CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Schneider Electric 4Modicon Lmc058 Firmware Modicon M241 FirmwareModicon M251 Firmware+1 moreJun 23, 2026 Mar 10, 2026 5.1 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause condition where authenticated attackers can have a victim’s browser run arbitrary JavaScri...Show more |
1Schneider Electric 5Modicon Lmc058 Firmware Modicon M241 FirmwareModicon M251 Firmware+2 moreJun 17, 2026 Jul 11, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a vulnerability leading to a cross-site scripting condition where attackers can have a vi...Show more |
1Schneider Electric 3Modicon M258 Firmware SomachineSomachine MotionJun 17, 2026 Dec 11, 2020 N/A· v4 6.8 MEDIUM· v3 5.2 MEDIUM· v2 A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Modicon M258 Firmware (All versions prior to V5.0.4.11) and SoMachine/SoMachine Motion software (All versions), t...Show more |
1Schneider Electric 7Ecostruxure Machine Expert Modicon M218 FirmwareModicon M241 Firmware+4 moreJun 17, 2026 Apr 22, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists which could leak sensitive information transmitted between the software and the Modicon M218, M241, M251, and M258 controllers. |
1Schneider Electric 7Ecostruxure Machine Expert Modicon M218 FirmwareModicon M241 Firmware+4 moreJun 17, 2026 Apr 22, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists which could allow the attacker to execute malicious code on the Modicon M218, M241, M251, and M258 controllers. |
1Schneider Electric 12Atv Imc Drive Controller Firmware Modicon Lmc058 FirmwareModicon Lmc078 Firmware+9 moreJun 17, 2026 May 22, 2019 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 A CWE-306: Missing Authentication for Critical Function vulnerability exists which could cause a modification of device IP configuration (IP address, network mask and gateway IP address) when a specific Ethernet frame is...Show more |