VYPR

Vendor CVEs

Schneider Electric

All CVEs

880 total · sorted by risk
  • CVE-2017-7972MedSep 26, 2017
    risk 0.36cvss 5.5epss 0.00

    A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the ability to escape out of remote PowerSCADA Anywhere applications and launch other…

  • CVE-2017-7967MedMay 9, 2017
    risk 0.36cvss 5.5epss 0.00

    All versions of VAMPSET software produced by Schneider Electric, prior to V2.2.189, are susceptible to a memory corruption vulnerability when a corrupted vf2 file is used. This vulnerability causes the software to halt or not start when trying to open the corrupted file. This…

  • CVE-2025-13902MedMar 10, 2026
    risk 0.35cvss 5.4epss 0.00

    CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause condition where authenticated attackers can have a victim’s browser run arbitrary JavaScript when the victim hovers over a maliciously crafted…

  • CVE-2025-3905MedJun 10, 2025
    risk 0.35cvss 5.4epss 0.00

    CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists impacting PLC system variables that could cause an unvalidated data injected by authenticated malicious user leading to modify or read data in a victim’s browser.

  • CVE-2025-3899MedJun 10, 2025
    risk 0.35cvss 5.4epss 0.00

    CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in Certificates page on Webserver that could cause an unvalidated data injected by authenticated malicious user leading to modify or read data in a victim’s…

  • CVE-2024-6528MedJul 11, 2024
    risk 0.35cvss 5.4epss 0.00

    CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a vulnerability leading to a cross-site scripting condition where attackers can have a victim’s browser run arbitrary JavaScript when they visit a…

  • CVE-2024-5560MedJun 12, 2024
    risk 0.35cvss 5.3epss 0.01

    CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service of the device’s web interface when an attacker sends a specially crafted HTTP request.

  • CVE-2024-37040MedJun 12, 2024
    risk 0.35cvss 5.4epss 0.00

    CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability exists that could allow a user with access to the device’s web interface to cause a fault on the device when sending a malformed HTTP request.

  • CVE-2020-25180MedMar 18, 2022
    risk 0.35cvss 5.3epss 0.01

    Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged commands. The password value passed to ISaGRAF Runtime is the result of encryption performed with a fixed key value using the tiny…

  • CVE-2022-24323MedMar 9, 2022
    risk 0.35cvss 5.3epss 0.01

    A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause a disruption of communication between the Modicon controller and the engineering software, when an attacker is able to intercept and manipulate specific Modbus response data.…

  • CVE-2022-22809MedFeb 9, 2022
    risk 0.35cvss 5.3epss 0.01

    A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow modifications of the touch configurations in an unauthorized manner when an attacker attempts to modify the touch configurations. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser…

  • CVE-2022-22804MedFeb 4, 2022
    risk 0.35cvss 5.4epss 0.00

    A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could allow an authenticated attacker to view data, change settings, or impact availability of the software when the user visits a page containing the…

  • CVE-2021-22815MedJan 28, 2022
    risk 0.35cvss 5.3epss 0.01

    A CWE-200: Information Exposure vulnerability exists which could cause the troubleshooting archive to be accessed. Affected Products: 1-Phase Uninterruptible Power Supply (UPS) using NMC2 including Smart-UPS, Symmetra, and Galaxy 3500 with Network Management Card 2 (NMC2):…

  • CVE-2021-22722MedJul 21, 2021
    risk 0.35cvss 5.4epss 0.00

    A CWE-79: Improper Neutralization of Input During Web Page Generation ('Stored Cross-site Scripting') vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink…

  • CVE-2021-22721MedJul 21, 2021
    risk 0.35cvss 5.3epss 0.01

    A CWE-200: Information Exposure vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could…

  • CVE-2021-22764MedJun 11, 2021
    risk 0.35cvss 5.3epss 0.02

    A CWE-287: Improper Authentication vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could cause loss of connectivity to the device via Modbus TCP protocol when an…

  • CVE-2021-22749MedJun 11, 2021
    risk 0.35cvss 5.3epss 0.01

    A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Modicon X80 BMXNOR0200H RTU SV1.70 IR22 and prior that could cause information leak concerning the current RTU configuration including communication parameters dedicated to telemetry,…

  • CVE-2020-7549MedDec 11, 2020
    risk 0.35cvss 5.3epss 0.01

    A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause…

  • CVE-2020-7541MedDec 11, 2020
    risk 0.35cvss 5.3epss 0.01

    A CWE-425: Direct Request ('Forced Browsing') vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause disclosure of…

  • CVE-2020-7546MedDec 1, 2020
    risk 0.35cvss 5.4epss 0.01

    A CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow an attacker to perform actions on behalf of…

  • CVE-2020-7571MedNov 19, 2020
    risk 0.35cvss 5.4epss 0.01

    A CWE-79 Multiple Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Reflected) vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause a remote attacker to inject arbitrary web script or HTML due to incorrect…

  • CVE-2020-7570MedNov 19, 2020
    risk 0.35cvss 5.4epss 0.01

    A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Stored) vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to inject arbitrary web script or HTML due to…

  • CVE-2020-7504MedJun 16, 2020
    risk 0.35cvss 5.3epss 0.01

    A CWE-20: Improper Input Validation vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to disable the webserver service on the device when specially crafted network packets are sent.

