← Back

Schneider Electric

schneider-electric

783 CVEs • 1,762 products

Products (1,762)

Click to collapse
Toggle
Proclima
proclima
Clearscada
clearscada

CVEs (783)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Schneider Electric
1Ecostruxure Power Build Rapsody
Jun 17, 2026
Jan 15, 2026
8.4 HIGH· v4
7.8 HIGH· v3
N/A· v2
CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rapsody.
1Schneider Electric
1Ecostruxure Power Build Rapsody
Jun 17, 2026
Jan 15, 2026
8.4 HIGH· v4
5.3 MEDIUM· v3
N/A· v2
CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody.
1Schneider Electric
3Powerlogic Pm5320 Firmware
Powerlogic Pm5340 FirmwarePowerlogic Pm5341 Firmware
Jun 17, 2026
Nov 13, 2024
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
CWE-400: An Uncontrolled Resource Consumption vulnerability exists that could cause the device to become unresponsive resulting in communication loss when a large amount of IGMP packets is present in the network.
1Schneider Electric
1Ecostruxure It Gateway
Jun 17, 2026
Nov 13, 2024
10.0 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access when enabled on the network and potentially impacting connected devices.
1Schneider Electric
1Zelio Soft 2
Jun 17, 2026
Oct 8, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when application user opens a malicious Zelio Soft 2 project file.
1Schneider Electric
2Vijeo Designer
Vijeo Designer Embedded In Ecostruxure Machine Expert
Jun 17, 2026
Sep 11, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and availability of the workstation when non-admin authenticated user tries to perform...Show more
CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and availability of the workstation when non-admin authenticated user tries to perform privilege escalation by tampering with the binaries.Show less
1Schneider Electric
1Whc 5918a Firmware
Jun 17, 2026
Jul 11, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
CWE-200: Information Exposure vulnerability exists that could cause disclosure of credentials when a specially crafted message is sent to the device.
1Schneider Electric
5Modicon Lmc058 Firmware
Modicon M241 FirmwareModicon M251 Firmware+2 more
Jun 17, 2026
Jul 11, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a vulnerability leading to a cross-site scripting condition where attackers can have a vi...Show more
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a vulnerability leading to a cross-site scripting condition where attackers can have a victim’s browser run arbitrary JavaScript when they visit a page containing the injected payload.Show less
1Schneider Electric
1Ecostruxure Foxboro Dcs Control Core Services
Jun 17, 2026
Jul 11, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service, privilege escalation, and potentially kernel execution when a malicious actor with local user access crafts a script/progra...Show more
CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service, privilege escalation, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.Show less
1Schneider Electric
1Ecostruxure Foxboro Dcs Control Core Services
Jun 17, 2026
Jul 11, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys drive...Show more
CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.Show less
1Schneider Electric
1Ecostruxure Foxboro Dcs Control Core Services
Jun 17, 2026
Jul 11, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, or kernel memory leak when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.s...Show more
CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, or kernel memory leak when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.Show less
1Schneider Electric
1Foxrtu Station
Jun 17, 2026
Jul 11, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could result in remote code execution when an authenticated user executes a saved project file that has bee...Show more
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could result in remote code execution when an authenticated user executes a saved project file that has been tampered by a malicious actor.Show less
1Schneider Electric
1Powerlogic P5 Firmware
Jun 17, 2026
Jun 12, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists that could cause denial of service, device reboot, or an attacker gaining full control of the relay when a specially crafted reset token is e...Show more
CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists that could cause denial of service, device reboot, or an attacker gaining full control of the relay when a specially crafted reset token is entered into the front panel of the device.Show less
1Schneider Electric
1Easergy Studio
Jun 17, 2026
Jun 12, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
CWE-428: Unquoted search path or element vulnerability exists in Easergy Studio, which could cause privilege escalation when a valid user replaces a trusted file name on the system and reboots the machine.
1Schneider Electric
1Ecostruxure It Gateway
Jun 17, 2026
Jun 12, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
CWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege escalation when logged in as a non-administrative user.
1Schneider Electric
1Sage Rtu Firmware
Jun 17, 2026
Jun 12, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service of the device’s web interface when an attacker sends a specially crafted HTTP request.
1Schneider Electric
2Spacelogic As B Firmware
Spacelogic As P Firmware
Jun 17, 2026
Jun 12, 2024
N/A· v4
6.4 MEDIUM· v3
N/A· v2
CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists that could cause escalation of privileges when an attacker abuses a limited admin account.
1Schneider Electric
2Spacelogic As B Firmware
Spacelogic As P Firmware
Jun 17, 2026
Jun 12, 2024
N/A· v4
4.5 MEDIUM· v3
N/A· v2
CWE-532: Insertion of Sensitive Information into Log File vulnerability exists that could cause exposure of SNMP credentials when an attacker has access to the controller logs.
1Schneider Electric
1Sage Rtu Firmware
Jun 17, 2026
Jun 12, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability exists that could allow a user with access to the device’s web interface to cause a fault on the device when sending a malform...Show more
CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability exists that could allow a user with access to the device’s web interface to cause a fault on the device when sending a malformed HTTP request.Show less
1Schneider Electric
1Sage Rtu Firmware
Jun 17, 2026
Jun 12, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request.