Schneider Electric
schneider-electric
771 CVEs • 1,745 products
Products (1,745)
Click to collapseToggle
Products (1,745)
Click to collapse
CVEs (771)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Schneider Electric 6Ofs Test Client Tlxcdlfofs33 Ofs Test Client Tlxcdltofs33Ofs Test Client Tlxcdluofs33+3 moreApr 29, 2026 Feb 28, 2014 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 - 3.35, TLXCDSTOFS33 - 3.35, TLXCDLUOFS33 - 3.35, TLXCDLTOFS33 - 3.35, and TLXCDLFOFS33 - 3.35 allows local...Show more |
1Schneider Electric 1Floating License Manager May 28, 2026 Feb 28, 2014 N/A· v4 5.9 MEDIUM· v3 6.9 MEDIUM· v2 Unquoted Windows search path vulnerability in Schneider Electric Floating License Manager 1.0.0 through 1.4.0 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substr...Show more |
1Schneider Electric 4Citectscada Powerlogic ScadaStruxureware Powerscada Expert+1 moreApr 29, 2026 Feb 26, 2014 N/A· v4 N/A· v3 7.8 HIGH· v2 Schneider Electric StruxureWare SCADA Expert Vijeo Citect 7.40, Vijeo Citect 7.20 through 7.30SP1, CitectSCADA 7.20 through 7.30SP1, StruxureWare PowerSCADA Expert 7.30 through 7.30SR1, and PowerLogic SCADA 7.20 through...Show more |
1Schneider Electric 1Telvent Sage 3030 Firmware Apr 29, 2026 Jan 31, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Schneider Electric Telvent SAGE 3030 RTU with firmware C3413-500-001D3_P4 and C3413-500-001F0_PB allows remote attackers to cause a denial of service (temporary outage and CPU consumption) via malformed DNP3 traffic. |
1Schneider Electric 2Tburjr900 Tburjr900 FirmwareApr 29, 2026 Aug 28, 2013 N/A· v4 N/A· v3 9.3 HIGH· v2 Schneider Electric Trio J-Series License Free Ethernet Radio with firmware 3.6.0 through 3.6.3 uses the same AES encryption key across different customers' installations, which makes it easier for remote attackers to def...Show more |
1Schneider Electric 3Citectscada Powerlogic ScadaVijeo CitectApr 29, 2026 Aug 9, 2013 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Schneider Electric Vijeo Citect 7.20 and earlier, CitectSCADA 7.20 and earlier, and PowerLogic SCADA 7.20 and earlier allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a den...Show more |
2Mitsubishi Automation Schneider Electric3Citectfacilities CitectscadaMitsubishi Mx ComponentApr 29, 2026 Apr 19, 2013 N/A· v4 N/A· v3 10.0 HIGH· v2 Multiple buffer overflows in ActUWzd.dll 1.0.0.1 in Mitsubishi MX Component 3, as distributed in Citect CitectFacilities 7.10 and CitectScada 7.10r1, allow remote attackers to execute arbitrary code via a long string, as...Show more |
1Schneider Electric 1Micom S1 Studio Apr 29, 2026 Apr 18, 2013 N/A· v4 N/A· v3 6.6 MEDIUM· v2 The installer routine in Schneider Electric MiCOM S1 Studio uses world-writable permissions for executable files, which allows local users to modify the service or the configuration files, and consequently gain privilege...Show more |
1Schneider Electric 12Modicon M340 Bmx Noc 0401 Firmware Modicon M340 Bmx Noe 0100 FirmwareModicon M340 Bmx Noe 0100h Firmware+9 moreApr 29, 2026 Apr 4, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Schneider Electric M340 PLC modules allow remote attackers to cause a denial of service (resource consumption) via unspecified vectors. NOTE: the vendor reportedly disputes this issue because it "could not be duplic...Show more |
The Schneider Electric Magelis XBT HMI controller has a default password for authentication of configuration uploads, which makes it easier for remote attackers to bypass intended access restrictions via crafted configur...Show more |
The Schneider Electric M340 BMXNOE01xx and BMXP3420xx PLC modules allow remote authenticated users to cause a denial of service (module crash) via crafted FTP traffic, as demonstrated by the FileZilla FTP client. |
1Schneider Electric 3Modicon M340 Modicon PremiumModicon Quantum PlcApr 29, 2026 Apr 4, 2013 N/A· v4 N/A· v3 8.5 HIGH· v2 The FactoryCast service on the Schneider Electric Quantum 140NOE77111 and 140NWM10000, M340 BMXNOE0110x, and Premium TSXETY5103 PLC modules allows remote authenticated users to send Modbus messages, and consequently exec...Show more |
1Schneider Electric 3Modicon M340 Modicon PremiumModicon Quantum PlcApr 29, 2026 Apr 4, 2013 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability on the Schneider Electric Quantum 140NOE77111, 140NOE77101, and 140NWM10000; M340 BMXNOC0401, BMXNOE0100x, and BMXNOE011xx; and Premium TSXETY4103, TSXETY5103, and TSXWMY10...Show more |
1Schneider Electric 1Accutech Manager Apr 29, 2026 Feb 15, 2013 N/A· v4 N/A· v3 10.0 HIGH· v2 Heap-based buffer overflow in RFManagerService.exe in Schneider Electric Accutech Manager 2.00.1 and earlier allows remote attackers to execute arbitrary code via a crafted HTTP request. |
1Schneider Electric 1Interactive Graphical Scada System Apr 29, 2026 Jan 21, 2013 N/A· v4 N/A· v3 10.0 HIGH· v2 Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA System (IGSS) 10 and earlier allows remote attackers to execute arbitrary code by sending TCP port-12397 data that does not comply with a prot...Show more |
1Schneider Electric 1Software Update Utility Apr 29, 2026 Jan 21, 2013 N/A· v4 N/A· v3 9.3 HIGH· v2 The client in Schneider Electric Software Update (SESU) Utility 1.0.x and 1.1.x does not ensure that updates have a valid origin, which allows man-in-the-middle attackers to spoof updates, and consequently execute arbitr...Show more |
2Mitsubishi Automation Schneider Electric2Citectscada Mx4 ScadaApr 29, 2026 Sep 15, 2012 N/A· v4 N/A· v3 4.6 MEDIUM· v2 Buffer overflow in an unspecified third-party component in the Batch module for Schneider Electric CitectSCADA before 7.20 and Mitsubishi MX4 SCADA before 7.20 allows local users to execute arbitrary code via a long stri...Show more |
Multiple cross-site scripting (XSS) vulnerabilities in Schneider Electric Kerweb before 3.0.1 and Kerwin before 6.0.1 allow remote attackers to inject arbitrary web script or HTML via (1) the evtvariablename parameter in...Show more |
1Schneider Electric 1Modicon Quantum Plc Apr 29, 2026 Jan 28, 2012 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Schneider Electric Modicon Quantum PLC does not perform authentication between the Unity software and PLC, which allows remote attackers to cause a denial of service or possibly execute arbitrary code via unspecified vec...Show more |
1Schneider Electric 1Modicon Quantum Plc Apr 29, 2026 Jan 28, 2012 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Schneider Electric Modicon Quantum PLC allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |