AID
Automation
Information Directory
HomeCVE FeedBrands
AID
Automation Information Directory
CVE data sourced from NIST NVD · Documentation links from official sources
Home›Brands›Schneider Electric
SC
Platform

Schneider Electric

Global energy management and automation leader. Products include Modicon M340/M580 PLCs, Altivar drives, Harmony HMI, and EcoStruxure platform.

https://www.se.com/ww/en/work/products/industrial-automation-and-control/ →
216
Total CVEs
10
Resources
42
CRIT
98
HIGH
68
MED
8
LOW
CVEsCVEsSpecsTech SpecsDocsTech DocsImplImplementationsExamplesExamples
68 / 216
CVE-2017-9964MEDIUM

A Path Traversal issue was discovered in Schneider Electric Pelco VideoXpert Enterprise all versions prior to 2.1. By sniffing communications, an unauthorized person can execute a directory traversal attack resulting in authentication bypass or session hijack.

Jan 2, 2018
6.9
CVE-2015-3940MEDIUM

Untrusted search path vulnerability in Schneider Electric Wonderware System Platform before 2014 R2 Patch 01 allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.

Aug 4, 2015
6.9
CVE-2014-9206MEDIUM

Stack-based buffer overflow in Device Type Manager (DTM) 3.1.6 and earlier for Schneider Electric Invensys SRD Control Valve Positioner devices 960 and 991 allows local users to gain privileges via a malformed DLL file.

Mar 14, 2015
6.9
CVE-2014-0759MEDIUM

Unquoted Windows search path vulnerability in Schneider Electric Floating License Manager 1.0.0 through 1.4.0 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character.

Feb 28, 2014
6.9
CVE-2013-2796MEDIUM

Schneider Electric Vijeo Citect 7.20 and earlier, CitectSCADA 7.20 and earlier, and PowerLogic SCADA 7.20 and earlier allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Aug 9, 2013
6.9
CVE-2021-30066MEDIUM

On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an arbitrary firmware image can be loaded because firmware signature verification (for a USB stick) can be bypassed. NOTE: this issue exists because of an incomplete fix of CVE-2017-11400.

Apr 3, 2022
6.8
CVE-2021-30061MEDIUM

On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, physically proximate attackers can execute code via a crafted file on a USB stick.

Apr 3, 2022
6.8
CVE-2017-8371MEDIUM

Schneider Electric StruxureWare Data Center Expert before 7.4.0 uses cleartext RAM storage for passwords, which might allow remote attackers to obtain sensitive information via unspecified vectors.

Apr 30, 2017
6.8
CVE-2015-8561MEDIUM

The F1BookView ActiveX control in F1 Bookview in Schneider Electric ProClima before 6.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted integer value to the (1) AttachToSS, (2) CopyAll, (3) CopyRange, (4) CopyRangeEx, or (5) SwapTable method, a different vulnerability than CVE-2015-7918.

Dec 15, 2015
6.8
CVE-2015-7918MEDIUM

Multiple buffer overflows in the F1BookView ActiveX control in F1 Bookview in Schneider Electric ProClima before 6.2 allow remote attackers to execute arbitrary code via the (1) Attach, (2) DefinedName, (3) DefinedNameLocal, (4) ODBCPrepareEx, (5) ObjCreatePolygon, (6) SetTabbedTextEx, or (7) SetValidationRule method, a different vulnerability than CVE-2015-8561.

Dec 15, 2015
6.8
CVE-2014-0779MEDIUM

The PLC driver in ServerMain.exe in the Kepware KepServerEX 4 component in Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R2 build 71.4165, 2010 R2.1 build 71.4325, 2010 R3 build 72.4560, 2010 R3.1 build 72.4644, 2013 R1 build 73.4729, 2013 R1.1 build 73.4832, 2013 R1.1a build 73.4903, 2013 R1.2 build 73.4955, and 2013 R2 build 74.5094 allows remote attackers to cause a denial of service (application crash) via a crafted OPF file (aka project file).

Mar 14, 2014
6.8
CVE-2014-0774MEDIUM

Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 - 3.35, TLXCDSTOFS33 - 3.35, TLXCDLUOFS33 - 3.35, TLXCDLTOFS33 - 3.35, and TLXCDLFOFS33 - 3.35 allows local users to gain privileges via vectors involving a malformed configuration file.

Feb 28, 2014
6.8
CVE-2013-0663MEDIUM

Cross-site request forgery (CSRF) vulnerability on the Schneider Electric Quantum 140NOE77111, 140NOE77101, and 140NWM10000; M340 BMXNOC0401, BMXNOE0100x, and BMXNOE011xx; and Premium TSXETY4103, TSXETY5103, and TSXWMY100 PLC modules allows remote attackers to hijack the authentication of arbitrary users for requests that execute commands, as demonstrated by modifying HTTP credentials.

Apr 4, 2013
6.8
CVE-2018-7522MEDIUM

In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, when a system call is made, registers are stored to a fixed memory location. Modifying the data in this location could allow attackers to gain supervisor-level access and control system states.

May 4, 2018
6.7
CVE-2017-9969MEDIUM

An information disclosure vulnerability exists in Schneider Electric's IGSS Mobile application version 3.01 and prior. Passwords are stored in clear text in the configuration which can result in exposure of sensitive information.

Feb 12, 2018
6.7
CVE-2017-7907MEDIUM

An Improper XML Parser Configuration issue was discovered in Schneider Electric Wonderware Historian Client 2014 R2 SP1 and prior. An improperly restricted XML parser (with improper restriction of XML external entity reference, or XXE) may allow an attacker to enter malicious input through the application which could cause a denial of service or disclose file contents from a server or connected network.

May 19, 2017
6.6
CVE-2013-0687MEDIUM

The installer routine in Schneider Electric MiCOM S1 Studio uses world-writable permissions for executable files, which allows local users to modify the service or the configuration files, and consequently gain privileges or trigger incorrect protective-relay operation, via a Trojan horse executable file.

Apr 18, 2013
6.6
CVE-2018-7770MEDIUM

The vulnerability exists within processing of sendmail.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The applet allows callers to select arbitrary files to send to an arbitrary email address.

Jul 3, 2018
6.5
CVE-2018-7758MEDIUM

A denial of service vulnerability exists in Schneider Electric's MiCOM Px4x (P540 range excluded) with legacy Ethernet board, MiCOM P540D Range with Legacy Ethernet Board, and MiCOM Px4x Rejuvenated could lose network communication in case of TCP/IP open requests on port 20000 (DNP3oE) if an older TCI/IP session is still open with identical IP address and port number.

Apr 18, 2018
6.5
CVE-2017-7971MEDIUM

A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the use of outdated cipher suites and improper verification of peer SSL Certificate.

Sep 26, 2017
6.5
CVE-2017-7970MEDIUM

A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the ability to specify Arbitrary Server Target Nodes in connection requests to the Secure Gateway and Server components.

Sep 26, 2017
6.5
CVE-2017-6030MEDIUM

A Predictable Value Range from Previous Values issue was discovered in Schneider Electric Modicon PLCs Modicon M221, firmware versions prior to Version 1.5.0.0, Modicon M241, firmware versions prior to Version 4.0.5.11, and Modicon M251, firmware versions prior to Version 4.0.5.11. The affected products generate insufficiently random TCP initial sequence numbers that may allow an attacker to predict the numbers from previous values. This may allow an attacker to spoof or disrupt TCP connections.

Jun 30, 2017
6.5
CVE-2014-5413MEDIUM

Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 uses the MD5 algorithm for an X.509 certificate, which makes it easier for remote attackers to spoof servers via a cryptographic attack against this algorithm.

