VYPR

Vendor CVEs

Schneider Electric

All CVEs

880 total · sorted by risk
  • CVE-2025-54923HigAug 20, 2025
    risk 0.57cvss epss 0.01

    CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution and compromise of system integrity when authenticated users send crafted data to a network-exposed service that performs unsafe deserialization.

  • CVE-2024-10497HigJan 17, 2025
    risk 0.57cvss 8.8epss 0.01

    CWE-639: Authorization Bypass Through User-Controlled Key vulnerability exists that could allow an authorized attacker to modify values outside those defined by their privileges (Elevation of Privileges) when the attacker sends modified HTTPS requests to the device.

  • CVE-2024-11999HigDec 17, 2024
    risk 0.57cvss 8.8epss 0.01

    CWE-1104: Use of Unmaintained Third-Party Components vulnerability exists that could cause complete control of the device when an authenticated user installs malicious code into HMI product.

  • CVE-2024-0568HigFeb 14, 2024
    risk 0.57cvss 8.8epss 0.00

    CWE-287: Improper Authentication vulnerability exists that could cause unauthorized tampering of device configuration over NFC communication.

  • CVE-2023-37197HigJul 12, 2023
    risk 0.57cvss 8.8epss 0.01

    A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to access unauthorized content, change, or delete content, or perform unauthorized actions…

  • CVE-2023-37196HigJul 12, 2023
    risk 0.57cvss 8.8epss 0.01

    A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to access unauthorized content, change, or delete content, or perform unauthorized actions when…

  • CVE-2022-46680HigMay 22, 2023
    risk 0.57cvss 8.8epss 0.00

    A CWE-319: Cleartext transmission of sensitive information vulnerability exists that could cause disclosure of sensitive information, denial of service, or modification of data if an attacker is able to intercept network traffic.

  • CVE-2023-25548HigApr 18, 2023
    risk 0.57cvss 8.8epss 0.01

    A CWE-863: Incorrect Authorization vulnerability exists that could allow access to device credentials on specific DCE endpoints not being properly secured when a hacker is using a low privileged user. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)

  • CVE-2023-25547HigApr 18, 2023
    risk 0.57cvss 8.8epss 0.01

    A CWE-863: Incorrect Authorization vulnerability exists that could allow remote code execution on upload and install packages when a hacker is using a low privileged user account. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)

  • CVE-2023-27976HigApr 18, 2023
    risk 0.57cvss 8.8epss 0.01

    A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause remote code execution when a valid user visits a malicious link provided through the web endpoints. Affected Products: EcoStruxure Control Expert (V15.1 and above)

  • CVE-2023-27982HigMar 21, 2023
    risk 0.57cvss 8.8epss 0.00

    A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause manipulation of dashboard files in the IGSS project report directory, when an attacker sends specific crafted messages to the Data Server TCP port, this could lead…

  • CVE-2023-27980HigMar 21, 2023
    risk 0.57cvss 8.8epss 0.01

    A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow the creation of a malicious report file in the IGSS project report directory, this could lead to remote code execution when a victim eventually opens…

  • CVE-2022-34756HigJul 13, 2022
    risk 0.57cvss 8.8epss 0.02

    A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution or the crash of HTTPs stack which is used for the device Web HMI. Affected Products: Easergy P5 (V01.401.102 and prior)

  • CVE-2021-22783HigMar 9, 2022
    risk 0.57cvss 8.8epss 0.00

    A CWE-200: Information Exposure vulnerability exists which could allow a session hijack when the door panel is communicating with the door. Affected Product: Ritto Wiser Door (All versions)

  • CVE-2021-22748HigFeb 11, 2022
    risk 0.57cvss 8.8epss 0.02

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could allow a remote code execution when a file is saved. Affected Product: C-Bus Toolkit (V1.15.9 and prior), C-Gate Server (V2.11.7 and prior)

  • CVE-2022-22808HigFeb 9, 2022
    risk 0.57cvss 8.8epss 0.01

    A CWE-352: Cross-Site Request Forgery (CSRF) exists that could cause a remote attacker to gain unauthorized access to the product when conducting cross-domain attacks based on same-origin policy or cross-site request forgery protections bypass. Affected Product: EcoStruxure EV…

