You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2025-8453
About this tag
CVE-2025-8453 is a privilege management vulnerability in Schneider Electric Saitel Remote Terminal Units (RTUs), disclosed in a CISA advisory on August 28, 2025. The flaw affects Saitel DR RTU firmware versions 11.06.29 and earlier, and Saitel DP RTU firmware versions 11.06.34 and earlier. With a CVSS v3.1 base score of 6.7, it allows an authenticated engineer with console access to escalate privileges by modifying a configuration file executed by a root-level daemon, potentially leading to arbitrary code execution. This vulnerability is part of a broader set of nine critical ICS advisories published by CISA, highlighting ongoing risks in industrial control systems from vendors including Mitsubishi Electric, Delta Electronics, and others. Operators are urged to apply patches and harden networks.
CISA on August 28, 2025, published a batch of nine Industrial Control Systems (ICS) advisories covering critical vulnerabilities across Mitsubishi Electric, Schneider Electric, Delta Electronics, GE Vernova, Hitachi Energy, and ICONICS/Mitsubishi integrations — a coordinated disclosure that...
Schneider Electric has published an advisory—republished by CISA—about an improper privilege management vulnerability in its Saitel family of Remote Terminal Units (RTUs) that has been assigned CVE‑2025‑8453 and carries a CVSS v3.1 base score of 6.7, affecting Saitel DR RTU firmware versions...