AID
Automation
Information Directory
HomeCVE FeedBrands
AID
Automation Information Directory
CVE data sourced from NIST NVD · Documentation links from official sources
Home›Brands›Schneider Electric
SC
Platform

Schneider Electric

Global energy management and automation leader. Products include Modicon M340/M580 PLCs, Altivar drives, Harmony HMI, and EcoStruxure platform.

https://www.se.com/ww/en/work/products/industrial-automation-and-control/ →
216
Total CVEs
10
Resources
42
CRIT
98
HIGH
68
MED
8
LOW
CVEsCVEsSpecsTech SpecsDocsTech DocsImplImplementationsExamplesExamples
216 entries
CVE-2016-8352CRITICAL

An issue was discovered in Schneider Electric ConneXium firewalls TCSEFEC23F3F20 all versions, TCSEFEC23F3F21 all versions, TCSEFEC23FCF20 all versions, TCSEFEC23FCF21 all versions, and TCSEFEC2CF3F20 all versions. A stack-based buffer overflow can be triggered during the SNMP login authentication process that may allow an attacker to remotely execute code.

Feb 13, 2017
10.0
CVE-2022-42971CRITICAL

A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution when the attacker uploads a malicious JSP file. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)

Feb 1, 2023
9.8
CVE-2022-42970CRITICAL

A CWE-306: Missing Authentication for Critical Function The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)

Feb 1, 2023
9.8
CVE-2021-30064CRITICAL

On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an SSH login can succeed with hardcoded default credentials (if the device is in the uncommissioned state).

Apr 3, 2022
9.8
CVE-2018-7791CRITICAL

A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to overwrite the original password with their password. If an attacker exploits this vulnerability and overwrite the password, the attacker can upload the original program from the PLC.

Aug 29, 2018
9.8
CVE-2018-7790CRITICAL

An Information Management Error vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to replay authentication sequences. If an attacker exploits this vulnerability and connects to a Modicon M221, the attacker can upload the original program from the PLC.

Aug 29, 2018
9.8
CVE-2018-7785CRITICAL

In Schneider Electric U.motion Builder software versions prior to v1.3.4, a remote command injection allows authentication bypass.

Jul 3, 2018
9.8
CVE-2018-7784CRITICAL

In Schneider Electric U.motion Builder software versions prior to v1.3.4, this exploit occurs when the submitted data of an input string is evaluated as a command by the application. In this way, the attacker could execute code, read the stack, or cause a segmentation fault in the running application.

Jul 3, 2018
9.8
CVE-2018-7780CRITICAL

In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, a buffer overflow vulnerability exist in cgi program "set".

Jul 3, 2018
9.8
CVE-2018-7778CRITICAL

In Schneider Electric Evlink Charging Station versions prior to v3.2.0-12_v1, the Web Interface has an issue that may allow a remote attacker to gain administrative privileges without properly authenticating remote users.

Jul 3, 2018
9.8
CVE-2018-7761CRITICAL

A vulnerability exists in the HTTP request parser in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200 which could allow arbitrary code execution.

Apr 18, 2018
9.8
CVE-2018-7760CRITICAL

An authorization bypass vulnerability exists in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200. Requests to CGI functions allow malicious users to bypass authorization.

Apr 18, 2018
9.8
CVE-2018-7246CRITICAL

A cleartext transmission of sensitive information vulnerability exists in Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. he integrated web server (Port 80/443/TCP) of the affected devices could allow remote attackers to discover an administrative account. If default on device, it is not using a SSL in settings and if multiple request of the page "Access Control" (IP-address device/ups/pas_cont.htm) account data will be sent in cleartext

Apr 18, 2018
9.8
CVE-2018-7243CRITICAL

An authorization bypass vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to get a full access to device, bypassing the authorization system.

Apr 18, 2018
9.8
CVE-2018-7242CRITICAL

Vulnerable hash algorithms exists in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, and BMXNOR0200 controllers in all versions of the communication modules. The algorithm used to encrypt the password is vulnerable to hash collision attacks.

Apr 18, 2018
9.8
CVE-2018-7241CRITICAL

Hard coded accounts exist in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, and BMXNOR0200 controllers in all versions of the communication modules.

Apr 18, 2018
9.8
CVE-2018-7238CRITICAL

A buffer overflow vulnerability exist in the web-based GUI of Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow an unauthenticated, remote attacker to execute arbitrary code.

Mar 9, 2018
9.8
CVE-2018-7233CRITICAL

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow execution of commands due to lack of validation of the shell meta characters with the value of 'model_name' or 'mac_address'.

Mar 9, 2018
9.8
CVE-2018-7232CRITICAL

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow execution of commands due to lack of validation of the shell meta characters with the value of 'network.ieee8021x.delete_certs'.

Mar 9, 2018
9.8
CVE-2018-7231CRITICAL

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow execution of commands due to lack of validation of the shell meta characters with the value of 'system.opkg.remove'.

Mar 9, 2018
9.8
CVE-2018-7229CRITICAL

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow an unauthenticated, remote attacker to bypass authentication and gain administrator privileges because the use of hardcoded credentials.

Mar 9, 2018
9.8
CVE-2018-7228CRITICAL

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow an unauthenticated, remote attacker to bypass authentication and get the administrator privileges.

Mar 9, 2018
9.8
CVE-2017-14024CRITICAL

A Stack-based Buffer Overflow issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 Patch 1 and prior versions, and InTouch Machine Edition v8.0 SP2 Patch 1 and prior versions. The stack-based buffer overflow vulnerability has been identified, which may allow remote code execution with high privileges.

Nov 13, 2017
9.8
CVE-2017-13997CRITICAL

A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 or prior, and InTouch Machine Edition v8.0 SP2 or prior. InduSoft Web Studio provides the capability for an HMI client to trigger script execution on the server for the purposes of performing customized calculations or actions. A remote malicious entity could bypass the server authentication and trigger the execution of an arbitrary command. The command is executed under high privileges and could lead to a complete compromise of the server.

Oct 3, 2017
9.8
CVE-2017-9957CRITICAL

A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the web service contains a hidden system account with a hardcoded password. An attacker can use this information to log into the system with high-privilege credentials.

Sep 26, 2017
9.8
CVE-2017-7974CRITICAL

A path traversal information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauthenticated user can execute arbitrary code and exfiltrate files.

Sep 26, 2017
9.8
CVE-2017-7973CRITICAL

A SQL injection vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauthenticated user can use calls to various paths allowing performance of arbitrary SQL commands against the underlying database.

Sep 26, 2017
9.8
CVE-2017-9629CRITICAL

A Stack-Based Buffer Overflow issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.2307.1 and prior. The stack-based buffer overflow vulnerability has been identified, which may allow a remote attacker to execute arbitrary code in the context of a highly privileged account.

Jul 7, 2017
9.8
CVE-2017-6034CRITICAL

An Authentication Bypass by Capture-Replay issue was discovered in Schneider Electric Modicon Modbus Protocol. Sensitive information is transmitted in cleartext in the Modicon Modbus protocol, which may allow an attacker to replay the following commands: run, stop, upload, and download.

Jun 30, 2017
9.8
CVE-2017-6028CRITICAL

An Insufficiently Protected Credentials issue was discovered in Schneider Electric Modicon PLCs Modicon M241, all firmware versions, and Modicon M251, all firmware versions. Log-in credentials are sent over the network with Base64 encoding leaving them susceptible to sniffing. Sniffed credentials could then be used to log into the web application.

Jun 30, 2017
9.8
CVE-2017-5158CRITICAL

An Information Exposure issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. Credentials may be exposed to external systems via specific URL parameters, as arbitrary destination addresses may be specified.

Apr 20, 2017
9.8
CVE-2017-7689CRITICAL

A Command Injection vulnerability in Schneider Electric homeLYnk Controller exists in all versions before 1.5.0.

Apr 11, 2017
9.8
CVE-2017-7575CRITICAL

Schneider Electric Modicon TM221CE16R 1.3.3.3 devices allow remote attackers to discover the application-protection password via a \x00\x01\x00\x00\x00\x05\x01\x5a\x00\x03\x00 request to the Modbus port (502/tcp). Subsequently the application may be arbitrarily downloaded, modified, and uploaded.

Apr 6, 2017
9.8
CVE-2017-7574CRITICAL

Schneider Electric SoMachine Basic 1.4 SP1 and Schneider Electric Modicon TM221CE16R 1.3.3.3 devices have a hardcoded-key vulnerability. The Project Protection feature is used to prevent unauthorized users from opening an XML protected project file, by prompting the user for a password. This XML file is AES-CBC encrypted; however, the key used for encryption (SoMachineBasicSoMachineBasicSoMa) cannot be changed. After decrypting the XML file with this key, the user password can be found in the decrypted data. After reading the user password, the project can be opened and modified with the Schneider product.

Apr 6, 2017
9.8
CVE-2017-5178CRITICAL

An issue was discovered in Schneider Electric Tableau Server/Desktop Versions 7.0 to 10.1.3 in Wonderware Intelligence Versions 2014R3 and prior. These versions contain a system account that is installed by default. The default system account is difficult to configure with non-default credentials after installation, and changing the default credentials in the embedded Tableau Server is not documented. If Tableau Server is used with Windows integrated security (Active Directory), the software is not vulnerable. However, when Tableau Server is used with local authentication mode, the software is vulnerable. The default system account could be used to gain unauthorized access.

Mar 8, 2017
9.8
CVE-2016-5818CRITICAL

An issue was discovered in Schneider Electric PowerLogic PM8ECC device 2.651 and older. Undocumented hard-coded credentials allow access to the device.

Feb 13, 2017
9.8
CVE-2016-5815CRITICAL

An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series, ION8650 series, ION8800 series, and PM5XXX series. No authentication is configured by default. An unauthorized user can access the device management portal and make configuration changes.

Feb 13, 2017
9.8
CVE-2016-4520CRITICAL

Schneider Electric Pelco Digital Sentry Video Management System with firmware before 7.14 has hardcoded credentials, which allows remote attackers to obtain access, and consequently execute arbitrary code, via unspecified vectors.

Jul 15, 2016
9.8
CVE-2012-0931CRITICAL

Schneider Electric Modicon Quantum PLC does not perform authentication between the Unity software and PLC, which allows remote attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors.

Jan 28, 2012
9.8
CVE-2018-7245CRITICAL

An improper authorization vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to change UPS control and shutdown parameters or other critical settings without authorization.

Apr 18, 2018
9.1
CVE-2018-7237CRITICAL

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow a remote attacker to delete arbitrary system file due to lack of validation of the /login/bin/set_param to the file name with the value of 'system.delete.sd_file'

Mar 9, 2018
9.1
CVE-2017-6026CRITICAL

A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware versions prior to Version 4.0.5.11, and Modicon M251, firmware versions prior to Version 4.0.5.11. The session numbers generated by the web application are lacking randomization and are shared between several users. This may allow a current session to be compromised.

Jun 30, 2017
9.1
CVE-2015-7937HIGH

Stack-based buffer overflow in the GoAhead Web Server on Schneider Electric Modicon M340 PLC BMXNOx and BMXPx devices allows remote attackers to execute arbitrary code via a long password in HTTP Basic Authentication data.

