AID
Automation
Information Directory
HomeCVE FeedBrands
AID
Automation Information Directory
CVE data sourced from NIST NVD · Documentation links from official sources
Home›Brands›Schneider Electric
SC
Platform

Schneider Electric

Global energy management and automation leader. Products include Modicon M340/M580 PLCs, Altivar drives, Harmony HMI, and EcoStruxure platform.

https://www.se.com/ww/en/work/products/industrial-automation-and-control/ →
216
Total CVEs
10
Resources
42
CRIT
98
HIGH
68
MED
8
LOW
CVEsCVEsSpecsTech SpecsDocsTech DocsImplImplementationsExamplesExamples
98 / 216
CVE-2015-7937HIGH

Stack-based buffer overflow in the GoAhead Web Server on Schneider Electric Modicon M340 PLC BMXNOx and BMXPx devices allows remote attackers to execute arbitrary code via a long password in HTTP Basic Authentication data.

Dec 21, 2015
10.0
CVE-2014-9198HIGH

The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to obtain access via an FTP session.

Jan 27, 2015
10.0
CVE-2014-9197HIGH

The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request.

Jan 27, 2015
10.0
CVE-2014-9190HIGH

Stack-based buffer overflow in Schneider Electric Wonderware InTouch Access Anywhere Server 10.6 and 11.0 allows remote attackers to execute arbitrary code via a request for a filename that does not exist.

Jan 10, 2015
10.0
CVE-2014-9188HIGH

Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8513 and CVE-2014-8514. NOTE: this may be clarified later based on details provided by researchers.

Dec 27, 2014
10.0
CVE-2014-8511HIGH

Buffer overflow in an ActiveX control in Atx45.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8512. NOTE: this may be clarified later based on details provided by researchers.

Dec 27, 2014
10.0
CVE-2014-0754HIGH

Directory traversal vulnerability in SchneiderWEB on Schneider Electric Modicon PLC Ethernet modules 140CPU65x Exec before 5.5, 140NOC78x Exec before 1.62, 140NOE77x Exec before 6.2, BMXNOC0401 before 2.05, BMXNOE0100 before 2.9, BMXNOE0110x Exec before 6.0, TSXETC101 Exec before 2.04, TSXETY4103x Exec before 5.7, TSXETY5103x Exec before 5.9, TSXP57x ETYPort Exec before 5.7, and TSXP57x Ethernet Copro Exec before 5.5 allows remote attackers to visit arbitrary resources via a crafted HTTP request.

Oct 3, 2014
10.0
CVE-2013-2762HIGH

The Schneider Electric Magelis XBT HMI controller has a default password for authentication of configuration uploads, which makes it easier for remote attackers to bypass intended access restrictions via crafted configuration data.

Apr 4, 2013
10.0
CVE-2013-0658HIGH

Heap-based buffer overflow in RFManagerService.exe in Schneider Electric Accutech Manager 2.00.1 and earlier allows remote attackers to execute arbitrary code via a crafted HTTP request.

Feb 15, 2013
10.0
CVE-2013-0657HIGH

Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA System (IGSS) 10 and earlier allows remote attackers to execute arbitrary code by sending TCP port-12397 data that does not comply with a protocol.

Jan 21, 2013
10.0
CVE-2011-4861HIGH

The modbus_125_handler function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) allows remote attackers to install arbitrary firmware updates via a MODBUS 125 function code to TCP port 502.

Dec 17, 2011
10.0
CVE-2011-4860HIGH

The ComputePassword function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) generates the password for the fwupgrade account by performing a calculation on the MAC address, which makes it easier for remote attackers to obtain access via a (1) ARP request message or (2) Neighbor Solicitation message.

Dec 17, 2011
10.0
CVE-2011-4859HIGH

The Schneider Electric Quantum Ethernet Module, as used in the Quantum 140NOE771* and 140CPU65* modules, the Premium TSXETY* and TSXP57* modules, the M340 BMXNOE01* and BMXP3420* modules, and the STB DIO STBNIC2212 and STBNIP2* modules, uses hardcoded passwords for the (1) AUTCSE, (2) AUT_CSE, (3) fdrusers, (4) ftpuser, (5) loader, (6) nic2212, (7) nimrohs2212, (8) nip2212, (9) noe77111_v500, (10) ntpupdate, (11) pcfactory, (12) sysdiag, (13) target, (14) test, (15) USER, and (16) webserver accounts, which makes it easier for remote attackers to obtain access via the (a) TELNET, (b) Windriver Debug, or (c) FTP port.

Dec 17, 2011
10.0
CVE-2013-0662HIGH

Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow remote attackers to execute arbitrary code via a large buffer-size value in a Modbus Application Header.

Apr 1, 2014
9.3
CVE-2013-2782HIGH

Schneider Electric Trio J-Series License Free Ethernet Radio with firmware 3.6.0 through 3.6.3 uses the same AES encryption key across different customers' installations, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.

Aug 28, 2013
9.3
CVE-2013-0655HIGH

The client in Schneider Electric Software Update (SESU) Utility 1.0.x and 1.1.x does not ensure that updates have a valid origin, which allows man-in-the-middle attackers to spoof updates, and consequently execute arbitrary code, by modifying the data stream on TCP port 80.

Jan 21, 2013
9.3
CVE-2011-4034HIGH

Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors.

Dec 2, 2011
9.3
CVE-2018-7782HIGH

In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, authenticated users can view passwords in clear text.

Jul 3, 2018
8.8
CVE-2018-7781HIGH

In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, by sending a specially crafted request an authenticated user can view password in clear text and results in privilege escalation.

Jul 3, 2018
8.8
CVE-2018-7777HIGH

The vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A remote, authenticated attacker can exploit this vulnerability by sending a crafted request to the target server.

Jul 3, 2018
8.8
CVE-2018-7774HIGH

The vulnerability exists within processing of localize.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the username input parameter.

Jul 3, 2018
8.8
CVE-2018-7773HIGH

The vulnerability exists within processing of nfcserver.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the sessionid input parameter.

Jul 3, 2018
8.8
CVE-2018-7772HIGH

The vulnerability exists within processing of applets which are exposed on the web service in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query to determine whether a user is logged in is subject to SQL injection on the loginSeed parameter, which can be embedded in the HTTP cookie of the request.

Jul 3, 2018
8.8
CVE-2018-7769HIGH

The vulnerability exists within processing of xmlserver.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the id input parameter.

Jul 3, 2018
8.8
CVE-2018-7768HIGH

The vulnerability exists within processing of loadtemplate.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the tpl input parameter.

Jul 3, 2018
8.8
CVE-2018-7767HIGH

The vulnerability exists within processing of editobject.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the type input parameter.

Jul 3, 2018
8.8
CVE-2018-7766HIGH

The vulnerability exists within processing of track_getdata.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the id input parameter.

Jul 3, 2018
8.8
CVE-2018-7765HIGH

The vulnerability exists within processing of track_import_export.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the object_id input parameter.

Jul 3, 2018
8.8
CVE-2018-7240HIGH

A vulnerability exists in Schneider Electric's Modicon Quantum in all versions of the communication modules which could allow arbitrary code execution. An FTP command used to upgrade the firmware of the module can be misused to cause a denial of service, or in extreme cases, to load a malicious firmware.

Apr 18, 2018
8.8
CVE-2018-7230HIGH

A XML external entity (XXE) vulnerability exists in the import.cgi of the web interface component of the Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67.

Mar 9, 2018
8.8
CVE-2017-7969HIGH

A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for multiple state-changing requests. This type of attack requires some level of social engineering in order to get a legitimate user to click on or access a malicious link/site containing the CSRF attack.

Sep 26, 2017
8.8
CVE-2017-7966HIGH

A DLL Hijacking vulnerability in the programming software in Schneider Electric's SoMachine HVAC v2.1.0 allows a remote attacker to execute arbitrary code on the targeted system. The vulnerability exists due to the improper loading of a DLL.

Jun 7, 2017
8.8
CVE-2017-5156HIGH

A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The client request may be forged from a different site. This will allow an external site to access internal RDP systems on behalf of the currently logged in user.

Apr 20, 2017
8.8
CVE-2016-5809HIGH

An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series, ION8650 series, ION8800 series, and PM5XXX series. There is no CSRF Token generated to authenticate the user during a session. Successful exploitation of this vulnerability can allow unauthorized configuration changes to be made and saved.

Feb 13, 2017
8.8
CVE-2017-9627HIGH

An Uncontrolled Resource Consumption issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.2307.1 and prior. The uncontrolled resource consumption vulnerability could allow an attacker to exhaust the memory resources of the machine, causing a denial of service.

Jul 7, 2017
8.6
CVE-2013-0664HIGH

The FactoryCast service on the Schneider Electric Quantum 140NOE77111 and 140NWM10000, M340 BMXNOE0110x, and Premium TSXETY5103 PLC modules allows remote authenticated users to send Modbus messages, and consequently execute arbitrary code, by embedding these messages in SOAP HTTP POST requests.

Apr 4, 2013
8.5
CVE-2018-8872HIGH

In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, system calls read directly from memory addresses within the control program area without any verification. Manipulating this data could allow attacker data to be copied anywhere within memory.

May 4, 2018
8.1
CVE-2018-7236HIGH

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could enable SSH service due to lack of authentication for /login/bin/set_param could enable SSH service.

Mar 9, 2018
8.1
CVE-2017-9963HIGH

A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for multiple state-changing requests. This type of attack requires some level of social engineering in order to get a legitimate user to click on or access a malicious link/site containing the CSRF attack.

Feb 12, 2018
8.1
CVE-2018-7771HIGH

The vulnerability exists within processing of editscript.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A directory traversal vulnerability allows a caller with standard user privileges to write arbitrary php files anywhere in the web service directory tree.

