VYPR

Vendor CVEs

Schneider Electric

All CVEs

880 total · sorted by risk
  • CVE-2025-6788MedJul 11, 2025
    risk 0.34cvss epss 0.00

    A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that exposes TGML diagram resources to the wrong control sphere, providing other authenticated users with potentially inappropriate access to TGML diagrams.

  • CVE-2025-30257MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated attackers can retrieve serial number of smart meters associated to a specific user account.

  • CVE-2025-26857MedApr 15, 2025
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated attackers can rename arbitrary devices of arbitrary users (i.e., EV chargers).

  • CVE-2025-0814MedFeb 13, 2025
    risk 0.34cvss 5.3epss 0.00

    CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the network services running on the product when malicious IEC61850-MMS packets are sent to the device. The core functionality of the breaker remains intact during the attack.

  • CVE-2023-6407MedDec 14, 2023
    risk 0.34cvss 5.3epss 0.00

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file deletion upon service restart when accessed by a local and low-privileged attacker.

  • CVE-2023-6032MedNov 15, 2023
    risk 0.34cvss 5.3epss 0.01

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause a file system enumeration and file download when an attacker navigates to the Network Management Card via HTTPS.

  • CVE-2023-3953MedAug 9, 2023
    risk 0.34cvss 5.3epss 0.00

    A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause memory corruption when an authenticated user opens a tampered log file from GP-Pro EX.

  • CVE-2023-0595MedFeb 24, 2023
    risk 0.34cvss 5.3epss 0.00

    A CWE-117: Improper Output Neutralization for Logs vulnerability exists that could cause the misinterpretation of log files when malicious packets are sent to the Geo SCADA server's database web port (default 443). Affected products: EcoStruxure Geo SCADA Expert 2019,…

  • CVE-2022-32512MedJan 30, 2023
    risk 0.34cvss 5.3epss 0.00

    A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause remote code execution when a command which exploits this vulnerability is utilized. Affected Products: CanBRASS (Versions prior to V7.5.1)

  • CVE-2022-24322MedMar 9, 2022
    risk 0.34cvss 5.3epss 0.01

    A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a disruption of communication between the Modicon controller and the engineering software when an attacker is able to intercept and manipulate specific Modbus…

  • CVE-2019-6841MedOct 29, 2019
    risk 0.34cvss 4.9epss 0.24

    A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 with firmware (version prior to V3.10), Modicon M340 (all firmware versions), and Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service attack…

  • CVE-2017-5160MedApr 20, 2017
    risk 0.34cvss 5.3epss 0.01

    An Inadequate Encryption Strength issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The software will connect via Transport Layer Security without verifying the peer's SSL certificate properly.

  • CVE-2026-2401MedApr 14, 2026
    risk 0.33cvss 5.0epss 0.00

    CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information to be exposed when a Web Admin user executes a malicious file provided by an attacker.

  • CVE-2023-2161MedMay 16, 2023
    risk 0.33cvss 5.0epss 0.00

    A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized read access to the file system when a malicious configuration file is loaded on to the software by a local user. 

  • CVE-2022-34758MedJul 13, 2022
    risk 0.33cvss 5.1epss 0.00

    A CWE-20: Improper Input Validation vulnerability exists that could cause the device watchdog function to be disabled if the attacker had access to privileged user credentials. Affected Products: Easergy P5 (V01.401.102 and prior)

  • CVE-2025-54927MedAug 20, 2025
    risk 0.32cvss 4.9epss 0.01

    CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause unauthorized access to sensitive files when an authenticated attackers uses a crafted path input that is processed by the system.

  • CVE-2025-5741MedJun 10, 2025
    risk 0.32cvss 4.9epss 0.01

    CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file reads from the charging station. The exploitation of this vulnerability does require an authenticated session of the web server.

  • CVE-2019-6847MedOct 29, 2019
    risk 0.32cvss 4.9epss 0.01

    A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service attack on the FTP service when upgrading the firmware with a version…

  • CVE-2019-6844MedOct 29, 2019
    risk 0.32cvss 4.9epss 0.01

    A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service atack on the PLC when upgrading the controller with a firmware package…

  • CVE-2019-6843MedOct 29, 2019
    risk 0.32cvss 4.9epss 0.01

    A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 with firmware (version prior to V3.10), Modicon M340 (all firmware versions), and Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service attack…

  • CVE-2019-6842MedOct 29, 2019
    risk 0.32cvss 4.9epss 0.01

    A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service attack on the PLC when upgrading the firmware with a missing web server…

  • CVE-2018-7824MedMay 22, 2019
    risk 0.32cvss 4.9epss 0.01

    An Externally Controlled Reference to a Resource (CWE-610) vulnerability exists in Schneider Electric Modbus Serial Driver (For 64-bit Windows OS:V3.17 IE 37 and prior , For 32-bit Windows OS:V2.17 IE 27 and prior, and as part of the Driver Suite version:V14.12 and prior) which…

  • CVE-2018-2599MedJan 18, 2018
    risk 0.32cvss 4.8epss 0.04

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows…

  • CVE-2023-5985MedNov 15, 2023
    risk 0.31cvss 4.8epss 0.00

    A CWE-79 Improper Neutralization of Input During Web Page Generation vulnerability exists that could cause compromise of a user’s browser when an attacker with admin privileges has modified system values.

  • CVE-2022-32530MedJun 24, 2022
    risk 0.31cvss 4.8epss 0.00

    A CWE-668 Exposure of Resource to Wrong Sphere vulnerability exists that could cause users to be misled, hiding alarms, showing the wrong server connection option or the wrong control request when a mobile device has been compromised by a malicious application. Affected Product:…

  • CVE-2020-7520MedJul 23, 2020
    risk 0.31cvss 4.7epss 0.01

    A CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability exists in Schneider Electric Software Update (SESU), V2.4.0 and prior, which could cause execution of malicious code on the victim's machine. In order to exploit this vulnerability, an attacker requires…

  • CVE-2018-1126MedMay 23, 2018
    risk 0.31cvss 4.8epss 0.02

    procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related to CVE-2018-1124.

  • CVE-2025-2441MedApr 9, 2025
    risk 0.30cvss 4.6epss 0.00

    CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could lead to loss of confidentiality when a malicious user, having physical access, sets the radio in factory default mode where the product does not correctly initialize all data.

  • CVE-2024-11139MedJan 17, 2025
    risk 0.30cvss epss 0.00

    CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could allow local attackers to exploit these issues to potentially execute arbitrary code when opening a malicious project file.

  • CVE-2026-9651MedJun 25, 2026
    risk 0.29cvss 4.4epss 0.00

    CWE-732 Incorrect Permission Assignment for Critical Resource vulnerability that could cause unauthorized disclosure of password hashes and potential account compromise when an attacker with privileged local access reads improperly protected system files.

  • CVE-2024-5557MedJun 12, 2024
    risk 0.29cvss 4.5epss 0.00

    CWE-532: Insertion of Sensitive Information into Log File vulnerability exists that could cause exposure of SNMP credentials when an attacker has access to the controller logs.

  • CVE-2021-22701MedFeb 19, 2021
    risk 0.29cvss 4.5epss 0.00

    A CWE-352: Cross-Site Request Forgery vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause a user to perform an unintended action on the target device when…

  • CVE-2018-2799MedApr 19, 2018
    risk 0.29cvss 5.3epss 0.15

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Java SE: 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows unauthenticated…

  • CVE-2018-2602MedJan 18, 2018
    risk 0.29cvss 4.5epss 0.01

    Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: I18n). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151. Difficult to exploit vulnerability allows unauthenticated attacker with…

  • CVE-2026-2403MedApr 14, 2026
    risk 0.28cvss 4.3epss 0.00

    CWE-1284 Improper Validation of Specified Quantity in Input vulnerability exists that could cause Event and Data Log truncation impacting log integrity when a Web Admin user alters the POST /logsettings request payload.

  • CVE-2026-2400MedApr 14, 2026
    risk 0.28cvss 4.3epss 0.00

    CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists that could cause application user credentials to reset when a Web Admin user alters the POST /setPCBEDesc request payload.

  • CVE-2022-2988MedJan 30, 2023
    risk 0.28cvss 4.3epss 0.00

    A CWE-787: Out-of-bounds Write vulnerability exists that could cause sensitive information leakage when accessing a malicious web page from the commissioning software. Affected Products: SoMachine HVAC (Versions prior to V2.1.0), EcoStruxure Machine Expert – HVAC (Versions…

  • CVE-2021-22819MedJan 28, 2022
    risk 0.28cvss 4.3epss 0.01

    A CWE-1021 Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause unintended modifications of the product settings or user accounts when deceiving the user to use the web interface rendered within iframes. Affected Products: EVlink City…

  • CVE-2021-22769MedJun 11, 2021
    risk 0.28cvss 4.3epss 0.01

    A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Easergy T300 with firmware V2.7.1 and older that could expose files or directory content when access from an attacker is not restricted or incorrectly restricted.

  • CVE-2020-7568MedNov 19, 2020
    risk 0.28cvss 4.3epss 0.01

    A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Modicon M221 (all references, all versions) that could allow non sensitive information disclosure when the attacker has captured the traffic between EcoStruxure Machine - Basic software…

  • CVE-2018-7776MedJul 3, 2018
    risk 0.28cvss 4.3epss 0.01

    The vulnerability exists within error.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. System information is returned to the attacker that contains sensitive data.

  • CVE-2018-7764MedJul 3, 2018
    risk 0.28cvss 4.3epss 0.01

    The vulnerability exists within runscript.php applet in Schneider Electric U.motion Builder software versions prior to v1.3.4. There is a directory traversal vulnerability in the processing of the 's' parameter of the applet.

  • CVE-2018-7763MedJul 3, 2018
    risk 0.28cvss 4.3epss 0.01

    The vulnerability exists within css.inc.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The 'css' parameter contains a directory traversal vulnerability.

  • CVE-2018-2800MedApr 19, 2018
    risk 0.28cvss 4.2epss 0.05

    Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u181, 7u171 and 8u162; JRockit: R28.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple…

  • CVE-2018-2678MedJan 18, 2018
    risk 0.28cvss 4.3epss 0.05

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulnerability allows…

  • CVE-2018-2677MedJan 18, 2018
    risk 0.28cvss 4.3epss 0.05

    Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151. Easily exploitable vulnerability allows unauthenticated attacker with network…

  • CVE-2018-2663MedJan 18, 2018
    risk 0.28cvss 4.3epss 0.05

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulnerability allows…

  • CVE-2018-2588MedJan 18, 2018
    risk 0.28cvss 4.3epss 0.03

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: LDAP). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulnerability allows low…

  • CVE-2025-8449MedAug 20, 2025
    risk 0.27cvss epss 0.00

    CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service when an authenticated user sends a specially crafted request to a specific endpoint from within the BMS network.

  • CVE-2025-2440MedApr 9, 2025
    risk 0.27cvss 4.2epss 0.00

    CWE-922: Insecure Storage of Sensitive Information vulnerability exists that could potentially lead to unauthorized access of confidential data when a malicious user, having physical access and advanced information on the file system, sets the radio in factory default mode.