← Back

Schneider Electric

schneider-electric

783 CVEs • 1,762 products

Products (1,762)

Click to collapse
Toggle
Proclima
proclima
Clearscada
clearscada

CVEs (783)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Schneider Electric
1Interactive Graphical Scada System
Jun 17, 2026
Nov 19, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A CWE-125 Out-of-bounds Read vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition...Show more
A CWE-125 Out-of-bounds Read vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.Show less
1Schneider Electric
1Interactive Graphical Scada System
Jun 17, 2026
Nov 19, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definitio...Show more
A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.Show less
1Schneider Electric
1Interactive Graphical Scada System
Jun 17, 2026
Nov 19, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definitio...Show more
A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.Show less
1Schneider Electric
1Interactive Graphical Scada System
Jun 17, 2026
Nov 19, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configur...Show more
A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.Show less
1Schneider Electric
1Interactive Graphical Scada System
Jun 17, 2026
Nov 19, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definitio...Show more
A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.Show less
1Schneider Electric
1Interactive Graphical Scada System
Jun 17, 2026
Nov 19, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A CWE-787: Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247, that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definit...Show more
A CWE-787: Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247, that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.Show less
1Schneider Electric
1Interactive Graphical Scada System
Jun 17, 2026
Nov 19, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A CWE-787: Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247, that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definit...Show more
A CWE-787: Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247, that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.Show less
1Schneider Electric
1Interactive Graphical Scada System
Jun 17, 2026
Nov 19, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 and prior that could cause Remote Code Execution when malicious CGF...Show more
A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 and prior that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.Show less
1Schneider Electric
1Operator Terminal Expert Runtime
Jun 17, 2026
Nov 19, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD) that could cause privilege escalation on the workstation when interacting directly with a driver in...Show more
A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD) that could cause privilege escalation on the workstation when interacting directly with a driver installed by the runtime software of EcoStruxureª Operator Terminal Expert.Show less
1Schneider Electric
1Ecostruxure Control Expert
Jun 17, 2026
Nov 19, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause a crash of the PLC simulator present in...Show more
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause a crash of the PLC simulator present in EcoStruxureª Control Expert software when receiving a specially crafted request over Modbus.Show less
1Schneider Electric
1Ecostruxure Control Expert
Jun 17, 2026
Nov 19, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A CWE-494: Download of Code Without Integrity Check vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when sending special...Show more
A CWE-494: Download of Code Without Integrity Check vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when sending specially crafted requests over Modbus.Show less
1Schneider Electric
1Ecostruxure Control Expert
Jun 17, 2026
Nov 19, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution whe...Show more
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when a brute force attack is done over Modbus.Show less
1Schneider Electric
1Ecostruxure Control Expert
Jun 17, 2026
Nov 19, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A CWE-863: Incorrect Authorization vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause bypass of authentication when overwriting memory using a debugger.
1Schneider Electric
1Enterprise Server Installer
Jun 17, 2026
Nov 19, 2020
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installer V1.9 - V3.1 and Enterprise Central installer V2.0 - V3.1 that could cause any local Windows user w...Show more
A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installer V1.9 - V3.1 and Enterprise Central installer V2.0 - V3.1 that could cause any local Windows user who has write permission on at least one of the subfolders of the Connect Agent service binary path, being able to gain the privilege of the user who started the service. By default, the Enterprise Server and Enterprise Central is always installed at a location requiring Administrator privileges so the vulnerability is only valid if the application has been installed on a non-secure location.Show less
1Schneider Electric
1Ecostruxure Building Operation
Jun 17, 2026
Nov 19, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability exists in EcoStruxure Building Operation WebStation V2.0 - V3.1 that could cause an attacker to inject HTML and Ja...Show more
A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability exists in EcoStruxure Building Operation WebStation V2.0 - V3.1 that could cause an attacker to inject HTML and JavaScript code into the user's browser.Show less
1Schneider Electric
20Modicon M340 Bmx Noc 0401 Firmware
Modicon M340 Bmx Noe 0100 FirmwareModicon M340 Bmx Noe 0100h Firmware+17 more
Jun 17, 2026
Nov 18, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules...Show more
A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause write access and the execution of commands when uploading a specially crafted file on the controller over FTP.Show less
1Schneider Electric
20Modicon M340 Bmx Noc 0401 Firmware
Modicon M340 Bmx Noe 0100 FirmwareModicon M340 Bmx Noe 0100h Firmware+17 more
Jun 17, 2026
Nov 18, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A CWE-787: Out-of-bounds Write vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause co...Show more
A CWE-787: Out-of-bounds Write vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause corruption of data, a crash, or code execution when uploading a specially crafted file on the controller over FTP.Show less
1Schneider Electric
20Modicon M340 Bmx Noc 0401 Firmware
Modicon M340 Bmx Noe 0100 FirmwareModicon M340 Bmx Noe 0100h Firmware+17 more
Jun 17, 2026
Nov 18, 2020
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
A CWE-125: Out-of-Bounds Read vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause a s...Show more
A CWE-125: Out-of-Bounds Read vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause a segmentation fault or a buffer overflow when uploading a specially crafted file on the controller over FTP.Show less
1Schneider Electric
1Scadapack X70 Security Administrator
Jun 17, 2026
Sep 16, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack x70 Security Administrator (V1.2.0 and prior) which could allow arbitrary code execution when an attacker builds a custom .SDB file containing...Show more
A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack x70 Security Administrator (V1.2.0 and prior) which could allow arbitrary code execution when an attacker builds a custom .SDB file containing a malicious serialized buffer.Show less
1Schneider Electric
1Scadapack 7x Remote Connect
Jun 17, 2026
Sep 16, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A CWE-284 Improper Access Control vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place executables in a specific folder and run code whenever RemoteConnect is execu...Show more
A CWE-284 Improper Access Control vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place executables in a specific folder and run code whenever RemoteConnect is executed by the user.Show less