  • CVE-2022-22727HigFeb 4, 2022
    risk 0.57cvss 8.8epss 0.01

    A CWE-20: Improper Input Validation vulnerability exists that could allow an unauthenticated attacker to view data, change settings, impact availability of the software, or potentially impact a user�s local machine when the user clicks a specially crafted link. Affected…

  • CVE-2022-22725HigFeb 4, 2022
    risk 0.57cvss 8.8epss 0.03

    A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could lead to a buffer overflow causing program crashes and arbitrary code execution when specially crafted packets are sent to the device over the network. Protection functions and tripping function…

  • CVE-2022-22723HigFeb 4, 2022
    risk 0.57cvss 8.8epss 0.03

    A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could lead to a buffer overflow causing program crashes and arbitrary code execution when specially crafted packets are sent to the device over the network. Protection functions and tripping function…

  • CVE-2020-7534HigFeb 4, 2022
    risk 0.57cvss 8.8epss 0.00

    A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could cause a leak of sensitive data or unauthorized actions on the web server during the time the user is logged in. Affected Products: Modicon M340 CPUs: BMXP34 (All Versions),…

  • CVE-2021-22827HigJan 28, 2022
    risk 0.57cvss 8.8epss 0.01

    A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits a page containing the injected payload. This CVE is unique from CVE-2021-22826. Affected Product: EcoStruxure� Power Monitoring Expert 9.0 and prior versions

  • CVE-2021-22826HigJan 28, 2022
    risk 0.57cvss 8.8epss 0.01

    A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits a page containing the injected payload. This CVE is unique from CVE-2021-22827. Affected Product: EcoStruxure� Power Monitoring Expert 9.0 and prior versions

  • CVE-2021-22725HigJan 28, 2022
    risk 0.57cvss 8.8epss 0.00

    A CVE-352 Cross-Site Request Forgery (CSRF) vulnerability exists that could allow an attacker to impersonate the user or carry out actions on their behalf when crafted malicious parameters are submitted in POST requests sent to the charging station web server. Affected Products:…

  • CVE-2021-22724HigJan 28, 2022
    risk 0.57cvss 8.8epss 0.00

    A CVE-352 Cross-Site Request Forgery (CSRF) vulnerability exists that could allow an attacker to impersonate the user or carry out actions on their behalf when crafted malicious parameters are submitted in POST requests sent to the charging station web server. Affected Products:…

  • CVE-2020-7547HigDec 1, 2020
    risk 0.57cvss 8.8epss 0.01

    A CWE-284: Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow a user the ability to perform actions via the web interface at a higher privilege…

  • CVE-2020-7572HigNov 19, 2020
    risk 0.57cvss 8.8epss 0.02

    A CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to inject arbitrary XML code and obtain disclosure of confidential data, denial…

  • CVE-2020-7569HigNov 19, 2020
    risk 0.57cvss 8.8epss 0.02

    A CWE-434 Unrestricted Upload of File with Dangerous Type vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to upload arbitrary files due to incorrect verification of user supplied files and…

  • CVE-2020-28213HigNov 19, 2020
    risk 0.57cvss 8.8epss 0.01

    A CWE-494: Download of Code Without Integrity Check vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when sending specially crafted requests over Modbus.

  • CVE-2020-7564HigNov 18, 2020
    risk 0.57cvss 8.8epss 0.01

    A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause write…

  • CVE-2020-7563HigNov 18, 2020
    risk 0.57cvss 8.8epss 0.01

    A CWE-787: Out-of-bounds Write vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause corruption of data, a crash, or code execution when uploading…

  • CVE-2020-7530HigSep 16, 2020
    risk 0.57cvss 8.8epss 0.01

    A CWE-285 Improper Authorization vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows improper access to executable code folders.

  • CVE-2020-7526HigAug 31, 2020
    risk 0.57cvss 8.8epss 0.02

    Improper Input Validation vulnerability exists in PowerChute Business Edition (software V9.0.x and earlier) which could cause remote code execution when a script is executed during a shutdown event.

  • CVE-2020-7503HigJun 16, 2020
    risk 0.57cvss 8.8epss 0.01

    A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to execute malicious commands on behalf of a legitimate user when xsrf-token data is intercepted.

