Vulnerability index

Browse CVEs

159 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Modicon M580 Firmware MEDIUM 5.3
CVE-2018-7850

A CWE-807: Reliance on Untrusted Inputs in a Security Decision vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantu…

Mitigation only
Fix from $1,600 2019-05-22
Opc Factory Server HIGH 7.3
CVE-2015-1014

A successful exploit of these vulnerabilities requires the local user to load a crafted DLL file in the system directory on servers running Schneider…

Mitigation only
Fix from $1,950 2019-03-25
Bmxnoc0401 Firmware MEDIUM 5.4
CVE-2015-6461

Remote file inclusion allows an attacker to craft a specific URL referencing the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNO…

Mitigation only
Fix from $1,600 2019-03-21
Bmxnoc0401 Firmware MEDIUM 5.4
CVE-2015-6462

Reflected Cross-Site Scripting (nonpersistent) allows an attacker to craft a specific URL, which contains Java script that will be executed on the Sc…

Mitigation only
Fix from $1,600 2019-03-21
Guicon HIGH 7.8
CVE-2018-7813

A Type Confusion (CWE-843) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0) on pcwin.dll which could cause remo…

Mitigation only
Fix from $1,950 2019-02-06
Guicon HIGH 7.8
CVE-2018-7814

A Stack-based Buffer Overflow (CWE-121) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0) which could cause remo…

Mitigation only
Fix from $1,950 2019-02-06
Guicon HIGH 7.8
CVE-2018-7815

A Type Confusion (CWE-843) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0) on c3core.dll which could cause rem…

Mitigation only
Fix from $1,950 2019-02-06
Iiot Monitor MEDIUM 5.5
CVE-2018-7839

A Cryptographic Issue (CWE-310) vulnerability exists in IIoT Monitor 3.1.38 which could allow information disclosure.

No fix yet
Fix from $1,600 2019-02-06
Iiot Monitor CRITICAL 9.8
CVE-2018-7836EPSS 32%

An unrestricted Upload of File with Dangerous Type vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow uplo…

Mitigation only
Fix from $2,300 2018-12-24
Foxboro Dcs HIGH 8.7
CVE-2018-7793

A Credential Management vulnerability exists in FoxView HMI SCADA (All Foxboro DCS, Foxboro Evo, and IA Series versions prior to Foxboro DCS Control …

Mitigation only
Fix from $1,950 2018-12-24
Iiot Monior HIGH 7.5
CVE-2018-7835

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in IIoT Monitor 3.1.38 which could allow acces…

Mitigation only
Fix from $1,950 2018-12-24
Iiot Monior HIGH 7.5
CVE-2018-7837

An Improper Restriction of XML External Entity Reference ('XXE') vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that co…

Mitigation only
Fix from $1,950 2018-12-24
Powersuite 2 MEDIUM 6.3
CVE-2018-7796

A Buffer Error vulnerability exists in PowerSuite 2, all released versions (VW3A8104 & Patches), which could cause an overflow in the memcpy function…

Mitigation only
Fix from $1,600 2018-12-24
Modicom M340 Firmware HIGH 7.5
CVE-2018-7812

An Information Exposure through Discrepancy vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR020…

Mitigation only
Fix from $1,950 2018-12-17
Modicom M340 Firmware HIGH 7.5
CVE-2018-7833

An Improper Check for Unusual or Exceptional Conditions vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs a…

Mitigation only
Fix from $1,950 2018-12-17
Ecostruxure Energy Expert MEDIUM 6.1
CVE-2018-7797

A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME)…

Mitigation only
Fix from $1,600 2018-12-17
Modicom M340 Firmware MEDIUM 6.1
CVE-2018-7804

A URL Redirection to Untrusted Site vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where …

Mitigation only
Fix from $1,600 2018-12-17
Modicom M340 Firmware CRITICAL 9.8
CVE-2018-7809

An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could …

No fix yet
Fix from $2,300 2018-11-30
Modicom M340 Firmware CRITICAL 9.8
CVE-2018-7811

An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could …

No fix yet
Fix from $2,300 2018-11-30
Struxureware Data Center Operation HIGH 8.8
CVE-2018-7806

Data Center Operation allows for the upload of a zip file from its user interface to the server. A carefully crafted, malicious file could be mistake…

Mitigation only
Fix from $1,950 2018-11-30
Modicom M340 Firmware HIGH 8.8
CVE-2018-7831

An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability exists in the embedded web servers in all Modicon M340…

No fix yet
Fix from $1,950 2018-11-30
Modicom M340 Firmware HIGH 7.5
CVE-2018-7830

Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability exists in the embedded web servers in all Modicon…

No fix yet
Fix from $1,950 2018-11-30
Modicom M340 Firmware MEDIUM 6.1
CVE-2018-7810

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in the embedded web servers in all Modic…

No fix yet
Fix from $1,600 2018-11-30
Somachine Basic HIGH 8.2
CVE-2018-7798

A Insufficient Verification of Data Authenticity (CWE-345) vulnerability exists in the Modicon M221, all versions, which could cause a change of IPv4…

Mitigation only
Fix from $1,950 2018-11-02
Bmxnor0200 Firmware CRITICAL 9.8
CVE-2018-7241

Hard coded accounts exist in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, and BMXNOR0200 controllers in all versions of the c…

Mitigation only
Fix from $2,300 2018-04-18
Bmxnor0200 Firmware CRITICAL 9.8
CVE-2018-7242

Vulnerable hash algorithms exists in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, and BMXNOR0200 controllers in all versions …

Mitigation only
Fix from $2,300 2018-04-18
66074 Mge Network Management Card Transverse CRITICAL 9.8
CVE-2018-7243

An authorization bypass vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. T…

Mitigation only
Fix from $2,300 2018-04-18
66074 Mge Network Management Card Transverse CRITICAL 9.8
CVE-2018-7246

A cleartext transmission of sensitive information vulnerability exists in Schneider Electric's 66074 MGE Network Management Card Transverse installed…

Mitigation only
Fix from $2,300 2018-04-18
Bmxnor0200 Firmware CRITICAL 9.8
CVE-2018-7760

An authorization bypass vulnerability exists in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200. Requests to CGI …

Mitigation only
Fix from $2,300 2018-04-18
Bmxnor0200 Firmware CRITICAL 9.8
CVE-2018-7761

A vulnerability exists in the HTTP request parser in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200 which could …

Mitigation only
Fix from $2,300 2018-04-18