Schneider Electric
schneider-electric
783 CVEs • 1,762 products
Products (1,762)
Click to collapseToggle
Products (1,762)
Click to collapse
CVEs (783)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Schneider Electric 3Custom Reports Igss DashboardIgss Data ServerJun 17, 2026 Mar 21, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro to be executed, potentially leading to remote code execution when a user opens a malicious report file planted by an att...Show more |
1Schneider Electric 3Custom Reports Igss DashboardIgss Data ServerJun 17, 2026 Mar 21, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Custom Reports that could cause a remote code execution when a victim tries to open a malicious report. Affected Products: IGS...Show more |
1Schneider Electric 3Custom Reports Igss DashboardIgss Data ServerJun 17, 2026 Mar 21, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets t...Show more |
1Schneider Electric 3Custom Reports Igss DashboardIgss Data ServerJun 17, 2026 Mar 21, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause manipulation of dashboard files in the IGSS project report directory, when an attacker sends specific cra...Show more |
1Schneider Electric 3Custom Reports Igss DashboardIgss Data ServerJun 17, 2026 Mar 21, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow the creation of a malicious report file in the IGSS project report directory, this could lead...Show more |
1Schneider Electric 4Clearscada Ecostruxure Geo Scada Expert 2019Ecostruxure Geo Scada Expert 2020+1 moreJun 17, 2026 Feb 24, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A CWE-117: Improper Output Neutralization for Logs vulnerability exists that could cause the misinterpretation of log files when malicious packets are sent to the Geo SCADA server's database web port (default 443). Affec...Show more |
1Schneider Electric 1Ecostruxure Power Commission Jun 17, 2026 Feb 1, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A CWE-285: Improper Authorization vulnerability exists that could cause unauthorized access to certain software functions when an attacker gets access to localhost interface of the EcoStruxure Power Commission applicatio...Show more |
1Schneider Electric 2Apc Easy Ups Online Monitoring Software Easy Ups Online Monitoring SoftwareJun 17, 2026 Feb 1, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause local privilege escalation when local attacker connects to the database. Affected Products: APC Easy UPS Online Monitoring Software (Windows...Show more |
1Schneider Electric 2Apc Easy Ups Online Monitoring Software Easy Ups Online Monitoring SoftwareJun 17, 2026 Feb 1, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cause local privilege escalation when a local attacker modifies the webroot directory. Affected Products: APC Easy UPS Onli...Show more |
1Schneider Electric 2Apc Easy Ups Online Monitoring Software Easy Ups Online Monitoring SoftwareJun 17, 2026 Feb 1, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution when the attacker uploads a malicious JSP file. Affected Products: APC Easy UPS Online Monitoring Sof...Show more |
1Schneider Electric 2Apc Easy Ups Online Monitoring Software Easy Ups Online Monitoring SoftwareJun 17, 2026 Feb 1, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A CWE-306: Missing Authentication for Critical Function The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. Affected Pr...Show more |
1Schneider Electric 1Interactive Graphical Scada System Jun 17, 2026 Feb 1, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to denial of service and potentially remote code execution when an attacker sends multiple specially cra...Show more |
1Schneider Electric 1Interactive Graphical Scada System Jun 17, 2026 Feb 1, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leading to remote code execution when an attacker sends a specially crafted message. A...Show more |
1Schneider Electric 41Modicon M340 Bmxp341000 Firmware Modicon M340 Bmxp342000 FirmwareModicon M340 Bmxp3420102 Firmware+38 moreJun 17, 2026 Feb 1, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A CWE-200: Information Exposure vulnerability exists that could cause the exposure of sensitive information stored on the memory of the controller when communicating over the Modbus TCP protocol. Affected Products: Modic...Show more |
1Schneider Electric 3Ecostruxure Geo Scada Expert 2019 Ecostruxure Geo Scada Expert 2020Ecostruxure Geo Scada Expert 2021Jun 17, 2026 Jan 31, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information disclosure when specific messages are sent to the server over the database server TCP port. Affected...Show more |
1Schneider Electric 3Ecostruxure Geo Scada Expert 2019 Ecostruxure Geo Scada Expert 2020Ecostruxure Geo Scada Expert 2021Jun 17, 2026 Jan 31, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2
A CWE-863: Incorrect Authorization vulnerability exists that could cause Denial of
Service against the Geo SCADA server when specific messages are sent to the server over the
database server TCP port.
|
1Schneider Electric 37Ecostruxure Control Expert Ecostruxure Process ExpertModicon M340 Bmxp341000 Firmware+34 moreJun 17, 2026 Jan 31, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session. Affected Products: Eco...Show more |
1Schneider Electric 1Ecostruxure Cybersecurity Admin Expert Jun 17, 2026 Jan 30, 2023 N/A· v4 8.3 HIGH· v3 N/A· v2 A CWE-295: Improper Certificate Validation vulnerability exists that could cause the CAE software to give wrong data to end users when using CAE to configure devices. Additionally, credentials could leak which would enab...Show more |
1Schneider Electric 1Ecostruxure Cybersecurity Admin Expert Jun 17, 2026 Jan 30, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 A CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause legitimate users to be locked out of devices or facilitate backdoor account creation by spoofing a device on the local network. Affected...Show more |
1Schneider Electric 1Interactive Graphical Scada System Jun 17, 2026 Jan 30, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted log data re...Show more |