VYPR

Vendor CVEs

Schneider Electric

All CVEs

880 total · sorted by risk
  • CVE-2021-22753HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.01

    A CWE-125: Out-of-bounds read vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing length checks, when a malicious WSP file is being parsed by IGSS Definition.

  • CVE-2021-22752HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.01

    A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing size checks, when a malicious WSP (Workspace) file is being parsed by IGSS Definition.

  • CVE-2021-22751HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.01

    A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or execution of arbitrary code due to lack of input validation, when a malicious CGF (Configuration Group File) file is imported…

  • CVE-2021-22750HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.01

    A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21041 and prior that could result in loss of data or remote code execution due to missing length checks, when a malicious CGF file is imported to IGSS Definition.

  • CVE-2021-22733HigMay 26, 2021
    risk 0.51cvss 7.8epss 0.00

    Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause shell access when unauthorized code is loaded into the system folder.

  • CVE-2021-22732HigMay 26, 2021
    risk 0.51cvss 7.8epss 0.00

    Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a code execution issue when an attacker loads unauthorized code on the web server.

  • CVE-2021-22705HigMay 26, 2021
    risk 0.51cvss 7.8epss 0.00

    Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service or unauthorized access to system information when interacting directly with a driver installed by Vijeo Designer or EcoStruxure Machine Expert

  • CVE-2021-22716HigApr 13, 2021
    risk 0.51cvss 7.8epss 0.01

    A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could allow remote code execution when an unprivileged user modifies a file. Affected Product: C-Bus Toolkit (V1.15.9 and prior)

  • CVE-2021-22712HigMar 11, 2021
    risk 0.51cvss 7.8epss 0.01

    A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in arbitrary read or write conditions when malicious CGF…

  • CVE-2021-22711HigMar 11, 2021
    risk 0.51cvss 7.8epss 0.01

    A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in arbitrary read or write conditions when malicious CGF…

  • CVE-2021-22710HigMar 11, 2021
    risk 0.51cvss 7.8epss 0.02

    A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could cause remote code execution when malicious CGF (Configuration Group File)…

  • CVE-2021-22709HigMar 11, 2021
    risk 0.51cvss 7.8epss 0.02

    A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in loss of data or remote code execution when malicious CGF…

  • CVE-2021-22698HigJan 26, 2021
    risk 0.51cvss 7.8epss 0.04

    A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior) that could allow a stack-based buffer overflow to occur which could result in remote code execution when a malicious SSD file is…

  • CVE-2021-22697HigJan 26, 2021
    risk 0.51cvss 7.8epss 0.03

    A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior) that could allow a use-after-free condition which could result in remote code execution when a malicious SSD file is uploaded and…

  • CVE-2020-28219HigDec 11, 2020
    risk 0.51cvss 7.8epss 0.00

    A CWE-522: Insufficiently Protected Credentials vulnerability exists in EcoStruxure Geo SCADA Expert 2019 (Original release and Monthly Updates to September 2020, from 81.7268.1 to 81.7578.1) and EcoStruxure Geo SCADA Expert 2020 (Original release and Monthly Updates to…

  • CVE-2020-7558HigNov 19, 2020
    risk 0.51cvss 7.8epss 0.02

    A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.

  • CVE-2020-7557HigNov 19, 2020
    risk 0.51cvss 7.8epss 0.03

    A CWE-125 Out-of-bounds Read vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.

  • CVE-2020-7556HigNov 19, 2020
    risk 0.51cvss 7.8epss 0.02

    A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.

  • CVE-2020-7555HigNov 19, 2020
    risk 0.51cvss 7.8epss 0.02

    A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.

  • CVE-2020-7554HigNov 19, 2020
    risk 0.51cvss 7.8epss 0.02

    A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.

  • CVE-2020-7553HigNov 19, 2020
    risk 0.51cvss 7.8epss 0.02

    A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.

  • CVE-2020-7552HigNov 19, 2020
    risk 0.51cvss 7.8epss 0.02

    A CWE-787: Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247, that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.

  • CVE-2020-7551HigNov 19, 2020
    risk 0.51cvss 7.8epss 0.02

    A CWE-787: Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247, that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.

  • CVE-2020-7550HigNov 19, 2020
    risk 0.51cvss 7.8epss 0.02

    A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 and prior that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS…

  • CVE-2020-7544HigNov 19, 2020
    risk 0.51cvss 7.8epss 0.00

    A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD) that could cause privilege escalation on the workstation when interacting directly with a driver installed by the runtime software of EcoStruxureª Operator…

  • CVE-2020-28211HigNov 19, 2020
    risk 0.51cvss 7.8epss 0.00

    A CWE-863: Incorrect Authorization vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause bypass of authentication when overwriting memory using a debugger.

  • CVE-2020-7532HigSep 16, 2020
    risk 0.51cvss 7.8epss 0.01

    A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack x70 Security Administrator (V1.2.0 and prior) which could allow arbitrary code execution when an attacker builds a custom .SDB file containing a malicious serialized buffer.

  • CVE-2020-7531HigSep 16, 2020
    risk 0.51cvss 7.8epss 0.01

    A CWE-284 Improper Access Control vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place executables in a specific folder and run code whenever RemoteConnect is executed by the user.

  • CVE-2020-7528HigSep 16, 2020
    risk 0.51cvss 7.8epss 0.01

    A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which could allow arbitrary code execution when an attacker builds a custom .PRJ file containing a malicious serialized buffer.

  • CVE-2020-7527HigAug 31, 2020
    risk 0.51cvss 7.8epss 0.00

    Incorrect Default Permission vulnerability exists in SoMove (V2.8.1) and prior which could cause elevation of privilege and provide full access control to local system users to SoMove component and services when a SoMove installer script is launched.

