Full Report
[Control systems] Schneider Electric security advisory (AV26-912)
Analysis Summary
# Vulnerability: Multiple Flaws in Schneider Electric EcoStruxure IT Data Center Expert and PowerLogic T300
## CVE Details
*Note: Specific CVE IDs were not enumerated in the summary text provided, but the advisory references specific vulnerability types (OS Command Injection).*
- **CVE ID:** CVE-2026-XXXX (Refer to SEVD-2026-251-01 and SEVD-2026-251-02)
- **CVSS Score:** Not explicitly listed (Typically High/Critical for OS Command Injection)
- **CWE:** CWE-78 (Improper Neutralization of Special Elements used in an OS Command)
## Affected Systems
- **Products:**
- EcoStruxure™ IT Data Center Expert (formerly StruxureWare Data Center Expert)
- PowerLogic T300
- **Versions:**
- EcoStruxure IT Data Center Expert: Versions 9.1.2 and prior
- PowerLogic T300: Versions 2.9.8-5620 and prior
- **Configurations:** Systems utilizing web-based management interfaces or command-line utilities exposed to untrusted inputs.
## Vulnerability Description
The primary vulnerability identified in the PowerLogic T300 involves the **Improper Neutralization of Special Elements used in an OS Command**. This flaw allows an attacker to inject and execute arbitrary operating system commands by bypassing input validation mechanisms. In the EcoStruxure IT Data Center Expert, multiple vulnerabilities exist that could potentially allow for unauthorized access or system compromise.
## Exploitation
- **Status:** Not reported as exploited in the wild (as of advisory date)
- **Complexity:** Low to Medium
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Potential for full data exfiltration)
- **Integrity:** High (Potential for system modification)
- **Availability:** High (Potential for Denial of Service or system takeover)
## Remediation
### Patches
Schneider Electric recommends upgrading to the following versions:
- **EcoStruxure™ IT Data Center Expert:** Apply latest updates as specified in SEVD-2026-251-01.
- **PowerLogic T300:** Update to versions newer than 2.9.8-5620.
### Workarounds
- Disable unnecessary services and ports.
- Ensure the devices are located behind a properly configured firewall.
- Use VPNs for remote access to management interfaces.
- Restrict access to authorized IP addresses only.
## Detection
- **Indicators of Compromise:** Unusual administrative account activity, unexpected outbound network traffic from the control system, and evidence of unauthorized command execution in system logs.
- **Detection methods and tools:** Monitor system logs for special characters (`;`, `&`, `|`, `$`) in web request parameters and audit file integrity on affected modules.
## References
- **Vendor Advisories:**
- hxxps[://]download[.]se[.]com/files?p_Doc_Ref=SEVD-2026-251-01
- hxxps[://]download[.]se[.]com/files?p_Doc_Ref=SEVD-2026-251-02
- hxxps[://]www[.]se[.]com/ww/en/work/support/cybersecurity/security-notifications[.]jsp
- **Cyber Centre Advisory:**
- hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/control-systems-schneider-electric-security-advisory-av26-912