Schneider Electric
schneider-electric
771 CVEs • 1,745 products
Products (1,745)
Click to collapseToggle
Products (1,745)
Click to collapse
CVEs (771)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Schneider Electric 2Os Loader Unity LoaderNov 21, 2024 Jun 16, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-798: Use of Hard-coded Credentials vulnerability exists in the Unity Loader and OS Loader Software (all versions). The fixed credentials are used to simplify file transfer. Today the use of fixed credentials is con...Show more |
1Schneider Electric 1Ecostruxure Operator Terminal Expert Nov 21, 2024 Jun 16, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)which could c...Show more |
1Schneider Electric 1Ecostruxure Operator Terminal Expert Nov 21, 2024 Jun 16, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability during zip file extraction exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly know...Show more |
1Schneider Electric 1Ecostruxure Operator Terminal Expert Nov 21, 2024 Jun 16, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could...Show more |
1Schneider Electric 1Ecostruxure Operator Terminal Expert Nov 21, 2024 Jun 16, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which...Show more |
1Schneider Electric 1Gp Pro Ex Firmware Nov 21, 2024 Jun 16, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A CWE-521: Weak Password Requirements vulnerability exists in the GP-Pro EX V1.00 to V4.09.100 which could cause the discovery of the password when the user is entering the password because it is not masqueraded. |
2Fazecast Schneider Electric2Ecostruxure It Gateway JserialcommNov 21, 2024 May 14, 2020 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 In Fazecast jSerialComm, Version 2.2.2 and prior, an uncontrolled search path element vulnerability could allow a malicious DLL file with the same name of any resident DLLs inside the software installation to execute arb...Show more |
1Schneider Electric 1Vijeo Designer Nov 21, 2024 Apr 22, 2020 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 A CWE-426: Untrusted Search Path vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 15 and prior) and Vijeo Designer (V6.9 SP9 and prior), which could cause arbitrary code execution on the system running Vijeo Bas...Show more |
1Schneider Electric 5Ecostruxure Machine Expert Modicon M100 FirmwareModicon M200 Firmware+2 moreMay 28, 2026 Apr 22, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability exists on EcoStruxure Machine Expert – Basic or SoMachine Basic programming software (versions in...Show more |
1Schneider Electric 7Ecostruxure Machine Expert Modicon M218 FirmwareModicon M241 Firmware+4 moreMay 28, 2026 Apr 22, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists which could leak sensitive information transmitted between the software and the Modicon M218, M241, M251, and M258 controllers. |
1Schneider Electric 7Ecostruxure Machine Expert Modicon M218 FirmwareModicon M241 Firmware+4 moreNov 21, 2024 Apr 22, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists which could allow the attacker to execute malicious code on the Modicon M218, M241, M251, and M258 controllers. |
1Schneider Electric 10140 Cpu6x Firmware 140 Noc 77101 Firmware140 Noc 78x00 Firmware+7 moreNov 21, 2024 Apr 22, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-798: Use of Hardcoded Credentials vulnerability exists in Modicon Controllers (All versions of the following CPUs and Communication Module product references listed in the Security Notifications), which could cause...Show more |
1Schneider Electric 6Tricon Tcm 4351 Firmware Tricon Tcm 4351a FirmwareTricon Tcm 4351b Firmware+3 moreNov 21, 2024 Apr 16, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 **VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause TCM modules to reset when under high network load in TCM v10.4.x and in system v10.3.x. This vulnerability was discovered and remediated in version v10....Show more |
1Schneider Electric 1Tristation 1131 Nov 21, 2024 Apr 16, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 **VERSION NOT SUPPORTED WHEN ASSIGNED** A legacy support account in the TriStation software version v4.9.0 and earlier could cause improper access to the TriStation host machine. This was addressed in TriStation version...Show more |
1Schneider Electric 1Tristation 1131 Nov 21, 2024 Apr 16, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 **VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability with the former 'password' feature could allow a denial of service attack if the user is not following documented guidelines pertaining to dedicated TriStation conn...Show more |
1Schneider Electric 1Tristation 1131 Nov 21, 2024 Apr 16, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 **VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause certain data to be visible on the network when the 'password' feature is enabled. This vulnerability was discovered in and remediated in versions v4.9.1...Show more |
1Schneider Electric 11Andover Continuum 5720 Firmware Andover Continuum 5740 FirmwareAndover Continuum 9200 Firmware+8 moreNov 21, 2024 Mar 23, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A CWE-79:Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists Andover Continuum (All versions), which could cause a Reflective Cross-site Scripting (XSS attack) when u...Show more |
1Schneider Electric 11Andover Continuum 5720 Firmware Andover Continuum 5740 FirmwareAndover Continuum 9200 Firmware+8 moreNov 21, 2024 Mar 23, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A CWE-79:Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists Andover Continuum (All versions), which could enable a successful Cross-site Scripting (XSS attack) when...Show more |
1Schneider Electric 11Andover Continuum 5720 Firmware Andover Continuum 5740 FirmwareAndover Continuum 9200 Firmware+8 moreNov 21, 2024 Mar 23, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists in Andover Continuum (All versions), which could cause files on the application server filesystem to be viewable when an attacker i...Show more |
1Schneider Electric 1Interactive Graphical Scada System Nov 21, 2024 Mar 23, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A CWE-306: Missing Authentication for Critical Function vulnerability exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which could allow a local user to execute processes that otherwise require escal...Show more |