Dec 21, 2015
10.0
CVE-2014-9198HIGH

The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to obtain access via an FTP session.

Jan 27, 2015
10.0
CVE-2014-9197HIGH

The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request.

Jan 27, 2015
10.0
CVE-2014-9190HIGH

Stack-based buffer overflow in Schneider Electric Wonderware InTouch Access Anywhere Server 10.6 and 11.0 allows remote attackers to execute arbitrary code via a request for a filename that does not exist.

Jan 10, 2015
10.0
CVE-2014-9188HIGH

Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8513 and CVE-2014-8514. NOTE: this may be clarified later based on details provided by researchers.

Dec 27, 2014
10.0
CVE-2014-8511HIGH

Buffer overflow in an ActiveX control in Atx45.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8512. NOTE: this may be clarified later based on details provided by researchers.

Dec 27, 2014
10.0
CVE-2014-0754HIGH

Directory traversal vulnerability in SchneiderWEB on Schneider Electric Modicon PLC Ethernet modules 140CPU65x Exec before 5.5, 140NOC78x Exec before 1.62, 140NOE77x Exec before 6.2, BMXNOC0401 before 2.05, BMXNOE0100 before 2.9, BMXNOE0110x Exec before 6.0, TSXETC101 Exec before 2.04, TSXETY4103x Exec before 5.7, TSXETY5103x Exec before 5.9, TSXP57x ETYPort Exec before 5.7, and TSXP57x Ethernet Copro Exec before 5.5 allows remote attackers to visit arbitrary resources via a crafted HTTP request.

Oct 3, 2014
10.0
CVE-2013-2762HIGH

The Schneider Electric Magelis XBT HMI controller has a default password for authentication of configuration uploads, which makes it easier for remote attackers to bypass intended access restrictions via crafted configuration data.

Apr 4, 2013
10.0
CVE-2013-0658HIGH

Heap-based buffer overflow in RFManagerService.exe in Schneider Electric Accutech Manager 2.00.1 and earlier allows remote attackers to execute arbitrary code via a crafted HTTP request.

Feb 15, 2013
10.0
CVE-2013-0657HIGH

Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA System (IGSS) 10 and earlier allows remote attackers to execute arbitrary code by sending TCP port-12397 data that does not comply with a protocol.

Jan 21, 2013
10.0
CVE-2011-4861HIGH

The modbus_125_handler function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) allows remote attackers to install arbitrary firmware updates via a MODBUS 125 function code to TCP port 502.

Dec 17, 2011
10.0
CVE-2011-4860HIGH

The ComputePassword function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) generates the password for the fwupgrade account by performing a calculation on the MAC address, which makes it easier for remote attackers to obtain access via a (1) ARP request message or (2) Neighbor Solicitation message.

Dec 17, 2011
10.0
CVE-2011-4859HIGH

The Schneider Electric Quantum Ethernet Module, as used in the Quantum 140NOE771* and 140CPU65* modules, the Premium TSXETY* and TSXP57* modules, the M340 BMXNOE01* and BMXP3420* modules, and the STB DIO STBNIC2212 and STBNIP2* modules, uses hardcoded passwords for the (1) AUTCSE, (2) AUT_CSE, (3) fdrusers, (4) ftpuser, (5) loader, (6) nic2212, (7) nimrohs2212, (8) nip2212, (9) noe77111_v500, (10) ntpupdate, (11) pcfactory, (12) sysdiag, (13) target, (14) test, (15) USER, and (16) webserver accounts, which makes it easier for remote attackers to obtain access via the (a) TELNET, (b) Windriver Debug, or (c) FTP port.

Dec 17, 2011
10.0
CVE-2013-0662HIGH

Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow remote attackers to execute arbitrary code via a large buffer-size value in a Modbus Application Header.

Apr 1, 2014
9.3
CVE-2013-2782HIGH

Schneider Electric Trio J-Series License Free Ethernet Radio with firmware 3.6.0 through 3.6.3 uses the same AES encryption key across different customers' installations, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.

Aug 28, 2013
9.3
CVE-2013-0655HIGH

The client in Schneider Electric Software Update (SESU) Utility 1.0.x and 1.1.x does not ensure that updates have a valid origin, which allows man-in-the-middle attackers to spoof updates, and consequently execute arbitrary code, by modifying the data stream on TCP port 80.

Jan 21, 2013
9.3
CVE-2011-4034HIGH

Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors.

Dec 2, 2011
9.3
CVE-2018-7782HIGH

In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, authenticated users can view passwords in clear text.

Jul 3, 2018
8.8
CVE-2018-7781HIGH

In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, by sending a specially crafted request an authenticated user can view password in clear text and results in privilege escalation.

Jul 3, 2018
8.8
CVE-2018-7777HIGH

The vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A remote, authenticated attacker can exploit this vulnerability by sending a crafted request to the target server.

Jul 3, 2018
8.8
CVE-2018-7774HIGH

The vulnerability exists within processing of localize.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the username input parameter.

Jul 3, 2018
8.8
CVE-2018-7773HIGH

The vulnerability exists within processing of nfcserver.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the sessionid input parameter.

Jul 3, 2018
8.8
CVE-2018-7772HIGH

The vulnerability exists within processing of applets which are exposed on the web service in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query to determine whether a user is logged in is subject to SQL injection on the loginSeed parameter, which can be embedded in the HTTP cookie of the request.

Jul 3, 2018
8.8
CVE-2018-7769HIGH

The vulnerability exists within processing of xmlserver.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the id input parameter.

Jul 3, 2018
8.8
CVE-2018-7768HIGH

The vulnerability exists within processing of loadtemplate.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the tpl input parameter.

Jul 3, 2018
8.8
CVE-2018-7767HIGH

The vulnerability exists within processing of editobject.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the type input parameter.

Jul 3, 2018
8.8
CVE-2018-7766HIGH

The vulnerability exists within processing of track_getdata.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the id input parameter.

Jul 3, 2018
8.8
CVE-2018-7765HIGH

The vulnerability exists within processing of track_import_export.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the object_id input parameter.

Jul 3, 2018
8.8
CVE-2018-7240HIGH

A vulnerability exists in Schneider Electric's Modicon Quantum in all versions of the communication modules which could allow arbitrary code execution. An FTP command used to upgrade the firmware of the module can be misused to cause a denial of service, or in extreme cases, to load a malicious firmware.

Apr 18, 2018
8.8
CVE-2018-7230HIGH

A XML external entity (XXE) vulnerability exists in the import.cgi of the web interface component of the Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67.

Mar 9, 2018
8.8
CVE-2017-7969HIGH

A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for multiple state-changing requests. This type of attack requires some level of social engineering in order to get a legitimate user to click on or access a malicious link/site containing the CSRF attack.

Sep 26, 2017
8.8
CVE-2017-7966HIGH

A DLL Hijacking vulnerability in the programming software in Schneider Electric's SoMachine HVAC v2.1.0 allows a remote attacker to execute arbitrary code on the targeted system. The vulnerability exists due to the improper loading of a DLL.

Jun 7, 2017
8.8
CVE-2017-5156HIGH

A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The client request may be forged from a different site. This will allow an external site to access internal RDP systems on behalf of the currently logged in user.

Apr 20, 2017
8.8
CVE-2016-5809HIGH

An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series, ION8650 series, ION8800 series, and PM5XXX series. There is no CSRF Token generated to authenticate the user during a session. Successful exploitation of this vulnerability can allow unauthorized configuration changes to be made and saved.

Feb 13, 2017
8.8
CVE-2017-9627HIGH

An Uncontrolled Resource Consumption issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.2307.1 and prior. The uncontrolled resource consumption vulnerability could allow an attacker to exhaust the memory resources of the machine, causing a denial of service.

Jul 7, 2017
8.6
CVE-2013-0664HIGH

The FactoryCast service on the Schneider Electric Quantum 140NOE77111 and 140NWM10000, M340 BMXNOE0110x, and Premium TSXETY5103 PLC modules allows remote authenticated users to send Modbus messages, and consequently execute arbitrary code, by embedding these messages in SOAP HTTP POST requests.

Apr 4, 2013
8.5
CVE-2018-8872HIGH

In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, system calls read directly from memory addresses within the control program area without any verification. Manipulating this data could allow attacker data to be copied anywhere within memory.

May 4, 2018
8.1
CVE-2018-7236HIGH

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could enable SSH service due to lack of authentication for /login/bin/set_param could enable SSH service.

Mar 9, 2018
8.1
CVE-2017-9963HIGH

A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for multiple state-changing requests. This type of attack requires some level of social engineering in order to get a legitimate user to click on or access a malicious link/site containing the CSRF attack.

Feb 12, 2018
8.1
CVE-2018-7771HIGH

The vulnerability exists within processing of editscript.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A directory traversal vulnerability allows a caller with standard user privileges to write arbitrary php files anywhere in the web service directory tree.

Jul 3, 2018
8.0
CVE-2022-42973HIGH

A CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause local privilege escalation when local attacker connects to the database. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)

Feb 1, 2023
7.8
CVE-2022-42972HIGH

A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cause local privilege escalation when a local attacker modifies the webroot directory. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)

Feb 1, 2023
7.8
CVE-2021-22808HIGH

A CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution when a malicious *.gd1 configuration file is loaded into the GUIcon tool. Affected Product: Eurotherm by Schneider Electric GUIcon Version 2.0 (Build 683.003) and prior

Jan 28, 2022
7.8
CVE-2021-22807HIGH

A CWE-787: Out-of-bounds Write vulnerability exists that could cause arbitrary code execution when a malicious *.gd1 configuration file is loaded into the GUIcon tool. Affected Product: Eurotherm by Schneider Electric GUIcon Version 2.0 (Build 683.003) and prior

Jan 28, 2022
7.8
CVE-2020-7523HIGH

Improper Privilege Management vulnerability exists in Schneider Electric Modbus Serial Driver (see security notification for versions) which could cause local privilege escalation when the Modbus Serial Driver service is invoked. The driver does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Aug 31, 2020
7.8
CVE-2018-7815HIGH

A Type Confusion (CWE-843) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0) on c3core.dll which could cause remote code to be executed when parsing a GD1 file

Feb 6, 2019
7.8
CVE-2018-7814HIGH

A Stack-based Buffer Overflow (CWE-121) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0) which could cause remote code to be executed when parsing a GD1 file

Feb 6, 2019
7.8
CVE-2018-7813HIGH

A Type Confusion (CWE-843) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0) on pcwin.dll which could cause remote code to be executed when parsing a GD1 file

Feb 6, 2019
7.8
CVE-2018-7799HIGH

A DLL hijacking vulnerability exists in Schneider Electric Software Update (SESU), all versions prior to V2.2.0, which could allow an attacker to execute arbitrary code on the targeted system when placing a specific DLL file.

Nov 2, 2018
7.8
CVE-2018-7239HIGH

A DLL hijacking vulnerability exists in Schneider Electric's SoMove Software and associated DTM software components in all versions prior to 2.6.2 which could allow an attacker to execute arbitrary code.

