Ecostruxure Power Monitoring Expert
ecostruxure_power_monitoring_expert
Vendor: Schneider Electric • 14 CVEs
CVEs (14)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Schneider Electric 2Ecostruxure Power Monitoring Expert Ecostruxure Power OperationJun 24, 2026 Mar 10, 2026 8.5 HIGH· v4 7.8 HIGH· v3 N/A· v2 CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a locally authenticated attacker sends a crafted data stream, triggering unsaf...Show more |
1Schneider Electric 1Ecostruxure Power Monitoring Expert Jun 17, 2026 Nov 15, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability that could cause a vulnerability leading to a cross site scripting condition where attackers can have a victim’s...Show more |
1Schneider Electric 1Ecostruxure Power Monitoring Expert Jun 17, 2026 Nov 15, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting attack. By providing a URL-encoded input attackers can cause the software...Show more |
1Schneider Electric 3Ecostruxure Power Monitoring Expert Ecostruxure Power Operation With Advanced ReportsEcostruxure Power Scada Operation With Advanced ReportsJun 17, 2026 Oct 4, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2
A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to
execute arbitrary code on the targeted system by sending a specifically crafted packet to the
application.
|
1Schneider Electric 1Ecostruxure Power Monitoring Expert Jun 17, 2026 Apr 18, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A CWE-613: Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain unauthorized access over a hijacked session in PME after the legitimate user has signed out of their account....Show more |
1Schneider Electric 1Ecostruxure Power Monitoring Expert Jun 17, 2026 Feb 4, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could allow an authenticated attacker to view data, change settings, or impact availability of the...Show more |
1Schneider Electric 1Ecostruxure Power Monitoring Expert Jun 17, 2026 Feb 4, 2022 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A CWE-20: Improper Input Validation vulnerability exists that could allow an unauthenticated attacker to view data, change settings, impact availability of the software, or potentially impact a user�s local machine when...Show more |
1Schneider Electric 1Ecostruxure Power Monitoring Expert Jun 17, 2026 Feb 4, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A CWE-20: Improper Input Validation vulnerability exists that could allow arbitrary files on the server to be read by authenticated users through a limited operating system service account. Affected Product: EcoStruxure...Show more |
1Schneider Electric 1Ecostruxure Power Monitoring Expert Jun 17, 2026 Jan 28, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits a page containing the injected payload. This CVE is unique from CVE-2021-22826. Affected Product: Ec...Show more |
1Schneider Electric 1Ecostruxure Power Monitoring Expert Jun 17, 2026 Jan 28, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits a page containing the injected payload. This CVE is unique from CVE-2021-22827. Affected Product: Ec...Show more |
1Schneider Electric 5Ecostruxure Energy Expert Ecostruxure Power Monitoring ExpertPower Manager+2 moreJun 17, 2026 Dec 1, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A CWE-284: Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow a user the ability to pe...Show more |
1Schneider Electric 5Ecostruxure Energy Expert Ecostruxure Power Monitoring ExpertPower Manager+2 moreJun 17, 2026 Dec 1, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that c...Show more |
1Schneider Electric 5Ecostruxure Energy Expert Ecostruxure Power Monitoring ExpertPower Manager+2 moreJun 17, 2026 Dec 1, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow for arbitrary code execut...Show more |
1Schneider Electric 3Ecostruxure Energy Expert Ecostruxure Power Monitoring ExpertEcostruxure Power Scada OperationJun 17, 2026 Dec 17, 2018 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME) v8.2 (all editions), EcoStruxure Energy Expert 1.3 (formerly Power Man...Show more |