Jul 3, 2018
8.0
CVE-2022-42973HIGH

A CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause local privilege escalation when local attacker connects to the database. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)

Feb 1, 2023
7.8
CVE-2022-42972HIGH

A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cause local privilege escalation when a local attacker modifies the webroot directory. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)

Feb 1, 2023
7.8
CVE-2021-22808HIGH

A CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution when a malicious *.gd1 configuration file is loaded into the GUIcon tool. Affected Product: Eurotherm by Schneider Electric GUIcon Version 2.0 (Build 683.003) and prior

Jan 28, 2022
7.8
CVE-2021-22807HIGH

A CWE-787: Out-of-bounds Write vulnerability exists that could cause arbitrary code execution when a malicious *.gd1 configuration file is loaded into the GUIcon tool. Affected Product: Eurotherm by Schneider Electric GUIcon Version 2.0 (Build 683.003) and prior

Jan 28, 2022
7.8
CVE-2020-7523HIGH

Improper Privilege Management vulnerability exists in Schneider Electric Modbus Serial Driver (see security notification for versions) which could cause local privilege escalation when the Modbus Serial Driver service is invoked. The driver does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Aug 31, 2020
7.8
CVE-2018-7815HIGH

A Type Confusion (CWE-843) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0) on c3core.dll which could cause remote code to be executed when parsing a GD1 file

Feb 6, 2019
7.8
CVE-2018-7814HIGH

A Stack-based Buffer Overflow (CWE-121) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0) which could cause remote code to be executed when parsing a GD1 file

Feb 6, 2019
7.8
CVE-2018-7813HIGH

A Type Confusion (CWE-843) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0) on pcwin.dll which could cause remote code to be executed when parsing a GD1 file

Feb 6, 2019
7.8
CVE-2018-7799HIGH

A DLL hijacking vulnerability exists in Schneider Electric Software Update (SESU), all versions prior to V2.2.0, which could allow an attacker to execute arbitrary code on the targeted system when placing a specific DLL file.

Nov 2, 2018
7.8
CVE-2018-7239HIGH

A DLL hijacking vulnerability exists in Schneider Electric's SoMove Software and associated DTM software components in all versions prior to 2.6.2 which could allow an attacker to execute arbitrary code.

Mar 9, 2018
7.8
CVE-2017-9967HIGH

A security misconfiguration vulnerability exists in Schneider Electric's IGSS SCADA Software versions 12 and prior. Security configuration settings such as Address Space Layout Randomization (ASLR) and Data Execution prevention (DEP) were not properly configured resulting in weak security.

Feb 12, 2018
7.8
CVE-2017-9961HIGH

A vulnerability exists in Schneider Electric's Pro-Face GP Pro EX version 4.07.000 that allows an attacker to execute arbitrary code. Malicious code installation requires an access to the computer. By placing a specific DLL/OCX file, an attacker is able to force the process to load arbitrary DLL and execute arbitrary code in the context of the process.

Sep 26, 2017
7.8
CVE-2017-9958HIGH

An improper access control vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an improper handling of the system configuration can allow an attacker to execute arbitrary code under the context of root.

Sep 26, 2017
7.8
CVE-2017-7968HIGH

An Incorrect Default Permissions issue was discovered in Schneider Electric Wonderware InduSoft Web Studio v8.0 Patch 3 and prior versions. Upon installation, Wonderware InduSoft Web Studio creates a new directory and two files, which are placed in the system's path and can be manipulated by non-administrators. This could allow an authenticated user to escalate his or her privileges.

May 19, 2017
7.8
CVE-2017-6033HIGH

A DLL Hijacking issue was discovered in Schneider Electric Interactive Graphical SCADA System (IGSS) Software, Version 12 and previous versions. The software will execute a malicious file if it is named the same as a legitimate file and placed in a location that is earlier in the search path.

Apr 7, 2017
7.8
CVE-2014-2380HIGH

Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows remote attackers to obtain sensitive information by reading a credential file.

Aug 28, 2014
7.8
CVE-2013-2824HIGH

Schneider Electric StruxureWare SCADA Expert Vijeo Citect 7.40, Vijeo Citect 7.20 through 7.30SP1, CitectSCADA 7.20 through 7.30SP1, StruxureWare PowerSCADA Expert 7.30 through 7.30SR1, and PowerLogic SCADA 7.20 through 7.20SR1 do not properly handle exceptions, which allows remote attackers to cause a denial of service via a crafted packet.

Feb 26, 2014
7.8
CVE-2015-3977HIGH

Buffer overflow in Schneider Electric IMT25 Magnetic Flow DTM before 1.500.004 for the HART Protocol allows remote authenticated users to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HART reply.

Nov 15, 2015
7.7
CVE-2021-30065HIGH

On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, crafted ModBus packets can bypass the ModBus enforcer. NOTE: this issue exists because of an incomplete fix of CVE-2017-11401.

Apr 3, 2022
7.5
CVE-2021-30063HIGH

On Schneider Electric ConneXium Tofino OPCLSM TCSEFM0000 before 03.23 and Belden Tofino Xenon Security Appliance, crafted OPC packets can cause an OPC enforcer denial of service.

Apr 3, 2022
7.5
CVE-2021-30062HIGH

On Schneider Electric ConneXium Tofino OPCLSM TCSEFM0000 before 03.23 and Belden Tofino Xenon Security Appliance, crafted OPC packets can bypass the OPC enforcer.

