PT-2026-40037 · Schneider Electric · Ecostruxure Panel Server+5
CVE-2026-6866
·
Published
2026-05-12
·
Updated
2026-06-11
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Schneider Electric EcoStruxure Panel Server (affected versions not specified)
Description
An insecure default resource initialization issue exists that may cause credentials to revert to initial settings under rare circumstances. This allows unauthorized authentication using known credentials, potentially leading to the unauthorized disclosure of sensitive information. Real-world incidents have been observed where attackers gained administrative control and performed lateral movement across connected Operational Technology (OT) systems following the initial compromise.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Implement runtime segmentation to contain post-compromise activity within critical infrastructure networks.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ecostruxure Panel Server
Ecostruxure Panel Server Pas400 Firmware
Ecostruxure Panel Server Pas600 Firmware
Ecostruxure Panel Server Pas600V2 Firmware
Ecostruxure Panel Server Pas800 Firmware
Ecostruxure Panel Server Pas800V2 Firmware