Schneider Electric
schneider-electric
783 CVEs • 1,762 products
Products (1,762)
Click to collapseToggle
Products (1,762)
Click to collapse
CVEs (783)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Schneider Electric 1Interactive Graphical Scada System Jun 17, 2026 Sep 14, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allow a local attacker to change update source, potentially leading to remote code execution when the at...Show more |
1Schneider Electric 1Pro Face Gp Pro Ex Jun 17, 2026 Aug 9, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory
Buffer vulnerability exists that could cause memory corruption when an authenticated user
opens a tampered log file from GP-Pro EX. |
1Schneider Electric 1Accutech Manager Jun 17, 2026 Jul 12, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2
A CWE-120: Buffer Copy without Checking Size of Input (Classic Buffer Overflow) vulnerability
exists that could cause user privilege escalation if a local user sends specific string input to a
local function call.
|
1Schneider Electric 1Struxureware Data Center Expert Jun 17, 2026 Jul 12, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that
could cause remote code execution when an admin user on DCE tampers with backups which
are then manually restored.
|
1Schneider Electric 1Struxureware Data Center Expert Jun 17, 2026 Jul 12, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that
could cause remote code execution when an admin user on DCE uploads or tampers with install
packages.
|
1Schneider Electric 1Struxureware Data Center Expert Jun 17, 2026 Jul 12, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to access unauthorized content, ch...Show more |
1Schneider Electric 1Struxureware Data Center Expert Jun 17, 2026 Jul 12, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to access unauthorized content, chan...Show more |
A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets...Show more |
1Schneider Electric 1Ecostruxure Foxboro Dcs Control Core Services Jun 17, 2026 Jun 14, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service, and potentially kernel execution when a malicious actor with local user access crafts a script/program using...Show more |
1Schneider Electric 1Ecostruxure Foxboro Dcs Control Core Services Jun 17, 2026 Jun 14, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, elevation of privilege, and potentially kernel execution when a malicious actor with local user access crafts a script/progra...Show more |
1Schneider Electric 2Ecostruxure Operator Terminal Expert Pro Face BlueJun 17, 2026 Jun 14, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause execution of malicious code when an unsuspicious user loads a project file from the local filesystem into the HMI...Show more |
1Schneider Electric 5Powerlogic Ion7400 Firmware Powerlogic Ion8650 FirmwarePowerlogic Ion8800 Firmware+2 moreJun 17, 2026 May 22, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A CWE-319: Cleartext transmission of sensitive information vulnerability exists that could cause disclosure of sensitive information, denial of service, or modification of data if an attacker is able to intercept networ...Show more |
1Schneider Electric 1Opc Factory Server Jun 17, 2026 May 16, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized read access to the file system when a malicious configuration file is loaded on to the software by a lo...Show more |
1Schneider Electric 8140cpu65 Firmware Bmeh58s FirmwareBmep58s Firmware+5 moreJun 17, 2026 Apr 19, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of service of the controller when a malicious project file is loaded onto the controller by an authenticated...Show more |
1Schneider Electric 7Bmeh58s Firmware Bmep58s FirmwareModicon M340 Firmware+4 moreJun 17, 2026 Apr 19, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that
could cause denial of service of the controller when communicating over the Modbus TCP
protocol.
|
1Schneider Electric 3Conext Gateway Firmware Insightfacility FirmwareInsighthome FirmwareJun 17, 2026 Apr 18, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A CWE-20: Improper Input Validation vulnerability exists that could allow an authenticated attacker to gain the same privilege as the application on the server when a malicious payload is provided over HTTP for the serv...Show more |
1Schneider Electric 1Powerlogic Hdpm6000 Firmware Jun 17, 2026 Apr 18, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2
A CWE-129: Improper validation of an array index vulnerability exists where a specially crafted
Ethernet request could result in denial of service or remote code execution.
|
1Schneider Electric 2Apc Easy Ups Online Monitoring Software Easy Ups Online Monitoring SoftwareJun 17, 2026 Apr 18, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause
Denial-of-Service when accessed by an unauthenticated user on the Schneider UPS Monitor
service.
|
1Schneider Electric 2Apc Easy Ups Online Monitoring Software Easy Ups Online Monitoring SoftwareJun 17, 2026 Apr 18, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when manipulating internal methods through Java RMI interface...Show more |
1Schneider Electric 2Apc Easy Ups Online Monitoring Software Easy Ups Online Monitoring SoftwareJun 17, 2026 Apr 18, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to potential remote code execution without requiring prior authentication on t...Show more |