Apr 3, 2022
7.5
CVE-2020-7524HIGH

Out-of-bounds Write vulnerability exists in Modicon M218 Logic Controller (V5.0.0.7 and prior) which could cause Denial of Service when sending specific crafted IPV4 packet to the controller: Sending a specific IPv4 protocol package to Schneider Electric Modicon M218 Logic Controller can cause IPv4 devices to go down. The device does not work properly and must be powered back on to return to normal.

Aug 31, 2020
7.5
CVE-2019-13537HIGH

The IEC870IP driver for AVEVA’s Vijeo Citect and Citect SCADA and Schneider Electric’s Power SCADA Operation has a buffer overflow vulnerability that could result in a server-side crash.

Jan 14, 2020
7.5
CVE-2018-7792HIGH

A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to decode the password using rainbow table.

Aug 29, 2018
7.5
CVE-2018-7789HIGH

An Improper Check for Unusual or Exceptional Conditions vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to remotely reboot Modicon M221 using crafted programing protocol frames.

Aug 29, 2018
7.5
CVE-2018-7783HIGH

Schneider Electric SoMachine Basic prior to v1.6 SP1 suffers from an XML External Entity (XXE) vulnerability using the DTD parameter entities technique resulting in disclosure and retrieval of arbitrary data on the affected node via out-of-band (OOB) attack. The vulnerability is triggered when input passed to the xml parser is not sanitized while parsing the xml project/template file.

Jul 3, 2018
7.5
CVE-2018-7779HIGH

In Schneider Electric Wiser for KNX V2.1.0 and prior, homeLYnk V2.0.1 and prior; and spaceLYnk V2.1.0 and prior, weak and unprotected FTP access could allow an attacker unauthorized access.

Jul 3, 2018
7.5
CVE-2017-6021HIGH

In Schneider Electric ClearSCADA 2014 R1 (build 75.5210) and prior, 2014 R1.1 (build 75.5387) and prior, 2015 R1 (build 76.5648) and prior, and 2015 R2 (build 77.5882) and prior, an attacker with network access to the ClearSCADA server can send specially crafted sequences of commands and data packets to the ClearSCADA server that can cause the ClearSCADA server process and ClearSCADA communications driver processes to terminate. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

May 14, 2018
7.5
CVE-2018-7762HIGH

A vulnerability exists in the web services to process SOAP requests in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200 which could allow result in a buffer overflow.

Apr 18, 2018
7.5
CVE-2018-7759HIGH

A buffer overflow vulnerability exists in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200. The buffer overflow vulnerability is caused by the length of the source string specified (instead of the buffer size) as the number of bytes to be copied.

Apr 18, 2018
7.5
CVE-2018-7235HIGH

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow arbitrary system file download due to lack of validation of the shell meta characters with the value of 'system.download.sd_file'

Mar 9, 2018
7.5
CVE-2018-7234HIGH

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow arbitrary system file download due to lack of validation of SSL certificate.

Mar 9, 2018
7.5
CVE-2017-9962HIGH

Schneider Electric's ClearSCADA versions released prior to August 2017 are susceptible to a memory allocation vulnerability, whereby malformed requests can be sent to ClearSCADA client applications to cause unexpected behavior. Client applications affected include ViewX and the Server Icon.

Sep 26, 2017
7.5
CVE-2017-9631HIGH

A Null Pointer Dereference issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.2307.1 and prior. The null pointer dereference vulnerability could allow an attacker to crash the logger process, causing a denial of service for logging and log-viewing (applications that use the Wonderware ArchestrA Logger continue to run when the Wonderware ArchestrA Logger service is unavailable).

Jul 7, 2017
7.5
CVE-2017-6017HIGH

A Resource Exhaustion issue was discovered in Schneider Electric Modicon M340 PLC BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP341000, BMXP342000, BMXP3420102, BMXP3420102CL, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, and BMXP342030H. A remote attacker could send a specially crafted set of packets to the PLC causing it to freeze, requiring the operator to physically press the reset button on the PLC in order to recover.

Jun 30, 2017
7.5
CVE-2017-6019HIGH

An issue was discovered in Schneider Electric Conext ComBox, model 865-1058, all firmware versions prior to V3.03 BN 830. A series of rapid requests to the device may cause it to reboot.

Apr 7, 2017
7.5
CVE-2016-8374HIGH

An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all versions, Magelis GTU Universal Panel, all versions, Magelis STO5xx and STU Small panels, all versions, Magelis XBT GH Advanced Hand-held Panels, all versions, Magelis XBT GK Advanced Touchscreen Panels with Keyboard, all versions, Magelis XBT GT Advanced Touchscreen Panels, all versions, and Magelis XBT GTW Advanced Open Touchscreen Panels (Windows XPe). An attacker may be able to disrupt a targeted web server, resulting in a denial of service because of UNCONTROLLED RESOURCE CONSUMPTION.

Feb 13, 2017
7.5
CVE-2015-7375HIGH

Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code or cause a denial of service (unhandled runtime exception and application crash) via a crafted Indusoft Project file.

Sep 25, 2015
7.5
CVE-2015-7374HIGH

The Remote Agent component in Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code via unspecified vectors, aka ZDI-CAN-2649.

