Schneider Electric
schneider-electric
783 CVEs • 1,762 products
Products (1,762)
Click to collapseToggle
Products (1,762)
Click to collapse
CVEs (783)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Schneider Electric 5Ecostruxure Machine Expert Modicon M100 FirmwareModicon M200 Firmware+2 moreJun 17, 2026 Apr 22, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability exists on EcoStruxure Machine Expert – Basic or SoMachine Basic programming software (versions in...Show more |
1Schneider Electric 7Ecostruxure Machine Expert Modicon M218 FirmwareModicon M241 Firmware+4 moreJun 17, 2026 Apr 22, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists which could leak sensitive information transmitted between the software and the Modicon M218, M241, M251, and M258 controllers. |
1Schneider Electric 7Ecostruxure Machine Expert Modicon M218 FirmwareModicon M241 Firmware+4 moreJun 17, 2026 Apr 22, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists which could allow the attacker to execute malicious code on the Modicon M218, M241, M251, and M258 controllers. |
1Schneider Electric 10140 Cpu6x Firmware 140 Noc 77101 Firmware140 Noc 78x00 Firmware+7 moreJun 17, 2026 Apr 22, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-798: Use of Hardcoded Credentials vulnerability exists in Modicon Controllers (All versions of the following CPUs and Communication Module product references listed in the Security Notifications), which could cause...Show more |
1Schneider Electric 6Tricon Tcm 4351 Firmware Tricon Tcm 4351a FirmwareTricon Tcm 4351b Firmware+3 moreJun 17, 2026 Apr 16, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 **VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause TCM modules to reset when under high network load in TCM v10.4.x and in system v10.3.x. This vulnerability was discovered and remediated in version v10....Show more |
1Schneider Electric 1Tristation 1131 Jun 17, 2026 Apr 16, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 **VERSION NOT SUPPORTED WHEN ASSIGNED** A legacy support account in the TriStation software version v4.9.0 and earlier could cause improper access to the TriStation host machine. This was addressed in TriStation version...Show more |
1Schneider Electric 1Tristation 1131 Jun 17, 2026 Apr 16, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 **VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability with the former 'password' feature could allow a denial of service attack if the user is not following documented guidelines pertaining to dedicated TriStation conn...Show more |
1Schneider Electric 1Tristation 1131 Jun 17, 2026 Apr 16, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 **VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause certain data to be visible on the network when the 'password' feature is enabled. This vulnerability was discovered in and remediated in versions v4.9.1...Show more |
1Schneider Electric 11Andover Continuum 5720 Firmware Andover Continuum 5740 FirmwareAndover Continuum 9200 Firmware+8 moreJun 17, 2026 Mar 23, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A CWE-79:Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists Andover Continuum (All versions), which could cause a Reflective Cross-site Scripting (XSS attack) when u...Show more |
1Schneider Electric 11Andover Continuum 5720 Firmware Andover Continuum 5740 FirmwareAndover Continuum 9200 Firmware+8 moreJun 17, 2026 Mar 23, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A CWE-79:Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists Andover Continuum (All versions), which could enable a successful Cross-site Scripting (XSS attack) when...Show more |
1Schneider Electric 11Andover Continuum 5720 Firmware Andover Continuum 5740 FirmwareAndover Continuum 9200 Firmware+8 moreJun 17, 2026 Mar 23, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists in Andover Continuum (All versions), which could cause files on the application server filesystem to be viewable when an attacker i...Show more |
1Schneider Electric 1Interactive Graphical Scada System Jun 17, 2026 Mar 23, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A CWE-306: Missing Authentication for Critical Function vulnerability exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which could allow a local user to execute processes that otherwise require escal...Show more |
1Schneider Electric 1Interactive Graphical Scada System Jun 17, 2026 Mar 23, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which could allow a remote unauthenticated attacker to read arbitrary files from...Show more |
1Schneider Electric 28140cpu65150 Firmware 140cpu65160 Firmware140cpu65160s Firmware+25 moreJun 17, 2026 Mar 23, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Quantum Ethernet Network module 140NOE771x1 (Versions 7.0 and prior), Quantum processors with integrated Ethernet – 140CPU65xxxxx (a...Show more |
1Schneider Electric 1Ulti Zigbee Installation Toolkit Jun 17, 2026 Mar 23, 2020 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 A CWE-426: Untrusted Search Path vulnerability exists in ZigBee Installation Kit (Versions prior to 1.0.1), which could cause execution of malicious code when a malicious file is put in the search path. |
1Schneider Electric 4Ecostruxure Control Expert Modicon M340 FirmwareModicon M580 Firmware+1 moreJun 17, 2026 Mar 23, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity...Show more |
1Schneider Electric 1Pmepxm0100 Prosoft Configurator Jun 17, 2026 Mar 23, 2020 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProSoft Configurator (v1.002 and prior), for the PMEPXM0100 (H) module, which could cause the execution of untrusted code when using double click to ope...Show more |
1Schneider Electric 1Msx Configurator Jun 17, 2026 Jan 22, 2020 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 A CWE-427:Uncontrolled Search Path Element vulnerability exists in MSX Configurator (Software Version prior to V1.0.8.1), which could cause privilege escalation when injecting a malicious DLL. |
1Schneider Electric 29140cpu65150 Firmware 140cpu65160 Firmware140cpu65160s Firmware+26 moreJun 17, 2026 Jan 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium (see security notification for specific versions) which could cause a D...Show more |
1Schneider Electric 29140cpu65150 Firmware 140cpu65160 Firmware140cpu65160s Firmware+26 moreJun 17, 2026 Jan 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium (see security notification for specific versions) which could cause a D...Show more |