Schneider Electric
schneider-electric
771 CVEs • 1,745 products
Products (1,745)
Click to collapseToggle
Products (1,745)
Click to collapse
CVEs (771)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Schneider Electric 1Conext Combox Firmware Nov 21, 2024 Jan 30, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could cause system’s configurations override and cause a reboot loop when the product suffers from POST-Based Cross-Site Request Forgery (CSRF). Affe...Show more |
1Schneider Electric 1Conext Combox Firmware Nov 21, 2024 Jan 30, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause brute force attacks to take over the admin account when the product does not implement a rate limit mechanism on...Show more |
1Schneider Electric 65500ac2 Firmware 5500nac2 Firmware5500nac Firmware+3 moreNov 21, 2024 Jan 30, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A CWE-287: Improper Authentication vulnerability exists that could allow an attacker to gain control of the device when logging into a web page. Affected Products: C-Bus Network Automation Controller - LSS5500NAC (Versio...Show more |
1Schneider Electric 65500ac2 Firmware 5500nac2 Firmware5500nac Firmware+3 moreNov 21, 2024 Jan 30, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A CWE-521: Weak Password Requirements vulnerability exists that could allow an attacker to gain control of the device when the attacker brute forces the password. Affected Products: C-Bus Network Automation Controller -...Show more |
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause remote code execution when a command which exploits this vulnerability is utilized. Affected Produc...Show more |
1Schneider Electric 1Ecostruxure Power Commission Nov 21, 2024 Jan 30, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause all remote domains to access the resources (data) supplied by the server when an attacker sends a fetch request from third-party site...Show more |
1Schneider Electric 1Ecostruxure Power Commission Nov 21, 2024 Jan 30, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in a function that could allow an attacker to create or overwrite critical files that are used to execute code...Show more |
1Schneider Electric 1Ecostruxure Power Commission Nov 21, 2024 Jan 30, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could allow an attacker to create or overwrite critical files that are used to execute code, such as prog...Show more |
1Schneider Electric 55Ecostruxure Control Expert Ecostruxure Process ExpertModicon M340 Bmxp341000 Firmware+52 moreNov 21, 2024 Jan 30, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when a malicious project file is l...Show more |
1Schneider Electric 2Ecostruxure Machine Expert Hvac Somachine HvacNov 21, 2024 Jan 30, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A CWE-787: Out-of-bounds Write vulnerability exists that could cause sensitive information leakage when accessing a malicious web page from the commissioning software. Affected Products: SoMachine HVAC (Versions prior to...Show more |
1Schneider Electric 14Modicon M340 Bmxnoe0100 Firmware Modicon M340 Bmxnoe0110 FirmwareModicon M340 Bmxnoe0110h Firmware+11 moreNov 21, 2024 Nov 22, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A CWE-269: Improper Privilege Management vulnerability exists that could cause a denial of service of the Ethernet communication of the controller when sending a specific request over SNMP. Affected products: Modicon M34...Show more |
1Schneider Electric 48Modicon M340 Bmx P34 2010 Firmware Modicon M340 Bmx P34 2030 FirmwareModicon M580 Bmeh582040 Firmware+45 moreNov 21, 2024 Nov 22, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A CWE-191: Integer Underflow (Wrap or Wraparound) vulnerability exists that could cause a denial of service of the controller due to memory access violations when using the Modbus TCP protocol. Affected products: Modicon...Show more |
1Schneider Electric 2Ecostruxure Operator Terminal Expert Pro Face BlueNov 21, 2024 Nov 4, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 A CWE-89: Improper Neutralization of Special Elements used in SQL Command (‘SQL Injection’) vulnerability exists that allows adversaries with local user privileges to craft a malicious SQL query and execute as part of pr...Show more |
1Schneider Electric 2Ecostruxure Operator Terminal Expert Pro Face BlueNov 21, 2024 Nov 4, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in the SGIUtility component that allows adversaries with local user privileges to load malicious DLL which cou...Show more |
1Schneider Electric 2Ecostruxure Operator Terminal Expert Pro Face BlueNov 21, 2024 Nov 4, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in the SGIUtility component that allows adversaries with local user privileges to load a malicious DLL which could result in execution of m...Show more |
1Schneider Electric 2Ecostruxure Operator Terminal Expert Pro Face BlueNov 21, 2024 Nov 4, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 A CWE-704: Incorrect Project Conversion vulnerability exists that allows adversaries with local user privileges to load a project file from an adversary-controlled network share which could result in execution of malicio...Show more |
1Schneider Electric 2Ecostruxure Operator Terminal Expert Pro Face BlueNov 21, 2024 Nov 4, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that allows adversaries with local user privileges to load a malicious DLL which could lead to execution of ma...Show more |
1Schneider Electric 2Ecostruxure Operator Terminal Expert Pro Face BlueNov 21, 2024 Nov 4, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that allows adversaries with local user privileges to load a malicious DLL which could lead to execution of malicious code. Affected Produc...Show more |
1Schneider Electric 1Ecostruxure Control Expert Nov 21, 2024 Sep 13, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a crash of the Control Expert software when an incorrect project file is opened. Affected Products:...Show more |
1Schneider Electric 36Ecostruxure Control Expert Ecostruxure Process ExpertModicon M340 Bmxp341000 Firmware+33 moreNov 21, 2024 Sep 12, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode to the controller when communicating over Modbus. Affected Products: Eco...Show more |