← Back

Schneider Electric

schneider-electric

771 CVEs • 1,745 products

Products (1,745)

Click to collapse
Toggle
Proclima
proclima
Clearscada
clearscada

CVEs (771)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Schneider Electric
2Tcm 4351b Firmware
Triconex Model 3009 Mp Firmware
Nov 21, 2024
May 26, 2021
N/A· v4
3.9 LOW· v3
2.1 LOW· v2
Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while t...Show more
Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the write-protect keyswitch is in the program position. This CVE ID is unique from CVE-2021-22742, CVE-2021-22744, CVE-2021-22746, and CVE-2021-22747.Show less
1Schneider Electric
2Tcm 4351b Firmware
Triconex Model 3009 Mp Firmware
Nov 21, 2024
May 26, 2021
N/A· v4
3.9 LOW· v3
2.1 LOW· v2
Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while t...Show more
Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the write-protect keyswitch is in the program position. This CVE ID is unique from CVE-2021-22742, CVE-2021-22745, CVE-2021-22746, and CVE-2021-22747.Show less
1Schneider Electric
2Tcm 4351b Firmware
Triconex Model 3009 Mp Firmware
Nov 21, 2024
May 26, 2021
N/A· v4
3.9 LOW· v3
2.1 LOW· v2
Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex TCM 4351B installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the w...Show more
Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex TCM 4351B installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the write-protect keyswitch is in the program position.Show less
1Schneider Electric
2Tcm 4351b Firmware
Triconex Model 3009 Mp Firmware
Nov 21, 2024
May 26, 2021
N/A· v4
3.9 LOW· v3
2.1 LOW· v2
Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while t...Show more
Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex Model 3009 MP installed on Tricon V11.3.x systems that could cause module reset when TCM receives malformed TriStation packets while the write-protect keyswitch is in the program position.Show less
1Schneider Electric
3Clearscada
Ecostruxure Geo Scada Expert 2019Ecostruxure Geo Scada Expert 2020
Nov 21, 2024
May 26, 2021
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Use of Password Hash with Insufficient Computational Effort vulnerability exists in ClearSCADA (all versions), EcoStruxure Geo SCADA Expert 2019 (all versions), and EcoStruxure Geo SCADA Expert 2020 (V83.7742.1 and prior...Show more
Use of Password Hash with Insufficient Computational Effort vulnerability exists in ClearSCADA (all versions), EcoStruxure Geo SCADA Expert 2019 (all versions), and EcoStruxure Geo SCADA Expert 2020 (V83.7742.1 and prior), which could cause the revealing of account credentials when server database files are available. Exposure of these files to an attacker can make the system vulnerable to password decryption attacks. Note that “.sde” configuration export files do not contain user account password hashes.Show less
1Schneider Electric
2Homelynk Firmware
Spacelynk Firmware
Nov 21, 2024
May 26, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Information Exposure vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause information to be exposed when an unauthorized file is uploaded.
1Schneider Electric
2Homelynk Firmware
Spacelynk Firmware
Nov 21, 2024
May 26, 2021
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Information Exposure vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a device to be compromised when it is first configured.
1Schneider Electric
2Homelynk Firmware
Spacelynk Firmware
Nov 21, 2024
May 26, 2021
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that could cause unauthorized access when credentials are discovered after a brute force att...Show more
Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that could cause unauthorized access when credentials are discovered after a brute force attack.Show less
1Schneider Electric
2Homelynk Firmware
Spacelynk Firmware
Nov 21, 2024
May 26, 2021
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Insufficiently Protected Credentials vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior that could cause unauthorized access of when credentials are discovered after a brute force attack.
1Schneider Electric
2Homelynk Firmware
Spacelynk Firmware
Nov 21, 2024
May 26, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a denial of service when an unauthorized fil...Show more
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a denial of service when an unauthorized file is uploaded.Show less
1Schneider Electric
2Homelynk Firmware
Spacelynk Firmware
Nov 21, 2024
May 26, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Improper Verification of Cryptographic Signature vulnerability exists inhomeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could allow remote code execution when unauthorized code is copied to the device.
1Schneider Electric
2Homelynk Firmware
Spacelynk Firmware
Nov 21, 2024
May 26, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Improper Verification of Cryptographic Signature vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause remote code execution when an attacker loads unauthorized code.
1Schneider Electric
2Homelynk Firmware
Spacelynk Firmware
Nov 21, 2024
May 26, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause shell access when unauthorized code is loaded into the system folder.
1Schneider Electric
2Homelynk Firmware
Spacelynk Firmware
Nov 21, 2024
May 26, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a code execution issue when an attacker loads unauthorized code on the web server.
1Schneider Electric
16Mcsesm043f23f0 Firmware
Mcsesm053f1cs0 FirmwareMcsesm053f1cu0 Firmware+13 more
Nov 21, 2024
May 26, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Weak Password Recovery Mechanism for Forgotten Password vulnerability exists on Modicon Managed Switch MCSESM* and MCSESP* V8.21 and prior which could cause an unauthorized password change through HTTP / HTTPS when basic...Show more
Weak Password Recovery Mechanism for Forgotten Password vulnerability exists on Modicon Managed Switch MCSESM* and MCSESP* V8.21 and prior which could cause an unauthorized password change through HTTP / HTTPS when basic user information is known by a remote attacker.Show less
1Schneider Electric
2Ecostruxure Machine Expert
Vijeo Designer
Nov 21, 2024
May 26, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service or unauthorized access to system information when interacting directly with a driver install...Show more
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service or unauthorized access to system information when interacting directly with a driver installed by Vijeo Designer or EcoStruxure Machine ExpertShow less
1Schneider Electric
2Modicon M241 Firmware
Modicon M251 Firmware
Nov 21, 2024
May 26, 2021
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Improper Input Validation vulnerability exists in Modicon M241/M251 logic controllers firmware prior to V5.1.9.1 that could cause denial of service when specific crafted requests are sent to the controller over HTTP.
1Schneider Electric
1C Bus Toolkit
Nov 21, 2024
Apr 13, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when restoring a project.
1Schneider Electric
1C Bus Toolkit
Nov 21, 2024
Apr 13, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when a file is uploaded.
1Schneider Electric
1C Bus Toolkit
Nov 21, 2024
Apr 13, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when restoring project files.