Mar 9, 2018
7.8
CVE-2017-9967HIGH

A security misconfiguration vulnerability exists in Schneider Electric's IGSS SCADA Software versions 12 and prior. Security configuration settings such as Address Space Layout Randomization (ASLR) and Data Execution prevention (DEP) were not properly configured resulting in weak security.

Feb 12, 2018
7.8
CVE-2017-9961HIGH

A vulnerability exists in Schneider Electric's Pro-Face GP Pro EX version 4.07.000 that allows an attacker to execute arbitrary code. Malicious code installation requires an access to the computer. By placing a specific DLL/OCX file, an attacker is able to force the process to load arbitrary DLL and execute arbitrary code in the context of the process.

Sep 26, 2017
7.8
CVE-2017-9958HIGH

An improper access control vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an improper handling of the system configuration can allow an attacker to execute arbitrary code under the context of root.

Sep 26, 2017
7.8
CVE-2017-7968HIGH

An Incorrect Default Permissions issue was discovered in Schneider Electric Wonderware InduSoft Web Studio v8.0 Patch 3 and prior versions. Upon installation, Wonderware InduSoft Web Studio creates a new directory and two files, which are placed in the system's path and can be manipulated by non-administrators. This could allow an authenticated user to escalate his or her privileges.

May 19, 2017
7.8
CVE-2017-6033HIGH

A DLL Hijacking issue was discovered in Schneider Electric Interactive Graphical SCADA System (IGSS) Software, Version 12 and previous versions. The software will execute a malicious file if it is named the same as a legitimate file and placed in a location that is earlier in the search path.

Apr 7, 2017
7.8
CVE-2014-2380HIGH

Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows remote attackers to obtain sensitive information by reading a credential file.

Aug 28, 2014
7.8
CVE-2013-2824HIGH

Schneider Electric StruxureWare SCADA Expert Vijeo Citect 7.40, Vijeo Citect 7.20 through 7.30SP1, CitectSCADA 7.20 through 7.30SP1, StruxureWare PowerSCADA Expert 7.30 through 7.30SR1, and PowerLogic SCADA 7.20 through 7.20SR1 do not properly handle exceptions, which allows remote attackers to cause a denial of service via a crafted packet.

Feb 26, 2014
7.8
CVE-2015-3977HIGH

Buffer overflow in Schneider Electric IMT25 Magnetic Flow DTM before 1.500.004 for the HART Protocol allows remote authenticated users to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HART reply.

Nov 15, 2015
7.7
CVE-2021-30065HIGH

On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, crafted ModBus packets can bypass the ModBus enforcer. NOTE: this issue exists because of an incomplete fix of CVE-2017-11401.

Apr 3, 2022
7.5
CVE-2021-30063HIGH

On Schneider Electric ConneXium Tofino OPCLSM TCSEFM0000 before 03.23 and Belden Tofino Xenon Security Appliance, crafted OPC packets can cause an OPC enforcer denial of service.

Apr 3, 2022
7.5
CVE-2021-30062HIGH

On Schneider Electric ConneXium Tofino OPCLSM TCSEFM0000 before 03.23 and Belden Tofino Xenon Security Appliance, crafted OPC packets can bypass the OPC enforcer.

Apr 3, 2022
7.5
CVE-2020-7524HIGH

Out-of-bounds Write vulnerability exists in Modicon M218 Logic Controller (V5.0.0.7 and prior) which could cause Denial of Service when sending specific crafted IPV4 packet to the controller: Sending a specific IPv4 protocol package to Schneider Electric Modicon M218 Logic Controller can cause IPv4 devices to go down. The device does not work properly and must be powered back on to return to normal.

Aug 31, 2020
7.5
CVE-2019-13537HIGH

The IEC870IP driver for AVEVA’s Vijeo Citect and Citect SCADA and Schneider Electric’s Power SCADA Operation has a buffer overflow vulnerability that could result in a server-side crash.

Jan 14, 2020
7.5
CVE-2018-7792HIGH

A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to decode the password using rainbow table.

Aug 29, 2018
7.5
CVE-2018-7789HIGH

An Improper Check for Unusual or Exceptional Conditions vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to remotely reboot Modicon M221 using crafted programing protocol frames.

Aug 29, 2018
7.5
CVE-2018-7783HIGH

Schneider Electric SoMachine Basic prior to v1.6 SP1 suffers from an XML External Entity (XXE) vulnerability using the DTD parameter entities technique resulting in disclosure and retrieval of arbitrary data on the affected node via out-of-band (OOB) attack. The vulnerability is triggered when input passed to the xml parser is not sanitized while parsing the xml project/template file.

Jul 3, 2018
7.5
CVE-2018-7779HIGH

In Schneider Electric Wiser for KNX V2.1.0 and prior, homeLYnk V2.0.1 and prior; and spaceLYnk V2.1.0 and prior, weak and unprotected FTP access could allow an attacker unauthorized access.

Jul 3, 2018
7.5
CVE-2017-6021HIGH

In Schneider Electric ClearSCADA 2014 R1 (build 75.5210) and prior, 2014 R1.1 (build 75.5387) and prior, 2015 R1 (build 76.5648) and prior, and 2015 R2 (build 77.5882) and prior, an attacker with network access to the ClearSCADA server can send specially crafted sequences of commands and data packets to the ClearSCADA server that can cause the ClearSCADA server process and ClearSCADA communications driver processes to terminate. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

May 14, 2018
7.5
CVE-2018-7762HIGH

A vulnerability exists in the web services to process SOAP requests in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200 which could allow result in a buffer overflow.

Apr 18, 2018
7.5
CVE-2018-7759HIGH

A buffer overflow vulnerability exists in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200. The buffer overflow vulnerability is caused by the length of the source string specified (instead of the buffer size) as the number of bytes to be copied.

Apr 18, 2018
7.5
CVE-2018-7235HIGH

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow arbitrary system file download due to lack of validation of the shell meta characters with the value of 'system.download.sd_file'

Mar 9, 2018
7.5
CVE-2018-7234HIGH

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow arbitrary system file download due to lack of validation of SSL certificate.

Mar 9, 2018
7.5
CVE-2017-9962HIGH

Schneider Electric's ClearSCADA versions released prior to August 2017 are susceptible to a memory allocation vulnerability, whereby malformed requests can be sent to ClearSCADA client applications to cause unexpected behavior. Client applications affected include ViewX and the Server Icon.

Sep 26, 2017
7.5
CVE-2017-9631HIGH

A Null Pointer Dereference issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.2307.1 and prior. The null pointer dereference vulnerability could allow an attacker to crash the logger process, causing a denial of service for logging and log-viewing (applications that use the Wonderware ArchestrA Logger continue to run when the Wonderware ArchestrA Logger service is unavailable).

Jul 7, 2017
7.5
CVE-2017-6017HIGH

A Resource Exhaustion issue was discovered in Schneider Electric Modicon M340 PLC BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP341000, BMXP342000, BMXP3420102, BMXP3420102CL, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, and BMXP342030H. A remote attacker could send a specially crafted set of packets to the PLC causing it to freeze, requiring the operator to physically press the reset button on the PLC in order to recover.

Jun 30, 2017
7.5
CVE-2017-6019HIGH

An issue was discovered in Schneider Electric Conext ComBox, model 865-1058, all firmware versions prior to V3.03 BN 830. A series of rapid requests to the device may cause it to reboot.

Apr 7, 2017
7.5
CVE-2016-8374HIGH

An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all versions, Magelis GTU Universal Panel, all versions, Magelis STO5xx and STU Small panels, all versions, Magelis XBT GH Advanced Hand-held Panels, all versions, Magelis XBT GK Advanced Touchscreen Panels with Keyboard, all versions, Magelis XBT GT Advanced Touchscreen Panels, all versions, and Magelis XBT GTW Advanced Open Touchscreen Panels (Windows XPe). An attacker may be able to disrupt a targeted web server, resulting in a denial of service because of UNCONTROLLED RESOURCE CONSUMPTION.

Feb 13, 2017
7.5
CVE-2015-7375HIGH

Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code or cause a denial of service (unhandled runtime exception and application crash) via a crafted Indusoft Project file.

Sep 25, 2015
7.5
CVE-2015-7374HIGH

The Remote Agent component in Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code via unspecified vectors, aka ZDI-CAN-2649.

Sep 25, 2015
7.5
CVE-2015-0982HIGH

Buffer overflow in an unspecified DLL in Schneider Electric Pelco DS-NVs before 7.8.90 allows remote attackers to execute arbitrary code via unspecified vectors.

Mar 14, 2015
7.5
CVE-2014-9200HIGH

Stack-based buffer overflow in an unspecified DLL file in a DTM development kit in Schneider Electric Unity Pro, SoMachine, SoMove, SoMove Lite, Modbus Communication Library 2.2.6 and earlier, CANopen Communication Library 1.0.2 and earlier, EtherNet/IP Communication Library 1.0.0 and earlier, EM X80 Gateway DTM (MB TCP/SL), Advantys DTM for OTB, Advantys DTM for STB, KINOS DTM, SOLO DTM, and Xantrex DTMs allows remote attackers to execute arbitrary code via unspecified vectors.

Feb 1, 2015
7.5
CVE-2014-8514HIGH

Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8513 and CVE-2014-9188. NOTE: this may be clarified later based on details provided by researchers.

Dec 27, 2014
7.5
CVE-2014-8513HIGH

Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8514 and CVE-2014-9188. NOTE: this may be clarified later based on details provided by researchers.

Dec 27, 2014
7.5
CVE-2014-8512HIGH

Buffer overflow in an ActiveX control in Atx45.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8511. NOTE: this may be clarified later based on details provided by researchers.

Dec 27, 2014
7.5
CVE-2014-5399HIGH

SQL injection vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Aug 28, 2014
7.5
CVE-2014-5397HIGH

Cross-site scripting (XSS) vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Aug 28, 2014
7.5
CVE-2012-0929HIGH

Multiple buffer overflows in Schneider Electric Modicon Quantum PLC allow remote attackers to cause a denial of service via malformed requests to the (1) FTP server or (2) HTTP server.

Jan 28, 2012
7.5
CVE-2019-6834HIGH

A CWE-502: Deserialization of Untrusted Data vulnerability exists which could allow an attacker to execute arbitrary code on the targeted system with SYSTEM privileges when placing a malicious user to be authenticated for this vulnerability to be successfully exploited. Affected Product: Schneider Electric Software Update (SESU) SUT Service component (V2.1.1 to V2.3.0)

Apr 13, 2022
7.3
CVE-2015-1014HIGH

A successful exploit of these vulnerabilities requires the local user to load a crafted DLL file in the system directory on servers running Schneider Electric OFS v3.5 with version v7.40 of SCADA Expert Vijeo Citect/CitectSCADA, OFS v3.5 with version v7.30 of Vijeo Citect/CitectSCADA, and OFS v3.5 with version v7.20 of Vijeo Citect/CitectSCADA.. If the application attempts to open that file, the application could crash or allow the attacker to execute arbitrary code. Schneider Electric recommends vulnerable users upgrade the OFS to V3.5 and install the latest service pack (SP 6 or newer) for their associated version.