Sep 18, 2014
6.4
CVE-2014-5412MEDIUM

Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allows remote attackers to read database records by leveraging access to the guest account.

Sep 18, 2014
6.4
CVE-2018-7795MEDIUM

A Cross Protocol Injection vulnerability exists in Schneider Electric's PowerLogic (PM5560 prior to FW version 2.5.4) product. The vulnerability makes the product susceptible to cross site scripting attack on its web browser. User inputs can be manipulated to cause execution of java script code.

Aug 29, 2018
6.1
CVE-2018-7786MEDIUM

In Schneider Electric U.motion Builder software versions prior to v1.3.4, a cross site scripting (XSS) vulnerability exists which could allow injection of malicious scripts.

Jul 3, 2018
6.1
CVE-2017-5157MEDIUM

An issue was discovered in Schneider Electric homeLYnk Controller, LSS100100, all versions prior to V1.5.0. The homeLYnk controller is susceptible to a cross-site scripting attack. User inputs can be manipulated to cause execution of JavaScript code.

Feb 13, 2017
6.1
CVE-2016-4513MEDIUM

Cross-site scripting (XSS) vulnerability in the Schneider Electric PowerLogic PM8ECC module before 2.651 for PowerMeter 800 devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Jun 26, 2016
6.1
CVE-2012-0930MEDIUM

Cross-site scripting (XSS) vulnerability in Schneider Electric Modicon Quantum PLC allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Jan 28, 2012
6.1
CVE-2017-9968MEDIUM

A security misconfiguration vulnerability exists in Schneider Electric's IGSS Mobile application versions 3.01 and prior in which a lack of certificate pinning during the TLS/SSL connection establishing process can result in a man-in-the-middle attack.

Feb 12, 2018
5.9
CVE-2017-9965MEDIUM

An exposure of sensitive information vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2.0 and prior. Using a directory traversal attack, an unauthorized person can view web server files.

Jan 2, 2018
5.8
CVE-2015-3963MEDIUM

Wind River VxWorks before 5.5.1, 6.5.x through 6.7.x before 6.7.1.1, 6.8.x before 6.8.3, 6.9.x before 6.9.4.4, and 7.x before 7 ipnet_coreip 1.2.2.0, as used on Schneider Electric SAGE RTU devices before J2 and other devices, does not properly generate TCP initial sequence number (ISN) values, which makes it easier for remote attackers to spoof TCP sessions by predicting an ISN value.

Aug 4, 2015
5.8
CVE-2021-22809MEDIUM

A CWE-125:Out-of-Bounds Read vulnerability exists that could cause unintended data disclosure when a malicious *.gd1 configuration file is loaded into the GUIcon tool. Affected Product: Eurotherm by Schneider Electric GUIcon Version 2.0 (Build 683.003) and prior

Jan 28, 2022
5.5
CVE-2017-9959MEDIUM

A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system accepts reboot in session from unauthenticated users, supporting a denial of service condition.

Sep 26, 2017
5.5
CVE-2017-7972MEDIUM

A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the ability to escape out of remote PowerSCADA Anywhere applications and launch other processes.

Sep 26, 2017
5.5
CVE-2017-7967MEDIUM

All versions of VAMPSET software produced by Schneider Electric, prior to V2.2.189, are susceptible to a memory corruption vulnerability when a corrupted vf2 file is used. This vulnerability causes the software to halt or not start when trying to open the corrupted file. This vulnerability occurs when fill settings are intentionally malformed and is opened in a standalone state, without connection to a protection relay. This attack is not considered to be remotely exploitable. This vulnerability has no effect on the operation of the protection relay to which VAMPSET is connected. As Windows operating system remains operational and VAMPSET responds, it is able to be shut down through its normal closing protocol.

May 9, 2017
5.5
CVE-2015-6462MEDIUM

Reflected Cross-Site Scripting (nonpersistent) allows an attacker to craft a specific URL, which contains Java script that will be executed on the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H PLC client browser.

