Schneider Electric
schneider-electric
771 CVEs • 1,745 products
Products (1,745)
Click to collapseToggle
Products (1,745)
Click to collapse
CVEs (771)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Schneider Electric 3Clearscada Ecostruxure Geo Scada Expert 2019Ecostruxure Geo Scada Expert 2020Nov 21, 2024 Feb 9, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and Geo SCADA web server are intercepted. Affected Product: ClearSCADA (Al...Show more |
1Schneider Electric 3Clearscada Ecostruxure Geo Scada Expert 2019Ecostruxure Geo Scada Expert 2020Nov 21, 2024 Feb 9, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-326: Inadequate Encryption Strength vulnerability exists that could cause non-encrypted communication with the server when outdated versions of the ViewX client are used. Affected Product: ClearSCADA (All Versions)...Show more |
1Schneider Electric 1Interactive Graphical Scada System Data Server Nov 21, 2024 Feb 9, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-862: Missing Authorization vulnerability exists that could cause information exposure when an attacker sends a specific message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and p...Show more |
1Schneider Electric 1Interactive Graphical Scada System Data Server Nov 21, 2024 Feb 9, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-665: Improper Initialization vulnerability exists that could cause information exposure when an attacker sends a specially crafted message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0....Show more |
1Schneider Electric 1Interactive Graphical Scada System Data Server Nov 21, 2024 Feb 9, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service when an attacker repeatedly sends a specially crafted message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0...Show more |
1Schneider Electric 1Interactive Graphical Scada System Data Server Nov 21, 2024 Feb 9, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-125: Out-of-bounds Read vulnerability exists that could cause memory leaks potentially resulting in denial of service when an attacker repeatedly sends a specially crafted message. Affected Product: Interactive Gra...Show more |
1Schneider Electric 1Interactive Graphical Scada System Data Server Nov 21, 2024 Feb 9, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leading to remote code execution when an attacker sends a specially crafted message. A...Show more |
1Schneider Electric 1Interactive Graphical Scada System Data Server Nov 21, 2024 Feb 9, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause modification of an existing file by adding at end of file or create a new file in the context of the Data Server...Show more |
1Schneider Electric 1Interactive Graphical Scada System Data Server Nov 21, 2024 Feb 9, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause modification of an existing file by inserting at beginning of file or create a new file in the context of the Da...Show more |
1Schneider Electric 1Interactive Graphical Scada System Data Server Nov 21, 2024 Feb 9, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to denial of service and potentially remote code execution when an attacker sends multiple specially cra...Show more |
1Schneider Electric 33Easergy P141 Firmware Easergy P142 FirmwareEasergy P143 Firmware+30 moreNov 21, 2024 Feb 9, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-798: Use of Hard-coded Credentials vulnerability exists. If an attacker were to obtain the TLS cryptographic key and take active control of the Courier tunneling communication network, they could potentially observ...Show more |
1Schneider Electric 3Fellerlynk Firmware Spacelynk FirmwareWiser For Knx FirmwareNov 21, 2024 Feb 9, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a web session compromise when an attacker injects and then executes arbitrary malicious...Show more |
1Schneider Electric 3Fellerlynk Firmware Spacelynk FirmwareWiser For Knx FirmwareNov 21, 2024 Feb 9, 2022 N/A· v4 8.1 HIGH· v3 8.8 HIGH· v2 A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could induce users to perform unintended actions, leading to the override of the system�s configurations when an attacker persuades a user to visit a...Show more |
1Schneider Electric 3Fellerlynk Firmware Spacelynk FirmwareWiser For Knx FirmwareNov 21, 2024 Feb 9, 2022 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to manipulate the admin after numerous attempts at guessing credentials. Affected Product: spaceLYnk...Show more |
1Schneider Electric 3Fellerlynk Firmware Spacelynk FirmwareWiser For Knx FirmwareNov 21, 2024 Feb 9, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow modifications of the touch configurations in an unauthorized manner when an attacker attempts to modify the touch configuratio...Show more |
1Schneider Electric 7Hmibscea53d1edb Firmware Hmibscea53d1edl FirmwareHmibscea53d1edm Firmware+4 moreNov 21, 2024 Feb 9, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A CWE-352: Cross-Site Request Forgery (CSRF) exists that could cause a remote attacker to gain unauthorized access to the product when conducting cross-domain attacks based on same-origin policy or cross-site request for...Show more |
1Schneider Electric 7Hmibscea53d1edb Firmware Hmibscea53d1edl FirmwareHmibscea53d1edm Firmware+4 moreNov 21, 2024 Feb 9, 2022 N/A· v4 7.4 HIGH· v3 4.3 MEDIUM· v2 A CWE-1021 Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause unintended modifications of the product settings or user accounts when deceiving the user to use the web interface ren...Show more |
1Schneider Electric 37Hmibmiea5dd1001 Firmware Hmibmiea5dd100a FirmwareHmibmiea5dd1101 Firmware+34 moreNov 21, 2024 Feb 9, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local privilege escalation. Affected Product: Harmony/Magelis iPC Series (A...Show more |
1Schneider Electric 1Ecostruxure Power Monitoring Expert Nov 21, 2024 Feb 4, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could allow an authenticated attacker to view data, change settings, or impact availability of the...Show more |
1Schneider Electric 1Ecostruxure Power Monitoring Expert Nov 21, 2024 Feb 4, 2022 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A CWE-20: Improper Input Validation vulnerability exists that could allow an unauthenticated attacker to view data, change settings, impact availability of the software, or potentially impact a user�s local machine when...Show more |