  • CVE-2020-7523HigAug 31, 2020
    risk 0.51cvss 7.8epss 0.00

    Improper Privilege Management vulnerability exists in Schneider Electric Modbus Serial Driver (see security notification for versions) which could cause local privilege escalation when the Modbus Serial Driver service is invoked. The driver does not properly assign, modify,…

  • CVE-2020-7516HigJul 23, 2020
    risk 0.51cvss 7.8epss 0.00

    A CWE-316: Cleartext Storage of Sensitive Information in Memory vulnerability exists in Easergy Builder V1.4.7.2 and prior which could allow an attacker access to login credentials.

  • CVE-2020-7515HigJul 23, 2020
    risk 0.51cvss 7.8epss 0.00

    A CWE-321: Use of hard-coded cryptographic key stored in cleartext vulnerability exists in Easergy Builder V1.4.7.2 and prior which could allow an attacker to decrypt a password.

  • CVE-2020-7514HigJul 23, 2020
    risk 0.51cvss 7.8epss 0.00

    A CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker access to the authorization credentials for a device and gain full access.

  • CVE-2020-7496HigJun 16, 2020
    risk 0.51cvss 7.8epss 0.01

    A CWE-88: Argument Injection or Modification vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)which could cause unauthorized write access when opening the project file.

  • CVE-2020-7494HigJun 16, 2020
    risk 0.51cvss 7.8epss 0.01

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause malicious code execution when opening the project…

  • CVE-2020-7493HigJun 16, 2020
    risk 0.51cvss 7.8epss 0.01

    A CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause malicious code execution when opening the…

  • CVE-2020-10626HigMay 14, 2020
    risk 0.51cvss 7.8epss 0.01

    In Fazecast jSerialComm, Version 2.2.2 and prior, an uncontrolled search path element vulnerability could allow a malicious DLL file with the same name of any resident DLLs inside the software installation to execute arbitrary code.

  • CVE-2020-7490HigApr 22, 2020
    risk 0.51cvss 7.8epss 0.00

    A CWE-426: Untrusted Search Path vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 15 and prior) and Vijeo Designer (V6.9 SP9 and prior), which could cause arbitrary code execution on the system running Vijeo Basic when a malicious DLL library is loaded by the Product.

  • CVE-2020-7479HigMar 23, 2020
    risk 0.51cvss 7.8epss 0.01

    A CWE-306: Missing Authentication for Critical Function vulnerability exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which could allow a local user to execute processes that otherwise require escalation privileges when sending local network commands to the…

  • CVE-2020-7476HigMar 23, 2020
    risk 0.51cvss 7.8epss 0.00

    A CWE-426: Untrusted Search Path vulnerability exists in ZigBee Installation Kit (Versions prior to 1.0.1), which could cause execution of malicious code when a malicious file is put in the search path.

  • CVE-2020-7474HigMar 23, 2020
    risk 0.51cvss 7.8epss 0.00

    A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProSoft Configurator (v1.002 and prior), for the PMEPXM0100 (H) module, which could cause the execution of untrusted code when using double click to open a project file which may trigger execution of a malicious…

  • CVE-2019-6858HigJan 22, 2020
    risk 0.51cvss 7.8epss 0.00

    A CWE-427:Uncontrolled Search Path Element vulnerability exists in MSX Configurator (Software Version prior to V1.0.8.1), which could cause privilege escalation when injecting a malicious DLL.

  • CVE-2019-6854HigJan 6, 2020
    risk 0.51cvss 7.8epss 0.00

    A CWE-287: Improper Authentication vulnerability exists in a folder within EcoStruxure Geo SCADA Expert (ClearSCADA) -with initial releases before 1 January 2019- which could cause a low privilege user to delete or modify database, setting or certificate files. Those users must…

  • CVE-2019-6851HigOct 29, 2019
    risk 0.51cvss 7.5epss 0.30

    A CWE-538: File and Directory Information Exposure vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions), which could cause the disclosure of information from the controller when using TFTP protocol.

  • CVE-2019-6826HigSep 17, 2019
    risk 0.51cvss 7.8epss 0.01

    A CWE-426: Untrusted Search Path vulnerability exists in SoMachine HVAC v2.4.1 and earlier versions, which could cause arbitrary code execution on the system running SoMachine HVAC when a malicious DLL library is loaded by the product.

  • CVE-2019-6827HigJul 15, 2019
    risk 0.51cvss 7.8epss 0.01

    A CWE-787: Out-of-bounds Write vulnerability exists in Interactive Graphical SCADA System (IGSS), Version 14 and prior, which could cause a software crash when data in the mdb database is manipulated.

  • CVE-2019-6825HigJul 15, 2019
    risk 0.51cvss 7.8epss 0.01

    A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProClima (all versions prior to version 8.0.0) which could allow a malicious DLL file, with the same name of any resident DLLs inside the software installation, to execute arbitrary code in all versions of…

  • CVE-2019-6822HigJul 15, 2019
    risk 0.51cvss 7.8epss 0.04

    A Use After Free: CWE-416 vulnerability exists in Zelio Soft 2, V5.2 and earlier, which could cause remote code execution when opening a specially crafted Zelio Soft 2 project file.

  • CVE-2019-10981HigMay 31, 2019
    risk 0.51cvss 7.8epss 0.00

    In Vijeo Citect 7.30 and 7.40, and CitectSCADA 7.30 and 7.40, a vulnerability has been identified that may allow an authenticated local user access to Citect user credentials.

Page 7 of 18