schneider-electric

765 tracked vulnerabilities.

CVE-2024-37040 MEDIUM
Sage RTU Firmware < c3414-500-s02k5_p9 - Authenticated Denial of Service via Malformed HTTP Request
Jun 12, 2024
CVSS 5.4
EPSS 0.00
CVE-2024-37039 MEDIUM
Sage RTU Firmware < c3414-500-s02k5_p9 - Denial of Service via Crafted HTTP Request
Jun 12, 2024
CVSS 5.9
EPSS 0.01
CVE-2024-37038 HIGH
Schneider Electric SAGE RTU < c3414-500-s02k5_p9 - Authenticated Unauthorized File/Firmware Upload
Jun 12, 2024
CVSS 7.5
EPSS 0.00
CVE-2024-37037 HIGH
Sage RTU Firmware < c3414-500-s02k5_p9 - Authenticated Path Traversal via Crafted HTTP Request
Jun 12, 2024
CVSS 8.1
EPSS 0.01
CVE-2024-37036 CRITICAL
Sage RTU Firmware < c3414-500-s02k5_p8 - Authentication Bypass via Malformed POST Request
Jun 12, 2024
CVSS 9.8
EPSS 0.00
CVE-2024-5313 MEDIUM
EVlink Home Firmware - Exposure of SSH Interface to Unauthorized Network Access
Jun 12, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-5056 MEDIUM
Modicon M340 Firmware - Files or Directories Accessible to External Parties
Jun 12, 2024
CVSS 6.5
EPSS 0.00
CVE-2023-6409 HIGH
EcoStruxure Control Expert - Info Disclosure
Feb 14, 2024
CVSS 7.7
EPSS 0.00
CVE-2023-6408 HIGH
Schneider Electric EcoStruxure Control Expert and Process Expert - Denial of Service via Man-in-the-Middle Attack
Feb 14, 2024
CVSS 8.1
EPSS 0.00
CVE-2023-27975 HIGH
EcoStruxure Control Expert < 16.0 and EcoStruxure Process Expert < 2023 - Unauthorized Access via Memory Tampering
Feb 14, 2024
CVSS 7.1
EPSS 0.00
CVE-2023-7032 HIGH
Easergy Studio < 9.3.5 - Authenticated Privilege Escalation via Deserialization of Untrusted Data
Jan 09, 2024
CVSS 7.8
EPSS 0.00
CVE-2023-6407 MEDIUM
Schneider Electric Easy UPS Online Monitoring Software <= 2.6-ga-01-23248 - Path Traversal
Dec 14, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-5630 MEDIUM
Schneider-electric Eb450 Firmware - Download Without Integrity Check
Dec 14, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-5629 HIGH
Schneider-electric Eb450 Firmware < 2.7.0 - Open Redirect
Dec 14, 2023
CVSS 8.2
EPSS 0.00
CVE-2023-6032 MEDIUM
Network Management Card - Path Traversal
Nov 15, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-5987 MEDIUM
EcoStruxure Power Monitoring Expert - Cross-Site Scripting
Nov 15, 2023
CVSS 6.1
EPSS 0.00
CVE-2023-5986 HIGH
EcoStruxure Power Monitoring Expert - Open Redirect via URL-Encoded Input
Nov 15, 2023
CVSS 8.2
EPSS 0.00
CVE-2023-5985 MEDIUM
ION8650 and ION8800 Firmware - Authenticated Stored Cross-Site Scripting via Modified System Values
Nov 15, 2023
CVSS 4.8
EPSS 0.00
CVE-2023-5984 HIGH
ION8650 and ION8800 Firmware - Authenticated Firmware Upload Without Integrity Check
Nov 15, 2023
CVSS 7.2
EPSS 0.00
CVE-2023-5399 CRITICAL
Schneider Electric SpaceLogic C-Bus Toolkit < 1.16.4 - Path Traversal via File Command
Oct 04, 2023
CVSS 9.8
EPSS 0.25
CVE-2023-5391 CRITICAL
EcoStruxure Power Monitoring Expert - Remote Code Execution via Untrusted Data Deserialization
Oct 04, 2023
CVSS 9.8
EPSS 0.00
CVE-2023-5402 CRITICAL
C-Bus Toolkit < 1.16.3 - Remote Code Execution via Transfer Command
Oct 04, 2023
CVSS 9.8
EPSS 0.00
CVE-2023-4516 HIGH
Schneider Electric IGSS Update Service - Missing Authentication Code Execution
Sep 14, 2023
CVSS 7.8
EPSS 0.00
CVE-2023-3953 MEDIUM
pro-face GP-Pro EX < 4.09.500 - Authenticated Memory Corruption via Tampered Log File
Aug 09, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-29414 HIGH
Schneider Electric Accutech Manager < 2.7 - Local Privilege Escalation via Buffer Overflow
Jul 12, 2023
CVSS 7.8
EPSS 0.00