Schneider Electric
schneider-electric
783 CVEs • 1,762 products
Products (1,762)
Click to collapseToggle
Products (1,762)
Click to collapse
CVEs (783)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Schneider Electric 1Easergy T300 Firmware Jun 17, 2026 Dec 11, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to read network traffic over HTTP protocol. |
1Schneider Electric 1Easergy T300 Firmware Jun 17, 2026 Dec 11, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-862: Missing Authorization vulnerability exists in Easergy T300 (firmware 2.7 and older), that could cause a wide range of problems, including information exposures, denial of service, and arbitrary code execution...Show more |
1Schneider Electric 1Modicon M221 Firmware Jun 17, 2026 Dec 11, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A CWE-760: Use of a One-Way Hash with a Predictable Salt vulnerability exists in Modicon M221 (all references, all versions), that could allow an attacker to pre-compute the hash value using dictionary attack technique s...Show more |
1Schneider Electric 7Acti9 Powertag Link Firmware Acti9 Powertag Link Hd FirmwareActi9 Smartlink El B Firmware+4 moreJun 17, 2026 Dec 1, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-330 - Use of Insufficiently Random Values vulnerability exists in Smartlink, PowerTag, and Wiser Series Gateways (see security notification for version information) that could allow unauthorized users to login. |
1Schneider Electric 5Ecostruxure Energy Expert Ecostruxure Power Monitoring ExpertPower Manager+2 moreJun 17, 2026 Dec 1, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A CWE-284: Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow a user the ability to pe...Show more |
1Schneider Electric 5Ecostruxure Energy Expert Ecostruxure Power Monitoring ExpertPower Manager+2 moreJun 17, 2026 Dec 1, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that c...Show more |
1Schneider Electric 5Ecostruxure Energy Expert Ecostruxure Power Monitoring ExpertPower Manager+2 moreJun 17, 2026 Dec 1, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow for arbitrary code execut...Show more |
1Schneider Electric 16140cpu65260 Firmware 140noc77101 Firmware140noc78000 Firmware+13 moreJun 17, 2026 Dec 1, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 CWE-287: Improper Authentication vulnerability exists which could cause the execution of
commands on the webserver without authentication when sending specially crafted HTTP
requests. |
1Schneider Electric 1Webreports Jun 17, 2026 Nov 19, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 A CWE-284 Improper Access Control vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause a remote attacker being able to access a restricted web resources due to improper access co...Show more |
1Schneider Electric 1Webreports Jun 17, 2026 Nov 19, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to inject arbitrary X...Show more |
A CWE-79 Multiple Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Reflected) vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause a remote attac...Show more |
A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Stored) vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote us...Show more |
1Schneider Electric 1Webreports Jun 17, 2026 Nov 19, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A CWE-434 Unrestricted Upload of File with Dangerous Type vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to upload arbitrary files d...Show more |
1Schneider Electric 1Modicon M221 Firmware Jun 17, 2026 Nov 19, 2020 N/A· v4 4.3 MEDIUM· v3 3.3 LOW· v2 A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Modicon M221 (all references, all versions) that could allow non sensitive information disclosure when the attacker has captur...Show more |
1Schneider Electric 1Modicon M221 Firmware Jun 17, 2026 Nov 19, 2020 N/A· v4 5.7 MEDIUM· v3 2.9 LOW· v2 A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to find the password hash when the attacker has captured the traffic betwe...Show more |
1Schneider Electric 1Modicon M221 Firmware Jun 17, 2026 Nov 19, 2020 N/A· v4 7.3 HIGH· v3 4.3 MEDIUM· v2 A CWE-334: Small Space of Random Values vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to break the encryption keys when the attacker has captured the traffic between Ec...Show more |
1Schneider Electric 1Modicon M221 Firmware Jun 17, 2026 Nov 19, 2020 N/A· v4 7.3 HIGH· v3 4.3 MEDIUM· v2 A CWE-326: Inadequate Encryption Strength vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to break the encryption key when the attacker has captured the traffic between E...Show more |
1Schneider Electric 1Easergy T300 Firmware Jun 17, 2026 Nov 19, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T300 (with firmware 2.7 and older) that could cause a wide range of problems, including information exposure, denial of service, and...Show more |
1Schneider Electric 1Ecostruxure Control Expert Jun 17, 2026 Nov 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause a crash of the PLC si...Show more |
1Schneider Electric 1Interactive Graphical Scada System Jun 17, 2026 Nov 19, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definitio...Show more |