Schneider Electric Vulnerabilities and Affected Products
Vulnerabilities associated with EcoStruxure Process Expert.
Products
Clear product- StruxureWare Data Center Expert15 vulnerabilities
- EcoStruxure Control Expert12 vulnerabilities
- Modicon M340 CPU (part numbers BMXP34*)12 vulnerabilities
- IGSS Data Server (IGSSdataServer.exe)10 vulnerabilities
- PowerChute™ Serial Shutdown10 vulnerabilities
- EcoStruxure Process Expert9 vulnerabilities
- IGSS Dashboard (DashBoard.exe)9 vulnerabilities
- Custom Reports (RMS16.dll)8 vulnerabilities
- IGSS Data Server(IGSSdataServer.exe)8 vulnerabilities
- EcoStruxure™ IT Data Center Expert7 vulnerabilities
- Modicon Controllers M241/M2517 vulnerabilities
- Modicon M580 CPU Safety (part numbers BMEP58*S and BMEH58*S)7 vulnerabilities
- Modicon Momentum Unity M1E Processor (171CBU*)7 vulnerabilities
- OPC UA Modicon Communication Module7 vulnerabilities
- Pro-face BLUE7 vulnerabilities
- X80 advanced RTU Communication Module7 vulnerabilities
- Data Center Expert6 vulnerabilities
- EcoStruxure Operator Terminal Expert6 vulnerabilities
- EcoStruxure™ Power Monitoring Expert (PME)6 vulnerabilities
- EcoStruxure™ Power Operation (EPO) Advanced Reporting and Dashboards Module6 vulnerabilities
- Modicon M580 CPU (part numbers BMEP* and BMEH*)6 vulnerabilities
- Sage 14106 vulnerabilities
- Sage 14306 vulnerabilities
- Sage 14506 vulnerabilities
- Sage 24006 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-0327HIGH | CWE-269: Improper Privilege Management vulnerability exists for two services (of which one managing audit trail data and the other acting as server managing client request) that could cause a loss of Confidentiality, Integrity and Availability of engineering workstation when an attacker with standard privilege modifies the executable path of the windows services. To be exploited, services need to be restarted. CWE-269Feb 13, 2025 | CVSS8.5v4.0 | EPSS0.162% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-27975HIGH | CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized access to the project file in EcoStruxure Control Expert when a local user tampers with the memory of the engineering workstation. CWE-522Feb 14, 2024 | CVSS7.1v3.1 | EPSS0.15% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-6408HIGH | CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a denial of service and loss of confidentiality, integrity of controllers when conducting a Man in the Middle attack. CWE-924Feb 14, 2024 | CVSS8.1v3.1 | EPSS0.317% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-6409HIGH | CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to a project file protected with application password when opening the file with EcoStruxure Control Expert. CWE-798Feb 14, 2024 | CVSS7.7v3.1 | EPSS0.232% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-45789HIGH | A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session. Affected Products: EcoStruxure Control Expert (All Versions), EcoStruxure Process Expert (All Versions), Modicon M340 CPU - part numbers BMXP34* (All Versions), Modicon M580 CPU - part numbers BMEP* and BMEH* (All Versions), Modicon M580 CPU Safety - part numbers BMEP58*S and BMEH58*S (All Versions) CWE-294Jan 31, 2023 | CVSS8.1v3.1 | EPSS1.44% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-45788HIGH | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when a malicious project file is loaded onto the controller. Affected Products: EcoStruxure Control Expert (All Versions), EcoStruxure Process Expert (All Versions), Modicon M340 CPU - part numbers BMXP34* (All Versions), Modicon M580 CPU - part numbers BMEP* and BMEH* (All Versions), Modicon M580 CPU Safety - pa… CWE-754Jan 30, 2023 | CVSS7.5v3.1 | EPSS1.16% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-37300CRITICAL | A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode to the controller when communicating over Modbus. Affected Products: EcoStruxure Control Expert Including all Unity Pro versions (former name of EcoStruxure Control Expert) (V15.0 SP1 and prior), EcoStruxure Process Expert, Including all versions of EcoStruxure Hybrid DCS (former name of EcoStruxure Process Expert) (V2021 and prior), Modicon M340 CPU… CWE-640Sep 12, 2022 | CVSS9.8v3.1 | EPSS0.674% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-22797HIGH | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be deployed in an unauthorized location and may result in code execution on the engineering workstation when a malicious project file is loaded in the engineering software. Affected Product: EcoStruxure Control Expert (V15.0 SP1 and prior, including former Unity Pro), EcoStruxure Process Expert (2020 and prior, including former HDCS), SCADAPack RemoteC… CWE-22Mar 28, 2022 | CVSS7.8v3.1 | EPSS26.1% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-24323MEDIUM | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause a disruption of communication between the Modicon controller and the engineering software, when an attacker is able to intercept and manipulate specific Modbus response data. Affected Product: EcoStruxure Process Expert (V2021 and prior), EcoStruxure Control Expert (V15.0 SP1 and prior) CWE-754Mar 9, 2022 | CVSS5.3v3.1 | EPSS0.86% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |