Schneider Electric
schneider-electric
783 CVEs • 1,762 products
Products (1,762)
Click to collapseToggle
Products (1,762)
Click to collapse
CVEs (783)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Schneider Electric 1Sage Rtu Firmware Jun 17, 2026 Jun 12, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perform unauthorized file and firmware uploads when crafting custom web requ...Show more |
1Schneider Electric 1Sage Rtu Firmware Jun 17, 2026 Jun 12, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability exists that could allow an authenticated user with access to the device’s web interface to corrupt files and impact dev...Show more |
1Schneider Electric 1Sage Rtu Firmware Jun 17, 2026 Jun 12, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 CWE-787: Out-of-bounds Write vulnerability exists that could result in an authentication bypass
when sending a malformed POST request and particular configuration parameters are set. |
1Schneider Electric 1Evlink Home Firmware Jun 17, 2026 Jun 12, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 CWE-668: Exposure of the Resource Wrong Sphere vulnerability exists that exposes a SSH interface over the product network interface. This does not allow to directly exploit the product or make any unintended operation as...Show more |
1Schneider Electric 3Bmxnoe0100 Firmware Bmxnoe0110 FirmwareModicon M340 FirmwareJun 17, 2026 Jun 12, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 CWE-552: Files or Directories Accessible to External Parties vulnerability exists which may prevent user to update the device firmware and prevent proper behavior of the webserver when specific files or directories are r...Show more |
1Schneider Electric 2Ecostruxure Control Expert Ecostruxure Process ExpertJun 17, 2026 Feb 14, 2024 N/A· v4 7.7 HIGH· v3 N/A· v2
CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized
access to a project file protected with application password when opening the file with
EcoStruxure Control Expert.
|
1Schneider Electric 46Ecostruxure Control Expert Ecostruxure Process ExpertModicon M340 Bmxp341000 Firmware+43 moreJun 17, 2026 Feb 14, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a denial of service and loss of confidentiality, integrity of controllers when cond...Show more |
1Schneider Electric 2Ecostruxure Control Expert Ecostruxure Process ExpertJun 17, 2026 Feb 14, 2024 N/A· v4 7.1 HIGH· v3 N/A· v2 CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized access to the project file in EcoStruxure Control Expert when a local user tampers with the memory of the engineering work...Show more |
A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker
logged in with a user level account to gain higher privileges by providing a harmful serialized
object.
|
1Schneider Electric 1Easy Ups Online Monitoring Software Jun 17, 2026 Dec 14, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file deletion upon service restart when accessed by a local and low-privileged att...Show more |
1Schneider Electric 16Eb450 Firmware Eb45e FirmwareEh450 Firmware+13 moreJun 17, 2026 Dec 14, 2023 N/A· v4 4.9 MEDIUM· v3 N/A· v2
A CWE-494: Download of Code Without Integrity Check vulnerability exists that could allow a
privileged user to install an untrusted firmware.
|
1Schneider Electric 16Eb450 Firmware Eb45e FirmwareEh450 Firmware+13 moreJun 17, 2026 Dec 14, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2
A CWE-601:URL Redirection to Untrusted Site (‘Open Redirect’) vulnerability exists that could
cause disclosure of information through phishing attempts over HTTP.
|
1Schneider Electric 2Galaxy Vl Firmware Galaxy Vs FirmwareJun 17, 2026 Nov 15, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause a file system enumeration and file download when an attacker navigates to the Network Manage...Show more |
1Schneider Electric 1Ecostruxure Power Monitoring Expert Jun 17, 2026 Nov 15, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability that could cause a vulnerability leading to a cross site scripting condition where attackers can have a victim’s...Show more |
1Schneider Electric 1Ecostruxure Power Monitoring Expert Jun 17, 2026 Nov 15, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting attack. By providing a URL-encoded input attackers can cause the software...Show more |
1Schneider Electric 2Ion8650 Firmware Ion8800 FirmwareJun 17, 2026 Nov 15, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2
A CWE-79 Improper Neutralization of Input During Web Page Generation vulnerability
exists that could cause compromise of a user’s browser when an attacker with admin privileges
has modified system values.
|
1Schneider Electric 2Ion8650 Firmware Ion8800 FirmwareJun 17, 2026 Nov 15, 2023 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A CWE-494 Download of Code Without Integrity Check vulnerability exists that could allow modified firmware to be uploaded when an authorized admin user begins a firmware update procedure which could result in full contr...Show more |
1Schneider Electric 1Spacelogic C Bus Toolkit Jun 17, 2026 Oct 4, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause tampering of files on the personal computer running C-Bus when using the File Command....Show more |
1Schneider Electric 3Ecostruxure Power Monitoring Expert Ecostruxure Power Operation With Advanced ReportsEcostruxure Power Scada Operation With Advanced ReportsJun 17, 2026 Oct 4, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2
A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to
execute arbitrary code on the targeted system by sending a specifically crafted packet to the
application.
|
A CWE-269: Improper Privilege Management vulnerability exists that could cause a remote
code execution when the transfer command is used over the network.
|