Schneider Electric ASCO 5310 and 5350 Remote Annunciators Unrestricted File Upload Vulnerability

Vulnerability

A vulnerability allowing unrestricted upload of files with dangerous types has been identified in Schneider Electric's ASCO 5310 Single-Channel Remote Annunciator and ASCO 5350 Eight-Channel Remote Annunciator. This vulnerability could lead to the device becoming inoperable if a malicious file is downloaded. The issue affects all versions of both products.

Impact

Exploitation of this vulnerability could render the affected device inoperable, disrupting its ability to monitor transfer switch status and perform transfer or retransfer operations. However, the basic operation of the transfer switch itself would not be affected.

Remediation

Schneider Electric is developing a remediation plan for future versions of the ASCO 5310 and ASCO 5350 Remote Annunciators. Until this update is available, users should apply the following mitigations: use the devices only in protected environments, change default passwords, implement network segmentation and firewalls to block unauthorized access to the device's web server, and consult the respective installation manuals for additional guidance. For ongoing updates, subscribe to Schneider Electric's security notification service.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.