Showing 1 vulnerability on this page for EcoStruxure™ Automation Expert

Signals CISA KEV Ransomware Nuclei
Schneider Electric vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Generated title:EcoStruxure Automation Expert Code Injection via Malicious Project File

CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untrusted commands on the engineering workstation which could result in a limited compromise of the workstation and a potential loss of Confidentiality, Integrity and Availability of the subsequent system when an authenticated user opens a malicious project file.

CWE-94Mar 10, 2026
CVSS7.2v4.0EPSS0.227%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX