Schneider Electric
schneider-electric
783 CVEs • 1,762 products
Products (1,762)
Click to collapseToggle
Products (1,762)
Click to collapse
CVEs (783)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Schneider Electric 1Modicon Quantum Firmware Jun 17, 2026 May 22, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A CWE-255 Credentials Management vulnerability exists in Modicon Quantum with firmware versions prior to V2.40. which could cause a Denial Of Service when using a Telnet connection. |
5Abb PhoenixcontactSchneider Electric+2 more106ed1052 1cc01 0ba8 Firmware 6es7211 1ae40 0xb0 Firmware6es7314 6eh04 0ab0 Firmware+7 moreJun 17, 2026 Apr 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network...Show more |
1Schneider Electric 1Opc Factory Server Nov 21, 2024 Mar 25, 2019 N/A· v4 7.3 HIGH· v3 4.4 MEDIUM· v2 A successful exploit of these vulnerabilities requires the local user to load a crafted DLL file in the system directory on servers running Schneider Electric OFS v3.5 with version v7.40 of SCADA Expert Vijeo Citect/Cite...Show more |
1Schneider Electric 11Bmxnoc0401 Firmware Bmxnoe0100 FirmwareBmxnoe0110 Firmware+8 moreNov 21, 2024 Mar 21, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Reflected Cross-Site Scripting (nonpersistent) allows an attacker to craft a specific URL, which contains Java script that will be executed on the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110...Show more |
1Schneider Electric 11Bmxnoc0401 Firmware Bmxnoe0100 FirmwareBmxnoe0110 Firmware+8 moreNov 21, 2024 Mar 21, 2019 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 Remote file inclusion allows an attacker to craft a specific URL referencing the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302,...Show more |
1Schneider Electric 1Iiot Monitor Jun 17, 2026 Feb 6, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A Cryptographic Issue (CWE-310) vulnerability exists in IIoT Monitor 3.1.38 which could allow information disclosure. |
1Schneider Electric 1Zelio Soft 2 Jun 17, 2026 Feb 6, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A Use After Free (CWE-416) vulnerability exists in Zelio Soft 2 v5.1 and prior versions which could cause remote code execution when opening a specially crafted Zelio Soft project file. |
A Type Confusion (CWE-843) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0) on c3core.dll which could cause remote code to be executed when parsing a GD1 file |
A Stack-based Buffer Overflow (CWE-121) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0) which could cause remote code to be executed when parsing a GD1 file |
A Type Confusion (CWE-843) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0) on pcwin.dll which could cause remote code to be executed when parsing a GD1 file |
1Schneider Electric 1Iiot Monior Jun 17, 2026 Dec 24, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An Improper Restriction of XML External Entity Reference ('XXE') vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow the software to resolve documents outside of the intended sph...Show more |
1Schneider Electric 1Iiot Monitor Jun 17, 2026 Dec 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An unrestricted Upload of File with Dangerous Type vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow upload and execution of malicious files. |
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in IIoT Monitor 3.1.38 which could allow access to files available to SYSTEM user. |
1Schneider Electric 1Pro Face Gp Pro Ex Jun 17, 2026 Dec 24, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An Improper Input Validation vulnerability exists in Pro-Face GP-Pro EX v4.08 and previous versions which could cause the execution arbitrary executable when GP-Pro EX is launched. |
1Schneider Electric 1Evlink Parking Firmware Jun 17, 2026 Dec 24, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A SQL Injection vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could give access to the web interface with full privileges. |
1Schneider Electric 1Evlink Parking Firmware Jun 17, 2026 Dec 24, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A Code Injection vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could enable access with maximum privileges when a remote code execution is performed. |
1Schneider Electric 1Evlink Parking Firmware Jun 17, 2026 Dec 24, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A Hard-coded Credentials vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could enable an attacker to gain access to the device. |
1Schneider Electric 1Powersuite 2 Jun 17, 2026 Dec 24, 2018 N/A· v4 6.3 MEDIUM· v3 6.8 MEDIUM· v2 A Buffer Error vulnerability exists in PowerSuite 2, all released versions (VW3A8104 & Patches), which could cause an overflow in the memcpy function, leading to corruption of data and program instability. |
1Schneider Electric 4Foxboro Dcs Foxboro EvoFoxview+1 moreJun 17, 2026 Dec 24, 2018 N/A· v4 8.7 HIGH· v3 4.6 MEDIUM· v2 A Credential Management vulnerability exists in FoxView HMI SCADA (All Foxboro DCS, Foxboro Evo, and IA Series versions prior to Foxboro DCS Control Core Services 9.4 (CCS 9.4) and FoxView 10.5.) which could cause unauth...Show more |
1Schneider Electric 4Modicom Bmxnor0200h Firmware Modicom M340 FirmwareModicom Premium Firmware+1 moreJun 17, 2026 Dec 17, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An Improper Check for Unusual or Exceptional Conditions vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where an unauthenticated user can send a specially crafte...Show more |