Sep 25, 2015
7.5
CVE-2015-0982HIGH

Buffer overflow in an unspecified DLL in Schneider Electric Pelco DS-NVs before 7.8.90 allows remote attackers to execute arbitrary code via unspecified vectors.

Mar 14, 2015
7.5
CVE-2014-9200HIGH

Stack-based buffer overflow in an unspecified DLL file in a DTM development kit in Schneider Electric Unity Pro, SoMachine, SoMove, SoMove Lite, Modbus Communication Library 2.2.6 and earlier, CANopen Communication Library 1.0.2 and earlier, EtherNet/IP Communication Library 1.0.0 and earlier, EM X80 Gateway DTM (MB TCP/SL), Advantys DTM for OTB, Advantys DTM for STB, KINOS DTM, SOLO DTM, and Xantrex DTMs allows remote attackers to execute arbitrary code via unspecified vectors.

Feb 1, 2015
7.5
CVE-2014-8514HIGH

Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8513 and CVE-2014-9188. NOTE: this may be clarified later based on details provided by researchers.

Dec 27, 2014
7.5
CVE-2014-8513HIGH

Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8514 and CVE-2014-9188. NOTE: this may be clarified later based on details provided by researchers.

Dec 27, 2014
7.5
CVE-2014-8512HIGH

Buffer overflow in an ActiveX control in Atx45.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8511. NOTE: this may be clarified later based on details provided by researchers.

Dec 27, 2014
7.5
CVE-2014-5399HIGH

SQL injection vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Aug 28, 2014
7.5
CVE-2014-5397HIGH

Cross-site scripting (XSS) vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Aug 28, 2014
7.5
CVE-2012-0929HIGH

Multiple buffer overflows in Schneider Electric Modicon Quantum PLC allow remote attackers to cause a denial of service via malformed requests to the (1) FTP server or (2) HTTP server.

Jan 28, 2012
7.5
CVE-2019-6834HIGH

A CWE-502: Deserialization of Untrusted Data vulnerability exists which could allow an attacker to execute arbitrary code on the targeted system with SYSTEM privileges when placing a malicious user to be authenticated for this vulnerability to be successfully exploited. Affected Product: Schneider Electric Software Update (SESU) SUT Service component (V2.1.1 to V2.3.0)

Apr 13, 2022
7.3
CVE-2015-1014HIGH

A successful exploit of these vulnerabilities requires the local user to load a crafted DLL file in the system directory on servers running Schneider Electric OFS v3.5 with version v7.40 of SCADA Expert Vijeo Citect/CitectSCADA, OFS v3.5 with version v7.30 of Vijeo Citect/CitectSCADA, and OFS v3.5 with version v7.20 of Vijeo Citect/CitectSCADA.. If the application attempts to open that file, the application could crash or allow the attacker to execute arbitrary code. Schneider Electric recommends vulnerable users upgrade the OFS to V3.5 and install the latest service pack (SP 6 or newer) for their associated version.

Mar 25, 2019
7.3
CVE-2017-9956HIGH

An authentication bypass vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system contains a hard-coded valid session. An attacker can use that session ID as part of the HTTP cookie of a web request, resulting in authentication bypass

Sep 26, 2017
7.3
CVE-2017-7965HIGH

A buffer overflow vulnerability exists in Programming Software executable AlTracePrint.exe, in Schneider Electric's SoMachine HVAC v2.1.0 for Modicon M171/M172 Controller.

Jun 7, 2017
7.3
CVE-2017-5155HIGH

An issue was discovered in Schneider Electric Wonderware Historian 2014 R2 SP1 P01 and earlier. Wonderware Historian creates logins with default passwords, which can allow a malicious entity to compromise Historian databases. In some installation scenarios, resources beyond those created by Wonderware Historian may be compromised as well.

Feb 13, 2017
7.3
CVE-2016-4529HIGH

An unspecified ActiveX control in Schneider Electric SoMachine HVAC Programming Software for M171/M172 Controllers before 2.1.0 allows remote attackers to execute arbitrary code via unknown vectors, related to the INTERFACESAFE_FOR_UNTRUSTED_CALLER (aka safe for scripting) flag.

Jul 15, 2016
7.3
CVE-2017-9970HIGH

A remote code execution vulnerability exists in Schneider Electric's StruxureOn Gateway versions 1.1.3 and prior. Uploading a zip which contains carefully crafted metadata allows for the file to be uploaded to any directory on the host machine information which could lead to remote code execution.

Feb 12, 2018
7.2
CVE-2016-2278HIGH

Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows remote authenticated administrators to execute arbitrary OS commands by defeating an msh (aka Minimal Shell) protection mechanism.

Mar 2, 2016
7.2
CVE-2011-3330HIGH

Buffer overflow in the UnitelWay Windows Device Driver, as used in Schneider Electric Unity Pro 6 and earlier, OPC Factory Server 3.34, Vijeo Citect 7.20 and earlier, Telemecanique Driver Pack 2.6 and earlier, Monitor Pro 7.6 and earlier, and PL7 Pro 4.5 and earlier, allows local users, and possibly remote attackers, to execute arbitrary code via an unspecified system parameter.

