← Back

Schneider Electric

schneider-electric

771 CVEs • 1,745 products

Products (1,745)

Click to collapse
Toggle
Proclima
proclima
Clearscada
clearscada

CVEs (771)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Schneider Electric
20140cpu65150 Firmware
140noc77101 Firmware140noc78000 Firmware+17 more
Nov 21, 2024
Dec 11, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A CWE-754 Improper Check for Unusual or Exceptional Conditions vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security...Show more
A CWE-754 Improper Check for Unusual or Exceptional Conditions vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause a denial of service vulnerability when a specially crafted packet is sent to the controller over HTTP.Show less
1Schneider Electric
19Modicon M340 Bmxp341000 Firmware
Modicon M340 Bmxp342000 FirmwareModicon M340 Bmxp3420102 Firmware+16 more
Nov 21, 2024
Dec 11, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Legacy Controllers Modicon Quantum & Modicon Premium (see security notifications for affected versions),...Show more
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Legacy Controllers Modicon Quantum & Modicon Premium (see security notifications for affected versions), that could cause denial of service when a specially crafted Read Physical Memory request over Modbus is sent to the controller.Show less
1Schneider Electric
10Bmxnoe0100 Firmware
Bmxnoe0110 FirmwareBmxnor0200h Firmware+7 more
Nov 21, 2024
Dec 11, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A CWE-754:Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M340 CPUs (BMXP34* versions prior to V3.30) Modicon M340 Communication Ethernet modules (BMXNOE0100 (H) versions prior to V3....Show more
A CWE-754:Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M340 CPUs (BMXP34* versions prior to V3.30) Modicon M340 Communication Ethernet modules (BMXNOE0100 (H) versions prior to V3.4 BMXNOE0110 (H) versions prior to V6.6 BMXNOR0200H all versions), that could cause the device to be unreachable when modifying network parameters over SNMP.Show less
1Schneider Electric
21140cpu65150 Firmware
140cpu65160 Firmware140noc77101 Firmware+18 more
Nov 21, 2024
Dec 11, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal' Vulnerability Type) vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and as...Show more
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal' Vulnerability Type) vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause disclosure of information when sending a specially crafted request to the controller over HTTP.Show less
1Schneider Electric
3Modicon M258 Firmware
SomachineSomachine Motion
May 28, 2026
Dec 11, 2020
N/A· v4
6.8 MEDIUM· v3
5.2 MEDIUM· v2
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Modicon M258 Firmware (All versions prior to V5.0.4.11) and SoMachine/SoMachine Motion software (All versions), t...Show more
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Modicon M258 Firmware (All versions prior to V5.0.4.11) and SoMachine/SoMachine Motion software (All versions), that could cause a buffer overflow when the length of a file transferred to the webserver is not verified.Show less
1Schneider Electric
2Ecostruxure Geo Scada Expert 2019
Ecostruxure Geo Scada Expert 2020
Nov 21, 2024
Dec 11, 2020
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
A CWE-522: Insufficiently Protected Credentials vulnerability exists in EcoStruxure Geo SCADA Expert 2019 (Original release and Monthly Updates to September 2020, from 81.7268.1 to 81.7578.1) and EcoStruxure Geo SCADA Ex...Show more
A CWE-522: Insufficiently Protected Credentials vulnerability exists in EcoStruxure Geo SCADA Expert 2019 (Original release and Monthly Updates to September 2020, from 81.7268.1 to 81.7578.1) and EcoStruxure Geo SCADA Expert 2020 (Original release and Monthly Updates to September 2020, from 83.7551.1 to 83.7578.1), that could cause exposure of credentials to server-side users when web users are logged in to Virtual ViewX.Show less
1Schneider Electric
1Easergy T300 Firmware
Nov 21, 2024
Dec 11, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to trick a user into initiating an unintended action.
1Schneider Electric
1Easergy T300 Firmware
Nov 21, 2024
Dec 11, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to read network traffic over HTTP protocol.
1Schneider Electric
1Easergy T300 Firmware
Nov 21, 2024
Dec 11, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to read network traffic over HTTP protocol.
1Schneider Electric
1Easergy T300 Firmware
Nov 21, 2024
Dec 11, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A CWE-862: Missing Authorization vulnerability exists in Easergy T300 (firmware 2.7 and older), that could cause a wide range of problems, including information exposures, denial of service, and arbitrary code execution...Show more