  • CVE-2019-6835MedSep 17, 2019
    risk 0.35cvss 5.4epss 0.01

    A Cross-Site Scripting (XSS) CWE-79 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could allow an…

  • CVE-2018-7850MedMay 22, 2019
    risk 0.35cvss 5.3epss 0.02

    A CWE-807: Reliance on Untrusted Inputs in a Security Decision vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause invalid information displayed in Unity Pro software.

  • CVE-2018-7827MedMay 22, 2019
    risk 0.35cvss 5.4epss 0.01

    A Cross-Site Scripting (XSS) vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera which a remote attacker can execute arbitrary HTML and script code in a user’s browser session.

  • CVE-2018-7823MedMay 22, 2019
    risk 0.35cvss 5.3epss 0.01

    A Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause remote launch of SoMachine Basic when sending crafted ethernet message.

  • CVE-2015-6462MedMar 21, 2019
    risk 0.35cvss 5.4epss 0.01

    Reflected Cross-Site Scripting (nonpersistent) allows an attacker to craft a specific URL, which contains Java script that will be executed on the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030,…

  • CVE-2015-6461MedMar 21, 2019
    risk 0.35cvss 5.4epss 0.01

    Remote file inclusion allows an attacker to craft a specific URL referencing the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H PLC web server, which, when…

  • CVE-2018-7795MedAug 29, 2018
    risk 0.35cvss 5.4epss 0.02

    A Cross Protocol Injection vulnerability exists in Schneider Electric's PowerLogic (PM5560 prior to FW version 2.5.4) product. The vulnerability makes the product susceptible to cross site scripting attack on its web browser. User inputs can be manipulated to cause execution of…

  • CVE-2018-7787MedJul 3, 2018
    risk 0.35cvss 5.3epss 0.01

    In Schneider Electric U.motion Builder software versions prior to v1.3.4, this vulnerability is due to improper validation of input of context parameter in HTTP GET request.

  • CVE-2018-2815MedApr 19, 2018
    risk 0.35cvss 5.3epss 0.05

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows…

  • CVE-2018-2798MedApr 19, 2018
    risk 0.35cvss 5.3epss 0.08

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows…

  • CVE-2018-2797MedApr 19, 2018
    risk 0.35cvss 5.3epss 0.08

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JMX). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows…

  • CVE-2018-2796MedApr 19, 2018
    risk 0.35cvss 5.3epss 0.07

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Concurrency). Supported versions that are affected are Java SE: 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows…

  • CVE-2018-2795MedApr 19, 2018
    risk 0.35cvss 5.3epss 0.08

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows…

  • CVE-2018-7244MedApr 18, 2018
    risk 0.35cvss 5.3epss 0.01

    An information disclosure vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to obtain sensitive device…

  • CVE-2018-7227MedMar 9, 2018
    risk 0.35cvss 5.3epss 0.01

    A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow retrieving of specially crafted URLs without authentication that can reveal sensitive information to an attacker.

  • CVE-2018-2657MedJan 18, 2018
    risk 0.35cvss 5.3epss 0.08

    Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u171 and 7u161; JRockit: R28.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via…

  • CVE-2018-2629MedJan 18, 2018
    risk 0.35cvss 5.3epss 0.05

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JGSS). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows…

  • CVE-2018-2603MedJan 18, 2018
    risk 0.35cvss 5.3epss 0.07

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulnerability allows…

  • CVE-2017-9960MedSep 26, 2017
    risk 0.35cvss 5.3epss 0.01

    An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system response to error provides more information than should be available to an unauthenticated user.

  • CVE-2017-6032MedJun 30, 2017
    risk 0.35cvss 5.3epss 0.02

    A Violation of Secure Design Principles issue was discovered in Schneider Electric Modicon Modbus Protocol. The Modicon Modbus protocol has a session-related weakness making it susceptible to brute-force attacks.

  • CVE-2016-8367MedFeb 13, 2017
    risk 0.35cvss 5.3epss 0.04

    An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all versions, Magelis GTU Universal Panel, all versions, Magelis STO5xx and STU Small panels, all versions, Magelis XBT GH Advanced Hand-held Panels, all versions, Magelis XBT GK…

  • CVE-2015-6485MedMar 12, 2016
    risk 0.35cvss 5.3epss 0.01

    Schneider Electric Telvent Sage 2300 RTUs with firmware before C3413-500-S01, and LANDAC II-2, Sage 1410, Sage 1430, Sage 1450, Sage 2400, and Sage 3030M RTUs with firmware before C3414-500-S02J2, allow remote attackers to obtain sensitive information from device memory by…

  • CVE-2026-2404MedApr 14, 2026
    risk 0.34cvss 5.3epss 0.00

    CWE-116 Improper Encoding or Escaping of Output vulnerability exists that could cause log injection and forged log when an attacker alters the POST /j_security check request payload.

  • CVE-2026-2402MedApr 14, 2026
    risk 0.34cvss 5.3epss 0.00

    CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to gain access to the user account by performing an arbitrary number of authentication attempts with different credentials on a sequence of requests to multiple…

  • CVE-2025-13901MedMar 10, 2026
    risk 0.34cvss 5.3epss 0.00

    CWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of Service on Machine Expert protocol when an unauthenticated attacker sends malicious payload to occupy active communication channels.

  • CVE-2025-13844MedJan 15, 2026
    risk 0.34cvss 5.3epss 0.00

    CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody.

  • CVE-2025-7746MedSep 9, 2025
    risk 0.34cvss epss 0.00

    CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause an unvalidated data injected by a malicious user potentially leading to modify or read data in a victim’s browser.

Page 15 of 18