Mar 25, 2019
7.3
CVE-2017-9956HIGH

An authentication bypass vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system contains a hard-coded valid session. An attacker can use that session ID as part of the HTTP cookie of a web request, resulting in authentication bypass

Sep 26, 2017
7.3
CVE-2017-7965HIGH

A buffer overflow vulnerability exists in Programming Software executable AlTracePrint.exe, in Schneider Electric's SoMachine HVAC v2.1.0 for Modicon M171/M172 Controller.

Jun 7, 2017
7.3
CVE-2017-5155HIGH

An issue was discovered in Schneider Electric Wonderware Historian 2014 R2 SP1 P01 and earlier. Wonderware Historian creates logins with default passwords, which can allow a malicious entity to compromise Historian databases. In some installation scenarios, resources beyond those created by Wonderware Historian may be compromised as well.

Feb 13, 2017
7.3
CVE-2016-4529HIGH

An unspecified ActiveX control in Schneider Electric SoMachine HVAC Programming Software for M171/M172 Controllers before 2.1.0 allows remote attackers to execute arbitrary code via unknown vectors, related to the INTERFACESAFE_FOR_UNTRUSTED_CALLER (aka safe for scripting) flag.

Jul 15, 2016
7.3
CVE-2017-9970HIGH

A remote code execution vulnerability exists in Schneider Electric's StruxureOn Gateway versions 1.1.3 and prior. Uploading a zip which contains carefully crafted metadata allows for the file to be uploaded to any directory on the host machine information which could lead to remote code execution.

Feb 12, 2018
7.2
CVE-2016-2278HIGH

Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows remote authenticated administrators to execute arbitrary OS commands by defeating an msh (aka Minimal Shell) protection mechanism.

Mar 2, 2016
7.2
CVE-2011-3330HIGH

Buffer overflow in the UnitelWay Windows Device Driver, as used in Schneider Electric Unity Pro 6 and earlier, OPC Factory Server 3.34, Vijeo Citect 7.20 and earlier, Telemecanique Driver Pack 2.6 and earlier, Monitor Pro 7.6 and earlier, and PL7 Pro 4.5 and earlier, allows local users, and possibly remote attackers, to execute arbitrary code via an unspecified system parameter.

Nov 4, 2011
7.2
CVE-2017-9966HIGH

A privilege escalation vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2.0 and prior. By replacing certain files, an unauthorized user can obtain system privileges and the inserted code would execute at an elevated privilege level.

Jan 2, 2018
7.1
CVE-2016-8354HIGH

An issue was discovered in Schneider Electric Unity PRO prior to V11.1. Unity projects can be compiled as x86 instructions and loaded onto the PLC Simulator delivered with Unity PRO. These x86 instructions are subsequently executed directly by the simulator. A specially crafted patched Unity project file can make the simulator execute malicious code by redirecting the control flow of these instructions.

Feb 13, 2017
7.0
CVE-2017-9964MEDIUM

A Path Traversal issue was discovered in Schneider Electric Pelco VideoXpert Enterprise all versions prior to 2.1. By sniffing communications, an unauthorized person can execute a directory traversal attack resulting in authentication bypass or session hijack.

Jan 2, 2018
6.9
CVE-2015-3940MEDIUM

Untrusted search path vulnerability in Schneider Electric Wonderware System Platform before 2014 R2 Patch 01 allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.

Aug 4, 2015
6.9
CVE-2014-9206MEDIUM

Stack-based buffer overflow in Device Type Manager (DTM) 3.1.6 and earlier for Schneider Electric Invensys SRD Control Valve Positioner devices 960 and 991 allows local users to gain privileges via a malformed DLL file.

Mar 14, 2015
6.9
CVE-2014-0759MEDIUM

Unquoted Windows search path vulnerability in Schneider Electric Floating License Manager 1.0.0 through 1.4.0 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character.

Feb 28, 2014
6.9
CVE-2013-2796MEDIUM

Schneider Electric Vijeo Citect 7.20 and earlier, CitectSCADA 7.20 and earlier, and PowerLogic SCADA 7.20 and earlier allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Aug 9, 2013
6.9
CVE-2021-30066MEDIUM

On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an arbitrary firmware image can be loaded because firmware signature verification (for a USB stick) can be bypassed. NOTE: this issue exists because of an incomplete fix of CVE-2017-11400.

Apr 3, 2022
6.8
CVE-2021-30061MEDIUM

On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, physically proximate attackers can execute code via a crafted file on a USB stick.

Apr 3, 2022
6.8
CVE-2017-8371MEDIUM

Schneider Electric StruxureWare Data Center Expert before 7.4.0 uses cleartext RAM storage for passwords, which might allow remote attackers to obtain sensitive information via unspecified vectors.

Apr 30, 2017
6.8
CVE-2015-8561MEDIUM

The F1BookView ActiveX control in F1 Bookview in Schneider Electric ProClima before 6.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted integer value to the (1) AttachToSS, (2) CopyAll, (3) CopyRange, (4) CopyRangeEx, or (5) SwapTable method, a different vulnerability than CVE-2015-7918.

Dec 15, 2015
6.8
CVE-2015-7918MEDIUM

Multiple buffer overflows in the F1BookView ActiveX control in F1 Bookview in Schneider Electric ProClima before 6.2 allow remote attackers to execute arbitrary code via the (1) Attach, (2) DefinedName, (3) DefinedNameLocal, (4) ODBCPrepareEx, (5) ObjCreatePolygon, (6) SetTabbedTextEx, or (7) SetValidationRule method, a different vulnerability than CVE-2015-8561.

Dec 15, 2015
6.8
CVE-2014-0779MEDIUM

The PLC driver in ServerMain.exe in the Kepware KepServerEX 4 component in Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R2 build 71.4165, 2010 R2.1 build 71.4325, 2010 R3 build 72.4560, 2010 R3.1 build 72.4644, 2013 R1 build 73.4729, 2013 R1.1 build 73.4832, 2013 R1.1a build 73.4903, 2013 R1.2 build 73.4955, and 2013 R2 build 74.5094 allows remote attackers to cause a denial of service (application crash) via a crafted OPF file (aka project file).

Mar 14, 2014
6.8
CVE-2014-0774MEDIUM

Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 - 3.35, TLXCDSTOFS33 - 3.35, TLXCDLUOFS33 - 3.35, TLXCDLTOFS33 - 3.35, and TLXCDLFOFS33 - 3.35 allows local users to gain privileges via vectors involving a malformed configuration file.

Feb 28, 2014
6.8
CVE-2013-0663MEDIUM

Cross-site request forgery (CSRF) vulnerability on the Schneider Electric Quantum 140NOE77111, 140NOE77101, and 140NWM10000; M340 BMXNOC0401, BMXNOE0100x, and BMXNOE011xx; and Premium TSXETY4103, TSXETY5103, and TSXWMY100 PLC modules allows remote attackers to hijack the authentication of arbitrary users for requests that execute commands, as demonstrated by modifying HTTP credentials.

Apr 4, 2013
6.8
CVE-2018-7522MEDIUM

In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, when a system call is made, registers are stored to a fixed memory location. Modifying the data in this location could allow attackers to gain supervisor-level access and control system states.

May 4, 2018
6.7
CVE-2017-9969MEDIUM

An information disclosure vulnerability exists in Schneider Electric's IGSS Mobile application version 3.01 and prior. Passwords are stored in clear text in the configuration which can result in exposure of sensitive information.

Feb 12, 2018
6.7
CVE-2017-7907MEDIUM

An Improper XML Parser Configuration issue was discovered in Schneider Electric Wonderware Historian Client 2014 R2 SP1 and prior. An improperly restricted XML parser (with improper restriction of XML external entity reference, or XXE) may allow an attacker to enter malicious input through the application which could cause a denial of service or disclose file contents from a server or connected network.

May 19, 2017
6.6
CVE-2013-0687MEDIUM

The installer routine in Schneider Electric MiCOM S1 Studio uses world-writable permissions for executable files, which allows local users to modify the service or the configuration files, and consequently gain privileges or trigger incorrect protective-relay operation, via a Trojan horse executable file.

Apr 18, 2013
6.6
CVE-2018-7770MEDIUM

The vulnerability exists within processing of sendmail.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The applet allows callers to select arbitrary files to send to an arbitrary email address.

Jul 3, 2018
6.5
CVE-2018-7758MEDIUM

A denial of service vulnerability exists in Schneider Electric's MiCOM Px4x (P540 range excluded) with legacy Ethernet board, MiCOM P540D Range with Legacy Ethernet Board, and MiCOM Px4x Rejuvenated could lose network communication in case of TCP/IP open requests on port 20000 (DNP3oE) if an older TCI/IP session is still open with identical IP address and port number.

Apr 18, 2018
6.5
CVE-2017-7971MEDIUM

A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the use of outdated cipher suites and improper verification of peer SSL Certificate.

Sep 26, 2017
6.5
CVE-2017-7970MEDIUM

A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the ability to specify Arbitrary Server Target Nodes in connection requests to the Secure Gateway and Server components.

Sep 26, 2017
6.5
CVE-2017-6030MEDIUM

A Predictable Value Range from Previous Values issue was discovered in Schneider Electric Modicon PLCs Modicon M221, firmware versions prior to Version 1.5.0.0, Modicon M241, firmware versions prior to Version 4.0.5.11, and Modicon M251, firmware versions prior to Version 4.0.5.11. The affected products generate insufficiently random TCP initial sequence numbers that may allow an attacker to predict the numbers from previous values. This may allow an attacker to spoof or disrupt TCP connections.

Jun 30, 2017
6.5
CVE-2014-5413MEDIUM

Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 uses the MD5 algorithm for an X.509 certificate, which makes it easier for remote attackers to spoof servers via a cryptographic attack against this algorithm.

Sep 18, 2014
6.4
CVE-2014-5412MEDIUM

Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allows remote attackers to read database records by leveraging access to the guest account.

Sep 18, 2014
6.4
CVE-2018-7795MEDIUM

A Cross Protocol Injection vulnerability exists in Schneider Electric's PowerLogic (PM5560 prior to FW version 2.5.4) product. The vulnerability makes the product susceptible to cross site scripting attack on its web browser. User inputs can be manipulated to cause execution of java script code.

Aug 29, 2018
6.1
CVE-2018-7786MEDIUM

In Schneider Electric U.motion Builder software versions prior to v1.3.4, a cross site scripting (XSS) vulnerability exists which could allow injection of malicious scripts.

Jul 3, 2018
6.1
CVE-2017-5157MEDIUM

An issue was discovered in Schneider Electric homeLYnk Controller, LSS100100, all versions prior to V1.5.0. The homeLYnk controller is susceptible to a cross-site scripting attack. User inputs can be manipulated to cause execution of JavaScript code.

Feb 13, 2017
6.1
CVE-2016-4513MEDIUM

Cross-site scripting (XSS) vulnerability in the Schneider Electric PowerLogic PM8ECC module before 2.651 for PowerMeter 800 devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Jun 26, 2016
6.1
CVE-2012-0930MEDIUM

Cross-site scripting (XSS) vulnerability in Schneider Electric Modicon Quantum PLC allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Jan 28, 2012
6.1
CVE-2017-9968MEDIUM

A security misconfiguration vulnerability exists in Schneider Electric's IGSS Mobile application versions 3.01 and prior in which a lack of certificate pinning during the TLS/SSL connection establishing process can result in a man-in-the-middle attack.

Feb 12, 2018
5.9
CVE-2017-9965MEDIUM

An exposure of sensitive information vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2.0 and prior. Using a directory traversal attack, an unauthorized person can view web server files.

Jan 2, 2018
5.8
CVE-2015-3963MEDIUM

Wind River VxWorks before 5.5.1, 6.5.x through 6.7.x before 6.7.1.1, 6.8.x before 6.8.3, 6.9.x before 6.9.4.4, and 7.x before 7 ipnet_coreip 1.2.2.0, as used on Schneider Electric SAGE RTU devices before J2 and other devices, does not properly generate TCP initial sequence number (ISN) values, which makes it easier for remote attackers to spoof TCP sessions by predicting an ISN value.

Aug 4, 2015
5.8
CVE-2021-22809MEDIUM

A CWE-125:Out-of-Bounds Read vulnerability exists that could cause unintended data disclosure when a malicious *.gd1 configuration file is loaded into the GUIcon tool. Affected Product: Eurotherm by Schneider Electric GUIcon Version 2.0 (Build 683.003) and prior

Jan 28, 2022
5.5
CVE-2017-9959MEDIUM

A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system accepts reboot in session from unauthenticated users, supporting a denial of service condition.

Sep 26, 2017
5.5
CVE-2017-7972MEDIUM

A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the ability to escape out of remote PowerSCADA Anywhere applications and launch other processes.

Sep 26, 2017
5.5
CVE-2017-7967MEDIUM

All versions of VAMPSET software produced by Schneider Electric, prior to V2.2.189, are susceptible to a memory corruption vulnerability when a corrupted vf2 file is used. This vulnerability causes the software to halt or not start when trying to open the corrupted file. This vulnerability occurs when fill settings are intentionally malformed and is opened in a standalone state, without connection to a protection relay. This attack is not considered to be remotely exploitable. This vulnerability has no effect on the operation of the protection relay to which VAMPSET is connected. As Windows operating system remains operational and VAMPSET responds, it is able to be shut down through its normal closing protocol.

May 9, 2017
5.5
CVE-2015-6462MEDIUM

Reflected Cross-Site Scripting (nonpersistent) allows an attacker to craft a specific URL, which contains Java script that will be executed on the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H PLC client browser.

Mar 21, 2019
5.4
CVE-2015-6461MEDIUM

Remote file inclusion allows an attacker to craft a specific URL referencing the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H PLC web server, which, when launched, will result in the browser redirecting to a remote file via a Java script loaded with the web page.

Mar 21, 2019
5.4
CVE-2018-7787MEDIUM

In Schneider Electric U.motion Builder software versions prior to v1.3.4, this vulnerability is due to improper validation of input of context parameter in HTTP GET request.

Jul 3, 2018
5.3
CVE-2018-7244MEDIUM

An information disclosure vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to obtain sensitive device information if network access was obtained.

Apr 18, 2018
5.3
CVE-2018-7227MEDIUM

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow retrieving of specially crafted URLs without authentication that can reveal sensitive information to an attacker.

Mar 9, 2018
5.3
CVE-2017-9960MEDIUM

An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system response to error provides more information than should be available to an unauthenticated user.

Sep 26, 2017
5.3
CVE-2017-6032MEDIUM

A Violation of Secure Design Principles issue was discovered in Schneider Electric Modicon Modbus Protocol. The Modicon Modbus protocol has a session-related weakness making it susceptible to brute-force attacks.

Jun 30, 2017
5.3
CVE-2017-5160MEDIUM

An Inadequate Encryption Strength issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The software will connect via Transport Layer Security without verifying the peer's SSL certificate properly.

Apr 20, 2017
5.3
CVE-2016-8367MEDIUM

An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all versions, Magelis GTU Universal Panel, all versions, Magelis STO5xx and STU Small panels, all versions, Magelis XBT GH Advanced Hand-held Panels, all versions, Magelis XBT GK Advanced Touchscreen Panels with Keyboard, all versions, Magelis XBT GT Advanced Touchscreen Panels, all versions, and Magelis XBT GTW Advanced Open Touchscreen Panels (Windows XPe). An attacker can open multiple connections to a targeted web server and keep connections open preventing new connections from being made, rendering the web server unavailable during an attack.

Feb 13, 2017
5.3
CVE-2015-6485MEDIUM

Schneider Electric Telvent Sage 2300 RTUs with firmware before C3413-500-S01, and LANDAC II-2, Sage 1410, Sage 1430, Sage 1450, Sage 2400, and Sage 3030M RTUs with firmware before C3414-500-S02J2, allow remote attackers to obtain sensitive information from device memory by reading a padding field of an Ethernet packet.

Mar 12, 2016
5.3
CVE-2015-3962MEDIUM

Schneider Electric StruxureWare Building Expert MPM before 2.15 does not use encryption for the client-server data stream, which allows remote attackers to discover credentials by sniffing the network.

Sep 18, 2015
5.0
CVE-2015-0997MEDIUM

Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 provide an HMI user interface that lists all valid usernames, which makes it easier for remote attackers to obtain access via a brute-force password-guessing attack.

Mar 29, 2015
5.0
CVE-2014-0789MEDIUM

Multiple buffer overflows in the OPC Automation 2.0 Server Object ActiveX control in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 3.5 and earlier, TLXCDSTOFS33 3.5 and earlier, TLXCDLUOFS33 3.5 and earlier, TLXCDLTOFS33 3.5 and earlier, and TLXCDLFOFS33 3.5 and earlier allow remote attackers to cause a denial of service via long arguments to unspecified functions.

Apr 4, 2014
5.0
CVE-2013-6143MEDIUM

The Schneider Electric Telvent SAGE 3030 RTU with firmware C3413-500-001D3_P4 and C3413-500-001F0_PB allows remote attackers to cause a denial of service (temporary outage and CPU consumption) via malformed DNP3 traffic.

Jan 31, 2014
5.0
CVE-2013-2763MEDIUM

The Schneider Electric M340 PLC modules allow remote attackers to cause a denial of service (resource consumption) via unspecified vectors. NOTE: the vendor reportedly disputes this issue because it "could not be duplicated" and "an attacker could not remotely exploit this observed behavior to deny PLC control functions.

Apr 4, 2013
5.0
CVE-2011-4036MEDIUM

Directory traversal vulnerability in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier allows remote attackers to read arbitrary files via unspecified vectors.

Dec 2, 2011
5.0
CVE-2018-7824MEDIUM

An Externally Controlled Reference to a Resource (CWE-610) vulnerability exists in Schneider Electric Modbus Serial Driver (For 64-bit Windows OS:V3.17 IE 37 and prior , For 32-bit Windows OS:V2.17 IE 27 and prior, and as part of the Driver Suite version:V14.12 and prior) which could allow write access to system files available only to users with SYSTEM privilege or other important user files.

May 22, 2019
4.9
CVE-2014-5411MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

Sep 18, 2014
4.9
CVE-2020-7520MEDIUM

A CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability exists in Schneider Electric Software Update (SESU), V2.4.0 and prior, which could cause execution of malicious code on the victim's machine. In order to exploit this vulnerability, an attacker requires privileged access on the engineering workstation to modify a Windows registry key which would divert all traffic updates to go through a server in the attacker's possession. A man-in-the-middle attack is then used to complete the exploit.

Jul 23, 2020
4.7
CVE-2011-5163MEDIUM

Buffer overflow in an unspecified third-party component in the Batch module for Schneider Electric CitectSCADA before 7.20 and Mitsubishi MX4 SCADA before 7.20 allows local users to execute arbitrary code via a long string in a login sequence.

Sep 15, 2012
4.6
CVE-2014-8390MEDIUM

Multiple buffer overflows in Schneider Electric VAMPSET before 2.2.168 allow local users to gain privileges via malformed disturbance-recording data in a (1) CFG or (2) DAT file.

Apr 3, 2015
4.4
CVE-2018-7776MEDIUM

The vulnerability exists within error.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. System information is returned to the attacker that contains sensitive data.

Jul 3, 2018
4.3
CVE-2018-7764MEDIUM

The vulnerability exists within runscript.php applet in Schneider Electric U.motion Builder software versions prior to v1.3.4. There is a directory traversal vulnerability in the processing of the 's' parameter of the applet.

Jul 3, 2018
4.3
CVE-2018-7763MEDIUM

The vulnerability exists within css.inc.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The 'css' parameter contains a directory traversal vulnerability.

Jul 3, 2018
4.3
CVE-2013-6142MEDIUM

DNP3Driver.exe in the DNP3 driver in Schneider Electric ClearSCADA 2010 R2 through 2010 R3.1 and SCADA Expert ClearSCADA 2013 R1 through 2013 R1.2 allows remote attackers to cause a denial of service (resource consumption) via IP packets containing errors that trigger event-journal messages.

Jan 15, 2014
4.3
CVE-2012-1990MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in Schneider Electric Kerweb before 3.0.1 and Kerwin before 6.0.1 allow remote attackers to inject arbitrary web script or HTML via (1) the evtvariablename parameter in an evts.xml action to kw.dll, (2) unspecified search fields, or (3) unspecified content-display fields.

May 22, 2012
4.3
CVE-2011-4263MEDIUM

Cross-site scripting (XSS) vulnerability in Schneider Electric PowerChute Business Edition before 8.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Dec 7, 2011
4.3
CVE-2011-4035MEDIUM

Cross-site scripting (XSS) vulnerability in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Dec 2, 2011
4.3
CVE-2011-4033MEDIUM

Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier, allows remote attackers to cause a denial of service via unspecified vectors.

Dec 2, 2011
4.3
CVE-2017-9637MEDIUM

Schneider Electric Ampla MES 6.4 provides capability to interact with data from third party databases. When connectivity to those databases is configured to use a SQL user name and password, an attacker may be able to sniff details from the connection string. Schneider Electric recommends that users of Ampla MES versions 6.4 and prior should upgrade to Ampla MES version 6.5 as soon as possible.

May 18, 2018
4.1
CVE-2014-5407MEDIUM

Multiple stack-based buffer overflows in Schneider Electric VAMPSET 2.2.136 and earlier allow local users to cause a denial of service (application halt) via a malformed (1) setting file or (2) disturbance recording file.

Sep 15, 2014
4.1
CVE-2013-2761MEDIUM

The Schneider Electric M340 BMXNOE01xx and BMXP3420xx PLC modules allow remote authenticated users to cause a denial of service (module crash) via crafted FTP traffic, as demonstrated by the FileZilla FTP client.

Apr 4, 2013
4.0
CVE-2017-9635LOW

Schneider Electric Ampla MES 6.4 provides capability to configure users and their privileges. When Ampla MES users are configured to use Simple Security, a weakness in the password hashing algorithm could be exploited to reverse the user's password. Schneider Electric recommends that users of Ampla MES versions 6.4 and prior should upgrade to Ampla MES version 6.5 as soon as possible.