A CWE-862: Missing Authorization vulnerability exists in Easergy T300 (firmware 2.7 and older), that could cause a wide range of problems, including information exposures, denial of service, and arbitrary code execution when access control checks are not applied consistently.Show less
1Schneider Electric
1Modicon M221 Firmware
May 28, 2026
Dec 11, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A CWE-760: Use of a One-Way Hash with a Predictable Salt vulnerability exists in Modicon M221 (all references, all versions), that could allow an attacker to pre-compute the hash value using dictionary attack technique s...Show more
A CWE-760: Use of a One-Way Hash with a Predictable Salt vulnerability exists in Modicon M221 (all references, all versions), that could allow an attacker to pre-compute the hash value using dictionary attack technique such as rainbow tables, effectively disabling the protection that an unpredictable salt would provide.Show less
1Schneider Electric
7Acti9 Powertag Link Firmware
Acti9 Powertag Link Hd FirmwareActi9 Smartlink El B Firmware+4 more
Nov 21, 2024
Dec 1, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A CWE-330 - Use of Insufficiently Random Values vulnerability exists in Smartlink, PowerTag, and Wiser Series Gateways (see security notification for version information) that could allow unauthorized users to login.
1Schneider Electric
5Ecostruxure Energy Expert
Ecostruxure Power Monitoring ExpertPower Manager+2 more
Nov 21, 2024
Dec 1, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A CWE-284: Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow a user the ability to pe...Show more
A CWE-284: Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow a user the ability to perform actions via the web interface at a higher privilege level.Show less
1Schneider Electric
5Ecostruxure Energy Expert
Ecostruxure Power Monitoring ExpertPower Manager+2 more
Nov 21, 2024
Dec 1, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that c...Show more
A CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow an attacker to perform actions on behalf of the authorized user when accessing an affected webpage.Show less
1Schneider Electric
5Ecostruxure Energy Expert
Ecostruxure Power Monitoring ExpertPower Manager+2 more
Nov 21, 2024
Dec 1, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow for arbitrary code execut...Show more
A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow for arbitrary code execution on the server when an authorized user access an affected webpage.Show less
1Schneider Electric
16140cpu65260 Firmware
140noc77101 Firmware140noc78000 Firmware+13 more
Jun 10, 2025
Dec 1, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CWE-287: Improper Authentication vulnerability exists which could cause the execution of commands on the webserver without authentication when sending specially crafted HTTP requests.
1Schneider Electric
1Webreports
Nov 21, 2024
Nov 19, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
A CWE-284 Improper Access Control vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause a remote attacker being able to access a restricted web resources due to improper access co...Show more
A CWE-284 Improper Access Control vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause a remote attacker being able to access a restricted web resources due to improper access control.Show less
1Schneider Electric
1Webreports
Nov 21, 2024
Nov 19, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to inject arbitrary X...Show more
A CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to inject arbitrary XML code and obtain disclosure of confidential data, denial of service, server side request forgery due to improper configuration of the XML parser.Show less
1Schneider Electric
1Webreports
Nov 21, 2024
Nov 19, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A CWE-79 Multiple Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Reflected) vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause a remote attac...Show more
A CWE-79 Multiple Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Reflected) vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause a remote attacker to inject arbitrary web script or HTML due to incorrect sanitization of user supplied data and achieve a Cross-Site Scripting reflected attack against other WebReport users.Show less
1Schneider Electric
1Webreports
Nov 21, 2024
Nov 19, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Stored) vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote us...Show more
A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Stored) vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a Cross-Site Scripting stored attack against other WebReport users.Show less