Schneider Electric
schneider-electric
783 CVEs • 1,762 products
Products (1,762)
Click to collapseToggle
Products (1,762)
Click to collapse
CVEs (783)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Schneider Electric 1Ecostruxure Power Build Rapsody Jun 17, 2026 Jan 15, 2026 8.4 HIGH· v4 7.8 HIGH· v3 N/A· v2 CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rapsody. |
1Schneider Electric 1Ecostruxure Power Build Rapsody Jun 17, 2026 Jan 15, 2026 8.4 HIGH· v4 5.3 MEDIUM· v3 N/A· v2 CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody. |
1Schneider Electric 3Powerlogic Pm5320 Firmware Powerlogic Pm5340 FirmwarePowerlogic Pm5341 FirmwareJun 17, 2026 Nov 13, 2024 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 CWE-400: An Uncontrolled Resource Consumption vulnerability exists that could cause the device to become
unresponsive resulting in communication loss when a large amount of IGMP packets is present in the network. |
1Schneider Electric 1Ecostruxure It Gateway Jun 17, 2026 Nov 13, 2024 10.0 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access when enabled on
the network and potentially impacting connected devices. |
CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution, denial
of service and loss of confidentiality & integrity when application user opens a malicious Zelio
Soft 2 project file. |
1Schneider Electric 2Vijeo Designer Vijeo Designer Embedded In Ecostruxure Machine ExpertJun 17, 2026 Sep 11, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and availability of the workstation when non-admin authenticated user tries to perform...Show more |
1Schneider Electric 1Whc 5918a Firmware Jun 17, 2026 Jul 11, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 CWE-200: Information Exposure vulnerability exists that could cause disclosure of
credentials when a specially crafted message is sent to the device. |
1Schneider Electric 5Modicon Lmc058 Firmware Modicon M241 FirmwareModicon M251 Firmware+2 moreJun 17, 2026 Jul 11, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a vulnerability leading to a cross-site scripting condition where attackers can have a vi...Show more |
1Schneider Electric 1Ecostruxure Foxboro Dcs Control Core Services Jun 17, 2026 Jul 11, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service, privilege escalation, and potentially kernel execution when a malicious actor with local user access crafts a script/progra...Show more |
1Schneider Electric 1Ecostruxure Foxboro Dcs Control Core Services Jun 17, 2026 Jul 11, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys drive...Show more |
1Schneider Electric 1Ecostruxure Foxboro Dcs Control Core Services Jun 17, 2026 Jul 11, 2024 N/A· v4 7.1 HIGH· v3 N/A· v2 CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, or kernel memory leak when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.s...Show more |
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could result in remote code execution when an authenticated user executes a saved project file that has bee...Show more |
1Schneider Electric 1Powerlogic P5 Firmware Jun 17, 2026 Jun 12, 2024 N/A· v4 6.8 MEDIUM· v3 N/A· v2 CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists that could cause denial of service, device reboot, or an attacker gaining full control of the relay when a specially crafted reset token is e...Show more |
CWE-428: Unquoted search path or element vulnerability exists in Easergy Studio, which could
cause privilege escalation when a valid user replaces a trusted file name on the system and
reboots the machine. |
1Schneider Electric 1Ecostruxure It Gateway Jun 17, 2026 Jun 12, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 CWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege
escalation when logged in as a non-administrative user. |
1Schneider Electric 1Sage Rtu Firmware Jun 17, 2026 Jun 12, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service of the
device’s web interface when an attacker sends a specially crafted HTTP request. |
1Schneider Electric 2Spacelogic As B Firmware Spacelogic As P FirmwareJun 17, 2026 Jun 12, 2024 N/A· v4 6.4 MEDIUM· v3 N/A· v2 CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists that could
cause escalation of privileges when an attacker abuses a limited admin account. |
1Schneider Electric 2Spacelogic As B Firmware Spacelogic As P FirmwareJun 17, 2026 Jun 12, 2024 N/A· v4 4.5 MEDIUM· v3 N/A· v2 CWE-532: Insertion of Sensitive Information into Log File vulnerability exists that could cause
exposure of SNMP credentials when an attacker has access to the controller logs. |
1Schneider Electric 1Sage Rtu Firmware Jun 17, 2026 Jun 12, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability exists that could allow a user with access to the device’s web interface to cause a fault on the device when sending a malform...Show more |
1Schneider Electric 1Sage Rtu Firmware Jun 17, 2026 Jun 12, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the
device when an attacker sends a specially crafted HTTP request. |