Cyber Resilience

CVE-2026-9651

LPE in Schneider-Electric Easylogic T150 Firmware ≤ 11.06.32

Published
25 June 2026
Modified
14 July 2026
Patch / advisory
CVSS Score v4 6.7
Click a component to see what it means
Raw vectorCVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Score 0.0011 1th percentile
Risk Priority 35 floored blend · peak EPSS

Summary

CVE-2026-9651 is a medium-severity Incorrect Permission Assignment for Critical Resource (CWE-732) vulnerability in Schneider-Electric Easylogic T150 Firmware. Its CVSS base score is 6.7 (Medium).

Operationally, exploitation aligns with the MITRE ATT&CK technique Credentials In Files (T1552.001); ranked at the 1th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified map to AC-3 (Access Enforcement) and AC-6 (Least Privilege) — see the control section below for these in your framework.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability Data

CWE-732 Incorrect Permission Assignment for Critical Resource vulnerability that could cause unauthorized disclosure of password hashes and potential account compromise when an attacker with privileged local access reads improperly protected system files.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise TechniquesAI

T1552.001 Credentials In Files Credential Access
Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials.
Why these techniques?

Incorrect file permissions directly enable reading credential-containing system files (password hashes).

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

Likely ATT&CK TechniquesAI

Techniques this vulnerability likely enables, inferred from its description, weakness type, and attributed-actor tradecraft. Confidence is per-technique.

T1003.002 Security Account Manager Credential Accessconfidence: HIGH
Direct read of improperly protected system files containing password hashes enables Security Account Manager credential dumping.
T1003.004 LSA Secrets Credential Accessconfidence: HIGH
Improper file permissions allow an attacker to read LSA Secrets stored in system files.
T1552.001 Credentials In Files Credential Accessconfidence: HIGH
The vulnerability directly exposes credentials stored in files due to incorrect permission assignment.
T1005 Data from Local System Collectionconfidence: MEDIUM
Reading improperly protected system files constitutes data collection from the local system.
inferred from description + CWE · MITRE ATT&CK Enterprise v19.0

CVEs Like This One

CVE-2026-9650Same product: Schneider-Electric Easylogic T150
CVE-2026-2401Same vendor: Schneider-Electric
CVE-2025-68462Shared CWE-732
CVE-2025-70342Shared CWE-732
CVE-2026-1344Shared CWE-732
CVE-2026-45246Shared CWE-732
CVE-2026-32810Shared CWE-732
CVE-2026-13769Shared CWE-732
CVE-2023-27980Same vendor: Schneider-Electric
CVE-2021-22707Same vendor: Schneider-Electric

Affected Assets

schneider-electric
easylogic t150 firmware
≤ 11.06.32
schneider-electric
saitel dp firmware
≤ 11.06.38

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)
  • AC-3 Access Enforcement
  • AC-6 Least Privilege
  • CM-6 Configuration Settings
Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)
  • 7 hardening rules · 4 OS baselines
Validate
Prove the fix (OWASP ASVS)

Mitigating Controls (NIST 800-53 r5) AI

prevent

Directly enforces access control policies on system files, blocking unauthorized reads of password hashes when permissions are misassigned.

prevent

Requires assignment of only the minimum necessary permissions to critical resources such as password hash files, directly addressing CWE-732.

prevent

Mandates secure configuration settings that include proper file permissions on sensitive system resources to prevent local disclosure.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.AA-05 full match
prevents

Directly requires defining, enforcing, and reviewing access permissions and least privilege on resources.

PR.PS-01 mostly match
prevents

Hardened baselines and configuration management explicitly include correct permission settings for critical resources.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

prevents

By requiring owners to determine and document the exact permissions needed for each asset, the control reduces the likelihood that default or overly permissive file and resource permissions will be left in place.

prevents

Documented provisioning and revocation procedures reduce the chance that critical resources retain overly permissive default or leftover permissions after personnel changes.

prevents

Documented authorization, expiry rules, and audit logging of privileged accounts make it harder for critical resources to retain overly permissive or stale permission assignments.

prevents

Requiring explicit configuration of access controls and permissions for files, applications and services counters the assignment of overly permissive default or incorrect file-system rights.

prevents

Enforcing differentiated permissions on the source-code repository and program listings stops the assignment of overly broad default or inherited permissions to critical resources.

prevents

By defining and enforcing secure permission settings in configuration templates, the control reduces the likelihood that critical resources receive incorrect permission assignments.

References