← Back

Schneider Electric

schneider-electric

771 CVEs • 1,745 products

Products (1,745)

Click to collapse
Toggle
Proclima
proclima
Clearscada
clearscada

CVEs (771)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Schneider Electric
1Ecostruxure Control Expert
Nov 21, 2024
Nov 19, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A CWE-863: Incorrect Authorization vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause bypass of authentication when overwriting memory using a debugger.
1Schneider Electric
1Enterprise Server Installer
May 28, 2026
Nov 19, 2020
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installer V1.9 - V3.1 and Enterprise Central installer V2.0 - V3.1 that could cause any local Windows user w...Show more
A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installer V1.9 - V3.1 and Enterprise Central installer V2.0 - V3.1 that could cause any local Windows user who has write permission on at least one of the subfolders of the Connect Agent service binary path, being able to gain the privilege of the user who started the service. By default, the Enterprise Server and Enterprise Central is always installed at a location requiring Administrator privileges so the vulnerability is only valid if the application has been installed on a non-secure location.Show less
1Schneider Electric
1Ecostruxure Building Operation
May 28, 2026
Nov 19, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability exists in EcoStruxure Building Operation WebStation V2.0 - V3.1 that could cause an attacker to inject HTML and Ja...Show more
A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability exists in EcoStruxure Building Operation WebStation V2.0 - V3.1 that could cause an attacker to inject HTML and JavaScript code into the user's browser.Show less
1Schneider Electric
20Modicon M340 Bmx Noc 0401 Firmware
Modicon M340 Bmx Noe 0100 FirmwareModicon M340 Bmx Noe 0100h Firmware+17 more
May 29, 2026
Nov 18, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules...Show more
A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause write access and the execution of commands when uploading a specially crafted file on the controller over FTP.Show less
1Schneider Electric
20Modicon M340 Bmx Noc 0401 Firmware
Modicon M340 Bmx Noe 0100 FirmwareModicon M340 Bmx Noe 0100h Firmware+17 more
May 29, 2026
Nov 18, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A CWE-787: Out-of-bounds Write vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause co...Show more
A CWE-787: Out-of-bounds Write vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause corruption of data, a crash, or code execution when uploading a specially crafted file on the controller over FTP.Show less
1Schneider Electric
20Modicon M340 Bmx Noc 0401 Firmware
Modicon M340 Bmx Noe 0100 FirmwareModicon M340 Bmx Noe 0100h Firmware+17 more
May 29, 2026
Nov 18, 2020
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
A CWE-125: Out-of-Bounds Read vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause a s...Show more
A CWE-125: Out-of-Bounds Read vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause a segmentation fault or a buffer overflow when uploading a specially crafted file on the controller over FTP.Show less
1Schneider Electric
1Scadapack X70 Security Administrator
Nov 21, 2024
Sep 16, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack x70 Security Administrator (V1.2.0 and prior) which could allow arbitrary code execution when an attacker builds a custom .SDB file containing...Show more
A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack x70 Security Administrator (V1.2.0 and prior) which could allow arbitrary code execution when an attacker builds a custom .SDB file containing a malicious serialized buffer.Show less
1Schneider Electric
1Scadapack 7x Remote Connect
Nov 21, 2024
Sep 16, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A CWE-284 Improper Access Control vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place executables in a specific folder and run code whenever RemoteConnect is execu...Show more
A CWE-284 Improper Access Control vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place executables in a specific folder and run code whenever RemoteConnect is executed by the user.Show less
1Schneider Electric
1Scadapack 7x Remote Connect
Nov 21, 2024
Sep 16, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A CWE-285 Improper Authorization vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows improper access to executable code folders.
1Schneider Electric
1Scadapack 7x Remote Connect
Nov 21, 2024
Sep 16, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Transversal') vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place content in any unprot...Show more
A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Transversal') vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place content in any unprotected folder on the target system using a crafted .RCZ file.Show less
1Schneider Electric
1Scadapack 7x Remote Connect
Nov 21, 2024
