← Back

Schneider Electric

schneider-electric

783 CVEs • 1,762 products

Products (1,762)

Click to collapse
Toggle
Proclima
proclima
Clearscada
clearscada

CVEs (783)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Schneider Electric
4Modicom Bmxnor0200h Firmware
Modicom M340 FirmwareModicom Premium Firmware+1 more
Jun 17, 2026
Dec 17, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Information Exposure through Discrepancy vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where the web server sends different responses in a way that exposes...Show more
An Information Exposure through Discrepancy vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where the web server sends different responses in a way that exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.Show less
1Schneider Electric
4Modicom Bmxnor0200h Firmware
Modicom M340 FirmwareModicom Premium Firmware+1 more
Jun 17, 2026
Dec 17, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
A URL Redirection to Untrusted Site vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where a user clicking on a specially crafted link can be redirected to a URL...Show more
A URL Redirection to Untrusted Site vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where a user clicking on a specially crafted link can be redirected to a URL of the attacker's choosing.Show less
1Schneider Electric
3Ecostruxure Energy Expert
Ecostruxure Power Monitoring ExpertEcostruxure Power Scada Operation
Jun 17, 2026
Dec 17, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME) v8.2 (all editions), EcoStruxure Energy Expert 1.3 (formerly Power Man...Show more
A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME) v8.2 (all editions), EcoStruxure Energy Expert 1.3 (formerly Power Manager), EcoStruxure Power SCADA Operation (PSO) 8.2 Advanced Reports and Dashboards Module, EcoStruxure Power Monitoring Expert (PME) v9.0, EcoStruxure Energy Expert v2.0, and EcoStruxure Power SCADA Operation (PSO) 9.0 Advanced Reports and Dashboards Module which could cause a phishing attack when redirected to a malicious site.Show less
1Schneider Electric
4Modicom Bmxnor0200h Firmware
Modicom M340 FirmwareModicom Premium Firmware+1 more
Jun 17, 2026
Nov 30, 2018
N/A· v4
8.8 HIGH· v3
4.3 MEDIUM· v2
An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 allowing an attacker to send a s...Show more
An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 allowing an attacker to send a specially crafted URL to a currently authenticated web server user to execute a password change on the web server.Show less
1Schneider Electric
4Modicom Bmxnor0200h Firmware
Modicom M340 FirmwareModicom Premium Firmware+1 more
Jun 17, 2026
Nov 30, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where a denial of service c...Show more
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where a denial of service can occur for ~1 minute by sending a specially crafted HTTP request.Show less
1Schneider Electric
4Modicom Bmxnor0200h Firmware
Modicom M340 FirmwareModicom Premium Firmware+1 more
Jun 17, 2026
Nov 30, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could allow an unauthenticated remote user to access the change password func...Show more
An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could allow an unauthenticated remote user to access the change password function of the web serverShow less
1Schneider Electric
4Modicom Bmxnor0200h Firmware
Modicom M340 FirmwareModicom Premium Firmware+1 more
Jun 17, 2026
Nov 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 allowing an attacker to c...Show more
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 allowing an attacker to craft a URL containing JavaScript that will be executed within the user's browser, potentially impacting the machine the browser is running on.Show less
1Schneider Electric
4Modicom Bmxnor0200h Firmware
Modicom M340 FirmwareModicom Premium Firmware+1 more
Jun 17, 2026
Nov 30, 2018
N/A· v4
9.8 CRITICAL· v3
6.4 MEDIUM· v2
An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could allow an unauthenticated remote user to access the password delete func...Show more
An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could allow an unauthenticated remote user to access the password delete function of the web server.Show less
1Schneider Electric
1Struxureware Data Center Expert
Jun 17, 2026
Nov 30, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Data Center Expert, versions 7.5.0 and earlier, allows for the upload of a zip file from its user interface to the server. A carefully crafted, malicious file could be mistakenly uploaded by an authenticated user via thi...Show more
Data Center Expert, versions 7.5.0 and earlier, allows for the upload of a zip file from its user interface to the server. A carefully crafted, malicious file could be mistakenly uploaded by an authenticated user via this feature which could contain path traversal file names. As such, it could allow for the arbitrary upload of files contained with the zip onto the server file system outside of the intended directory. This is leveraging the more commonly known ZipSlip vulnerability within Java code.Show less
