VYPR

Vendor CVEs

Schneider Electric

All CVEs

880 total · sorted by risk
  • CVE-2017-9963HigFeb 12, 2018
    risk 0.53cvss 8.1epss 0.00

    A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for multiple state-changing requests. This type…

  • CVE-2022-32747HigJan 30, 2023
    risk 0.52cvss 8.0epss 0.00

    A CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause legitimate users to be locked out of devices or facilitate backdoor account creation by spoofing a device on the local network. Affected Products: EcoStruxure™ Cybersecurity Admin Expert (CAE)…

  • CVE-2022-32520HigJan 30, 2023
    risk 0.52cvss 8.0epss 0.01

    A CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in unwanted access to a DCE instance when performed over a network by a malicious third-party. This CVE is unique from CVE-2022-32518. Affected Products: Data Center Expert (Versions prior to…

  • CVE-2022-32519HigJan 30, 2023
    risk 0.52cvss 8.0epss 0.00

    A CWE-257: Storing Passwords in a Recoverable Format vulnerability exists that could result in unwanted access to a DCE instance when performed over a network by a malicious third-party. Affected Products: Data Center Expert (Versions prior to V7.9.0)

  • CVE-2022-32518HigJan 30, 2023
    risk 0.52cvss 8.0epss 0.01

    A CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in unwanted access to a DCE instance when performed over a network by a malicious third-party. This CVE is unique from CVE-2022-32520. Affected Products: Data Center Expert (Versions prior to…

  • CVE-2022-30232HigJun 2, 2022
    risk 0.52cvss 8.0epss 0.01

    A CWE-20: Improper Input Validation vulnerability exists that could cause potential remote code execution when an attacker is able to intercept and modify a request on the same network or has configuration access to an ION device on the network. Affected Products: Wiser Smart,…

  • CVE-2021-22825HigJan 28, 2022
    risk 0.52cvss 8.0epss 0.01

    A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could allow an attacker to access the system with elevated privileges when a privileged account clicks on a malicious URL that compromises the security token. Affected Products:…

  • CVE-2018-7771HigJul 3, 2018
    risk 0.52cvss 8.0epss 0.01

    The vulnerability exists within processing of editscript.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A directory traversal vulnerability allows a caller with standard user privileges to write arbitrary php files anywhere in the web service…

  • CVE-2026-12927HigJul 29, 2026
    risk 0.51cvss epss 0.00

    CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execution when a malicious CGF file is imported to IGSS Definition.

  • CVE-2025-11739HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a locally authenticated attacker sends a crafted data stream, triggering unsafe deserialization.

  • CVE-2025-13845HigJan 15, 2026
    risk 0.51cvss 7.8epss 0.00

    CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rapsody.

  • CVE-2025-2223HigApr 9, 2025
    risk 0.51cvss 7.8epss 0.00

    CWE-20: Improper Input Validation vulnerability exists that could cause a loss of Confidentiality, Integrity and Availability of engineering workstation when a malicious project file is loaded by a user from the local system.

  • CVE-2025-2222HigApr 9, 2025
    risk 0.51cvss 7.8epss 0.00

    CWE-552: Files or Directories Accessible to External Parties vulnerability over https exists that could leak information and potential privilege escalation following man in the middle attack.

  • CVE-2025-0327HigFeb 13, 2025
    risk 0.51cvss 7.8epss 0.00

    CWE-269: Improper Privilege Management vulnerability exists for two services (of which one managing audit trail data and the other acting as server managing client request) that could cause a loss of Confidentiality, Integrity and Availability of engineering workstation when an…

  • CVE-2024-12476HigJan 17, 2025
    risk 0.51cvss 7.8epss 0.00

    CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure, impacts workstation integrity and potential remote code execution on the compromised computer, when specific crafted XML file is imported in the Web…

  • CVE-2024-8422HigOct 8, 2024
    risk 0.51cvss 7.8epss 0.00

    CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when application user opens a malicious Zelio Soft 2 project file.

  • CVE-2024-8306HigSep 11, 2024
    risk 0.51cvss 7.8epss 0.00

    CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and availability of the workstation when non-admin authenticated user tries to perform privilege escalation by tampering with the binaries.

  • CVE-2024-5681HigJul 11, 2024
    risk 0.51cvss 7.8epss 0.00

    CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service, privilege escalation, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.

  • CVE-2024-2747HigJun 12, 2024
    risk 0.51cvss 7.8epss 0.00

    CWE-428: Unquoted search path or element vulnerability exists in Easergy Studio, which could cause privilege escalation when a valid user replaces a trusted file name on the system and reboots the machine.

  • CVE-2024-0865HigJun 12, 2024
    risk 0.51cvss 7.8epss 0.00

    CWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege escalation when logged in as a non-administrative user.

  • CVE-2024-2229HigMar 18, 2024
    risk 0.51cvss 7.8epss 0.00

    CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution when a malicious project file is loaded into the application by a valid user.

  • CVE-2023-7032HigJan 9, 2024
    risk 0.51cvss 7.8epss 0.00

    A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker logged in with a user level account to gain higher privileges by providing a harmful serialized object.

  • CVE-2023-4516HigSep 14, 2023
    risk 0.51cvss 7.8epss 0.00

    A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allow a local attacker to change update source, potentially leading to remote code execution when the attacker force an update containing malicious content.

  • CVE-2023-29414HigJul 12, 2023
    risk 0.51cvss 7.8epss 0.00

    A CWE-120: Buffer Copy without Checking Size of Input (Classic Buffer Overflow) vulnerability exists that could cause user privilege escalation if a local user sends specific string input to a local function call.

