AID
Automation
Information Directory
HomeCVE FeedBrands
AID
Automation Information Directory
CVE data sourced from NIST NVD · Documentation links from official sources
Home›Brands›Schneider Electric
SC
Platform

Schneider Electric

Global energy management and automation leader. Products include Modicon M340/M580 PLCs, Altivar drives, Harmony HMI, and EcoStruxure platform.

https://www.se.com/ww/en/work/products/industrial-automation-and-control/ →
216
Total CVEs
10
Resources
42
CRIT
98
HIGH
68
MED
8
LOW
CVEsCVEsSpecsTech SpecsDocsTech DocsImplImplementationsExamplesExamples
42 / 216
CVE-2016-8352CRITICAL

An issue was discovered in Schneider Electric ConneXium firewalls TCSEFEC23F3F20 all versions, TCSEFEC23F3F21 all versions, TCSEFEC23FCF20 all versions, TCSEFEC23FCF21 all versions, and TCSEFEC2CF3F20 all versions. A stack-based buffer overflow can be triggered during the SNMP login authentication process that may allow an attacker to remotely execute code.

Feb 13, 2017
10.0
CVE-2022-42971CRITICAL

A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution when the attacker uploads a malicious JSP file. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)

Feb 1, 2023
9.8
CVE-2022-42970CRITICAL

A CWE-306: Missing Authentication for Critical Function The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)

Feb 1, 2023
9.8
CVE-2021-30064CRITICAL

On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an SSH login can succeed with hardcoded default credentials (if the device is in the uncommissioned state).

Apr 3, 2022
9.8
CVE-2018-7791CRITICAL

A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to overwrite the original password with their password. If an attacker exploits this vulnerability and overwrite the password, the attacker can upload the original program from the PLC.

Aug 29, 2018
9.8
CVE-2018-7790CRITICAL

An Information Management Error vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to replay authentication sequences. If an attacker exploits this vulnerability and connects to a Modicon M221, the attacker can upload the original program from the PLC.

Aug 29, 2018
9.8
CVE-2018-7785CRITICAL

In Schneider Electric U.motion Builder software versions prior to v1.3.4, a remote command injection allows authentication bypass.

Jul 3, 2018
9.8
CVE-2018-7784CRITICAL

In Schneider Electric U.motion Builder software versions prior to v1.3.4, this exploit occurs when the submitted data of an input string is evaluated as a command by the application. In this way, the attacker could execute code, read the stack, or cause a segmentation fault in the running application.

Jul 3, 2018
9.8
CVE-2018-7780CRITICAL

In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, a buffer overflow vulnerability exist in cgi program "set".

Jul 3, 2018
9.8
CVE-2018-7778CRITICAL

In Schneider Electric Evlink Charging Station versions prior to v3.2.0-12_v1, the Web Interface has an issue that may allow a remote attacker to gain administrative privileges without properly authenticating remote users.

Jul 3, 2018
9.8
CVE-2018-7761CRITICAL

A vulnerability exists in the HTTP request parser in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200 which could allow arbitrary code execution.

Apr 18, 2018
9.8
CVE-2018-7760CRITICAL

An authorization bypass vulnerability exists in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200. Requests to CGI functions allow malicious users to bypass authorization.

Apr 18, 2018
9.8
CVE-2018-7246CRITICAL

A cleartext transmission of sensitive information vulnerability exists in Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. he integrated web server (Port 80/443/TCP) of the affected devices could allow remote attackers to discover an administrative account. If default on device, it is not using a SSL in settings and if multiple request of the page "Access Control" (IP-address device/ups/pas_cont.htm) account data will be sent in cleartext

Apr 18, 2018
9.8
CVE-2018-7243CRITICAL

An authorization bypass vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to get a full access to device, bypassing the authorization system.

Apr 18, 2018
9.8
CVE-2018-7242CRITICAL

Vulnerable hash algorithms exists in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, and BMXNOR0200 controllers in all versions of the communication modules. The algorithm used to encrypt the password is vulnerable to hash collision attacks.

Apr 18, 2018
9.8
CVE-2018-7241CRITICAL

Hard coded accounts exist in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, and BMXNOR0200 controllers in all versions of the communication modules.

Apr 18, 2018
9.8
CVE-2018-7238CRITICAL

A buffer overflow vulnerability exist in the web-based GUI of Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow an unauthenticated, remote attacker to execute arbitrary code.