Mar 21, 2019
5.4
CVE-2015-6461MEDIUM

Remote file inclusion allows an attacker to craft a specific URL referencing the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H PLC web server, which, when launched, will result in the browser redirecting to a remote file via a Java script loaded with the web page.

Mar 21, 2019
5.4
CVE-2018-7787MEDIUM

In Schneider Electric U.motion Builder software versions prior to v1.3.4, this vulnerability is due to improper validation of input of context parameter in HTTP GET request.

Jul 3, 2018
5.3
CVE-2018-7244MEDIUM

An information disclosure vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to obtain sensitive device information if network access was obtained.

Apr 18, 2018
5.3
CVE-2018-7227MEDIUM

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow retrieving of specially crafted URLs without authentication that can reveal sensitive information to an attacker.

Mar 9, 2018
5.3
CVE-2017-9960MEDIUM

An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system response to error provides more information than should be available to an unauthenticated user.

Sep 26, 2017
5.3
CVE-2017-6032MEDIUM

A Violation of Secure Design Principles issue was discovered in Schneider Electric Modicon Modbus Protocol. The Modicon Modbus protocol has a session-related weakness making it susceptible to brute-force attacks.

Jun 30, 2017
5.3
CVE-2017-5160MEDIUM

An Inadequate Encryption Strength issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The software will connect via Transport Layer Security without verifying the peer's SSL certificate properly.

Apr 20, 2017
5.3
CVE-2016-8367MEDIUM

An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all versions, Magelis GTU Universal Panel, all versions, Magelis STO5xx and STU Small panels, all versions, Magelis XBT GH Advanced Hand-held Panels, all versions, Magelis XBT GK Advanced Touchscreen Panels with Keyboard, all versions, Magelis XBT GT Advanced Touchscreen Panels, all versions, and Magelis XBT GTW Advanced Open Touchscreen Panels (Windows XPe). An attacker can open multiple connections to a targeted web server and keep connections open preventing new connections from being made, rendering the web server unavailable during an attack.

Feb 13, 2017
5.3
CVE-2015-6485MEDIUM

Schneider Electric Telvent Sage 2300 RTUs with firmware before C3413-500-S01, and LANDAC II-2, Sage 1410, Sage 1430, Sage 1450, Sage 2400, and Sage 3030M RTUs with firmware before C3414-500-S02J2, allow remote attackers to obtain sensitive information from device memory by reading a padding field of an Ethernet packet.

Mar 12, 2016
5.3
CVE-2015-3962MEDIUM

Schneider Electric StruxureWare Building Expert MPM before 2.15 does not use encryption for the client-server data stream, which allows remote attackers to discover credentials by sniffing the network.

Sep 18, 2015
5.0
CVE-2015-0997MEDIUM

Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 provide an HMI user interface that lists all valid usernames, which makes it easier for remote attackers to obtain access via a brute-force password-guessing attack.

Mar 29, 2015
5.0
CVE-2014-0789MEDIUM

Multiple buffer overflows in the OPC Automation 2.0 Server Object ActiveX control in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 3.5 and earlier, TLXCDSTOFS33 3.5 and earlier, TLXCDLUOFS33 3.5 and earlier, TLXCDLTOFS33 3.5 and earlier, and TLXCDLFOFS33 3.5 and earlier allow remote attackers to cause a denial of service via long arguments to unspecified functions.

Apr 4, 2014
5.0
CVE-2013-6143MEDIUM

The Schneider Electric Telvent SAGE 3030 RTU with firmware C3413-500-001D3_P4 and C3413-500-001F0_PB allows remote attackers to cause a denial of service (temporary outage and CPU consumption) via malformed DNP3 traffic.

Jan 31, 2014
5.0
CVE-2013-2763MEDIUM

The Schneider Electric M340 PLC modules allow remote attackers to cause a denial of service (resource consumption) via unspecified vectors. NOTE: the vendor reportedly disputes this issue because it "could not be duplicated" and "an attacker could not remotely exploit this observed behavior to deny PLC control functions.

