schneider-electric

765 tracked vulnerabilities.

CVE-2019-6813 HIGH
Schneider Electric Modicon M340 and BMXNOR0200H - Denial of Service via Truncated SNMP Packets
Sep 17, 2019
CVSS 7.5
EPSS 0.01
CVE-2019-6811 HIGH
Modicon Quantum 140 NOE771x1 Firmware <= 6.9 - Denial of Service via Oversized IP Fragmented Packet
Sep 17, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-6810 HIGH
BMXNOR0200H Ethernet / Serial RTU module - Unauthenticated Command Execution via IEC 60870-5-104 Protocol
Sep 17, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-6809 HIGH
Modicon M580 < 2.90, M340 < 3.10, Premium, Quantum - Denial of Service via Invalid Data Handling
Sep 17, 2019
CVSS 7.5
EPSS 0.01
CVE-2019-6827 HIGH
Interactive Graphical SCADA System < 12.0 - Out-of-bounds Write via mdb Database Manipulation
Jul 15, 2019
CVSS 7.8
EPSS 0.00
CVE-2019-6825 HIGH
ProClima < 8.0.0 - Uncontrolled Search Path Element via Malicious DLL Execution
Jul 15, 2019
CVSS 7.8
EPSS 0.00
CVE-2019-6824 CRITICAL
ProClima < 8.0.0 - Unauthenticated Remote Code Execution
Jul 15, 2019
CVSS 9.8
EPSS 0.09
CVE-2019-6823 CRITICAL
ProClima < 8.0.0 - Unauthenticated Remote Code Execution
Jul 15, 2019
CVSS 9.8
EPSS 0.10
CVE-2019-6822 HIGH
Zelio Soft 2 <= 5.2 - Remote Code Execution via Crafted Project File
Jul 15, 2019
CVSS 7.8
EPSS 0.01
CVE-2019-10981 HIGH
CitectSCADA 7.30-7.40 and Vijeo Citect 7.30-7.40 - Authenticated Credential Exposure
May 31, 2019
CVSS 7.8
EPSS 0.00
CVE-2019-6808 CRITICAL
Modicon Premium, Quantum, M340, M580 Firmware - Unauthenticated Remote Code Execution via Modbus Configuration Overwrite
May 22, 2019
CVSS 9.8
EPSS 0.02
CVE-2019-6807 HIGH
Modicon M580 < 2.90, M340 < 3.10, Quantum, and Premium - Denial of Service via Modbus Sensitive Variable Write
May 22, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-6806 HIGH
Modicon M580 < 2.90, M340 < 3.10, Quantum, and Premium - Information Exposure via Modbus SNMP Variable Read
May 22, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-6821 MEDIUM
Modicon M580 <V2.30 - Use After Free
May 22, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-6820 HIGH
Schneider Electric Modicon and PacDrive Firmware - Unauthenticated IP Configuration Modification via Ethernet Frame
May 22, 2019
CVSS 8.2
EPSS 0.00
CVE-2019-6819 HIGH
Modicon M340 < 3.01, M580 < 2.80, Quantum, and Premium - Denial of Service via Modbus Frame Handling
May 22, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-6816 CRITICAL
Modicon Quantum Firmware - Code Injection via Modbus Protocol
May 22, 2019
CVSS 9.1
EPSS 0.00
CVE-2019-6815 CRITICAL
Modicon Quantum Firmware - Denial of Service or Unauthorized Configuration Modification via Ethernet/IP Protocol
May 22, 2019
CVSS 9.1
EPSS 0.00
CVE-2019-6814 CRITICAL
NET55XX Encoder Firmware < 2.1.9.7 - Improper Authentication
May 22, 2019
CVSS 9.8
EPSS 0.67
CVE-2019-6812 HIGH
BMX-NOR-0200H Firmware - Use of Hard-coded Credentials via FTP Protocol
May 22, 2019
CVSS 7.2
EPSS 0.00
CVE-2019-10953 HIGH
ABB PM554-TP-ETH Firmware - Denial of Service via Network Packet Flood
Apr 17, 2019
CVSS 7.5
EPSS 0.00
CVE-2018-7794 HIGH
Modicon M580 < 2.80, M340 < 3.01, Quantum/TSX < 3.20 - Denial of Service via Modbus TCP Invalid Index
Jan 06, 2020
CVSS 7.5
EPSS 0.00
CVE-2018-7820 CRITICAL
APC UPS Network Management Card 2 AOS <6.5.6 - Info Disclosure
Sep 17, 2019
CVSS 9.8
EPSS 0.00
CVE-2018-7838 HIGH
Schneider Electric Modicon M580 and BMENOC0301 - Denial of Service via FTP CWD Command
Jul 15, 2019
CVSS 7.5
EPSS 0.00
CVE-2018-7857 HIGH
Modicon Premium, Quantum, M340, M580 Firmware - Denial of Service via Modbus Out-of-Bounds Variable Write
May 22, 2019
CVSS 7.5
EPSS 0.00