CVE-2024-10575: Schneider Electric Ecostruxure It Gateway

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access when enabled on the network and potentially impacting connected devices.

Affected products

  • Schneider Electric Ecostruxure It Gateway: version 1.21.0.6 only; version 1.22.0.3 only; version 1.22.1.5 only; version 1.23.0.4 only

Published 2024-11-13. Last modified 2026-06-17.