CVE-2026-9651 Details
Description
CWE-732 Incorrect Permission Assignment for Critical Resource vulnerability that could cause unauthorized disclosure of password hashes and potential account compromise when an attacker with privileged local access reads improperly protected system files.
A vulnerability exists in Schneider Electric's EasyLogic T150 (formerly Saitel DR) and Saitel DP Remote Terminal Unit & Controller products, all versions through the ones specified in the Affected Products and Versions section. This vulnerability involves incorrect permission assignments that could lead to unauthorized access to password hashes, potentially allowing for account compromises. The issue arises when an attacker with privileged local access reads system files that are not properly secured.
Users can upgrade to version 11.06.32 of EasyLogic T150 or version 11.06.38 of Saitel DP Remote Terminal Unit & Controller, both of which include fixes for this vulnerability. These firmware versions are available through Schneider Electric's Customer Care Center. A reboot is required after the update.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-160-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-160-02.pdf | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-732 | Incorrect Permission Assignment for Critical Resource | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| schneider-electric easylogic t150 firmware | < 11.06.32 |
CPE
Remediation
| |
| schneider-electric easylogic t150 | All versions |
CPE
Remediation
| |
| schneider-electric saitel dp firmware | < 11.06.38 |
CPE
Remediation
| |
| schneider-electric saitel dp | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | Initial Analysis | [email protected] |
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 25, 2026 | New CVE Received | [email protected] |