  • CVE-2020-7501HigJun 16, 2020
    risk 0.57cvss 8.8epss 0.01

    A CWE-798: Use of Hard-coded Credentials vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 16 and prior) and Vijeo Designer (V6.2 SP9 and prior) which could cause unauthorized read and write when downloading and uploading project or firmware into Vijeo Designer Basic and…

  • CVE-2019-6839HigSep 17, 2019
    risk 0.57cvss 8.8epss 0.01

    A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15),…

  • CVE-2019-6810HigSep 17, 2019
    risk 0.57cvss 8.8epss 0.02

    CWE-284: Improper Access Control vulnerability exists in BMXNOR0200H Ethernet / Serial RTU module (all firmware versions), which could cause the execution of commands by unauthorized users when using IEC 60870-5-104 protocol.

  • CVE-2018-7829HigMay 22, 2019
    risk 0.57cvss 8.8epss 0.02

    An Improper Neutralization of Special Elements in Query vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera which allows an attacker to execute arbitrary system commands.

  • CVE-2018-7828HigMay 22, 2019
    risk 0.57cvss 8.8epss 0.01

    A Cross-Site Request Forgery (CSRF) vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera when an authenticated user clicks a specially crafted malicious link while logged into the camera.

  • CVE-2018-7826HigMay 22, 2019
    risk 0.57cvss 8.8epss 0.02

    A Command Injection vulnerability exists in the web-based GUI of the 1st Gen Pelco Sarix Enhanced Camera that could allow a remote attacker to execute arbitrary commands.

  • CVE-2018-7825HigMay 22, 2019
    risk 0.57cvss 8.8epss 0.02

    A Command Injection vulnerability exists in the web-based GUI of the 1st Gen PelcoSarix Enhanced Camera that could allow a remote attacker to execute arbitrary commands.

  • CVE-2018-7832HigDec 24, 2018
    risk 0.57cvss 8.8epss 0.02

    An Improper Input Validation vulnerability exists in Pro-Face GP-Pro EX v4.08 and previous versions which could cause the execution arbitrary executable when GP-Pro EX is launched.

  • CVE-2018-7802HigDec 24, 2018
    risk 0.57cvss 8.8epss 0.02

    A SQL Injection vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could give access to the web interface with full privileges.

  • CVE-2018-7793HigDec 24, 2018
    risk 0.57cvss 8.7epss 0.00

    A Credential Management vulnerability exists in FoxView HMI SCADA (All Foxboro DCS, Foxboro Evo, and IA Series versions prior to Foxboro DCS Control Core Services 9.4 (CCS 9.4) and FoxView 10.5.) which could cause unauthorized disclosure, modification, or disruption in service…

  • CVE-2018-7831HigNov 30, 2018
    risk 0.57cvss 8.8epss 0.01

    An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 allowing an attacker to send a specially crafted URL to a currently authenticated web…

  • CVE-2018-7807HigNov 30, 2018
    risk 0.57cvss 8.8epss 0.01

    Data Center Expert, versions 7.5.0 and earlier, allows for the upload of a zip file from its user interface to the server. A carefully crafted, malicious file could be mistakenly uploaded by an authenticated user via this feature which could contain path traversal file names. As…

  • CVE-2018-7806HigNov 30, 2018
    risk 0.57cvss 8.8epss 0.01

    Data Center Operation allows for the upload of a zip file from its user interface to the server. A carefully crafted, malicious file could be mistakenly uploaded by an authenticated user via this feature which could contain path traversal file names. As such, it could allow for…

  • CVE-2018-7782HigJul 3, 2018
    risk 0.57cvss 8.8epss 0.01

    In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, authenticated users can view passwords in clear text.

  • CVE-2018-7781HigJul 3, 2018
    risk 0.57cvss 8.8epss 0.01

    In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, by sending a specially crafted request an authenticated user can view password in clear text and results in privilege escalation.

  • CVE-2018-7774HigJul 3, 2018
    risk 0.57cvss 8.8epss 0.01

    The vulnerability exists within processing of localize.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the username input parameter.

  • CVE-2018-7773HigJul 3, 2018
    risk 0.57cvss 8.8epss 0.01

    The vulnerability exists within processing of nfcserver.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the sessionid input parameter.

Page 4 of 18