May 18, 2018
3.9
CVE-2021-22799LOW

A CWE-331: Insufficient Entropy vulnerability exists that could cause unintended connection from an internal network to an external network when an attacker manages to decrypt the SESU proxy password from the registry. Affected Product: Schneider Electric Software Update, V2.3.0 through V2.5.1

Jan 28, 2022
3.8
CVE-2015-0998LOW

Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 transmit cleartext credentials, which allows remote attackers to obtain sensitive information by sniffing the network.

Mar 29, 2015
3.3
CVE-2015-0999LOW

Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 store cleartext OPC User credentials in a configuration file, which allows local users to obtain sensitive information by reading this file.

Mar 29, 2015
2.1
CVE-2015-0996LOW

Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 rely on a hardcoded cleartext password to control read access to Project files and Project Configuration files, which makes it easier for local users to obtain sensitive information by discovering this password.

Mar 29, 2015
2.1
CVE-2014-5398LOW

Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Aug 28, 2014
2.1
CVE-2014-2381LOW

Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows local users to obtain sensitive information by reading a credential file.

Aug 28, 2014
2.1
CVE-2015-1009LOW

Schneider Electric InduSoft Web Studio before 7.1.3.5 Patch 5 and Wonderware InTouch Machine Edition through 7.1 SP3 Patch 4 use cleartext for project-window password storage, which allows local users to obtain sensitive information by reading a file.