  • CVE-2023-2569HigJun 14, 2023
    risk 0.51cvss 7.8epss 0.00

    A CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, elevation of privilege, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.

  • CVE-2023-1049HigJun 14, 2023
    risk 0.51cvss 7.8epss 0.01

    A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause execution of malicious code when an unsuspicious user loads a project file from the local filesystem into the HMI.

  • CVE-2023-25554HigApr 18, 2023
    risk 0.51cvss 7.8epss 0.01

    A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that allows a local privilege escalation on the appliance when a maliciously crafted Operating System command is entered on the device. Affected…

  • CVE-2023-27984HigMar 21, 2023
    risk 0.51cvss 7.8epss 0.01

    A CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro to be executed, potentially leading to remote code execution when a user opens a malicious report file planted by an attacker. Affected Products: IGSS Data…

  • CVE-2023-27981HigMar 21, 2023
    risk 0.51cvss 7.8epss 0.01

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Custom Reports that could cause a remote code execution when a victim tries to open a malicious report. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior),…

  • CVE-2023-27978HigMar 21, 2023
    risk 0.51cvss 7.8epss 0.06

    A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets the user to open a malicious file. Affected Products: IGSS…

  • CVE-2022-4062HigFeb 1, 2023
    risk 0.51cvss 7.8epss 0.00

    A CWE-285: Improper Authorization vulnerability exists that could cause unauthorized access to certain software functions when an attacker gets access to localhost interface of the EcoStruxure Power Commission application. Affected Products: EcoStruxure Power Commission…

  • CVE-2022-42973HigFeb 1, 2023
    risk 0.51cvss 7.8epss 0.00

    A CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause local privilege escalation when local attacker connects to the database. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions…

  • CVE-2022-42972HigFeb 1, 2023
    risk 0.51cvss 7.8epss 0.00

    A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cause local privilege escalation when a local attacker modifies the webroot directory. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server…

  • CVE-2022-32748HigJan 30, 2023
    risk 0.51cvss 7.9epss 0.00

    A CWE-295: Improper Certificate Validation vulnerability exists that could cause the CAE software to give wrong data to end users when using CAE to configure devices. Additionally, credentials could leak which would enable an attacker the ability to log into the configuration…

  • CVE-2020-25184HigMar 18, 2022
    risk 0.51cvss 7.8epss 0.00

    Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable file. ISaGRAF Runtime reads the file and saves the data in a variable without any additional modification. A local, unauthenticated…

  • CVE-2021-22796HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.01

    A CWE-287: Improper Authentication vulnerability exists that could allow remote code execution when a malicious file is uploaded. Affected Product: C-Bus Toolkit (V1.15.9 and prior), C-Gate Server (V2.11.7 and prior)

  • CVE-2021-22817HigFeb 9, 2022
    risk 0.51cvss 7.8epss 0.00

    A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local privilege escalation. Affected Product: Harmony/Magelis iPC Series (All Versions), Vijeo Designer (All Versions prior to V6.2…

  • CVE-2021-22808HigJan 28, 2022
    risk 0.51cvss 7.8epss 0.01

    A CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution when a malicious *.gd1 configuration file is loaded into the GUIcon tool. Affected Product: Eurotherm by Schneider Electric GUIcon Version 2.0 (Build 683.003) and prior

  • CVE-2021-22807HigJan 28, 2022
    risk 0.51cvss 7.8epss 0.01

    A CWE-787: Out-of-bounds Write vulnerability exists that could cause arbitrary code execution when a malicious *.gd1 configuration file is loaded into the GUIcon tool. Affected Product: Eurotherm by Schneider Electric GUIcon Version 2.0 (Build 683.003) and prior

  • CVE-2021-22775HigSep 2, 2021
    risk 0.51cvss 7.8epss 0.00

    A CWE-427: Uncontrolled Search Path Element vulnerability exists in GP-Pro EX,V4.09.250 and prior, that could cause local code execution with elevated privileges when installing the software.

  • CVE-2021-22777HigJul 21, 2021
    risk 0.51cvss 7.8epss 0.01

    A CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause code execution by opening a malicious project file.

  • CVE-2021-22762HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.01

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in remote code execution, when a malicious CGF or WSP file is being parsed by IGSS Definition.

  • CVE-2021-22761HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.01

    A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or remote code e+F15xecution due to missing length check on user supplied…

  • CVE-2021-22760HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.01

    A CWE-763: Release of invalid pointer or reference vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing checks of user-supplied input data, when a malicious CGF file is imported to IGSS…

  • CVE-2021-22759HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.01

    A CWE-416: Use after free vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to use of unchecked input data, when a malicious CGF file is imported to IGSS Definition.

  • CVE-2021-22758HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.01

    A CWE-824: Access of uninitialized pointer vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to lack validation of user-supplied input data, when a malicious CGF file is imported to IGSS…

  • CVE-2021-22757HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.01

    A CWE-125: Out-of-bounds read vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or remote code execution due to lack of sanity checks on user-supplied input data, when a malicious CGF file is imported to IGSS…

  • CVE-2021-22756HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.01

    A CWE-125: Out-of-bounds read vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or remote code execution due to lack of user-supplied data validation, when a malicious CGF file is imported to IGSS Definition.

  • CVE-2021-22755HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.01

    A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or remote code execution due to lack of sanity checks on user-supplied data, when a malicious CGF file is imported to IGSS…

  • CVE-2021-22754HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.01

    A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to lack of proper validation of user-supplied data, when a malicious CGF file is imported to IGSS Definition.

Page 6 of 18