Schneider Electric
schneider-electric
783 CVEs • 1,762 products
Products (1,762)
Click to collapseToggle
Products (1,762)
Click to collapse
CVEs (783)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Schneider Electric 4Proface Gp Pro Ex Ex Ed Proface Gp Pro Ex PfxexedlsProface Gp Pro Ex Pfxexedv+1 moreMay 6, 2026 Apr 6, 2016 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 The FTP server in Pro-face GP-Pro EX EX-ED before 4.05.000, PFXEXEDV before 4.05.000, PFXEXEDLS before 4.05.000, and PFXEXGRPLS before 4.05.000 has hardcoded credentials, which makes it easier for remote attackers to byp...Show more |
1Schneider Electric 1Telvent Rtu Firmware May 6, 2026 Mar 12, 2016 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Schneider Electric Telvent Sage 2300 RTUs with firmware before C3413-500-S01, and LANDAC II-2, Sage 1410, Sage 1430, Sage 1450, Sage 2400, and Sage 3030M RTUs with firmware before C3414-500-S02J2, allow remote attackers...Show more |
1Schneider Electric 2Struxureware Building Operations Automation Server As P Firmware Struxureware Building Operations Automation Server As FirmwareMay 6, 2026 Mar 2, 2016 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows remote authenticated administrators to execute arbitrary OS commands by defeating an msh (aka Minim...Show more |
1Schneider Electric 13Bmxnoc0401 Bmxnoe0100Bmxnoe0100h+10 moreMay 6, 2026 Dec 21, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 Stack-based buffer overflow in the GoAhead Web Server on Schneider Electric Modicon M340 PLC BMXNOx and BMXPx devices allows remote attackers to execute arbitrary code via a long password in HTTP Basic Authentication dat...Show more |
The F1BookView ActiveX control in F1 Bookview in Schneider Electric ProClima before 6.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted integer value to th...Show more |
Multiple buffer overflows in the F1BookView ActiveX control in F1 Bookview in Schneider Electric ProClima before 6.2 allow remote attackers to execute arbitrary code via the (1) Attach, (2) DefinedName, (3) DefinedNameLo...Show more |
1Schneider Electric 1Imt25 Magnetic Flow Dtm May 6, 2026 Nov 15, 2015 N/A· v4 N/A· v3 7.7 HIGH· v2 Buffer overflow in Schneider Electric IMT25 Magnetic Flow DTM before 1.500.004 for the HART Protocol allows remote authenticated users to execute arbitrary code or cause a denial of service (memory corruption) via a craf...Show more |
1Schneider Electric 1Struxureware Building Expert Multi Purpose Management May 6, 2026 Sep 18, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Schneider Electric StruxureWare Building Expert MPM before 2.15 does not use encryption for the client-server data stream, which allows remote attackers to discover credentials by sniffing the network. |
1Schneider Electric 1Wonderware System Platform 2014 May 6, 2026 Aug 4, 2015 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Untrusted search path vulnerability in Schneider Electric Wonderware System Platform before 2014 R2 Patch 01 allows local users to gain privileges via a Trojan horse DLL in an unspecified directory. |
Multiple buffer overflows in Schneider Electric VAMPSET before 2.2.168 allow local users to gain privileges via malformed disturbance-recording data in a (1) CFG or (2) DAT file. |
2Aveva Schneider Electric2Aveva Edge Wonderware Intouch 2014May 6, 2026 Mar 29, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 store cleartext OPC User credentials in a configuration file, which allows local users to obta...Show more |
2Aveva Schneider Electric2Aveva Edge Wonderware Intouch 2014May 6, 2026 Mar 29, 2015 N/A· v4 N/A· v3 3.3 LOW· v2 Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 transmit cleartext credentials, which allows remote attackers to obtain sensitive information...Show more |
2Aveva Schneider Electric2Aveva Edge Wonderware Intouch 2014May 6, 2026 Mar 29, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 provide an HMI user interface that lists all valid usernames, which makes it easier for remote...Show more |
2Aveva Schneider Electric2Aveva Edge Wonderware Intouch 2014May 6, 2026 Mar 29, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 rely on a hardcoded cleartext password to control read access to Project files and Project Con...Show more |
Buffer overflow in an unspecified DLL in Schneider Electric Pelco DS-NVs before 7.8.90 allows remote attackers to execute arbitrary code via unspecified vectors. |
1Schneider Electric 1Device Type Manager May 6, 2026 Mar 14, 2015 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Stack-based buffer overflow in Device Type Manager (DTM) 3.1.6 and earlier for Schneider Electric Invensys SRD Control Valve Positioner devices 960 and 991 allows local users to gain privileges via a malformed DLL file. |
1Schneider Electric 4Somachine SomoveSomove Lite+1 moreMay 6, 2026 Feb 1, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Stack-based buffer overflow in an unspecified DLL file in a DTM development kit in Schneider Electric Unity Pro, SoMachine, SoMove, SoMove Lite, Modbus Communication Library 2.2.6 and earlier, CANopen Communication Libra...Show more |
1Schneider Electric 5Etg3000 Factorycast Hmi Gateway Firmware Tsxetg3000Tsxetg3010+2 moreMay 6, 2026 Jan 27, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to obtain access via an FTP session. |
1Schneider Electric 5Etg3000 Factorycast Hmi Gateway Firmware Tsxetg3000Tsxetg3010+2 moreMay 6, 2026 Jan 27, 2015 N/A· v4 N/A· v3 7.8 HIGH· v2 The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and confi...Show more |
1Schneider Electric 1Wonderware Intouch Access Anywhere Server May 6, 2026 Jan 10, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 Stack-based buffer overflow in Schneider Electric Wonderware InTouch Access Anywhere Server 10.6 and 11.0 allows remote attackers to execute arbitrary code via a request for a filename that does not exist. |