1Schneider Electric
1Struxureware Data Center Operation
Jun 17, 2026
Nov 30, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Data Center Operation allows for the upload of a zip file from its user interface to the server. A carefully crafted, malicious file could be mistakenly uploaded by an authenticated user via this feature which could cont...Show more
Data Center Operation allows for the upload of a zip file from its user interface to the server. A carefully crafted, malicious file could be mistakenly uploaded by an authenticated user via this feature which could contain path traversal file names. As such, it could allow for the arbitrary upload of files contained with the zip onto the server file system outside of the intended directory. This is leveraging the more commonly known ZipSlip vulnerability within Java code.Show less
1Schneider Electric
1Software Update Utility
Jun 17, 2026
Nov 2, 2018
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A DLL hijacking vulnerability exists in Schneider Electric Software Update (SESU), all versions prior to V2.2.0, which could allow an attacker to execute arbitrary code on the targeted system when placing a specific DLL...Show more
A DLL hijacking vulnerability exists in Schneider Electric Software Update (SESU), all versions prior to V2.2.0, which could allow an attacker to execute arbitrary code on the targeted system when placing a specific DLL file.Show less
1Schneider Electric
1Somachine Basic
Jun 17, 2026
Nov 2, 2018
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
A Insufficient Verification of Data Authenticity (CWE-345) vulnerability exists in the Modicon M221, all versions, which could cause a change of IPv4 configuration (IP address, mask and gateway) when remotely connected t...Show more
A Insufficient Verification of Data Authenticity (CWE-345) vulnerability exists in the Modicon M221, all versions, which could cause a change of IPv4 configuration (IP address, mask and gateway) when remotely connected to the device.Show less
1Schneider Electric
1Modicon M221 Firmware
Jun 17, 2026
Aug 29, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to de...Show more
A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to decode the password using rainbow table.Show less
1Schneider Electric
1Modicon M221 Firmware
Jun 17, 2026
Aug 29, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to ov...Show more
A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to overwrite the original password with their password. If an attacker exploits this vulnerability and overwrite the password, the attacker can upload the original program from the PLC.Show less
1Schneider Electric
1Modicon M221 Firmware
Jun 17, 2026
Aug 29, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An Information Management Error vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to replay authentic...Show more
An Information Management Error vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to replay authentication sequences. If an attacker exploits this vulnerability and connects to a Modicon M221, the attacker can upload the original program from the PLC.Show less
1Schneider Electric
1Powerlogic Pm5560 Firmware
Jun 17, 2026
Aug 29, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Cross Protocol Injection vulnerability exists in Schneider Electric's PowerLogic (PM5560 prior to FW version 2.5.4) product. The vulnerability makes the product susceptible to cross site scripting attack on its web bro...Show more
A Cross Protocol Injection vulnerability exists in Schneider Electric's PowerLogic (PM5560 prior to FW version 2.5.4) product. The vulnerability makes the product susceptible to cross site scripting attack on its web browser. User inputs can be manipulated to cause execution of java script code.Show less
1Schneider Electric
1Modicon M221 Firmware
Jun 17, 2026
Aug 29, 2018
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
An Improper Check for Unusual or Exceptional Conditions vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized u...Show more
An Improper Check for Unusual or Exceptional Conditions vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to remotely reboot Modicon M221 using crafted programing protocol frames.Show less
7Arm
FujitsuIntel+4 more
225Atom C
Atom EAtom X3+222 more
Nov 21, 2024
Jul 10, 2018
N/A· v4
5.6 MEDIUM· v3
4.7 MEDIUM· v2
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a speculative buffer overflow and side-channel...Show more
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a speculative buffer overflow and side-channel analysis.Show less
1Schneider Electric
1U.motion Builder
Jun 17, 2026
Jul 3, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Schneider Electric U.motion Builder software versions prior to v1.3.4, this vulnerability is due to improper validation of input of context parameter in HTTP GET request.
1Schneider Electric
1U.motion Builder
Jun 17, 2026
Jul 3, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Schneider Electric U.motion Builder software versions prior to v1.3.4, a cross site scripting (XSS) vulnerability exists which could allow injection of malicious scripts.