Mar 9, 2018
9.8
CVE-2018-7233CRITICAL

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow execution of commands due to lack of validation of the shell meta characters with the value of 'model_name' or 'mac_address'.

Mar 9, 2018
9.8
CVE-2018-7232CRITICAL

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow execution of commands due to lack of validation of the shell meta characters with the value of 'network.ieee8021x.delete_certs'.

Mar 9, 2018
9.8
CVE-2018-7231CRITICAL

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow execution of commands due to lack of validation of the shell meta characters with the value of 'system.opkg.remove'.

Mar 9, 2018
9.8
CVE-2018-7229CRITICAL

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow an unauthenticated, remote attacker to bypass authentication and gain administrator privileges because the use of hardcoded credentials.

Mar 9, 2018
9.8
CVE-2018-7228CRITICAL

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow an unauthenticated, remote attacker to bypass authentication and get the administrator privileges.

Mar 9, 2018
9.8
CVE-2017-14024CRITICAL

A Stack-based Buffer Overflow issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 Patch 1 and prior versions, and InTouch Machine Edition v8.0 SP2 Patch 1 and prior versions. The stack-based buffer overflow vulnerability has been identified, which may allow remote code execution with high privileges.

Nov 13, 2017
9.8
CVE-2017-13997CRITICAL

A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 or prior, and InTouch Machine Edition v8.0 SP2 or prior. InduSoft Web Studio provides the capability for an HMI client to trigger script execution on the server for the purposes of performing customized calculations or actions. A remote malicious entity could bypass the server authentication and trigger the execution of an arbitrary command. The command is executed under high privileges and could lead to a complete compromise of the server.

Oct 3, 2017
9.8
CVE-2017-9957CRITICAL

A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the web service contains a hidden system account with a hardcoded password. An attacker can use this information to log into the system with high-privilege credentials.

Sep 26, 2017
9.8
CVE-2017-7974CRITICAL

A path traversal information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauthenticated user can execute arbitrary code and exfiltrate files.

Sep 26, 2017
9.8
CVE-2017-7973CRITICAL

A SQL injection vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauthenticated user can use calls to various paths allowing performance of arbitrary SQL commands against the underlying database.

Sep 26, 2017
9.8
CVE-2017-9629CRITICAL

A Stack-Based Buffer Overflow issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.2307.1 and prior. The stack-based buffer overflow vulnerability has been identified, which may allow a remote attacker to execute arbitrary code in the context of a highly privileged account.

Jul 7, 2017
9.8
CVE-2017-6034CRITICAL

An Authentication Bypass by Capture-Replay issue was discovered in Schneider Electric Modicon Modbus Protocol. Sensitive information is transmitted in cleartext in the Modicon Modbus protocol, which may allow an attacker to replay the following commands: run, stop, upload, and download.

Jun 30, 2017
9.8
CVE-2017-6028CRITICAL

An Insufficiently Protected Credentials issue was discovered in Schneider Electric Modicon PLCs Modicon M241, all firmware versions, and Modicon M251, all firmware versions. Log-in credentials are sent over the network with Base64 encoding leaving them susceptible to sniffing. Sniffed credentials could then be used to log into the web application.

Jun 30, 2017
9.8
CVE-2017-5158CRITICAL

An Information Exposure issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. Credentials may be exposed to external systems via specific URL parameters, as arbitrary destination addresses may be specified.

Apr 20, 2017
9.8
CVE-2017-7689CRITICAL

A Command Injection vulnerability in Schneider Electric homeLYnk Controller exists in all versions before 1.5.0.

Apr 11, 2017
9.8
CVE-2017-7575CRITICAL

Schneider Electric Modicon TM221CE16R 1.3.3.3 devices allow remote attackers to discover the application-protection password via a \x00\x01\x00\x00\x00\x05\x01\x5a\x00\x03\x00 request to the Modbus port (502/tcp). Subsequently the application may be arbitrarily downloaded, modified, and uploaded.

