CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Schneider Electric 5Ecostruxure Machine Expert Modicon M100 FirmwareModicon M200 Firmware+2 moreMay 28, 2026 Apr 22, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability exists on EcoStruxure Machine Expert – Basic or SoMachine Basic programming software (versions in...Show more |
1Schneider Electric 2Modicon M221 Firmware Somachine BasicNov 21, 2024 May 22, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause remote launch of SoMachine Basic when sending craf...Show more |
1Schneider Electric 2Modicon M221 Firmware Somachine BasicNov 21, 2024 May 22, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An Incorrect Default Permissions (CWE-276) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause unauthorized access to SoMach...Show more |
1Schneider Electric 2Modicon M221 Firmware Somachine BasicMay 29, 2026 May 22, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause cycle time impact when flooding the M221 ethernet...Show more |
1Schneider Electric 1Somachine Basic May 29, 2026 Nov 2, 2018 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 A Insufficient Verification of Data Authenticity (CWE-345) vulnerability exists in the Modicon M221, all versions, which could cause a change of IPv4 configuration (IP address, mask and gateway) when remotely connected t...Show more |
1Schneider Electric 1Somachine Basic Nov 21, 2024 Jul 3, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Schneider Electric SoMachine Basic prior to v1.6 SP1 suffers from an XML External Entity (XXE) vulnerability using the DTD parameter entities technique resulting in disclosure and retrieval of arbitrary data on the affec...Show more |