schneider-electric

765 tracked vulnerabilities.

CVE-2023-37199 MEDIUM
StruxureWare Data Center Expert < 7.9.3 - Authenticated Remote Code Execution via Backup Tampering
Jul 12, 2023
CVSS 6.8
EPSS 0.02
CVE-2023-37198 MEDIUM
StruxureWare Data Center Expert < 7.9.3 - Authenticated Remote Code Execution via Install Package Upload
Jul 12, 2023
CVSS 6.8
EPSS 0.02
CVE-2023-37197 HIGH
StruxureWare Data Center Expert < 7.9.3 - Authenticated SQL Injection via Mass Configuration Settings
Jul 12, 2023
CVSS 8.8
EPSS 0.00
CVE-2023-37196 HIGH
StruxureWare Data Center Expert < 7.9.3 - Authenticated SQL Injection via Alert Settings Tampering
Jul 12, 2023
CVSS 8.8
EPSS 0.00
CVE-2023-3001 HIGH
IGSS Dashboard < 16.0.0.23131 - Remote Code Execution via Malicious File Deserialization
Jun 14, 2023
CVSS 7.8
EPSS 0.03
CVE-2023-2570 HIGH
Schneider Electric EcoStruxure Foxboro DCS Control Core Services - Local DoS and Kernel Execution via IOCTL
Jun 14, 2023
CVSS 7.0
EPSS 0.00
CVE-2023-2569 HIGH
EcoStruxure Foxboro DCS Control Core Services - Out-of-Bounds Write via IOCTL Call in Foxboro.sys Driver
Jun 14, 2023
CVSS 7.8
EPSS 0.00
CVE-2023-1049 HIGH
EcoStruxure Operator Terminal Expert and Pro-Face Blue < 3.3 - Remote Code Execution via Malicious Project File
Jun 14, 2023
CVSS 7.8
EPSS 0.00
CVE-2023-2161 MEDIUM
Schneider Electric OPC Factory Server - XML External Entity Reference
May 16, 2023
CVSS 5.0
EPSS 0.00
CVE-2023-25620 MEDIUM
Schneider Electric Modicon M580 Firmware < 4.10 - Authenticated Denial of Service via Malicious Project File
Apr 19, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-25619 HIGH
Modicon M580 Firmware < 4.10 - Denial of Service via Modbus TCP Protocol
Apr 19, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-29410 HIGH
Schneider Electric InsightHome, InsightFacility, Conext Gateway Firmware < 1.16 - Authenticated Remote Code Execution
Apr 18, 2023
CVSS 7.2
EPSS 0.00
CVE-2023-28004 CRITICAL
PowerLogic HDPM6000 Firmware < 0.58.6 - Denial of Service or Remote Code Execution via Ethernet Request
Apr 18, 2023
CVSS 9.8
EPSS 0.01
CVE-2023-29413 HIGH
Schneider Electric APC Easy UPS Online Monitoring Software < 2.5 - Unauthenticated DoS
Apr 18, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-29412 CRITICAL
APC Easy UPS Online Monitoring Software < 2.5 Remote Code Execution via Java RMI
Apr 18, 2023
CVSS 9.8
EPSS 0.03
CVE-2023-29411 CRITICAL
APC Easy UPS Online Monitoring Software < 2.5-ga-01-22320 and < 2.5-gs-01-22320 - Remote Code Execution via Java RMI
Apr 18, 2023
CVSS 9.8
EPSS 0.08
CVE-2023-28003 MEDIUM
EcoStruxure Power Monitoring Expert < 2022 - Insufficient Session Expiration
Apr 18, 2023
CVSS 6.7
EPSS 0.00
CVE-2023-25555 MEDIUM
StruxureWare Data Center Expert < 7.9.2 - Authenticated OS Command Injection via SSH
Apr 18, 2023
CVSS 5.6
EPSS 0.01
CVE-2023-25554 HIGH
StruxureWare Data Center Expert <= 7.9.2 - OS Command Injection
Apr 18, 2023
CVSS 7.8
EPSS 0.00
CVE-2023-25553 MEDIUM
StruxureWare Data Center Expert <= 7.9.2 - Cross-Site Scripting via Logging Capabilities
Apr 18, 2023
CVSS 6.1
EPSS 0.01
CVE-2023-25552 HIGH
StruxureWare Data Center Expert < 7.9.2 - Missing Authorization via Device File Transfer Settings
Apr 18, 2023
CVSS 8.1
EPSS 0.00
CVE-2023-25551 MEDIUM
StruxureWare Data Center Expert <= 7.9.2 - Cross-Site Scripting via File Upload Endpoint
Apr 18, 2023
CVSS 6.1
EPSS 0.01
CVE-2023-25550 HIGH
StruxureWare Data Center Expert < 7.9.2 - Remote Code Execution via Hostname Parameter
Apr 18, 2023
CVSS 7.2
EPSS 0.02
CVE-2023-25549 HIGH
StruxureWare Data Center Expert <= 7.9.2 - Remote Code Execution via DCE Network Settings Endpoint
Apr 18, 2023
CVSS 7.2
EPSS 0.02
CVE-2023-25548 HIGH
StruxureWare Data Center Expert < 7.9.2 - Incorrect Authorization
Apr 18, 2023
CVSS 8.8
EPSS 0.00