Nov 4, 2011
7.2
CVE-2017-9966HIGH

A privilege escalation vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2.0 and prior. By replacing certain files, an unauthorized user can obtain system privileges and the inserted code would execute at an elevated privilege level.

Jan 2, 2018
7.1
CVE-2016-8354HIGH

An issue was discovered in Schneider Electric Unity PRO prior to V11.1. Unity projects can be compiled as x86 instructions and loaded onto the PLC Simulator delivered with Unity PRO. These x86 instructions are subsequently executed directly by the simulator. A specially crafted patched Unity project file can make the simulator execute malicious code by redirecting the control flow of these instructions.

Feb 13, 2017
7.0
CVE ID ⇅Severity ↓CVSS ⇅DescriptionPublished ⇅
CVE-2015-7937HIGH
10.0
Stack-based buffer overflow in the GoAhead Web Server on Schneider Electric Modicon M340 PLC BMXNOx …Dec 21, 2015›
CVE-2014-9198HIGH
10.0
The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 …Jan 27, 2015›
CVE-2014-9197HIGH
10.0
The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.ja…Jan 27, 2015›
CVE-2014-9190HIGH
10.0
Stack-based buffer overflow in Schneider Electric Wonderware InTouch Access Anywhere Server 10.6 and…Jan 10, 2015›
CVE-2014-9188HIGH
10.0
Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 all…Dec 27, 2014›
CVE-2014-8511HIGH
10.0
Buffer overflow in an ActiveX control in Atx45.ocx in Schneider Electric ProClima before 6.1.7 allow…Dec 27, 2014›
CVE-2014-0754HIGH
10.0
Directory traversal vulnerability in SchneiderWEB on Schneider Electric Modicon PLC Ethernet modules…Oct 3, 2014›
CVE-2013-2762HIGH
10.0
The Schneider Electric Magelis XBT HMI controller has a default password for authentication of confi…Apr 4, 2013›
CVE-2013-0658HIGH
10.0
Heap-based buffer overflow in RFManagerService.exe in Schneider Electric Accutech Manager 2.00.1 and…Feb 15, 2013›
CVE-2013-0657HIGH
10.0
Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA System (IGSS) 10 and e…Jan 21, 2013›
CVE-2011-4861HIGH
10.0
The modbus_125_handler function in the Schneider Electric Quantum Ethernet Module on the NOE 771 dev…Dec 17, 2011›
CVE-2011-4860HIGH
10.0
The ComputePassword function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device…Dec 17, 2011›
CVE-2011-4859HIGH
10.0
The Schneider Electric Quantum Ethernet Module, as used in the Quantum 140NOE771* and 140CPU65* modu…Dec 17, 2011›
CVE-2013-0662HIGH
9.3
Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.…Apr 1, 2014›
CVE-2013-2782HIGH
9.3
Schneider Electric Trio J-Series License Free Ethernet Radio with firmware 3.6.0 through 3.6.3 uses …Aug 28, 2013›
CVE-2013-0655HIGH
9.3
The client in Schneider Electric Software Update (SESU) Utility 1.0.x and 1.1.x does not ensure that…Jan 21, 2013›
CVE-2011-4034HIGH
9.3
Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historia…Dec 2, 2011›
CVE-2018-7782HIGH
8.8
In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior t…Jul 3, 2018›
CVE-2018-7781HIGH
8.8
In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior t…Jul 3, 2018›
CVE-2018-7777HIGH
8.8
The vulnerability is due to insufficient handling of update_file request parameter on update_module.…Jul 3, 2018›
CVE-2018-7774HIGH
8.8
The vulnerability exists within processing of localize.php in Schneider Electric U.motion Builder so…Jul 3, 2018›
CVE-2018-7773HIGH
8.8
The vulnerability exists within processing of nfcserver.php in Schneider Electric U.motion Builder s…Jul 3, 2018›
CVE-2018-7772HIGH
8.8
The vulnerability exists within processing of applets which are exposed on the web service in Schnei…Jul 3, 2018›
CVE-2018-7769HIGH
8.8
The vulnerability exists within processing of xmlserver.php in Schneider Electric U.motion Builder s…Jul 3, 2018›
CVE-2018-7768HIGH
8.8
The vulnerability exists within processing of loadtemplate.php in Schneider Electric U.motion Builde…Jul 3, 2018›
CVE-2018-7767HIGH
8.8
The vulnerability exists within processing of editobject.php in Schneider Electric U.motion Builder …Jul 3, 2018›
CVE-2018-7766HIGH
8.8
The vulnerability exists within processing of track_getdata.php in Schneider Electric U.motion Build…Jul 3, 2018›
CVE-2018-7765HIGH
8.8
The vulnerability exists within processing of track_import_export.php in Schneider Electric U.motion…Jul 3, 2018›
CVE-2018-7240HIGH
8.8
