CVE-2026-9651

EUVD-2026-39431
CWE-732 Incorrect Permission Assignment for Critical Resource vulnerability that could cause unauthorized disclosure of password hashes and potential account compromise when an attacker with privileged local access reads improperly protected system files.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.4 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 1.42%
Affected Products (NVD)
VendorProductVersion
schneider-electriceasylogic_t150_firmware
𝑥
< 11.06.32
schneider-electricsaitel_dp_firmware
𝑥
< 11.06.38
𝑥
= Vulnerable software versions