Aug 1, 2015
1.7
CVE ID ⇅Severity ↓CVSS ⇅DescriptionPublished ⇅
CVE-2016-8352CRITICAL
10.0
An issue was discovered in Schneider Electric ConneXium firewalls TCSEFEC23F3F20 all versions, TCSEF…Feb 13, 2017›
CVE-2022-42971CRITICAL
9.8
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause rem…Feb 1, 2023›
CVE-2022-42970CRITICAL
9.8
A CWE-306: Missing Authentication for Critical Function The software does not perform any authentica…Feb 1, 2023›
CVE-2021-30064CRITICAL
9.8
On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and …Apr 3, 2022›
CVE-2018-7791CRITICAL
9.8
A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M…Aug 29, 2018›
CVE-2018-7790CRITICAL
9.8
An Information Management Error vulnerability exists in Schneider Electric's Modicon M221 product (a…Aug 29, 2018›
CVE-2018-7785CRITICAL
9.8
In Schneider Electric U.motion Builder software versions prior to v1.3.4, a remote command injection…Jul 3, 2018›
CVE-2018-7784CRITICAL
9.8
In Schneider Electric U.motion Builder software versions prior to v1.3.4, this exploit occurs when t…Jul 3, 2018›
CVE-2018-7780CRITICAL
9.8
In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior t…Jul 3, 2018›
CVE-2018-7778CRITICAL
9.8
In Schneider Electric Evlink Charging Station versions prior to v3.2.0-12_v1, the Web Interface has …Jul 3, 2018›
CVE-2018-7761CRITICAL
9.8
A vulnerability exists in the HTTP request parser in Schneider Electric's Modicon M340, Modicon Prem…Apr 18, 2018›
CVE-2018-7760CRITICAL
9.8
An authorization bypass vulnerability exists in Schneider Electric's Modicon M340, Modicon Premium, …Apr 18, 2018›
CVE-2018-7246CRITICAL
9.8
A cleartext transmission of sensitive information vulnerability exists in Schneider Electric's 66074…Apr 18, 2018›
CVE-2018-7243CRITICAL
9.8
An authorization bypass vulnerability exists In Schneider Electric's 66074 MGE Network Management Ca…Apr 18, 2018›
CVE-2018-7242CRITICAL
9.8
Vulnerable hash algorithms exists in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon …Apr 18, 2018›
CVE-2018-7241CRITICAL
9.8
Hard coded accounts exist in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, an…Apr 18, 2018›
CVE-2018-7238CRITICAL
9.8
A buffer overflow vulnerability exist in the web-based GUI of Schneider Electric's Pelco Sarix Profe…Mar 9, 2018›
CVE-2018-7233CRITICAL
9.8
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions pri…Mar 9, 2018›
CVE-2018-7232CRITICAL
9.8
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions pri…Mar 9, 2018›
CVE-2018-7231CRITICAL
9.8
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions pri…Mar 9, 2018›
CVE-2018-7229CRITICAL
9.8
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions pri…Mar 9, 2018›
CVE-2018-7228CRITICAL
9.8
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions pri…Mar 9, 2018›
CVE-2017-14024CRITICAL
9.8
A Stack-based Buffer Overflow issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP…Nov 13, 2017›
CVE-2017-13997CRITICAL
9.8
A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft W…Oct 3, 2017›
CVE-2017-9957CRITICAL
9.8
A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in…Sep 26, 2017›
CVE-2017-7974CRITICAL
9.8
A path traversal information disclosure vulnerability exists in Schneider Electric's U.motion Builde…Sep 26, 2017›
CVE-2017-7973CRITICAL
9.8
A SQL injection vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.…Sep 26, 2017›
CVE-2017-9629CRITICAL
9.8
A Stack-Based Buffer Overflow issue was discovered in Schneider Electric Wonderware ArchestrA Logger…Jul 7, 2017›
CVE-2017-6034CRITICAL
9.8
An Authentication Bypass by Capture-Replay issue was discovered in Schneider Electric Modicon Modbus…Jun 30, 2017›
CVE-2017-6028CRITICAL
9.8
An Insufficiently Protected Credentials issue was discovered in Schneider Electric Modicon PLCs Modi…Jun 30, 2017›
CVE-2017-5158CRITICAL
9.8
An Information Exposure issue was discovered in Schneider Electric Wonderware InTouch Access Anywher…Apr 20, 2017›
CVE-2017-7689CRITICAL
9.8
A Command Injection vulnerability in Schneider Electric homeLYnk Controller exists in all versions b…Apr 11, 2017›
CVE-2017-7575CRITICAL
9.8
Schneider Electric Modicon TM221CE16R 1.3.3.3 devices allow remote attackers to discover the applica…Apr 6, 2017›
CVE-2017-7574CRITICAL
9.8
Schneider Electric SoMachine Basic 1.4 SP1 and Schneider Electric Modicon TM221CE16R 1.3.3.3 devices…Apr 6, 2017›
CVE-2017-5178CRITICAL
9.8
An issue was discovered in Schneider Electric Tableau Server/Desktop Versions 7.0 to 10.1.3 in Wonde…Mar 8, 2017›
CVE-2016-5818CRITICAL
9.8
An issue was discovered in Schneider Electric PowerLogic PM8ECC device 2.651 and older. Undocumented…Feb 13, 2017›
CVE-2016-5815CRITICAL
9.8
An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX se…Feb 13, 2017›
CVE-2016-4520CRITICAL
9.8
Schneider Electric Pelco Digital Sentry Video Management System with firmware before 7.14 has hardco…Jul 15, 2016›
CVE-2012-0931CRITICAL
9.8
Schneider Electric Modicon Quantum PLC does not perform authentication between the Unity software an…Jan 28, 2012›
CVE-2018-7245CRITICAL
9.1
An improper authorization vulnerability exists In Schneider Electric's 66074 MGE Network Management …Apr 18, 2018›
CVE-2018-7237CRITICAL
9.1
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions pri…Mar 9, 2018›
CVE-2017-6026CRITICAL
9.1
A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modico…Jun 30, 2017›
CVE-2015-7937HIGH
10.0
Stack-based buffer overflow in the GoAhead Web Server on Schneider Electric Modicon M340 PLC BMXNOx …Dec 21, 2015›
CVE-2014-9198HIGH
10.0
The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 …Jan 27, 2015›
CVE-2014-9197HIGH
10.0
The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.ja…Jan 27, 2015›
CVE-2014-9190HIGH
10.0
Stack-based buffer overflow in Schneider Electric Wonderware InTouch Access Anywhere Server 10.6 and…Jan 10, 2015›
CVE-2014-9188HIGH
10.0
Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 all…Dec 27, 2014›
CVE-2014-8511HIGH
10.0
Buffer overflow in an ActiveX control in Atx45.ocx in Schneider Electric ProClima before 6.1.7 allow…Dec 27, 2014›
CVE-2014-0754HIGH
10.0
Directory traversal vulnerability in SchneiderWEB on Schneider Electric Modicon PLC Ethernet modules…Oct 3, 2014›
CVE-2013-2762HIGH
10.0
The Schneider Electric Magelis XBT HMI controller has a default password for authentication of confi…Apr 4, 2013›
CVE-2013-0658HIGH
10.0
Heap-based buffer overflow in RFManagerService.exe in Schneider Electric Accutech Manager 2.00.1 and…Feb 15, 2013›
CVE-2013-0657HIGH
10.0
Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA System (IGSS) 10 and e…Jan 21, 2013›
CVE-2011-4861HIGH
10.0
The modbus_125_handler function in the Schneider Electric Quantum Ethernet Module on the NOE 771 dev…Dec 17, 2011›
CVE-2011-4860HIGH
10.0
The ComputePassword function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device…Dec 17, 2011›
CVE-2011-4859HIGH
10.0
The Schneider Electric Quantum Ethernet Module, as used in the Quantum 140NOE771* and 140CPU65* modu…Dec 17, 2011›
CVE-2013-0662HIGH
9.3
Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.…Apr 1, 2014›
CVE-2013-2782HIGH
9.3
Schneider Electric Trio J-Series License Free Ethernet Radio with firmware 3.6.0 through 3.6.3 uses …Aug 28, 2013›
CVE-2013-0655HIGH
9.3
The client in Schneider Electric Software Update (SESU) Utility 1.0.x and 1.1.x does not ensure that…Jan 21, 2013›
CVE-2011-4034HIGH
9.3
Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historia…Dec 2, 2011›
CVE-2018-7782HIGH
8.8
In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior t…Jul 3, 2018›
CVE-2018-7781HIGH
8.8
In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior t…Jul 3, 2018›
CVE-2018-7777HIGH
8.8
The vulnerability is due to insufficient handling of update_file request parameter on update_module.…Jul 3, 2018›
CVE-2018-7774HIGH
8.8
The vulnerability exists within processing of localize.php in Schneider Electric U.motion Builder so…Jul 3, 2018›
CVE-2018-7773HIGH
8.8
The vulnerability exists within processing of nfcserver.php in Schneider Electric U.motion Builder s…Jul 3, 2018›
CVE-2018-7772HIGH
8.8
The vulnerability exists within processing of applets which are exposed on the web service in Schnei…Jul 3, 2018›
CVE-2018-7769HIGH
8.8
The vulnerability exists within processing of xmlserver.php in Schneider Electric U.motion Builder s…Jul 3, 2018›
CVE-2018-7768HIGH
8.8
The vulnerability exists within processing of loadtemplate.php in Schneider Electric U.motion Builde…Jul 3, 2018›
CVE-2018-7767HIGH
8.8
The vulnerability exists within processing of editobject.php in Schneider Electric U.motion Builder …Jul 3, 2018›
CVE-2018-7766HIGH
8.8
The vulnerability exists within processing of track_getdata.php in Schneider Electric U.motion Build…Jul 3, 2018›
CVE-2018-7765HIGH
8.8
The vulnerability exists within processing of track_import_export.php in Schneider Electric U.motion…Jul 3, 2018›
CVE-2018-7240HIGH
8.8
A vulnerability exists in Schneider Electric's Modicon Quantum in all versions of the communication …Apr 18, 2018›
CVE-2018-7230HIGH
8.8
A XML external entity (XXE) vulnerability exists in the import.cgi of the web interface component of…Mar 9, 2018›
CVE-2017-7969HIGH
8.8
A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Elect…Sep 26, 2017›
CVE-2017-7966HIGH
8.8
A DLL Hijacking vulnerability in the programming software in Schneider Electric's SoMachine HVAC v2.…Jun 7, 2017›
CVE-2017-5156HIGH
8.8
A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access An…Apr 20, 2017›
CVE-2016-5809HIGH
8.8
An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX se…Feb 13, 2017›
CVE-2017-9627HIGH
8.6
An Uncontrolled Resource Consumption issue was discovered in Schneider Electric Wonderware ArchestrA…Jul 7, 2017›
CVE-2013-0664HIGH
8.5
The FactoryCast service on the Schneider Electric Quantum 140NOE77111 and 140NWM10000, M340 BMXNOE01…Apr 4, 2013›
CVE-2018-8872HIGH
8.1
In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, system calls read d…May 4, 2018›
CVE-2018-7236HIGH
8.1
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions pri…Mar 9, 2018›
CVE-2017-9963HIGH
8.1
A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Elect…Feb 12, 2018›
CVE-2018-7771HIGH
8.0
The vulnerability exists within processing of editscript.php in Schneider Electric U.motion Builder …Jul 3, 2018›
CVE-2022-42973HIGH
7.8
A CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause local privilege escal…Feb 1, 2023›
CVE-2022-42972HIGH
7.8
A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cau…Feb 1, 2023›
CVE-2021-22808HIGH
7.8
A CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution when a mali…Jan 28, 2022›
CVE-2021-22807HIGH
7.8
A CWE-787: Out-of-bounds Write vulnerability exists that could cause arbitrary code execution when a…Jan 28, 2022›
CVE-2020-7523HIGH
7.8
Improper Privilege Management vulnerability exists in Schneider Electric Modbus Serial Driver (see s…Aug 31, 2020›
CVE-2018-7815HIGH
7.8
A Type Confusion (CWE-843) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold…Feb 6, 2019›
CVE-2018-7814HIGH
7.8
A Stack-based Buffer Overflow (CWE-121) vulnerability exists in Eurotherm by Schneider Electric GUIc…Feb 6, 2019›
CVE-2018-7813HIGH
7.8
A Type Confusion (CWE-843) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold…Feb 6, 2019›
CVE-2018-7799HIGH
7.8
A DLL hijacking vulnerability exists in Schneider Electric Software Update (SESU), all versions prio…Nov 2, 2018›
CVE-2018-7239HIGH
7.8
A DLL hijacking vulnerability exists in Schneider Electric's SoMove Software and associated DTM soft…Mar 9, 2018›
CVE-2017-9967HIGH
7.8
A security misconfiguration vulnerability exists in Schneider Electric's IGSS SCADA Software version…Feb 12, 2018›
CVE-2017-9961HIGH
7.8
A vulnerability exists in Schneider Electric's Pro-Face GP Pro EX version 4.07.000 that allows an at…Sep 26, 2017›
CVE-2017-9958HIGH
7.8
An improper access control vulnerability exists in Schneider Electric's U.motion Builder software ve…Sep 26, 2017›
CVE-2017-7968HIGH
7.8
An Incorrect Default Permissions issue was discovered in Schneider Electric Wonderware InduSoft Web …May 19, 2017›
CVE-2017-6033HIGH
7.8
A DLL Hijacking issue was discovered in Schneider Electric Interactive Graphical SCADA System (IGSS)…Apr 7, 2017›
CVE-2014-2380HIGH
7.8
Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encrypti…Aug 28, 2014›
CVE-2013-2824HIGH
7.8
Schneider Electric StruxureWare SCADA Expert Vijeo Citect 7.40, Vijeo Citect 7.20 through 7.30SP1, C…Feb 26, 2014›
CVE-2015-3977HIGH
7.7
Buffer overflow in Schneider Electric IMT25 Magnetic Flow DTM before 1.500.004 for the HART Protocol…Nov 15, 2015›
CVE-2021-30065HIGH
7.5
On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and …Apr 3, 2022›
CVE-2021-30063HIGH
7.5
On Schneider Electric ConneXium Tofino OPCLSM TCSEFM0000 before 03.23 and Belden Tofino Xenon Securi…Apr 3, 2022›
CVE-2021-30062HIGH
7.5
On Schneider Electric ConneXium Tofino OPCLSM TCSEFM0000 before 03.23 and Belden Tofino Xenon Securi…Apr 3, 2022›
CVE-2020-7524HIGH
7.5
Out-of-bounds Write vulnerability exists in Modicon M218 Logic Controller (V5.0.0.7 and prior) which…Aug 31, 2020›
CVE-2019-13537HIGH
7.5
The IEC870IP driver for AVEVA’s Vijeo Citect and Citect SCADA and Schneider Electric’s Power SCADA O…Jan 14, 2020›
CVE-2018-7792HIGH
7.5
A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M…Aug 29, 2018›
CVE-2018-7789HIGH
7.5
An Improper Check for Unusual or Exceptional Conditions vulnerability exists in Schneider Electric's…Aug 29, 2018›
CVE-2018-7783HIGH
7.5
Schneider Electric SoMachine Basic prior to v1.6 SP1 suffers from an XML External Entity (XXE) vulne…Jul 3, 2018›
CVE-2018-7779HIGH
7.5
In Schneider Electric Wiser for KNX V2.1.0 and prior, homeLYnk V2.0.1 and prior; and spaceLYnk V2.1.…Jul 3, 2018›
