Schneider Electric
schneider-electric
783 CVEs • 1,762 products
Products (1,762)
Click to collapseToggle
Products (1,762)
Click to collapse
CVEs (783)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Schneider Electric 1Interactive Graphical Scada System Data Server Jun 17, 2026 Feb 9, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause modification of an existing file by inserting at beginning of file or create a new file in the context of the Da...Show more |
1Schneider Electric 1Interactive Graphical Scada System Data Server Jun 17, 2026 Feb 9, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to denial of service and potentially remote code execution when an attacker sends multiple specially cra...Show more |
1Schneider Electric 33Easergy P141 Firmware Easergy P142 FirmwareEasergy P143 Firmware+30 moreJun 17, 2026 Feb 9, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-798: Use of Hard-coded Credentials vulnerability exists. If an attacker were to obtain the TLS cryptographic key and take active control of the Courier tunneling communication network, they could potentially observ...Show more |
1Schneider Electric 3Fellerlynk Firmware Spacelynk FirmwareWiser For Knx FirmwareJun 17, 2026 Feb 9, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a web session compromise when an attacker injects and then executes arbitrary malicious...Show more |
1Schneider Electric 3Fellerlynk Firmware Spacelynk FirmwareWiser For Knx FirmwareJun 17, 2026 Feb 9, 2022 N/A· v4 8.1 HIGH· v3 8.8 HIGH· v2 A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could induce users to perform unintended actions, leading to the override of the system�s configurations when an attacker persuades a user to visit a...Show more |
1Schneider Electric 3Fellerlynk Firmware Spacelynk FirmwareWiser For Knx FirmwareJun 17, 2026 Feb 9, 2022 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to manipulate the admin after numerous attempts at guessing credentials. Affected Product: spaceLYnk...Show more |
1Schneider Electric 3Fellerlynk Firmware Spacelynk FirmwareWiser For Knx FirmwareJun 17, 2026 Feb 9, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow modifications of the touch configurations in an unauthorized manner when an attacker attempts to modify the touch configuratio...Show more |
1Schneider Electric 7Hmibscea53d1edb Firmware Hmibscea53d1edl FirmwareHmibscea53d1edm Firmware+4 moreJun 17, 2026 Feb 9, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A CWE-352: Cross-Site Request Forgery (CSRF) exists that could cause a remote attacker to gain unauthorized access to the product when conducting cross-domain attacks based on same-origin policy or cross-site request for...Show more |
1Schneider Electric 7Hmibscea53d1edb Firmware Hmibscea53d1edl FirmwareHmibscea53d1edm Firmware+4 moreJun 17, 2026 Feb 9, 2022 N/A· v4 7.4 HIGH· v3 4.3 MEDIUM· v2 A CWE-1021 Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause unintended modifications of the product settings or user accounts when deceiving the user to use the web interface ren...Show more |
1Schneider Electric 37Hmibmiea5dd1001 Firmware Hmibmiea5dd100a FirmwareHmibmiea5dd1101 Firmware+34 moreJun 17, 2026 Feb 9, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local privilege escalation. Affected Product: Harmony/Magelis iPC Series (A...Show more |
1Schneider Electric 1Ecostruxure Power Monitoring Expert Jun 17, 2026 Feb 4, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could allow an authenticated attacker to view data, change settings, or impact availability of the...Show more |
1Schneider Electric 1Ecostruxure Power Monitoring Expert Jun 17, 2026 Feb 4, 2022 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A CWE-20: Improper Input Validation vulnerability exists that could allow an unauthenticated attacker to view data, change settings, impact availability of the software, or potentially impact a user�s local machine when...Show more |
1Schneider Electric 1Ecostruxure Power Monitoring Expert Jun 17, 2026 Feb 4, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A CWE-20: Improper Input Validation vulnerability exists that could allow arbitrary files on the server to be read by authenticated users through a limited operating system service account. Affected Product: EcoStruxure...Show more |
1Schneider Electric 1Easergy P3 Firmware Jun 17, 2026 Feb 4, 2022 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could lead to a buffer overflow causing program crashes and arbitrary code execution when specially crafted packets are sent to the device o...Show more |
1Schneider Electric 6Modicon M340 Bmxp341000 Firmware Modicon M340 Bmxp342000 FirmwareModicon M340 Bmxp3420102 Firmware+3 moreJun 17, 2026 Feb 4, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service on ports 80 (HTTP) and 502 (Modbus), when sending a large number of TCP RST or FIN packets to any open TCP port of th...Show more |
1Schneider Electric 1Easergy P5 Firmware Jun 17, 2026 Feb 4, 2022 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could lead to a buffer overflow causing program crashes and arbitrary code execution when specially crafted packets are sent to the device o...Show more |
1Schneider Electric 1Easergy P5 Firmware Jun 17, 2026 Feb 4, 2022 N/A· v4 7.5 HIGH· v3 5.4 MEDIUM· v2 A CWE-798: Use of Hard-coded Credentials vulnerability exists that could result in information disclosure. If an attacker were to obtain the SSH cryptographic key for the device and take active control of the local opera...Show more |
1Schneider Electric 10140cpu65 Firmware 140noc78000 Firmware140noe77111 Firmware+7 moreJun 17, 2026 Feb 4, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could cause a leak of sensitive data or unauthorized actions on the web server during the time the user is logged in. Affecte...Show more |
1Schneider Electric 1Ecostruxure Power Monitoring Expert Jun 17, 2026 Jan 28, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits a page containing the injected payload. This CVE is unique from CVE-2021-22826. Affected Product: Ec...Show more |
1Schneider Electric 1Ecostruxure Power Monitoring Expert Jun 17, 2026 Jan 28, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits a page containing the injected payload. This CVE is unique from CVE-2021-22827. Affected Product: Ec...Show more |