Sep 16, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which could allow arbitrary code execution when an attacker builds a custom .PRJ file containing a ma...Show more
A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which could allow arbitrary code execution when an attacker builds a custom .PRJ file containing a malicious serialized buffer.Show less
1Schneider Electric
1Somove
Nov 21, 2024
Aug 31, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Incorrect Default Permission vulnerability exists in SoMove (V2.8.1) and prior which could cause elevation of privilege and provide full access control to local system users to SoMove component and services when a SoMove...Show more
Incorrect Default Permission vulnerability exists in SoMove (V2.8.1) and prior which could cause elevation of privilege and provide full access control to local system users to SoMove component and services when a SoMove installer script is launched.Show less
1Schneider Electric
2Spacelynk Firmware
Wiser For Knx Firmware
Nov 21, 2024
Aug 31, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Improper Restriction of Excessive Authentication Attempts vulnerability exists in all hardware versions of spaceLYnk and Wiser for KNX (formerly homeLYnk) which could allow an attacker to guess a password when brute forc...Show more
Improper Restriction of Excessive Authentication Attempts vulnerability exists in all hardware versions of spaceLYnk and Wiser for KNX (formerly homeLYnk) which could allow an attacker to guess a password when brute force is used.Show less
1Schneider Electric
1Modicon M218 Firmware
Nov 21, 2024
Aug 31, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Out-of-bounds Write vulnerability exists in Modicon M218 Logic Controller (V5.0.0.7 and prior) which could cause Denial of Service when sending specific crafted IPV4 packet to the controller: Sending a specific IPv4 prot...Show more
Out-of-bounds Write vulnerability exists in Modicon M218 Logic Controller (V5.0.0.7 and prior) which could cause Denial of Service when sending specific crafted IPV4 packet to the controller: Sending a specific IPv4 protocol package to Schneider Electric Modicon M218 Logic Controller can cause IPv4 devices to go down. The device does not work properly and must be powered back on to return to normal.Show less
1Schneider Electric
2Modbus Driver Suite
Modbus Serial Driver
Nov 21, 2024
Aug 31, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
Improper Privilege Management vulnerability exists in Schneider Electric Modbus Serial Driver (see security notification for versions) which could cause local privilege escalation when the Modbus Serial Driver service is...Show more
Improper Privilege Management vulnerability exists in Schneider Electric Modbus Serial Driver (see security notification for versions) which could cause local privilege escalation when the Modbus Serial Driver service is invoked. The driver does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.Show less
1Schneider Electric
1Apc Easy Ups Online Software
Nov 21, 2024
Aug 31, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line Software (V2.0 and earlier) when accessing a vulnerable method of `SoundUploadServle...Show more
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line Software (V2.0 and earlier) when accessing a vulnerable method of `SoundUploadServlet` which may lead to uploading executable files to non-specified directories.Show less
1Schneider Electric
1Apc Easy Ups Online Software
Nov 21, 2024
Aug 31, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line Software (V2.0 and earlier) when accessing a vulnerable method of `FileUploadServlet...Show more
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line Software (V2.0 and earlier) when accessing a vulnerable method of `FileUploadServlet` which may lead to uploading executable files to non-specified directories.Show less
1Schneider Electric
1Software Update Utility
Nov 21, 2024
Jul 23, 2020
N/A· v4
4.7 MEDIUM· v3
4.0 MEDIUM· v2
A CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability exists in Schneider Electric Software Update (SESU), V2.4.0 and prior, which could cause execution of malicious code on the victim's machine. I...Show more
A CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability exists in Schneider Electric Software Update (SESU), V2.4.0 and prior, which could cause execution of malicious code on the victim's machine. In order to exploit this vulnerability, an attacker requires privileged access on the engineering workstation to modify a Windows registry key which would divert all traffic updates to go through a server in the attacker's possession. A man-in-the-middle attack is then used to complete the exploit.Show less
1Schneider Electric
1Easergy Builder
Nov 21, 2024
Jul 23, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A CWE-521: Weak Password Requirements vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to compromise a user account.
1Schneider Electric
1Easergy Builder
Nov 21, 2024
Jul 23, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A CWE-20: Improper input validation vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to modify project configuration files.