schneider-electric

765 tracked vulnerabilities.

CVE-2020-7547 HIGH
EcoStruxure and SmartStruxure Power Monitoring and SCADA Software - Improper Access Control via Web Interface
Dec 01, 2020
CVSS 8.8
EPSS 0.00
CVE-2020-7546 MEDIUM
EcoStruxure and SmartStruxure Power Monitoring and SCADA Software - Cross-Site Scripting
Dec 01, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-7545 HIGH
EcoStruxure & SmartStruxure Power Monitoring/SCADA - Authenticated RCE via Web Access
Dec 01, 2020
CVSS 7.2
EPSS 0.00
CVE-2020-7533 CRITICAL
Schneider Electric Modicon M340 RCE via Crafted HTTP Requests
Dec 01, 2020
CVSS 9.8
EPSS 0.00
CVE-2020-7573 MEDIUM
EcoStruxure Building Operation WebReports 1.9-3.1 - Improper Access Control
Nov 19, 2020
CVSS 6.5
EPSS 0.00
CVE-2020-7572 HIGH
EcoStruxure Building Operation WebReports 1.9-3.1 - Authenticated XML External Entity Injection
Nov 19, 2020
CVSS 8.8
EPSS 0.00
CVE-2020-7571 MEDIUM
EcoStruxure Building Operation WebReports 1.9-3.1 - Reflected Cross-Site Scripting
Nov 19, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-7570 MEDIUM
EcoStruxure Building Operation WebReports 1.9-3.1 - Authenticated Stored Cross-Site Scripting
Nov 19, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-7569 HIGH
EcoStruxure Building Operation WebReports 1.9-3.1 - Authenticated Remote Code Execution via Unrestricted File Upload
Nov 19, 2020
CVSS 8.8
EPSS 0.01
CVE-2020-7568 MEDIUM
Modicon M221 Firmware - Exposure of Sensitive Information via Traffic Capture
Nov 19, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-7567 MEDIUM
Modicon M221 Firmware - Missing Encryption of Sensitive Data
Nov 19, 2020
CVSS 5.7
EPSS 0.00
CVE-2020-7566 HIGH
Modicon M221 Firmware - Small Space of Random Values in Encryption Key Generation
Nov 19, 2020
CVSS 7.3
EPSS 0.00
CVE-2020-7565 HIGH
Modicon M221 Firmware - Inadequate Encryption Strength
Nov 19, 2020
CVSS 7.3
EPSS 0.00
CVE-2020-7561 CRITICAL
Easergy T300 Firmware < 2.7 - Unauthenticated Improper Access Control
Nov 19, 2020
CVSS 9.8
EPSS 0.01
CVE-2020-7559 HIGH
EcoStruxure Control Expert - Classic Buffer Overflow via Modbus Request
Nov 19, 2020
CVSS 7.5
EPSS 0.01
CVE-2020-7558 HIGH
Interactive Graphical SCADA System < 14.0.0.20247 - Remote Code Execution via Malicious CGF File Import
Nov 19, 2020
CVSS 7.8
EPSS 0.01
CVE-2020-7557 HIGH
Interactive Graphical SCADA System < 14.0.0.20247 - Remote Code Execution via Malicious CGF File Import
Nov 19, 2020
CVSS 7.8
EPSS 0.01
CVE-2020-7556 HIGH
Interactive Graphical SCADA System < 14.0.0.20247 - Remote Code Execution via Malicious CGF File Import
Nov 19, 2020
CVSS 7.8
EPSS 0.01
CVE-2020-7555 HIGH
Interactive Graphical SCADA System < 14.0.0.20247 - Remote Code Execution via Malicious CGF File Import
Nov 19, 2020
CVSS 7.8
EPSS 0.01
CVE-2020-7554 HIGH
Interactive Graphical SCADA System < 14.0.0.20247 - Remote Code Execution via Malicious CGF File Import
Nov 19, 2020
CVSS 7.8
EPSS 0.01
CVE-2020-7553 HIGH
Interactive Graphical SCADA System < 14.0.0.20247 - Remote Code Execution via Malicious CGF File Import
Nov 19, 2020
CVSS 7.8
EPSS 0.01
CVE-2020-7552 HIGH
Interactive Graphical SCADA System < 14.0.0.20247 - Remote Code Execution via Malicious CGF File Import
Nov 19, 2020
CVSS 7.8
EPSS 0.01
CVE-2020-7551 HIGH
Interactive Graphical SCADA System < 14.0.0.20247 - Remote Code Execution via Malicious CGF File Import
Nov 19, 2020
CVSS 7.8
EPSS 0.01
CVE-2020-7550 HIGH
Interactive Graphical SCADA System < 14.0.0.20247 - Remote Code Execution via Malicious CGF File Import
Nov 19, 2020
CVSS 7.8
EPSS 0.01
CVE-2020-7544 HIGH
EcoStruxure Operator Terminal Expert Runtime - Privilege Escalation via Driver Interaction
Nov 19, 2020
CVSS 7.8
EPSS 0.00