schneider-electric

765 tracked vulnerabilities.

CVE-2018-2794 HIGH
Oracle Java SE <10 - Privilege Escalation
Apr 19, 2018
CVSS 7.7
EPSS 0.00
CVE-2018-2790 LOW
Oracle Java SE <10 - Info Disclosure
Apr 19, 2018
CVSS 3.1
EPSS 0.00
CVE-2018-7762 HIGH
Schneider Electric's Modicon - Buffer Overflow
Apr 18, 2018
CVSS 7.5
EPSS 0.01
CVE-2018-7761 CRITICAL
Schneider Electric Modicon M340, Premium, Quantum PLC, BMXNOR0200 - Remote Code Execution via HTTP Request Parser
Apr 18, 2018
CVSS 9.8
EPSS 0.01
CVE-2018-7760 CRITICAL
Schneider Electric Modicon M340 Premium Quantum PLC BMXNOR0200 - Authorization Bypass via CGI Function Requests
Apr 18, 2018
CVSS 9.8
EPSS 0.00
CVE-2018-7759 HIGH
Schneider Electric - Buffer Overflow
Apr 18, 2018
CVSS 7.5
EPSS 0.01
CVE-2018-7758 MEDIUM
Schneider Electric's MiCOM Px4x - DoS
Apr 18, 2018
CVSS 6.5
EPSS 0.00
CVE-2018-7246 CRITICAL
Schneider Electric 66074 MGE Network Management Card Cleartext Transmission of Sensitive Information
Apr 18, 2018
CVSS 9.8
EPSS 0.00
CVE-2018-7245 CRITICAL
Schneider Electric 66074 MGE Network Management Card Transverse - Unauthenticated Parameter Modification via Web Server
Apr 18, 2018
CVSS 9.1
EPSS 0.00
CVE-2018-7244 MEDIUM
Schneider Electric 66074 MGE Network Management Card - Sensitive Information Exposure
Apr 18, 2018
CVSS 5.3
EPSS 0.00
CVE-2018-7243 CRITICAL
Schneider Electric's 66074 MGE Network Management Card Transverse -...
Apr 18, 2018
CVSS 9.8
EPSS 0.02
CVE-2018-7242 CRITICAL
Schneider Electric Modicon and BMXNOR0200 - Inadequate Encryption Strength
Apr 18, 2018
CVSS 9.8
EPSS 0.00
CVE-2018-7241 CRITICAL
Schneider Electric Modicon and BMXNOR0200 Controllers - Use of Hard-coded Credentials
Apr 18, 2018
CVSS 9.8
EPSS 0.01
CVE-2018-7240 HIGH
Schneider Electric Modicon Quantum - Out-of-bounds Write via FTP Firmware Upgrade
Apr 18, 2018
CVSS 8.8
EPSS 0.00
CVE-2018-7239 HIGH
Schneider Electric SoMove and DTM Software < 2.6.2 - DLL Hijacking
Mar 09, 2018
CVSS 7.8
EPSS 0.00
CVE-2018-7238 CRITICAL
Schneider Electric Pelco Sarix Professional < 3.29.67 - Unauthenticated Remote Code Execution via Buffer Overflow
Mar 09, 2018
CVSS 9.8
EPSS 0.03
CVE-2018-7237 CRITICAL
Schneider Electric Pelco Sarix Professional < 3.29.67 - Unauthenticated Arbitrary File Deletion via set_param
Mar 09, 2018
CVSS 9.1
EPSS 0.01
CVE-2018-7236 HIGH
Schneider Electric Pelco Sarix Professional < 3.29.67 - Unauthenticated SSH Service Enablement via /login/bin/set_param
Mar 09, 2018
CVSS 8.1
EPSS 0.00
CVE-2018-7235 HIGH
Schneider Electric Pelco Sarix Professional < 3.29.67 - Arbitrary System File Download via system.download.sd_file
Mar 09, 2018
CVSS 7.5
EPSS 0.00
CVE-2018-7234 HIGH
Schneider Electric Pelco Sarix Professional < 3.29.67 - Arbitrary File Download via Improper Certificate Validation
Mar 09, 2018
CVSS 7.5
EPSS 0.00
CVE-2018-7233 CRITICAL
Schneider Electric Pelco Sarix Professional < 3.29.67 - OS Command Injection via model_name or mac_address Parameter
Mar 09, 2018
CVSS 9.8
EPSS 0.01
CVE-2018-7232 CRITICAL
Schneider Electric Pelco Sarix Professional < 3.29.67 - OS Command Injection
Mar 09, 2018
CVSS 9.8
EPSS 0.01
CVE-2018-7231 CRITICAL
Schneider Electric Pelco Sarix Professional < 3.29.67 - OS Command Injection via system.opkg.remove Parameter
Mar 09, 2018
CVSS 9.8
EPSS 0.01
CVE-2018-7230 HIGH
Schneider Electric Pelco Sarix Professional < 3.29.67 - XML External Entity Injection via Web Interface Import
Mar 09, 2018
CVSS 8.8
EPSS 0.00
CVE-2018-7229 CRITICAL
Schneider Electric Pelco Sarix Professional < 3.29.67 - Unauthenticated Authentication Bypass via Hardcoded Credentials
Mar 09, 2018
CVSS 9.8
EPSS 0.01