Apr 4, 2013
5.0
CVE-2011-4036MEDIUM

Directory traversal vulnerability in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier allows remote attackers to read arbitrary files via unspecified vectors.

Dec 2, 2011
5.0
CVE-2018-7824MEDIUM

An Externally Controlled Reference to a Resource (CWE-610) vulnerability exists in Schneider Electric Modbus Serial Driver (For 64-bit Windows OS:V3.17 IE 37 and prior , For 32-bit Windows OS:V2.17 IE 27 and prior, and as part of the Driver Suite version:V14.12 and prior) which could allow write access to system files available only to users with SYSTEM privilege or other important user files.

May 22, 2019
4.9
CVE-2014-5411MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

Sep 18, 2014
4.9
CVE-2020-7520MEDIUM

A CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability exists in Schneider Electric Software Update (SESU), V2.4.0 and prior, which could cause execution of malicious code on the victim's machine. In order to exploit this vulnerability, an attacker requires privileged access on the engineering workstation to modify a Windows registry key which would divert all traffic updates to go through a server in the attacker's possession. A man-in-the-middle attack is then used to complete the exploit.

Jul 23, 2020
4.7
CVE-2011-5163MEDIUM

Buffer overflow in an unspecified third-party component in the Batch module for Schneider Electric CitectSCADA before 7.20 and Mitsubishi MX4 SCADA before 7.20 allows local users to execute arbitrary code via a long string in a login sequence.

Sep 15, 2012
4.6
CVE-2014-8390MEDIUM

Multiple buffer overflows in Schneider Electric VAMPSET before 2.2.168 allow local users to gain privileges via malformed disturbance-recording data in a (1) CFG or (2) DAT file.

Apr 3, 2015
4.4
CVE-2018-7776MEDIUM

The vulnerability exists within error.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. System information is returned to the attacker that contains sensitive data.

Jul 3, 2018
4.3
CVE-2018-7764MEDIUM

The vulnerability exists within runscript.php applet in Schneider Electric U.motion Builder software versions prior to v1.3.4. There is a directory traversal vulnerability in the processing of the 's' parameter of the applet.

Jul 3, 2018
4.3
CVE-2018-7763MEDIUM

The vulnerability exists within css.inc.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The 'css' parameter contains a directory traversal vulnerability.

Jul 3, 2018
4.3
CVE-2013-6142MEDIUM

DNP3Driver.exe in the DNP3 driver in Schneider Electric ClearSCADA 2010 R2 through 2010 R3.1 and SCADA Expert ClearSCADA 2013 R1 through 2013 R1.2 allows remote attackers to cause a denial of service (resource consumption) via IP packets containing errors that trigger event-journal messages.

Jan 15, 2014
4.3
CVE-2012-1990MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in Schneider Electric Kerweb before 3.0.1 and Kerwin before 6.0.1 allow remote attackers to inject arbitrary web script or HTML via (1) the evtvariablename parameter in an evts.xml action to kw.dll, (2) unspecified search fields, or (3) unspecified content-display fields.

May 22, 2012
4.3
CVE-2011-4263MEDIUM

Cross-site scripting (XSS) vulnerability in Schneider Electric PowerChute Business Edition before 8.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Dec 7, 2011
4.3
CVE-2011-4035MEDIUM

Cross-site scripting (XSS) vulnerability in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Dec 2, 2011
4.3
CVE-2011-4033MEDIUM

Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier, allows remote attackers to cause a denial of service via unspecified vectors.

Dec 2, 2011
4.3
CVE-2017-9637MEDIUM

Schneider Electric Ampla MES 6.4 provides capability to interact with data from third party databases. When connectivity to those databases is configured to use a SQL user name and password, an attacker may be able to sniff details from the connection string. Schneider Electric recommends that users of Ampla MES versions 6.4 and prior should upgrade to Ampla MES version 6.5 as soon as possible.

May 18, 2018
4.1
CVE-2014-5407MEDIUM

Multiple stack-based buffer overflows in Schneider Electric VAMPSET 2.2.136 and earlier allow local users to cause a denial of service (application halt) via a malformed (1) setting file or (2) disturbance recording file.

Sep 15, 2014
4.1
CVE-2013-2761MEDIUM

The Schneider Electric M340 BMXNOE01xx and BMXP3420xx PLC modules allow remote authenticated users to cause a denial of service (module crash) via crafted FTP traffic, as demonstrated by the FileZilla FTP client.

Apr 4, 2013
4.0
CVE ID ⇅Severity ↓CVSS ⇅DescriptionPublished ⇅
CVE-2017-9964MEDIUM
6.9
A Path Traversal issue was discovered in Schneider Electric Pelco VideoXpert Enterprise all versions…Jan 2, 2018›
CVE-2015-3940MEDIUM
6.9
Untrusted search path vulnerability in Schneider Electric Wonderware System Platform before 2014 R2 …Aug 4, 2015›
CVE-2014-9206MEDIUM
6.9
Stack-based buffer overflow in Device Type Manager (DTM) 3.1.6 and earlier for Schneider Electric In…Mar 14, 2015›
CVE-2014-0759MEDIUM
6.9
Unquoted Windows search path vulnerability in Schneider Electric Floating License Manager 1.0.0 thro…Feb 28, 2014›
CVE-2013-2796MEDIUM
6.9
Schneider Electric Vijeo Citect 7.20 and earlier, CitectSCADA 7.20 and earlier, and PowerLogic SCADA…Aug 9, 2013›
CVE-2021-30066MEDIUM
6.8
On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and …Apr 3, 2022›
CVE-2021-30061MEDIUM
6.8
On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and …Apr 3, 2022›
CVE-2017-8371MEDIUM
6.8
Schneider Electric StruxureWare Data Center Expert before 7.4.0 uses cleartext RAM storage for passw…Apr 30, 2017›
CVE-2015-8561MEDIUM
6.8
The F1BookView ActiveX control in F1 Bookview in Schneider Electric ProClima before 6.2 allows remot…Dec 15, 2015›
CVE-2015-7918MEDIUM
6.8
Multiple buffer overflows in the F1BookView ActiveX control in F1 Bookview in Schneider Electric Pro…Dec 15, 2015›
CVE-2014-0779MEDIUM
6.8
The PLC driver in ServerMain.exe in the Kepware KepServerEX 4 component in Schneider Electric Struxu…Mar 14, 2014›
CVE-2014-0774MEDIUM
6.8
Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server (OFS) …Feb 28, 2014›
CVE-2013-0663MEDIUM
6.8
Cross-site request forgery (CSRF) vulnerability on the Schneider Electric Quantum 140NOE77111, 140NO…Apr 4, 2013›
CVE-2018-7522MEDIUM
6.7
In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, when a system call …May 4, 2018›
CVE-2017-9969MEDIUM
6.7
An information disclosure vulnerability exists in Schneider Electric's IGSS Mobile application versi…Feb 12, 2018›
CVE-2017-7907MEDIUM
6.6
An Improper XML Parser Configuration issue was discovered in Schneider Electric Wonderware Historian…May 19, 2017›
CVE-2013-0687MEDIUM
6.6
The installer routine in Schneider Electric MiCOM S1 Studio uses world-writable permissions for exec…Apr 18, 2013›
CVE-2018-7770MEDIUM
6.5
The vulnerability exists within processing of sendmail.php in Schneider Electric U.motion Builder so…Jul 3, 2018›
CVE-2018-7758MEDIUM
6.5
A denial of service vulnerability exists in Schneider Electric's MiCOM Px4x (P540 range excluded) wi…Apr 18, 2018›
CVE-2017-7971MEDIUM
6.5
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCAD…Sep 26, 2017›
