Schneider Electric
schneider-electric
783 CVEs • 1,762 products
Products (1,762)
Click to collapseToggle
Products (1,762)
Click to collapse
CVEs (783)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Schneider Electric 1Powerlogic P7 Firmware Jul 1, 2026 Jun 25, 2026 6.9 MEDIUM· v4 6.5 MEDIUM· v3 N/A· v2 CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-service condition, impacting system availability when a specially crafted request is sent to a vulnerable...Show more |
1Schneider Electric 1Powerlogic P7 Firmware Jul 1, 2026 Jun 25, 2026 8.6 HIGH· v4 7.2 HIGH· v3 N/A· v2 CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution of commands with elevated privileges, impacting system integrity, conf...Show more |
1Schneider Electric 1Powerlogic P7 Firmware Jul 1, 2026 Jun 25, 2026 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuration functionality unavailable when malformed requests are received over expos...Show more |
1Schneider Electric 2Easylogic T150 Firmware Saitel Dp FirmwareJul 14, 2026 Jun 25, 2026 6.7 MEDIUM· v4 4.4 MEDIUM· v3 N/A· v2 CWE-732 Incorrect Permission Assignment for Critical Resource vulnerability that could cause unauthorized disclosure of password hashes and potential account compromise when an attacker with privileged local access reads...Show more |
1Schneider Electric 2Easylogic T150 Firmware Saitel Dp FirmwareJul 14, 2026 Jun 25, 2026 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenticated attacker accesses credentials stored within firmware or system fi...Show more |
1Schneider Electric 1Struxureware Data Center Expert Jul 20, 2026 Jun 9, 2026 7.1 HIGH· v4 6.5 MEDIUM· v3 N/A· v2 CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert user account submits craf...Show more |
1Schneider Electric 1Ecostruxure Machine Expert Hvac Jun 17, 2026 May 14, 2026 6.8 MEDIUM· v4 7.5 HIGH· v3 N/A· v2 CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could result in revealing protected source code and loss of confidentiality, When...Show more |
1Schneider Electric 5Ecostruxure Panel Server Pas400 Firmware Ecostruxure Panel Server Pas600 FirmwareEcostruxure Panel Server Pas600v2 Firmware+2 moreJun 24, 2026 May 12, 2026 8.2 HIGH· v4 7.5 HIGH· v3 N/A· v2 CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in rare circumstances, ena...Show more |
1Schneider Electric 1Powerchute Serial Shutdown Jun 17, 2026 Apr 14, 2026 5.3 MEDIUM· v4 6.5 MEDIUM· v3 N/A· v2 CWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting zip file creation and denial of service when a Web Admin user floods the system with POST /helpabout requests. |
1Schneider Electric 1Powerchute Serial Shutdown Jun 17, 2026 Apr 14, 2026 6.9 MEDIUM· v4 5.3 MEDIUM· v3 N/A· v2 CWE-116 Improper Encoding or Escaping of Output vulnerability exists that could cause log injection and forged log when an attacker alters the POST /j_security check request payload. |
1Schneider Electric 1Powerchute Serial Shutdown Jun 17, 2026 Apr 14, 2026 5.3 MEDIUM· v4 4.3 MEDIUM· v3 N/A· v2 CWE-1284 Improper Validation of Specified Quantity in Input vulnerability exists that could cause Event and Data Log truncation impacting log integrity when a Web Admin user alters the POST /logsettings request payload. |
1Schneider Electric 1Powerchute Serial Shutdown Jun 17, 2026 Apr 14, 2026 6.9 MEDIUM· v4 5.3 MEDIUM· v3 N/A· v2 CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to gain access to the user account by performing an arbitrary number of authentication attempts with dif...Show more |
1Schneider Electric 1Powerchute Serial Shutdown Jun 17, 2026 Apr 14, 2026 2.4 LOW· v4 5.0 MEDIUM· v3 N/A· v2 CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information to be exposed when a Web Admin user executes a malicious file provided by an attacker. |
1Schneider Electric 1Powerchute Serial Shutdown Jun 17, 2026 Apr 14, 2026 5.3 MEDIUM· v4 4.3 MEDIUM· v3 N/A· v2 CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists that could cause application user credentials to reset when a Web Admin user alters the POST /setPCBEDesc request payload. |
1Schneider Electric 1Powerchute Serial Shutdown Jun 17, 2026 Apr 14, 2026 6.9 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause critical files overwritten with text data when a Web Admin user alters the POST /REST/upssleep r...Show more |
1Schneider Electric 1Ecostruxure Automation Expert Jun 23, 2026 Mar 10, 2026 7.2 HIGH· v4 8.2 HIGH· v3 N/A· v2 CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untrusted commands on the engineering workstation which could result in a limited compromise of the work...Show more |
1Schneider Electric 1Ecostruxure Foxboro Dcs Control Software Jun 24, 2026 Mar 10, 2026 7.0 HIGH· v4 6.5 MEDIUM· v3 N/A· v2 CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote code execution on workstation when an admin authenticated user opens a malicious...Show more |
1Schneider Electric 4Modicon Lmc058 Firmware Modicon M241 FirmwareModicon M251 Firmware+1 moreJun 23, 2026 Mar 10, 2026 5.1 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause condition where authenticated attackers can have a victim’s browser run arbitrary JavaScri...Show more |
1Schneider Electric 3Modicon M241 Firmware Modicon M251 FirmwareModicon M262 FirmwareJun 23, 2026 Mar 10, 2026 6.9 MEDIUM· v4 5.3 MEDIUM· v3 N/A· v2 CWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of Service on Machine Expert protocol when an unauthenticated attacker sends malicious payload to occupy active communica...Show more |
1Schneider Electric 2Ecostruxure Power Monitoring Expert Ecostruxure Power OperationJun 24, 2026 Mar 10, 2026 8.5 HIGH· v4 7.8 HIGH· v3 N/A· v2 CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a locally authenticated attacker sends a crafted data stream, triggering unsaf...Show more |