schneider-electric

765 tracked vulnerabilities.

CVE-2020-7538 HIGH
EcoStruxure Control Expert - Denial of Service via Modbus Request
Nov 19, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-28213 HIGH
EcoStruxure Control Expert - Unauthorized Command Execution via Modbus Requests
Nov 19, 2020
CVSS 8.8
EPSS 0.00
CVE-2020-28212 CRITICAL
EcoStruxure Control Expert - Unauthenticated Brute Force Attack via Modbus
Nov 19, 2020
CVSS 9.8
EPSS 0.00
CVE-2020-28211 HIGH
EcoStruxure Control Expert - Incorrect Authorization via Debugger Memory Overwrite
Nov 19, 2020
CVSS 7.8
EPSS 0.00
CVE-2020-28209 HIGH
EcoStruxure Building Operation <3.1 - Privilege Escalation
Nov 19, 2020
CVSS 7.0
EPSS 0.00
CVE-2020-28210 MEDIUM
EcoStruxure Building Operation 2.0-3.1 - Cross-Site Scripting
Nov 19, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-7564 HIGH
Modicon M340, Quantum and Premium Legacy - Classic Buffer Overflow via FTP File Upload
Nov 18, 2020
CVSS 8.8
EPSS 0.01
CVE-2020-7563 HIGH
Modicon M340, Quantum and Premium Legacy - Out-of-bounds Write via FTP File Upload
Nov 18, 2020
CVSS 8.8
EPSS 0.01
CVE-2020-7562 HIGH
Modicon M340, Quantum, and Premium Legacy - Out-of-bounds Read via FTP File Upload
Nov 18, 2020
CVSS 8.1
EPSS 0.01
CVE-2020-7532 HIGH
SCADAPack x70 Security Administrator < 1.2.0 - Remote Code Execution via Malicious .SDB File
Sep 16, 2020
CVSS 7.8
EPSS 0.00
CVE-2020-7531 HIGH
SCADAPack 7x Remote Connect < 3.6.3.574 - Unauthenticated Arbitrary Code Execution via Executable Placement
Sep 16, 2020
CVSS 7.8
EPSS 0.00
CVE-2020-7530 HIGH
SCADAPack 7x Remote Connect < 3.6.3.574 - Improper Authorization
Sep 16, 2020
CVSS 8.8
EPSS 0.00
CVE-2020-7529 MEDIUM
SCADAPack 7x Remote Connect < 3.6.3.574 - Path Traversal via Crafted .RCZ File
Sep 16, 2020
CVSS 5.5
EPSS 0.00
CVE-2020-7528 HIGH
SCADAPack 7x Remote Connect < 3.6.3.574 - Remote Code Execution via Malicious .PRJ File
Sep 16, 2020
CVSS 7.8
EPSS 0.00
CVE-2020-7527 HIGH
SoMove < 2.8.1 - Incorrect Default Permissions
Aug 31, 2020
CVSS 7.8
EPSS 0.00
CVE-2020-7525 HIGH
Schneider Electric spaceLYnk and Wiser for KNX Firmware < 2.5.1 - Unauthenticated Password Brute-Force
Aug 31, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-7524 HIGH
Modicon M218 Firmware < 5.0.0.7 - Denial of Service via Crafted IPv4 Packet
Aug 31, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-7523 HIGH
Schneider Electric Modbus Serial Driver - Local Privilege Escalation via Service Invocation
Aug 31, 2020
CVSS 7.8
EPSS 0.00
CVE-2020-7522 CRITICAL
APC Easy UPS On-Line Software <= 2.0 - Path Traversal via SoundUploadServlet
Aug 31, 2020
CVSS 9.8
EPSS 0.01
CVE-2020-7521 CRITICAL
APC Easy UPS On-Line Software < 2.0 - Path Traversal via FileUploadServlet
Aug 31, 2020
CVSS 9.8
EPSS 0.01
CVE-2020-7520 MEDIUM
Schneider Electric Software Update < 2.4.0 - Open Redirect via Windows Registry Key Manipulation
Jul 23, 2020
CVSS 4.7
EPSS 0.00
CVE-2020-7519 HIGH
Easergy Builder <1.4.7.2 - Info Disclosure
Jul 23, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-7518 HIGH
Easergy Builder < 1.4.7.2 - Unauthenticated Project Configuration File Modification
Jul 23, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-7517 MEDIUM
Easergy Builder < 1.4.7.2 - Cleartext Storage of Sensitive Information
Jul 23, 2020
CVSS 5.5
EPSS 0.00
CVE-2020-7516 HIGH
Easergy Builder < 1.4.7.2 - Cleartext Storage of Sensitive Information in Memory
Jul 23, 2020
CVSS 7.8
EPSS 0.00