CVE-2017-7970MEDIUM
6.5
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCAD…Sep 26, 2017›
CVE-2017-6030MEDIUM
6.5
A Predictable Value Range from Previous Values issue was discovered in Schneider Electric Modicon PL…Jun 30, 2017›
CVE-2014-5413MEDIUM
6.4
Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 uses the MD5 algorit…Sep 18, 2014›
CVE-2014-5412MEDIUM
6.4
Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allows remote attack…Sep 18, 2014›
CVE-2018-7795MEDIUM
6.1
A Cross Protocol Injection vulnerability exists in Schneider Electric's PowerLogic (PM5560 prior to …Aug 29, 2018›
CVE-2018-7786MEDIUM
6.1
In Schneider Electric U.motion Builder software versions prior to v1.3.4, a cross site scripting (XS…Jul 3, 2018›
CVE-2017-5157MEDIUM
6.1
An issue was discovered in Schneider Electric homeLYnk Controller, LSS100100, all versions prior to …Feb 13, 2017›
CVE-2016-4513MEDIUM
6.1
Cross-site scripting (XSS) vulnerability in the Schneider Electric PowerLogic PM8ECC module before 2…Jun 26, 2016›
CVE-2012-0930MEDIUM
6.1
Cross-site scripting (XSS) vulnerability in Schneider Electric Modicon Quantum PLC allows remote att…Jan 28, 2012›
CVE-2017-9968MEDIUM
5.9
A security misconfiguration vulnerability exists in Schneider Electric's IGSS Mobile application ver…Feb 12, 2018›
CVE-2017-9965MEDIUM
5.8
An exposure of sensitive information vulnerability exists in Schneider Electric's Pelco VideoXpert E…Jan 2, 2018›
CVE-2015-3963MEDIUM
5.8
Wind River VxWorks before 5.5.1, 6.5.x through 6.7.x before 6.7.1.1, 6.8.x before 6.8.3, 6.9.x befor…Aug 4, 2015›
CVE-2021-22809MEDIUM
5.5
A CWE-125:Out-of-Bounds Read vulnerability exists that could cause unintended data disclosure when a…Jan 28, 2022›
CVE-2017-9959MEDIUM
5.5
A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in…Sep 26, 2017›
CVE-2017-7972MEDIUM
5.5
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCAD…Sep 26, 2017›
CVE-2017-7967MEDIUM
5.5
All versions of VAMPSET software produced by Schneider Electric, prior to V2.2.189, are susceptible …May 9, 2017›
CVE-2015-6462MEDIUM
5.4
Reflected Cross-Site Scripting (nonpersistent) allows an attacker to craft a specific URL, which con…Mar 21, 2019›
CVE-2015-6461MEDIUM
5.4
Remote file inclusion allows an attacker to craft a specific URL referencing the Schneider Electric …Mar 21, 2019›
CVE-2018-7787MEDIUM
5.3
In Schneider Electric U.motion Builder software versions prior to v1.3.4, this vulnerability is due …Jul 3, 2018›
CVE-2018-7244MEDIUM
5.3
An information disclosure vulnerability exists In Schneider Electric's 66074 MGE Network Management …Apr 18, 2018›
CVE-2018-7227MEDIUM
5.3
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions pri…Mar 9, 2018›
CVE-2017-9960MEDIUM
5.3
An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software ver…Sep 26, 2017›
CVE-2017-6032MEDIUM
5.3
A Violation of Secure Design Principles issue was discovered in Schneider Electric Modicon Modbus Pr…Jun 30, 2017›
CVE-2017-5160MEDIUM
5.3
An Inadequate Encryption Strength issue was discovered in Schneider Electric Wonderware InTouch Acce…Apr 20, 2017›
CVE-2016-8367MEDIUM
5.3
An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all v…Feb 13, 2017›
CVE-2015-6485MEDIUM
5.3
Schneider Electric Telvent Sage 2300 RTUs with firmware before C3413-500-S01, and LANDAC II-2, Sage …Mar 12, 2016›
CVE-2015-3962MEDIUM
5.0
Schneider Electric StruxureWare Building Expert MPM before 2.15 does not use encryption for the clie…Sep 18, 2015›
CVE-2015-0997MEDIUM
5.0
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 b…Mar 29, 2015›
CVE-2014-0789MEDIUM
5.0
Multiple buffer overflows in the OPC Automation 2.0 Server Object ActiveX control in Schneider Elect…Apr 4, 2014›
CVE-2013-6143MEDIUM
5.0
The Schneider Electric Telvent SAGE 3030 RTU with firmware C3413-500-001D3_P4 and C3413-500-001F0_PB…Jan 31, 2014›
CVE-2013-2763MEDIUM
5.0
The Schneider Electric M340 PLC modules allow remote attackers to cause a denial of service (resourc…Apr 4, 2013›
CVE-2011-4036MEDIUM
5.0
Directory traversal vulnerability in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHist…Dec 2, 2011›
CVE-2018-7824MEDIUM
4.9
An Externally Controlled Reference to a Resource (CWE-610) vulnerability exists in Schneider Electri…May 22, 2019›
CVE-2014-5411MEDIUM
4.9
Multiple cross-site scripting (XSS) vulnerabilities in Schneider Electric StruxureWare SCADA Expert …Sep 18, 2014›
CVE-2020-7520MEDIUM
4.7
A CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability exists in Schneider Ele…Jul 23, 2020›
CVE-2011-5163MEDIUM
4.6
Buffer overflow in an unspecified third-party component in the Batch module for Schneider Electric C…Sep 15, 2012›
CVE-2014-8390MEDIUM
4.4
Multiple buffer overflows in Schneider Electric VAMPSET before 2.2.168 allow local users to gain pri…Apr 3, 2015›
CVE-2018-7776MEDIUM
4.3
The vulnerability exists within error.php in Schneider Electric U.motion Builder software versions p…Jul 3, 2018›
CVE-2018-7764MEDIUM
4.3
The vulnerability exists within runscript.php applet in Schneider Electric U.motion Builder software…Jul 3, 2018›
CVE-2018-7763MEDIUM
4.3
The vulnerability exists within css.inc.php in Schneider Electric U.motion Builder software versions…Jul 3, 2018›
CVE-2013-6142MEDIUM
4.3
DNP3Driver.exe in the DNP3 driver in Schneider Electric ClearSCADA 2010 R2 through 2010 R3.1 and SCA…Jan 15, 2014›
CVE-2012-1990MEDIUM
4.3
Multiple cross-site scripting (XSS) vulnerabilities in Schneider Electric Kerweb before 3.0.1 and Ke…May 22, 2012›
CVE-2011-4263MEDIUM
4.3
Cross-site scripting (XSS) vulnerability in Schneider Electric PowerChute Business Edition before 8.…Dec 7, 2011›
CVE-2011-4035MEDIUM
4.3
Cross-site scripting (XSS) vulnerability in Schneider Electric Vijeo Historian 4.30 and earlier, Cit…Dec 2, 2011›
CVE-2011-4033MEDIUM
4.3
Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historia…Dec 2, 2011›
CVE-2017-9637MEDIUM
4.1
Schneider Electric Ampla MES 6.4 provides capability to interact with data from third party database…May 18, 2018›
CVE-2014-5407MEDIUM
4.1
Multiple stack-based buffer overflows in Schneider Electric VAMPSET 2.2.136 and earlier allow local …Sep 15, 2014›
CVE-2013-2761MEDIUM
4.0
The Schneider Electric M340 BMXNOE01xx and BMXP3420xx PLC modules allow remote authenticated users t…Apr 4, 2013›