Schneider Electric Sage Series
Schneider Electric SAGE RTU products contain multiple critical vulnerabilities including buffer overflow (CWE-787, CWE-120), path traversal (CWE-22), and improper access control flaws (CWE-276, CWE-252, CWE-125) that allow unauthenticated remote code execution. These RTUs are hardware devices that collect utility substation information from meters and control devices and relay it to SCADA platforms. Exploitation could result in complete compromise of the affected RTU, leading to loss of substation telemetry data, inability to issue control commands, or degradation of power distribution operations.
- Network access to the SAGE RTU on its control network or via exposed network interface
- No valid credentials required
Patching may require device reboot — plan for process interruption
/api/v1/advisories/87fb16b6-463a-4000-9490-d9203a921bb1Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.