Schneider Electric
schneider-electric
771 CVEs • 1,745 products
Products (1,745)
Click to collapseToggle
Products (1,745)
Click to collapse
CVEs (771)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Att Schneider Electric4Ecostruxure Control Expert Ecostruxure Process ExpertRemoteconnect+1 moreNov 21, 2024 Apr 14, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any of: CVE-2021-21810, CVE-2021-21811, CVE...Show more |
1Schneider Electric 1Scadapack Workbench Nov 21, 2024 Apr 13, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could result in information disclosure when opening a malicious solution file provided by an attacker with SCADAPack Workbench. T...Show more |
1Schneider Electric 3Ecostruxure Control Expert Ecostruxure Process ExpertRemoteconnectNov 21, 2024 Apr 13, 2022 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be deployed in an unauthorized location and may result in code execution o...Show more |
1Schneider Electric 1Struxureware Data Center Expert Nov 21, 2024 Apr 13, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when performed over the network. Affected Product: StruxureW...Show more |
1Schneider Electric 1Struxureware Data Center Expert Nov 21, 2024 Apr 13, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution. Affected Product: StruxureWare Data Center Expert (V7.8.1 and prior) |
1Schneider Electric 1Software Update Nov 21, 2024 Apr 13, 2022 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 A CWE-502: Deserialization of Untrusted Data vulnerability exists which could allow an attacker to execute arbitrary code on the targeted system with SYSTEM privileges when placing a malicious user to be authenticated fo...Show more |
2Belden Schneider Electric13Eagle 20 Tofino 943 987 501 Tx/tx Firmware Eagle 20 Tofino 943 987 502 Tx/mm FirmwareEagle 20 Tofino 943 987 504 Mm/tx Firmware+10 moreNov 21, 2024 Apr 3, 2022 N/A· v4 6.8 MEDIUM· v3 7.2 HIGH· v2 On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an arbitrary firmware image can be loaded because firmware signature verificatio...Show more |
2Belden Schneider Electric13Eagle 20 Tofino 943 987 501 Tx/tx Firmware Eagle 20 Tofino 943 987 502 Tx/mm FirmwareEagle 20 Tofino 943 987 504 Mm/tx Firmware+10 moreNov 21, 2024 Apr 3, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, crafted ModBus packets can bypass the ModBus enforcer. NOTE: this issue exists b...Show more |
2Belden Schneider Electric13Eagle 20 Tofino 943 987 501 Tx/tx Firmware Eagle 20 Tofino 943 987 502 Tx/mm FirmwareEagle 20 Tofino 943 987 504 Mm/tx Firmware+10 moreNov 21, 2024 Apr 3, 2022 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an SSH login can succeed with hardcoded default credentials (if the device is in...Show more |
2Belden Schneider Electric11Eagle 20 Tofino 943 987 501 Tx/tx Firmware Eagle 20 Tofino 943 987 502 Tx/mm FirmwareEagle 20 Tofino 943 987 504 Mm/tx Firmware+8 moreNov 21, 2024 Apr 3, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 On Schneider Electric ConneXium Tofino OPCLSM TCSEFM0000 before 03.23 and Belden Tofino Xenon Security Appliance, crafted OPC packets can cause an OPC enforcer denial of service. |
2Belden Schneider Electric11Eagle 20 Tofino 943 987 501 Tx/tx Firmware Eagle 20 Tofino 943 987 502 Tx/mm FirmwareEagle 20 Tofino 943 987 504 Mm/tx Firmware+8 moreNov 21, 2024 Apr 3, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 On Schneider Electric ConneXium Tofino OPCLSM TCSEFM0000 before 03.23 and Belden Tofino Xenon Security Appliance, crafted OPC packets can bypass the OPC enforcer. |
2Belden Schneider Electric13Eagle 20 Tofino 943 987 501 Tx/tx Firmware Eagle 20 Tofino 943 987 502 Tx/mm FirmwareEagle 20 Tofino 943 987 504 Mm/tx Firmware+10 moreNov 21, 2024 Apr 3, 2022 N/A· v4 6.8 MEDIUM· v3 7.2 HIGH· v2 On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, physically proximate attackers can execute code via a crafted file on a USB stic...Show more |
3Rockwellautomation Schneider ElectricXylem17Aadvance Controller Easergy C5 FirmwareEasergy T300 Firmware+14 moreNov 21, 2024 Mar 18, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable file. ISaGRAF Runtime reads the file and saves the data in a variable wi...Show more |
3Rockwellautomation Schneider ElectricXylem17Aadvance Controller Easergy C5 FirmwareEasergy T300 Firmware+14 moreNov 21, 2024 Mar 18, 2022 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x searches for and loads DLLs as dynamic libraries. Uncontrolled loading of dynamic libraries could allow a local, unauthenticated attacker to execute arbitrary code...Show more |
3Rockwellautomation Schneider ElectricXylem17Aadvance Controller Easergy C5 FirmwareEasergy T300 Firmware+14 moreNov 21, 2024 Mar 18, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged commands. The password value passed to ISaGRAF Runtime is the result of enc...Show more |
3Rockwellautomation Schneider ElectricXylem17Aadvance Controller Easergy C5 FirmwareEasergy T300 Firmware+14 moreNov 21, 2024 Mar 18, 2022 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communication protocol provides various file system operations, as well as the uploading of applications. Da...Show more |
3Rockwellautomation Schneider ElectricXylem17Aadvance Controller Easergy C5 FirmwareEasergy T300 Firmware+14 moreNov 21, 2024 Mar 18, 2022 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in the file system. Since the parameter pointing to the file name is not ch...Show more |
1Schneider Electric 2Ecostruxure Control Expert Ecostruxure Process ExpertNov 21, 2024 Mar 9, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause a disruption of communication between the Modicon controller and the engineering software, when an attacker is able to...Show more |
1Schneider Electric 1Ecostruxure Control Expert Nov 21, 2024 Mar 9, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a disruption of communication between the Modicon controller and the engineering software when an a...Show more |
1Schneider Electric 1Ritto Wiser Door Nov 21, 2024 Mar 9, 2022 N/A· v4 7.6 HIGH· v3 4.8 MEDIUM· v2 A CWE-200: Information Exposure vulnerability exists which could allow a session hijack when the door panel is communicating with the door. Affected Product: Ritto Wiser Door (All versions) |