Schneider Electric ASCO 5310 and 5350 Remote Annunciators Cleartext Transmission of Sensitive Information Vulnerability

Vulnerability

A vulnerability allowing cleartext transmission of sensitive information has been identified in the ASCO 5310 Single-Channel Remote Annunciator and ASCO 5350 Eight-Channel Remote Annunciator. This vulnerability could lead to data exposure if network traffic is intercepted by an attacker.

Impact

Exploitation of this vulnerability could result in the unauthorized exposure of sensitive data being transmitted over the network.

Remediation

Users are advised to operate these remote annunciator devices in a protected environment, minimizing network exposure and ensuring they are not accessible from the public internet or untrusted networks. Default passwords should be changed to prevent unauthorized access to device settings and information. Network segmentation should be implemented, along with a firewall to block unauthorized access to the annunciator's HTTP port. For more details, refer to the 'Installation Manual' for the ASCO 5310 and ASCO 5350, available on the Schneider Electric website.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.