schneider-electric

765 tracked vulnerabilities.

CVE-2022-2329 CRITICAL
IGSS Data Server <V15.0.0.22073 - Buffer Overflow
Feb 01, 2023
CVSS 9.8
EPSS 0.04
CVE-2022-24324 CRITICAL
IGSS Data Server <V15.0.0.22073 - Buffer Overflow
Feb 01, 2023
CVSS 9.8
EPSS 0.02
CVE-2022-45789 HIGH
Schneider-electric Ecostruxure Control Expert - Authentication Bypass
Jan 31, 2023
CVSS 8.1
EPSS 0.00
CVE-2022-32748 HIGH
EcoStruxure Cybersecurity Admin Expert < 2.4 - Improper Certificate Validation
Jan 30, 2023
CVSS 7.9
EPSS 0.00
CVE-2022-32747 HIGH
EcoStruxure Cybersecurity Admin Expert < 2.4 - Authentication Bypass by Spoofing
Jan 30, 2023
CVSS 8.0
EPSS 0.00
CVE-2022-32529 CRITICAL
Interactive Graphical SCADA System < 15.0.0.22170 - Remote Code Execution via Crafted Log Data Request
Jan 30, 2023
CVSS 9.8
EPSS 0.02
CVE-2022-32528 HIGH
Schneider-electric Interactive Graphi... - Missing Authentication
Jan 30, 2023
CVSS 8.6
EPSS 0.00
CVE-2022-32527 CRITICAL
Interactive Graphical SCADA System < 15.0.0.22170 - Remote Code Execution via Crafted Alarm Cache Data Messages
Jan 30, 2023
CVSS 9.8
EPSS 0.02
CVE-2022-32526 CRITICAL
Interactive Graphical SCADA System < 15.0.0.22170 - Remote Code Execution via Crafted Setting Value Messages
Jan 30, 2023
CVSS 9.8
EPSS 0.03
CVE-2022-32525 CRITICAL
Schneider Electric IGSS < 15.0.0.22170 - Remote Code Execution via Alarm Data
Jan 30, 2023
CVSS 9.8
EPSS 0.03
CVE-2022-32524 CRITICAL
Interactive Graphical SCADA System < 15.0.0.22170 - Remote Code Execution via Crafted Time Reduced Data Messages
Jan 30, 2023
CVSS 9.8
EPSS 0.02
CVE-2022-32523 CRITICAL
Interactive Graphical SCADA System < 15.0.0.22170 - Remote Code Execution via Crafted Online Data Request
Jan 30, 2023
CVSS 9.8
EPSS 0.02
CVE-2022-32522 CRITICAL
Schneider-electric Interactive Graphi... - Buffer Overflow
Jan 30, 2023
CVSS 9.8
EPSS 0.02
CVE-2022-32521 HIGH
Schneider Electric Data Center Expert < 7.9.0 - Remote Code Execution via Unsafe Deserialization
Jan 30, 2023
CVSS 7.1
EPSS 0.01
CVE-2022-32520 HIGH
Data Center Expert < 7.9.0 - Insufficiently Protected Credentials
Jan 30, 2023
CVSS 8.0
EPSS 0.00
CVE-2022-32519 HIGH
Data Center Expert <7.9.0 - Info Disclosure
Jan 30, 2023
CVSS 8.0
EPSS 0.00
CVE-2022-32518 HIGH
Data Center Expert < 7.9.0 - Insufficiently Protected Credentials
Jan 30, 2023
CVSS 8.0
EPSS 0.00
CVE-2022-32517 MEDIUM
Conext ComBox Firmware - Clickjacking via Unrestricted UI Layer Rendering
Jan 30, 2023
CVSS 6.5
EPSS 0.00
CVE-2022-32516 HIGH
Conext ComBox Firmware - Cross-Site Request Forgery via POST Request
Jan 30, 2023
CVSS 7.5
EPSS 0.00
CVE-2022-32515 HIGH
Conext ComBox Firmware - Improper Restriction of Excessive Authentication Attempts
Jan 30, 2023
CVSS 8.6
EPSS 0.00
CVE-2022-32514 CRITICAL
Schneider-electric 5500ac2 Firmware < 1.11.0 - Authentication Bypass
Jan 30, 2023
CVSS 9.8
EPSS 0.00
CVE-2022-32513 CRITICAL
Schneider Electric C-Bus Automation Controllers < 1.11.0 - Weak Password Requirements
Jan 30, 2023
CVSS 9.8
EPSS 0.00
CVE-2022-32512 MEDIUM
CanBRASS < 7.5.1 - Remote Code Execution via Memory Buffer Overflow
Jan 30, 2023
CVSS 5.3
EPSS 0.00
CVE-2022-22732 LOW
EcoStruxure Power Commission < 2.22 - Exposure of Resource to Wrong Sphere via Fetch Request
Jan 30, 2023
CVSS 3.9
EPSS 0.00
CVE-2022-22731 MEDIUM
EcoStruxure Power Commission < 2.22 - Path Traversal and Arbitrary File Write
Jan 30, 2023
CVSS 6.5
EPSS 0.01