Apr 6, 2017
9.8
CVE-2017-7574CRITICAL

Schneider Electric SoMachine Basic 1.4 SP1 and Schneider Electric Modicon TM221CE16R 1.3.3.3 devices have a hardcoded-key vulnerability. The Project Protection feature is used to prevent unauthorized users from opening an XML protected project file, by prompting the user for a password. This XML file is AES-CBC encrypted; however, the key used for encryption (SoMachineBasicSoMachineBasicSoMa) cannot be changed. After decrypting the XML file with this key, the user password can be found in the decrypted data. After reading the user password, the project can be opened and modified with the Schneider product.

Apr 6, 2017
9.8
CVE-2017-5178CRITICAL

An issue was discovered in Schneider Electric Tableau Server/Desktop Versions 7.0 to 10.1.3 in Wonderware Intelligence Versions 2014R3 and prior. These versions contain a system account that is installed by default. The default system account is difficult to configure with non-default credentials after installation, and changing the default credentials in the embedded Tableau Server is not documented. If Tableau Server is used with Windows integrated security (Active Directory), the software is not vulnerable. However, when Tableau Server is used with local authentication mode, the software is vulnerable. The default system account could be used to gain unauthorized access.

Mar 8, 2017
9.8
CVE-2016-5818CRITICAL

An issue was discovered in Schneider Electric PowerLogic PM8ECC device 2.651 and older. Undocumented hard-coded credentials allow access to the device.

Feb 13, 2017
9.8
CVE-2016-5815CRITICAL

An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series, ION8650 series, ION8800 series, and PM5XXX series. No authentication is configured by default. An unauthorized user can access the device management portal and make configuration changes.

Feb 13, 2017
9.8
CVE-2016-4520CRITICAL

Schneider Electric Pelco Digital Sentry Video Management System with firmware before 7.14 has hardcoded credentials, which allows remote attackers to obtain access, and consequently execute arbitrary code, via unspecified vectors.

Jul 15, 2016
9.8
CVE-2012-0931CRITICAL

Schneider Electric Modicon Quantum PLC does not perform authentication between the Unity software and PLC, which allows remote attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors.

Jan 28, 2012
9.8
CVE-2018-7245CRITICAL

An improper authorization vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to change UPS control and shutdown parameters or other critical settings without authorization.

Apr 18, 2018
9.1
CVE-2018-7237CRITICAL

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow a remote attacker to delete arbitrary system file due to lack of validation of the /login/bin/set_param to the file name with the value of 'system.delete.sd_file'

Mar 9, 2018
9.1
CVE-2017-6026CRITICAL

A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware versions prior to Version 4.0.5.11, and Modicon M251, firmware versions prior to Version 4.0.5.11. The session numbers generated by the web application are lacking randomization and are shared between several users. This may allow a current session to be compromised.