A vulnerability exists in Schneider Electric's Modicon Quantum in all versions of the communication …Apr 18, 2018›
CVE-2018-7230HIGH
8.8
A XML external entity (XXE) vulnerability exists in the import.cgi of the web interface component of…Mar 9, 2018›
CVE-2017-7969HIGH
8.8
A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Elect…Sep 26, 2017›
CVE-2017-7966HIGH
8.8
A DLL Hijacking vulnerability in the programming software in Schneider Electric's SoMachine HVAC v2.…Jun 7, 2017›
CVE-2017-5156HIGH
8.8
A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access An…Apr 20, 2017›
CVE-2016-5809HIGH
8.8
An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX se…Feb 13, 2017›
CVE-2017-9627HIGH
8.6
An Uncontrolled Resource Consumption issue was discovered in Schneider Electric Wonderware ArchestrA…Jul 7, 2017›
CVE-2013-0664HIGH
8.5
The FactoryCast service on the Schneider Electric Quantum 140NOE77111 and 140NWM10000, M340 BMXNOE01…Apr 4, 2013›
CVE-2018-8872HIGH
8.1
In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, system calls read d…May 4, 2018›
CVE-2018-7236HIGH
8.1
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions pri…Mar 9, 2018›
CVE-2017-9963HIGH
8.1
A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Elect…Feb 12, 2018›
CVE-2018-7771HIGH
8.0
The vulnerability exists within processing of editscript.php in Schneider Electric U.motion Builder …Jul 3, 2018›
CVE-2022-42973HIGH
7.8
A CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause local privilege escal…Feb 1, 2023›
CVE-2022-42972HIGH
7.8
A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cau…Feb 1, 2023›
CVE-2021-22808HIGH
7.8
A CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution when a mali…Jan 28, 2022›
CVE-2021-22807HIGH
7.8
A CWE-787: Out-of-bounds Write vulnerability exists that could cause arbitrary code execution when a…Jan 28, 2022›
CVE-2020-7523HIGH
7.8
Improper Privilege Management vulnerability exists in Schneider Electric Modbus Serial Driver (see s…Aug 31, 2020›
CVE-2018-7815HIGH
7.8
A Type Confusion (CWE-843) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold…Feb 6, 2019›
CVE-2018-7814HIGH
7.8
A Stack-based Buffer Overflow (CWE-121) vulnerability exists in Eurotherm by Schneider Electric GUIc…Feb 6, 2019›
CVE-2018-7813HIGH
7.8
A Type Confusion (CWE-843) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold…Feb 6, 2019›
CVE-2018-7799HIGH
7.8
A DLL hijacking vulnerability exists in Schneider Electric Software Update (SESU), all versions prio…Nov 2, 2018›
CVE-2018-7239HIGH
7.8
A DLL hijacking vulnerability exists in Schneider Electric's SoMove Software and associated DTM soft…Mar 9, 2018›
CVE-2017-9967HIGH
7.8
A security misconfiguration vulnerability exists in Schneider Electric's IGSS SCADA Software version…Feb 12, 2018›
CVE-2017-9961HIGH
7.8
A vulnerability exists in Schneider Electric's Pro-Face GP Pro EX version 4.07.000 that allows an at…Sep 26, 2017›
CVE-2017-9958HIGH
7.8
An improper access control vulnerability exists in Schneider Electric's U.motion Builder software ve…Sep 26, 2017›
CVE-2017-7968HIGH
7.8
An Incorrect Default Permissions issue was discovered in Schneider Electric Wonderware InduSoft Web …May 19, 2017›
CVE-2017-6033HIGH
7.8
A DLL Hijacking issue was discovered in Schneider Electric Interactive Graphical SCADA System (IGSS)…Apr 7, 2017›
CVE-2014-2380HIGH
7.8
Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encrypti…Aug 28, 2014›
CVE-2013-2824HIGH
7.8
Schneider Electric StruxureWare SCADA Expert Vijeo Citect 7.40, Vijeo Citect 7.20 through 7.30SP1, C…Feb 26, 2014›
CVE-2015-3977HIGH
7.7
Buffer overflow in Schneider Electric IMT25 Magnetic Flow DTM before 1.500.004 for the HART Protocol…Nov 15, 2015›
CVE-2021-30065HIGH
7.5
On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and …Apr 3, 2022›
CVE-2021-30063HIGH
7.5
On Schneider Electric ConneXium Tofino OPCLSM TCSEFM0000 before 03.23 and Belden Tofino Xenon Securi…Apr 3, 2022›
CVE-2021-30062HIGH
7.5
On Schneider Electric ConneXium Tofino OPCLSM TCSEFM0000 before 03.23 and Belden Tofino Xenon Securi…Apr 3, 2022›
CVE-2020-7524HIGH
7.5
Out-of-bounds Write vulnerability exists in Modicon M218 Logic Controller (V5.0.0.7 and prior) which…Aug 31, 2020›
CVE-2019-13537HIGH
7.5
The IEC870IP driver for AVEVA’s Vijeo Citect and Citect SCADA and Schneider Electric’s Power SCADA O…Jan 14, 2020›
CVE-2018-7792HIGH
7.5