CVE-2017-6021HIGH
7.5
In Schneider Electric ClearSCADA 2014 R1 (build 75.5210) and prior, 2014 R1.1 (build 75.5387) and pr…May 14, 2018›
CVE-2018-7762HIGH
7.5
A vulnerability exists in the web services to process SOAP requests in Schneider Electric's Modicon …Apr 18, 2018›
CVE-2018-7759HIGH
7.5
A buffer overflow vulnerability exists in Schneider Electric's Modicon M340, Modicon Premium, Modico…Apr 18, 2018›
CVE-2018-7235HIGH
7.5
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions pri…Mar 9, 2018›
CVE-2018-7234HIGH
7.5
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions pri…Mar 9, 2018›
CVE-2017-9962HIGH
7.5
Schneider Electric's ClearSCADA versions released prior to August 2017 are susceptible to a memory a…Sep 26, 2017›
CVE-2017-9631HIGH
7.5
A Null Pointer Dereference issue was discovered in Schneider Electric Wonderware ArchestrA Logger, v…Jul 7, 2017›
CVE-2017-6017HIGH
7.5
A Resource Exhaustion issue was discovered in Schneider Electric Modicon M340 PLC BMXNOC0401, BMXNOE…Jun 30, 2017›
CVE-2017-6019HIGH
7.5
An issue was discovered in Schneider Electric Conext ComBox, model 865-1058, all firmware versions p…Apr 7, 2017›
CVE-2016-8374HIGH
7.5
An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all v…Feb 13, 2017›
CVE-2015-7375HIGH
7.5
Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code …Sep 25, 2015›
CVE-2015-7374HIGH
7.5
The Remote Agent component in Schneider Electric InduSoft Web Studio before 8.0 allows remote attack…Sep 25, 2015›
CVE-2015-0982HIGH
7.5
Buffer overflow in an unspecified DLL in Schneider Electric Pelco DS-NVs before 7.8.90 allows remote…Mar 14, 2015›
CVE-2014-9200HIGH
7.5
Stack-based buffer overflow in an unspecified DLL file in a DTM development kit in Schneider Electri…Feb 1, 2015›
CVE-2014-8514HIGH
7.5
Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 all…Dec 27, 2014›
CVE-2014-8513HIGH
7.5
Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 all…Dec 27, 2014›
CVE-2014-8512HIGH
7.5
Buffer overflow in an ActiveX control in Atx45.ocx in Schneider Electric ProClima before 6.1.7 allow…Dec 27, 2014›
CVE-2014-5399HIGH
7.5
SQL injection vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1…Aug 28, 2014›
CVE-2014-5397HIGH
7.5
Cross-site scripting (XSS) vulnerability in Schneider Electric Wonderware Information Server (WIS) P…Aug 28, 2014›
CVE-2012-0929HIGH
7.5
Multiple buffer overflows in Schneider Electric Modicon Quantum PLC allow remote attackers to cause …Jan 28, 2012›
CVE-2019-6834HIGH
7.3
A CWE-502: Deserialization of Untrusted Data vulnerability exists which could allow an attacker to e…Apr 13, 2022›
CVE-2015-1014HIGH
7.3
A successful exploit of these vulnerabilities requires the local user to load a crafted DLL file in …Mar 25, 2019›
CVE-2017-9956HIGH
7.3
An authentication bypass vulnerability exists in Schneider Electric's U.motion Builder software vers…Sep 26, 2017›
CVE-2017-7965HIGH
7.3
A buffer overflow vulnerability exists in Programming Software executable AlTracePrint.exe, in Schne…Jun 7, 2017›
CVE-2017-5155HIGH
7.3
An issue was discovered in Schneider Electric Wonderware Historian 2014 R2 SP1 P01 and earlier. Wond…Feb 13, 2017›
CVE-2016-4529HIGH
7.3
An unspecified ActiveX control in Schneider Electric SoMachine HVAC Programming Software for M171/M1…Jul 15, 2016›
CVE-2017-9970HIGH
7.2
A remote code execution vulnerability exists in Schneider Electric's StruxureOn Gateway versions 1.1…Feb 12, 2018›
CVE-2016-2278HIGH
7.2
Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.…Mar 2, 2016›
CVE-2011-3330HIGH
7.2
Buffer overflow in the UnitelWay Windows Device Driver, as used in Schneider Electric Unity Pro 6 an…Nov 4, 2011›
CVE-2017-9966HIGH
7.1
A privilege escalation vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise vers…Jan 2, 2018›
CVE-2016-8354HIGH
7.0
An issue was discovered in Schneider Electric Unity PRO prior to V11.1. Unity projects can be compil…Feb 13, 2017›
CVE-2017-9964MEDIUM
6.9
A Path Traversal issue was discovered in Schneider Electric Pelco VideoXpert Enterprise all versions…Jan 2, 2018›
CVE-2015-3940MEDIUM
6.9
Untrusted search path vulnerability in Schneider Electric Wonderware System Platform before 2014 R2 …Aug 4, 2015›
CVE-2014-9206MEDIUM
6.9
Stack-based buffer overflow in Device Type Manager (DTM) 3.1.6 and earlier for Schneider Electric In…Mar 14, 2015›
CVE-2014-0759MEDIUM
6.9
Unquoted Windows search path vulnerability in Schneider Electric Floating License Manager 1.0.0 thro…Feb 28, 2014›
CVE-2013-2796MEDIUM
6.9
Schneider Electric Vijeo Citect 7.20 and earlier, CitectSCADA 7.20 and earlier, and PowerLogic SCADA…Aug 9, 2013›
CVE-2021-30066MEDIUM
6.8
On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and …Apr 3, 2022›
CVE-2021-30061MEDIUM
6.8
On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and …Apr 3, 2022›
CVE-2017-8371MEDIUM
6.8
Schneider Electric StruxureWare Data Center Expert before 7.4.0 uses cleartext RAM storage for passw…Apr 30, 2017›
CVE-2015-8561MEDIUM
6.8
The F1BookView ActiveX control in F1 Bookview in Schneider Electric ProClima before 6.2 allows remot…Dec 15, 2015›
CVE-2015-7918MEDIUM
6.8
Multiple buffer overflows in the F1BookView ActiveX control in F1 Bookview in Schneider Electric Pro…Dec 15, 2015›
CVE-2014-0779MEDIUM
6.8
The PLC driver in ServerMain.exe in the Kepware KepServerEX 4 component in Schneider Electric Struxu…Mar 14, 2014›
CVE-2014-0774MEDIUM
6.8
Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server (OFS) …Feb 28, 2014›
CVE-2013-0663MEDIUM
6.8
Cross-site request forgery (CSRF) vulnerability on the Schneider Electric Quantum 140NOE77111, 140NO…Apr 4, 2013›
CVE-2018-7522MEDIUM
6.7
In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, when a system call …May 4, 2018›
CVE-2017-9969MEDIUM
6.7
An information disclosure vulnerability exists in Schneider Electric's IGSS Mobile application versi…Feb 12, 2018›
CVE-2017-7907MEDIUM
6.6
An Improper XML Parser Configuration issue was discovered in Schneider Electric Wonderware Historian…May 19, 2017›
CVE-2013-0687MEDIUM
6.6
The installer routine in Schneider Electric MiCOM S1 Studio uses world-writable permissions for exec…Apr 18, 2013›
CVE-2018-7770MEDIUM
6.5
The vulnerability exists within processing of sendmail.php in Schneider Electric U.motion Builder so…Jul 3, 2018›
CVE-2018-7758MEDIUM
6.5
A denial of service vulnerability exists in Schneider Electric's MiCOM Px4x (P540 range excluded) wi…Apr 18, 2018›
CVE-2017-7971MEDIUM
6.5
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCAD…Sep 26, 2017›
CVE-2017-7970MEDIUM
6.5
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCAD…Sep 26, 2017›
CVE-2017-6030MEDIUM
6.5
A Predictable Value Range from Previous Values issue was discovered in Schneider Electric Modicon PL…Jun 30, 2017›
CVE-2014-5413MEDIUM
6.4
Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 uses the MD5 algorit…Sep 18, 2014›
CVE-2014-5412MEDIUM
6.4
Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allows remote attack…Sep 18, 2014›
CVE-2018-7795MEDIUM
6.1
A Cross Protocol Injection vulnerability exists in Schneider Electric's PowerLogic (PM5560 prior to …Aug 29, 2018›
CVE-2018-7786MEDIUM
6.1
In Schneider Electric U.motion Builder software versions prior to v1.3.4, a cross site scripting (XS…Jul 3, 2018›
CVE-2017-5157MEDIUM
6.1
An issue was discovered in Schneider Electric homeLYnk Controller, LSS100100, all versions prior to …Feb 13, 2017›
CVE-2016-4513MEDIUM
6.1
Cross-site scripting (XSS) vulnerability in the Schneider Electric PowerLogic PM8ECC module before 2…Jun 26, 2016›
CVE-2012-0930MEDIUM
6.1
Cross-site scripting (XSS) vulnerability in Schneider Electric Modicon Quantum PLC allows remote att…Jan 28, 2012›
CVE-2017-9968MEDIUM
5.9
A security misconfiguration vulnerability exists in Schneider Electric's IGSS Mobile application ver…Feb 12, 2018›
CVE-2017-9965MEDIUM
5.8
An exposure of sensitive information vulnerability exists in Schneider Electric's Pelco VideoXpert E…Jan 2, 2018›
CVE-2015-3963MEDIUM
5.8
Wind River VxWorks before 5.5.1, 6.5.x through 6.7.x before 6.7.1.1, 6.8.x before 6.8.3, 6.9.x befor…Aug 4, 2015›
CVE-2021-22809MEDIUM
5.5
A CWE-125:Out-of-Bounds Read vulnerability exists that could cause unintended data disclosure when a…Jan 28, 2022›
CVE-2017-9959MEDIUM
5.5
A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in…Sep 26, 2017›
CVE-2017-7972MEDIUM
5.5
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCAD…Sep 26, 2017›
CVE-2017-7967MEDIUM
5.5
All versions of VAMPSET software produced by Schneider Electric, prior to V2.2.189, are susceptible …May 9, 2017›
CVE-2015-6462MEDIUM
5.4
Reflected Cross-Site Scripting (nonpersistent) allows an attacker to craft a specific URL, which con…Mar 21, 2019›
CVE-2015-6461MEDIUM
5.4
Remote file inclusion allows an attacker to craft a specific URL referencing the Schneider Electric …Mar 21, 2019›
CVE-2018-7787MEDIUM
5.3
In Schneider Electric U.motion Builder software versions prior to v1.3.4, this vulnerability is due …Jul 3, 2018›
CVE-2018-7244MEDIUM
5.3
An information disclosure vulnerability exists In Schneider Electric's 66074 MGE Network Management …Apr 18, 2018›
CVE-2018-7227MEDIUM
5.3
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions pri…Mar 9, 2018›
CVE-2017-9960MEDIUM
5.3
An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software ver…Sep 26, 2017›
CVE-2017-6032MEDIUM
5.3
A Violation of Secure Design Principles issue was discovered in Schneider Electric Modicon Modbus Pr…Jun 30, 2017›
CVE-2017-5160MEDIUM
5.3
An Inadequate Encryption Strength issue was discovered in Schneider Electric Wonderware InTouch Acce…Apr 20, 2017›
CVE-2016-8367MEDIUM
5.3
An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all v…Feb 13, 2017›
CVE-2015-6485MEDIUM
5.3
Schneider Electric Telvent Sage 2300 RTUs with firmware before C3413-500-S01, and LANDAC II-2, Sage …Mar 12, 2016›
CVE-2015-3962MEDIUM
5.0
Schneider Electric StruxureWare Building Expert MPM before 2.15 does not use encryption for the clie…Sep 18, 2015›
CVE-2015-0997MEDIUM
5.0
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 b…Mar 29, 2015›
CVE-2014-0789MEDIUM
5.0
Multiple buffer overflows in the OPC Automation 2.0 Server Object ActiveX control in Schneider Elect…Apr 4, 2014›
CVE-2013-6143MEDIUM
5.0
The Schneider Electric Telvent SAGE 3030 RTU with firmware C3413-500-001D3_P4 and C3413-500-001F0_PB…Jan 31, 2014›
CVE-2013-2763MEDIUM
5.0
The Schneider Electric M340 PLC modules allow remote attackers to cause a denial of service (resourc…Apr 4, 2013›
CVE-2011-4036MEDIUM
5.0
Directory traversal vulnerability in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHist…Dec 2, 2011›
CVE-2018-7824MEDIUM
4.9
An Externally Controlled Reference to a Resource (CWE-610) vulnerability exists in Schneider Electri…May 22, 2019›
CVE-2014-5411MEDIUM
4.9
Multiple cross-site scripting (XSS) vulnerabilities in Schneider Electric StruxureWare SCADA Expert …Sep 18, 2014›
CVE-2020-7520MEDIUM
4.7
A CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability exists in Schneider Ele…Jul 23, 2020›
CVE-2011-5163MEDIUM
4.6
Buffer overflow in an unspecified third-party component in the Batch module for Schneider Electric C…Sep 15, 2012›
CVE-2014-8390MEDIUM
4.4
Multiple buffer overflows in Schneider Electric VAMPSET before 2.2.168 allow local users to gain pri…Apr 3, 2015›
CVE-2018-7776MEDIUM
4.3
The vulnerability exists within error.php in Schneider Electric U.motion Builder software versions p…Jul 3, 2018›
CVE-2018-7764MEDIUM
4.3
The vulnerability exists within runscript.php applet in Schneider Electric U.motion Builder software…Jul 3, 2018›
CVE-2018-7763MEDIUM
4.3
The vulnerability exists within css.inc.php in Schneider Electric U.motion Builder software versions…Jul 3, 2018›
CVE-2013-6142MEDIUM
4.3
DNP3Driver.exe in the DNP3 driver in Schneider Electric ClearSCADA 2010 R2 through 2010 R3.1 and SCA…Jan 15, 2014›
CVE-2012-1990MEDIUM
4.3
Multiple cross-site scripting (XSS) vulnerabilities in Schneider Electric Kerweb before 3.0.1 and Ke…May 22, 2012›
CVE-2011-4263MEDIUM
4.3
Cross-site scripting (XSS) vulnerability in Schneider Electric PowerChute Business Edition before 8.…Dec 7, 2011›
CVE-2011-4035MEDIUM
4.3
Cross-site scripting (XSS) vulnerability in Schneider Electric Vijeo Historian 4.30 and earlier, Cit…Dec 2, 2011›
CVE-2011-4033MEDIUM
4.3
Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historia…Dec 2, 2011›
CVE-2017-9637MEDIUM
4.1
Schneider Electric Ampla MES 6.4 provides capability to interact with data from third party database…May 18, 2018›
CVE-2014-5407MEDIUM
4.1
Multiple stack-based buffer overflows in Schneider Electric VAMPSET 2.2.136 and earlier allow local …Sep 15, 2014›
CVE-2013-2761MEDIUM
4.0
The Schneider Electric M340 BMXNOE01xx and BMXP3420xx PLC modules allow remote authenticated users t…Apr 4, 2013›
CVE-2017-9635LOW
3.9
Schneider Electric Ampla MES 6.4 provides capability to configure users and their privileges. When A…May 18, 2018›
CVE-2021-22799LOW
3.8
A CWE-331: Insufficient Entropy vulnerability exists that could cause unintended connection from an …Jan 28, 2022›
CVE-2015-0998LOW
3.3
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 b…Mar 29, 2015›
CVE-2015-0999LOW
2.1
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 b…Mar 29, 2015›
CVE-2015-0996LOW
2.1
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 b…Mar 29, 2015›
CVE-2014-5398LOW
2.1
Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote atta…Aug 28, 2014›
CVE-2014-2381LOW
2.1
Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encrypti…Aug 28, 2014›
CVE-2015-1009LOW
1.7
Schneider Electric InduSoft Web Studio before 7.1.3.5 Patch 5 and Wonderware InTouch Machine Edition…Aug 1, 2015›