schneider-electric

765 tracked vulnerabilities.

CVE-2017-9963 HIGH
PowerSCADA Anywhere 1.0 - Cross-Site Request Forgery in Secure Gateway
Feb 12, 2018
CVSS 8.1
EPSS 0.00
CVE-2017-9966 HIGH
Pelco VideoXpert < 2.1 - Privilege Escalation via File Replacement
Jan 02, 2018
CVSS 7.1
EPSS 0.01
CVE-2017-9965 MEDIUM NUCLEI
Pelco VideoXpert < 2.1 - Unauthenticated Sensitive Information Exposure via Directory Traversal
Jan 02, 2018
CVSS 5.8
EPSS 0.00
CVE-2017-9964 MEDIUM
Schneider Electric Pelco VideoXpert < 2.1 - Path Traversal via Communication Sniffing
Jan 02, 2018
CVSS 6.9
EPSS 0.01
CVE-2017-14024 CRITICAL
Schneider Electric InduSoft Web Studio and InTouch Machine Edition < 8.0 - Stack-based Buffer Overflow
Nov 13, 2017
CVSS 9.8
EPSS 0.04
CVE-2017-13997 CRITICAL
Schneider Electric InduSoft Web Studio <8.0 SP2 - Auth Bypass
Oct 03, 2017
CVSS 9.8
EPSS 0.02
CVE-2017-9961 HIGH
Schneider Electric's Pro-Face GP Pro EX <4.07.000 - RCE
Sep 26, 2017
CVSS 7.8
EPSS 0.00
CVE-2017-9960 MEDIUM
Schneider Electric U.motion Builder <= 1.2.1 - Unauthenticated Sensitive Information Exposure via Error Response
Sep 26, 2017
CVSS 5.3
EPSS 0.00
CVE-2017-9959 MEDIUM
Schneider Electric U.motion Builder <= 1.2.1 - Unauthenticated Denial of Service via Reboot Command
Sep 26, 2017
CVSS 5.5
EPSS 0.00
CVE-2017-9958 HIGH
Schneider Electric U.motion Builder <= 1.2.1 - Unauthenticated Arbitrary Code Execution via Improper Access Control
Sep 26, 2017
CVSS 7.8
EPSS 0.00
CVE-2017-9957 CRITICAL
Schneider Electric U.motion Builder <= 1.2.1 - Use of Hard-coded Credentials
Sep 26, 2017
CVSS 9.8
EPSS 0.00
CVE-2017-9956 HIGH
Schneider Electric U.motion Builder <= 1.2.1 - Authentication Bypass via Hard-coded Session ID
Sep 26, 2017
CVSS 7.3
EPSS 0.00
CVE-2017-7974 CRITICAL
Schneider Electric U.motion Builder <= 1.2.1 - Unauthenticated Path Traversal and Arbitrary File Read
Sep 26, 2017
CVSS 9.8
EPSS 0.08
CVE-2017-7973 CRITICAL
Schneider Electric U.motion Builder <= 1.2.1 - Unauthenticated SQL Injection
Sep 26, 2017
CVSS 9.8
EPSS 0.00
CVE-2017-7972 MEDIUM
Schneider Electric's PowerSCADA Anywhere <1.0 - RCE
Sep 26, 2017
CVSS 5.5
EPSS 0.00
CVE-2017-7971 MEDIUM
Schneider Electric PowerSCADA Anywhere 1.0 and Citect Anywhere 1.0 - Improper Certificate Validation
Sep 26, 2017
CVSS 6.5
EPSS 0.00
CVE-2017-7970 MEDIUM
Schneider Electric's PowerSCADA - SSRF
Sep 26, 2017
CVSS 6.5
EPSS 0.00
CVE-2017-7969 HIGH
PowerSCADA Anywhere 1.0 and Citect Anywhere 1.0 - Cross-Site Request Forgery
Sep 26, 2017
CVSS 8.8
EPSS 0.00
CVE-2017-9631 HIGH
Schneider Electric Wonderware ArchestrA Logger <2017.426.2307.1 - DoS
Jul 07, 2017
CVSS 7.5
EPSS 0.01
CVE-2017-9629 CRITICAL
Schneider-electric Wonderware Archestra Logger < 2017.426.2307.1 - Memory Corruption
Jul 07, 2017
CVSS 9.8
EPSS 0.20
CVE-2017-9627 HIGH
Schneider Electric Wonderware ArchestrA Logger <2017.426.2307.1 - DoS
Jul 07, 2017
CVSS 8.6
EPSS 0.02
CVE-2017-6034 CRITICAL
Schneider Electric Modicon Modbus Protocol - Authentication Bypass by Capture-Replay via Cleartext Command Transmission
Jun 30, 2017
CVSS 9.8
EPSS 0.00
CVE-2017-6032 MEDIUM
Schneider Electric Modicon - Info Disclosure
Jun 30, 2017
CVSS 5.3
EPSS 0.00
CVE-2017-6030 MEDIUM
Schneider Electric Modicon PLCs - Predictable Value Range
Jun 30, 2017
CVSS 6.5
EPSS 0.00
CVE-2017-6028 CRITICAL
Schneider-electric Modicon M241 Firmware < 4.0.3.20 - Insufficiently Protected Credentials
Jun 30, 2017
CVSS 9.8
EPSS 0.00