Jun 30, 2017
9.1
CVE ID ⇅Severity ↓CVSS ⇅DescriptionPublished ⇅
CVE-2016-8352CRITICAL
10.0
An issue was discovered in Schneider Electric ConneXium firewalls TCSEFEC23F3F20 all versions, TCSEF…Feb 13, 2017›
CVE-2022-42971CRITICAL
9.8
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause rem…Feb 1, 2023›
CVE-2022-42970CRITICAL
9.8
A CWE-306: Missing Authentication for Critical Function The software does not perform any authentica…Feb 1, 2023›
CVE-2021-30064CRITICAL
9.8
On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and …Apr 3, 2022›
CVE-2018-7791CRITICAL
9.8
A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M…Aug 29, 2018›
CVE-2018-7790CRITICAL
9.8
An Information Management Error vulnerability exists in Schneider Electric's Modicon M221 product (a…Aug 29, 2018›
CVE-2018-7785CRITICAL
9.8
In Schneider Electric U.motion Builder software versions prior to v1.3.4, a remote command injection…Jul 3, 2018›
CVE-2018-7784CRITICAL
9.8
In Schneider Electric U.motion Builder software versions prior to v1.3.4, this exploit occurs when t…Jul 3, 2018›
CVE-2018-7780CRITICAL
9.8
In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior t…Jul 3, 2018›
CVE-2018-7778CRITICAL
9.8
In Schneider Electric Evlink Charging Station versions prior to v3.2.0-12_v1, the Web Interface has …Jul 3, 2018›
CVE-2018-7761CRITICAL
9.8
A vulnerability exists in the HTTP request parser in Schneider Electric's Modicon M340, Modicon Prem…Apr 18, 2018›
CVE-2018-7760CRITICAL
9.8
An authorization bypass vulnerability exists in Schneider Electric's Modicon M340, Modicon Premium, …Apr 18, 2018›
CVE-2018-7246CRITICAL
9.8
A cleartext transmission of sensitive information vulnerability exists in Schneider Electric's 66074…Apr 18, 2018›
CVE-2018-7243CRITICAL
9.8
An authorization bypass vulnerability exists In Schneider Electric's 66074 MGE Network Management Ca…Apr 18, 2018›
CVE-2018-7242CRITICAL
9.8
Vulnerable hash algorithms exists in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon …Apr 18, 2018›
CVE-2018-7241CRITICAL
9.8
Hard coded accounts exist in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, an…Apr 18, 2018›
CVE-2018-7238CRITICAL
9.8
A buffer overflow vulnerability exist in the web-based GUI of Schneider Electric's Pelco Sarix Profe…Mar 9, 2018›
CVE-2018-7233CRITICAL
9.8
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions pri…Mar 9, 2018›
CVE-2018-7232CRITICAL
9.8
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions pri…Mar 9, 2018›
CVE-2018-7231CRITICAL
9.8
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions pri…Mar 9, 2018›
CVE-2018-7229CRITICAL
9.8
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions pri…Mar 9, 2018›
CVE-2018-7228CRITICAL
9.8
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions pri…Mar 9, 2018›
CVE-2017-14024CRITICAL
9.8
A Stack-based Buffer Overflow issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP…Nov 13, 2017›
CVE-2017-13997CRITICAL
9.8
A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft W…Oct 3, 2017›
CVE-2017-9957CRITICAL
9.8
A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in…Sep 26, 2017›
CVE-2017-7974CRITICAL
9.8
A path traversal information disclosure vulnerability exists in Schneider Electric's U.motion Builde…Sep 26, 2017›
CVE-2017-7973CRITICAL
9.8
A SQL injection vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.…Sep 26, 2017›
CVE-2017-9629CRITICAL
9.8
A Stack-Based Buffer Overflow issue was discovered in Schneider Electric Wonderware ArchestrA Logger…Jul 7, 2017›
CVE-2017-6034CRITICAL
9.8
An Authentication Bypass by Capture-Replay issue was discovered in Schneider Electric Modicon Modbus…Jun 30, 2017›
CVE-2017-6028CRITICAL
9.8
An Insufficiently Protected Credentials issue was discovered in Schneider Electric Modicon PLCs Modi…Jun 30, 2017›
CVE-2017-5158CRITICAL
9.8
An Information Exposure issue was discovered in Schneider Electric Wonderware InTouch Access Anywher…Apr 20, 2017›
CVE-2017-7689CRITICAL
9.8
A Command Injection vulnerability in Schneider Electric homeLYnk Controller exists in all versions b…Apr 11, 2017›
CVE-2017-7575CRITICAL
9.8
Schneider Electric Modicon TM221CE16R 1.3.3.3 devices allow remote attackers to discover the applica…Apr 6, 2017›
CVE-2017-7574CRITICAL
9.8
Schneider Electric SoMachine Basic 1.4 SP1 and Schneider Electric Modicon TM221CE16R 1.3.3.3 devices…Apr 6, 2017›
CVE-2017-5178CRITICAL
9.8
An issue was discovered in Schneider Electric Tableau Server/Desktop Versions 7.0 to 10.1.3 in Wonde…Mar 8, 2017›
CVE-2016-5818CRITICAL
9.8
An issue was discovered in Schneider Electric PowerLogic PM8ECC device 2.651 and older. Undocumented…Feb 13, 2017›
CVE-2016-5815CRITICAL
9.8
An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX se…Feb 13, 2017›
CVE-2016-4520CRITICAL
9.8
Schneider Electric Pelco Digital Sentry Video Management System with firmware before 7.14 has hardco…Jul 15, 2016›
CVE-2012-0931CRITICAL
9.8
Schneider Electric Modicon Quantum PLC does not perform authentication between the Unity software an…Jan 28, 2012›
CVE-2018-7245CRITICAL
9.1
An improper authorization vulnerability exists In Schneider Electric's 66074 MGE Network Management …Apr 18, 2018›
CVE-2018-7237CRITICAL
9.1
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions pri…Mar 9, 2018›
CVE-2017-6026CRITICAL
9.1
A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modico…Jun 30, 2017›