schneider-electric

765 tracked vulnerabilities.

CVE-2019-6852 HIGH
Modicon Controllers - Info Disclosure
Nov 20, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-6851 HIGH
Schneider Electric Modicon M580, M340, Premium, Quantum - File and Directory Information Exposure via TFTP Protocol
Oct 29, 2019
CVSS 7.5
EPSS 0.02
CVE-2019-6850 HIGH
Modicon M580/BMENOC - Info Disclosure
Oct 29, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-6849 HIGH
Modicon M580,BMENOC 0311,BMENOC 0321 - Info Disclosure
Oct 29, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-6848 HIGH
Modicon M580 and BMENOC - Denial of Service via REST API
Oct 29, 2019
CVSS 8.6
EPSS 0.03
CVE-2019-6847 MEDIUM
Modicon M580, M340, BMxCRA, and 140CRA Firmware - Denial of Service via FTP Firmware Upgrade
Oct 29, 2019
CVSS 4.9
EPSS 0.00
CVE-2019-6846 MEDIUM
Modicon M580, M340, BMxCRA, and 140CRA Firmware - Cleartext Transmission of Sensitive Information via FTP
Oct 29, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-6845 HIGH
Modicon M580, M340, Premium, Quantum - Cleartext Transmission of Sensitive Information via Modbus TCP
Oct 29, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-6844 MEDIUM
Modicon M580, M340, BMxCRA and 140CRA Firmware - Denial of Service via Invalid Web Server Image in FTP Firmware Upgrade
Oct 29, 2019
CVSS 4.9
EPSS 0.00
CVE-2019-6843 MEDIUM
Modicon M580, M340, BMxCRA, and 140CRA - Denial of Service via Empty Firmware Package Upgrade
Oct 29, 2019
CVSS 4.9
EPSS 0.00
CVE-2019-6842 MEDIUM
Modicon M580, M340, BMxCRA, and 140CRA Firmware - Denial of Service via FTP Firmware Upgrade
Oct 29, 2019
CVSS 4.9
EPSS 0.00
CVE-2019-6841 MEDIUM
Modicon M580, M340, BMxCRA, and 140CRA - Denial of Service via FTP Firmware Upgrade
Oct 29, 2019
CVSS 4.9
EPSS 0.03
CVE-2019-6840 CRITICAL
Schneider Electric U.motion Server - Format String
Sep 17, 2019
CVSS 9.8
EPSS 0.01
CVE-2019-6839 HIGH
Schneider Electric U.motion Server - Unrestricted File Upload
Sep 17, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-6838 MEDIUM
U.motion Server - Incorrect Authorization
Sep 17, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-6837 CRITICAL
U.motion Server Firmware < 1.3.7 - Server-Side Request Forgery via URL Manipulation
Sep 17, 2019
CVSS 9.1
EPSS 0.00
CVE-2019-6836 HIGH
U.motion Server Firmware < 1.3.7 - Incorrect Authorization
Sep 17, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-6835 MEDIUM
U.motion Server Firmware < 1.3.7 - Cross-Site Scripting
Sep 17, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-6833 MEDIUM
Magelis HMI Panels - Info Disclosure
Sep 17, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-6832 HIGH
spaceLYnk <2.4.0 & Wiser for KNX <2.4.0 - Auth Bypass
Sep 17, 2019
CVSS 8.3
EPSS 0.00
CVE-2019-6831 HIGH
BMXNOR0200H Ethernet / Serial RTU Module - Denial of Service via High Volume IEC 60870-5-104 Packets
Sep 17, 2019
CVSS 8.6
EPSS 0.01
CVE-2019-6830 MEDIUM
Modicon M580 Firmware < 2.80 - Denial of Service via HTTP Request
Sep 17, 2019
CVSS 5.9
EPSS 0.00
CVE-2019-6829 HIGH
Modicon M580 <V2.90, Modicon M340 <V3.10 - DoS
Sep 17, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-6828 HIGH
Modicon M580 < 2.90, M340 < 3.10, Premium, Quantum - Denial of Service via Modbus Coil/Register Read
Sep 17, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-6826 HIGH
SoMachine HVAC < 2.4.1 - Untrusted Search Path DLL Loading
Sep 17, 2019
CVSS 7.8
EPSS 0.00