Schneider Electric Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Schneider Electric products.
Products
- StruxureWare Data Center Expert15 vulnerabilities
- EcoStruxure Control Expert12 vulnerabilities
- Modicon M340 CPU (part numbers BMXP34*)12 vulnerabilities
- IGSS Data Server (IGSSdataServer.exe)10 vulnerabilities
- PowerChute™ Serial Shutdown10 vulnerabilities
- EcoStruxure Process Expert9 vulnerabilities
- IGSS Dashboard (DashBoard.exe)9 vulnerabilities
- Custom Reports (RMS16.dll)8 vulnerabilities
- IGSS Data Server(IGSSdataServer.exe)8 vulnerabilities
- EcoStruxure™ IT Data Center Expert7 vulnerabilities
- Modicon Controllers M241/M2517 vulnerabilities
- Modicon M580 CPU Safety (part numbers BMEP58*S and BMEH58*S)7 vulnerabilities
- Modicon Momentum Unity M1E Processor (171CBU*)7 vulnerabilities
- OPC UA Modicon Communication Module7 vulnerabilities
- Pro-face BLUE7 vulnerabilities
- X80 advanced RTU Communication Module7 vulnerabilities
- Data Center Expert6 vulnerabilities
- EcoStruxure Operator Terminal Expert6 vulnerabilities
- EcoStruxure™ Power Monitoring Expert (PME)6 vulnerabilities
- EcoStruxure™ Power Operation (EPO) Advanced Reporting and Dashboards Module6 vulnerabilities
- Modicon M580 CPU (part numbers BMEP* and BMEH*)6 vulnerabilities
- Sage 14106 vulnerabilities
- Sage 14306 vulnerabilities
- Sage 14506 vulnerabilities
- Sage 24006 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-12927HIGH | Generated title:Schneider Electric IGSS Definition Out-of-Bounds Write VulnerabilityCWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execution when a malicious CGF file is imported to IGSS Definition. CWE-787Jul 29, 2026 | CVSS8.4v4.0 | EPSS0.201% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-0667CRITICAL | Generated title:Schneider Electric RemoteConnect and SCADAPack Modbus TCP Improper Check for Unusual or Exceptional Conditions VulnerabilityCWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when communicating over the Modbus TCP protocol. CWE-754Jul 29, 2026 | CVSS9.3v4.0 | EPSS0.369% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-14354HIGH | Generated title:EcoStruxure Cybersecurity Admin Expert Insufficiently Protected Credentials Authentication BypassCWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorized credential modification, potentially leading to compromise of managed devices, when a local privileged attacker leverages weaknesses in the handling and protection of stored credentials within the application. CWE-522Jul 29, 2026 | CVSS8.7v4.0 | EPSS0.117% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-9718MEDIUM | Generated title:Schneider Electric PowerLogic P7 Reachable Assertion Denial of ServiceCWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-service condition, impacting system availability when a specially crafted request is sent to a vulnerable network-exposed service. CWE-617Jun 25, 2026 | CVSS6.9v4.0 | EPSS0.243% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-9717HIGH | Generated title:Schneider Electric PowerLogic P7 OS Command InjectionCWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution of commands with elevated privileges, impacting system integrity, confidentiality, and availability when a privileged authenticated user interacts with a vulnerable network-exposed service. CWE-78Jun 25, 2026 | CVSS8.6v4.0 | EPSS1.19% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-9716HIGH | Generated title:Schneider Electric PowerLogic P7 NULL Pointer Dereference Denial-of-Service VulnerabilityCWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuration functionality unavailable when malformed requests are received over exposed network interfaces. CWE-476Jun 25, 2026 | CVSS8.7v4.0 | EPSS0.263% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-9651MEDIUM | Generated title:Schneider Electric EasyLogic T150 and Saitel DP Incorrect Permission Assignment for Critical ResourceCWE-732 Incorrect Permission Assignment for Critical Resource vulnerability that could cause unauthorized disclosure of password hashes and potential account compromise when an attacker with privileged local access reads improperly protected system files. CWE-732Jun 25, 2026 | CVSS6.7v4.0 | EPSS0.109% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-9650HIGH | Generated title:Schneider Electric EasyLogic T150 and Saitel DP Insufficiently Protected Credentials VulnerabilityCWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenticated attacker accesses credentials stored within firmware or system files. With this credential an attacker could subsequently compromise the device if they have physical access to the device. CWE-522Jun 25, 2026 | CVSS8.7v4.0 | EPSS0.24% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-8045HIGH | Generated title:EcoStruxure IT Data Center Expert XML External Entity Information DisclosureCWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert user account submits crafted XML payloads to SOAP service endpoints. CWE-611Jun 9, 2026 | CVSS7.1v4.0 | EPSS0.233% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-6332MEDIUM | Clear Text Storage of Sensitive Information on EcoStruxure™ Machine Expert HVACCWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could result in revealing protected source code and loss of confidentiality, When an authorized attacker accesses the source code for editing or compiling it. CWE-312May 14, 2026 | CVSS6.8v4.0 | EPSS0.125% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-6866HIGH | Initialization of a Resource with an Insecure Default vulnerability on EcoStruxure™ Panel ServerCWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in rare circumstances, enabling unauthorized authentication using known credentials. CWE-1188May 12, 2026 | CVSS8.2v4.0 | EPSS0.291% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-6865HIGH | Improper Limitation of a Pathname to a Restricted Directory Vulnerability on Multiple ProductsCWE-22: Improper Limitation of a Pathname to a Restricted Directory (“Path Traversal”) vulnerability that could cause unauthorized access to sensitive files when user-supplied input is improperly handled during server-side file path processing. CWE-22May 12, 2026 | CVSS7.1v4.0 | EPSS0.303% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-4827HIGH | Insufficient Entropy vulnerability on Multiple ProductsCWE‑331: Insufficient Entropy vulnerability exists that could lead to unauthorized access when an attacker on the network can exploit weaknesses in session‑management protections. CWE-331May 12, 2026 | CVSS8.7v4.0 | EPSS0.312% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Generated title:Buffer Overflow in Schneider Electric PowerChute Serial Shutdown Web Admin InterfaceCWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information to be exposed when a Web Admin user executes a malicious file provided by an attacker. CWE-532Apr 14, 2026 | CVSS2.4v4.0 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-2400MEDIUM | Generated title:Schneider Electric PowerChute Serial Shutdown CRLF Injection VulnerabilityCWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists that could cause application user credentials to reset when a Web Admin user alters the POST /setPCBEDesc request payload. CWE-93Apr 14, 2026 | CVSS5.3v4.0 | EPSS0.23% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-2403MEDIUM | Generated title:Schneider Electric PowerChute Serial Shutdown Improper Input Validation VulnerabilityCWE-1284 Improper Validation of Specified Quantity in Input vulnerability exists that could cause Event and Data Log truncation impacting log integrity when a Web Admin user alters the POST /logsettings request payload. CWE-1284Apr 14, 2026 | CVSS5.3v4.0 | EPSS0.17% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-2405MEDIUM | Generated title:Schneider Electric PowerChute Serial Shutdown Uncontrolled Resource Consumption Denial of ServiceCWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting zip file creation and denial of service when a Web Admin user floods the system with POST /helpabout requests. CWE-400Apr 14, 2026 | CVSS5.3v4.0 | EPSS0.245% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-2402MEDIUM | Generated title:Schneider Electric PowerChute Serial Shutdown Improper Restriction of Excessive Authentication Attempts VulnerabilityCWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to gain access to the user account by performing an arbitrary number of authentication attempts with different credentials on a sequence of requests to multiple endpoints. CWE-307Apr 14, 2026 | CVSS6.9v4.0 | EPSS0.274% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-2404MEDIUM | Generated title:Schneider Electric PowerChute Serial Shutdown Log Injection VulnerabilityCWE-116 Improper Encoding or Escaping of Output vulnerability exists that could cause log injection and forged log when an attacker alters the POST /j_security check request payload. CWE-116Apr 14, 2026 | CVSS6.9v4.0 | EPSS0.186% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-2399MEDIUM | Generated title:Schneider Electric PowerChute Serial Shutdown Path Traversal VulnerabilityCWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause critical files overwritten with text data when a Web Admin user alters the POST /REST/upssleep request payload. CWE-22Apr 14, 2026 | CVSS6.9v4.0 | EPSS0.204% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-4832MEDIUM | Generated title:Schneider Electric Easergy MiCOM Hard-coded Credentials VulnerabilityCWE-798 Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to sensitive device information when an unauthenticated attacker is able to interrogate the SNMP port. CWE-798Apr 14, 2026 | CVSS6.9v4.0 | EPSS0.271% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-2273HIGH | Generated title:EcoStruxure Automation Expert Code Injection via Malicious Project FileCWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untrusted commands on the engineering workstation which could result in a limited compromise of the workstation and a potential loss of Confidentiality, Integrity and Availability of the subsequent system when an authenticated user opens a malicious project file. CWE-94Mar 10, 2026 | CVSS7.2v4.0 | EPSS0.227% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-1286HIGH | Generated title:EcoStruxure Foxboro DCS Deserialization of Untrusted Data Remote Code ExecutionCWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote code execution on workstation when an admin authenticated user opens a malicious project file. CWE-502Mar 10, 2026 | CVSS7.0v4.0 | EPSS0.315% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-13902MEDIUM | Generated title:Schneider Electric Modicon Controllers M241/M251/M258/LMC058 Stored Cross-Site ScriptingCWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause condition where authenticated attackers can have a victim’s browser run arbitrary JavaScript when the victim hovers over a maliciously crafted element on a web server containing the injected payload. CWE-79Mar 10, 2026 | CVSS5.1v4.0 | EPSS0.225% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-13901MEDIUM | Generated title:Schneider Electric Modicon M241/M251/M262 Machine Expert Protocol Denial of ServiceCWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of Service on Machine Expert protocol when an unauthenticated attacker sends malicious payload to occupy active communication channels. CWE-404Mar 10, 2026 | CVSS6.9v4.0 | EPSS0.455% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |