Schneider Electric RemoteConnect and SCADAPack x70 Utilities Deserialization Vulnerability Leading to Remote Code Execution

Vulnerability

A deserialization vulnerability has been identified in all versions of Schneider Electric's RemoteConnect and SCADAPack x70 Utilities. This vulnerability allows for the potential loss of confidentiality and integrity, and could lead to remote code execution on the workstation of a non-admin authenticated user who opens a malicious project file.

Impact

Exploitation of this vulnerability could result in unauthorized remote code execution on the affected workstation.

Remediation

Schneider Electric is developing a remediation plan for future versions of RemoteConnect and SCADAPack x70 Utilities. Until this update is available, users should only open project files from trusted sources, verify the integrity of project files using hash checks, encrypt project files when stored, and use secure communication protocols for file exchanges. Additionally, follow the SCADAPack Security Guidelines.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.4
remediation
7.9
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.