CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenticated attacker accesses credentials stored within firmware or system files. With this credential an attacker could subsequently compromise the device if they have physical access to the device.
Metrics
Affected Vendors & Products
References
History
Thu, 25 Jun 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthorized access via exposed firmware credentials in Schneider Electric remote terminals |
Thu, 25 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 25 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenticated attacker accesses credentials stored within firmware or system files. With this credential an attacker could subsequently compromise the device if they have physical access to the device. | |
| Weaknesses | CWE-522 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: schneider
Published:
Updated: 2026-06-25T15:49:18.212Z
Reserved: 2026-05-26T19:45:16.940Z
Link: CVE-2026-9650
Updated: 2026-06-25T15:49:14.392Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-25T16:45:03Z