A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M…Aug 29, 2018›
CVE-2018-7789HIGH
7.5
An Improper Check for Unusual or Exceptional Conditions vulnerability exists in Schneider Electric's…Aug 29, 2018›
CVE-2018-7783HIGH
7.5
Schneider Electric SoMachine Basic prior to v1.6 SP1 suffers from an XML External Entity (XXE) vulne…Jul 3, 2018›
CVE-2018-7779HIGH
7.5
In Schneider Electric Wiser for KNX V2.1.0 and prior, homeLYnk V2.0.1 and prior; and spaceLYnk V2.1.…Jul 3, 2018›
CVE-2017-6021HIGH
7.5
In Schneider Electric ClearSCADA 2014 R1 (build 75.5210) and prior, 2014 R1.1 (build 75.5387) and pr…May 14, 2018›
CVE-2018-7762HIGH
7.5
A vulnerability exists in the web services to process SOAP requests in Schneider Electric's Modicon …Apr 18, 2018›
CVE-2018-7759HIGH
7.5
A buffer overflow vulnerability exists in Schneider Electric's Modicon M340, Modicon Premium, Modico…Apr 18, 2018›
CVE-2018-7235HIGH
7.5
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions pri…Mar 9, 2018›
CVE-2018-7234HIGH
7.5
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions pri…Mar 9, 2018›
CVE-2017-9962HIGH
7.5
Schneider Electric's ClearSCADA versions released prior to August 2017 are susceptible to a memory a…Sep 26, 2017›
CVE-2017-9631HIGH
7.5
A Null Pointer Dereference issue was discovered in Schneider Electric Wonderware ArchestrA Logger, v…Jul 7, 2017›
CVE-2017-6017HIGH
7.5
A Resource Exhaustion issue was discovered in Schneider Electric Modicon M340 PLC BMXNOC0401, BMXNOE…Jun 30, 2017›
CVE-2017-6019HIGH
7.5
An issue was discovered in Schneider Electric Conext ComBox, model 865-1058, all firmware versions p…Apr 7, 2017›
CVE-2016-8374HIGH
7.5
An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all v…Feb 13, 2017›
CVE-2015-7375HIGH
7.5
Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code …Sep 25, 2015›
CVE-2015-7374HIGH
7.5
The Remote Agent component in Schneider Electric InduSoft Web Studio before 8.0 allows remote attack…Sep 25, 2015›
CVE-2015-0982HIGH
7.5
Buffer overflow in an unspecified DLL in Schneider Electric Pelco DS-NVs before 7.8.90 allows remote…Mar 14, 2015›
CVE-2014-9200HIGH
7.5
Stack-based buffer overflow in an unspecified DLL file in a DTM development kit in Schneider Electri…Feb 1, 2015›
CVE-2014-8514HIGH
7.5
Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 all…Dec 27, 2014›
CVE-2014-8513HIGH
7.5
Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 all…Dec 27, 2014›
CVE-2014-8512HIGH
7.5
Buffer overflow in an ActiveX control in Atx45.ocx in Schneider Electric ProClima before 6.1.7 allow…Dec 27, 2014›
CVE-2014-5399HIGH
7.5
SQL injection vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1…Aug 28, 2014›
CVE-2014-5397HIGH
7.5
Cross-site scripting (XSS) vulnerability in Schneider Electric Wonderware Information Server (WIS) P…Aug 28, 2014›
CVE-2012-0929HIGH
7.5
Multiple buffer overflows in Schneider Electric Modicon Quantum PLC allow remote attackers to cause …Jan 28, 2012›
CVE-2019-6834HIGH
7.3
A CWE-502: Deserialization of Untrusted Data vulnerability exists which could allow an attacker to e…Apr 13, 2022›
CVE-2015-1014HIGH
7.3
A successful exploit of these vulnerabilities requires the local user to load a crafted DLL file in …Mar 25, 2019›
CVE-2017-9956HIGH
7.3
An authentication bypass vulnerability exists in Schneider Electric's U.motion Builder software vers…Sep 26, 2017›
CVE-2017-7965HIGH
7.3
A buffer overflow vulnerability exists in Programming Software executable AlTracePrint.exe, in Schne…Jun 7, 2017›
CVE-2017-5155HIGH
7.3
An issue was discovered in Schneider Electric Wonderware Historian 2014 R2 SP1 P01 and earlier. Wond…Feb 13, 2017›
CVE-2016-4529HIGH
7.3
An unspecified ActiveX control in Schneider Electric SoMachine HVAC Programming Software for M171/M1…Jul 15, 2016›
CVE-2017-9970HIGH
7.2
A remote code execution vulnerability exists in Schneider Electric's StruxureOn Gateway versions 1.1…Feb 12, 2018›
CVE-2016-2278HIGH
7.2
Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.…Mar 2, 2016›
CVE-2011-3330HIGH
7.2
Buffer overflow in the UnitelWay Windows Device Driver, as used in Schneider Electric Unity Pro 6 an…Nov 4, 2011›
CVE-2017-9966HIGH
7.1
A privilege escalation vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise vers…Jan 2, 2018›
CVE-2016-8354HIGH
7.0
An issue was discovered in Schneider Electric Unity PRO prior to V11.1. Unity projects can be compil…Feb 13, 2017›