CVE-2026-14354?

The identified vulnerability arises from the improper handling and protection of stored credentials within Schneider Electric managed devices. A local privileged attacker may exploit this weakness, leading to potential authentication bypass or unauthorized modification of credentials. This could result in the compromise of managed devices, highlighting the importance of securing sensitive information and ensuring robust countermeasures are in place.

Affected Version(s)

EcoStruxure™ Cybersecurity Admin Expert v4.2.0 and prior

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.