← Back

Schneider Electric

schneider-electric

771 CVEs • 1,745 products

Products (1,745)

Click to collapse
Toggle
Proclima
proclima
Clearscada
clearscada

CVEs (771)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Schneider Electric
59D6220 Firmware
D6220l FirmwareD6230 Firmware+56 more
Nov 21, 2024
May 22, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Cross-Site Scripting (XSS) vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera which a remote attacker can execute arbitrary HTML and script code in a user’s browser session...Show more
A Cross-Site Scripting (XSS) vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera which a remote attacker can execute arbitrary HTML and script code in a user’s browser session.Show less
1Schneider Electric
59D6220 Firmware
D6220l FirmwareD6230 Firmware+56 more
Nov 21, 2024
May 22, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A Command Injection vulnerability exists in the web-based GUI of the 1st Gen Pelco Sarix Enhanced Camera that could allow a remote attacker to execute arbitrary commands.
1Schneider Electric
59D6220 Firmware
D6220l FirmwareD6230 Firmware+56 more
Nov 21, 2024
May 22, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A Command Injection vulnerability exists in the web-based GUI of the 1st Gen PelcoSarix Enhanced Camera that could allow a remote attacker to execute arbitrary commands.
1Schneider Electric
2Driver Suite
Modbus Serial Driver
Nov 21, 2024
May 22, 2019
N/A· v4
4.9 MEDIUM· v3
6.8 MEDIUM· v2
An Externally Controlled Reference to a Resource (CWE-610) vulnerability exists in Schneider Electric Modbus Serial Driver (For 64-bit Windows OS:V3.17 IE 37 and prior , For 32-bit Windows OS:V2.17 IE 27 and prior, and a...Show more
An Externally Controlled Reference to a Resource (CWE-610) vulnerability exists in Schneider Electric Modbus Serial Driver (For 64-bit Windows OS:V3.17 IE 37 and prior , For 32-bit Windows OS:V2.17 IE 27 and prior, and as part of the Driver Suite version:V14.12 and prior) which could allow write access to system files available only to users with SYSTEM privilege or other important user files.Show less
1Schneider Electric
2Modicon M221 Firmware
Somachine Basic
Nov 21, 2024
May 22, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause remote launch of SoMachine Basic when sending craf...Show more
A Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause remote launch of SoMachine Basic when sending crafted ethernet message.Show less
1Schneider Electric
2Modicon M221 Firmware
Somachine Basic
Nov 21, 2024
May 22, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An Incorrect Default Permissions (CWE-276) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause unauthorized access to SoMach...Show more
An Incorrect Default Permissions (CWE-276) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause unauthorized access to SoMachine Basic resource files when logged on the system hosting SoMachine Basic.Show less
1Schneider Electric
2Modicon M221 Firmware
Somachine Basic
May 29, 2026
May 22, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause cycle time impact when flooding the M221 ethernet...Show more
An Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause cycle time impact when flooding the M221 ethernet interface while the Ethernet/IP adapter is activated.Show less
1Schneider Electric
59D6220 Firmware
D6220l FirmwareD6230 Firmware+56 more
Nov 21, 2024
May 22, 2019
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
A Permissions, Privileges, and Access Control vulnerability exists in the web-based GUI of the 1st Gen Pelco Sarix Enhanced Camera that could allow a remote attacker to delete an arbitrary file.
1Schneider Electric
1Modicon Quantum Firmware
Nov 21, 2024
May 22, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A CWE-255 Credentials Management vulnerability exists in Modicon Quantum with firmware versions prior to V2.40. which could cause a Denial Of Service when using a Telnet connection.
5Abb
PhoenixcontactSchneider Electric+2 more
106ed1052 1cc01 0ba8 Firmware
6es7211 1ae40 0xb0 Firmware6es7314 6eh04 0ab0 Firmware+7 more
Jun 4, 2026
Apr 17, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network...Show more
ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network packets.Show less
1Schneider Electric
1Opc Factory Server
Nov 21, 2024
Mar 25, 2019
N/A· v4
7.3 HIGH· v3
4.4 MEDIUM· v2
A successful exploit of these vulnerabilities requires the local user to load a crafted DLL file in the system directory on servers running Schneider Electric OFS v3.5 with version v7.40 of SCADA Expert Vijeo Citect/Cite...Show more
A successful exploit of these vulnerabilities requires the local user to load a crafted DLL file in the system directory on servers running Schneider Electric OFS v3.5 with version v7.40 of SCADA Expert Vijeo Citect/CitectSCADA, OFS v3.5 with version v7.30 of Vijeo Citect/CitectSCADA, and OFS v3.5 with version v7.20 of Vijeo Citect/CitectSCADA.. If the application attempts to open that file, the application could crash or allow the attacker to execute arbitrary code. Schneider Electric recommends vulnerable users upgrade the OFS to V3.5 and install the latest service pack (SP 6 or newer) for their associated version.Show less
1Schneider Electric
11Bmxnoc0401 Firmware
Bmxnoe0100 FirmwareBmxnoe0110 Firmware+8 more
Nov 21, 2024
Mar 21, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Reflected Cross-Site Scripting (nonpersistent) allows an attacker to craft a specific URL, which contains Java script that will be executed on the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110...Show more
Reflected Cross-Site Scripting (nonpersistent) allows an attacker to craft a specific URL, which contains Java script that will be executed on the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H PLC client browser.Show less
1Schneider Electric
11Bmxnoc0401 Firmware
Bmxnoe0100 FirmwareBmxnoe0110 Firmware+8 more
Nov 21, 2024
Mar 21, 2019
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
Remote file inclusion allows an attacker to craft a specific URL referencing the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302,...Show more
Remote file inclusion allows an attacker to craft a specific URL referencing the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H PLC web server, which, when launched, will result in the browser redirecting to a remote file via a Java script loaded with the web page.Show less
1Schneider Electric
1Iiot Monitor
Nov 21, 2024
Feb 6, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A Cryptographic Issue (CWE-310) vulnerability exists in IIoT Monitor 3.1.38 which could allow information disclosure.
1Schneider Electric
1Zelio Soft 2
Nov 21, 2024
Feb 6, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A Use After Free (CWE-416) vulnerability exists in Zelio Soft 2 v5.1 and prior versions which could cause remote code execution when opening a specially crafted Zelio Soft project file.
1Schneider Electric
1Guicon
Nov 21, 2024
Feb 6, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A Type Confusion (CWE-843) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0) on c3core.dll which could cause remote code to be executed when parsing a GD1 file
1Schneider Electric
1Guicon
Nov 21, 2024
Feb 6, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A Stack-based Buffer Overflow (CWE-121) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0) which could cause remote code to be executed when parsing a GD1 file
1Schneider Electric
1Guicon
Nov 21, 2024
Feb 6, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A Type Confusion (CWE-843) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0) on pcwin.dll which could cause remote code to be executed when parsing a GD1 file
1Schneider Electric
1Iiot Monior
Nov 21, 2024
Dec 24, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Improper Restriction of XML External Entity Reference ('XXE') vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow the software to resolve documents outside of the intended sph...Show more
An Improper Restriction of XML External Entity Reference ('XXE') vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow the software to resolve documents outside of the intended sphere of control, causing the software to embed incorrect documents into its output and expose restricted information.Show less
1Schneider Electric
1Iiot Monitor
Nov 21, 2024
Dec 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An unrestricted Upload of File with Dangerous Type vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow upload and execution of malicious files.