Vulnerability index

Browse CVEs

159 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Micom S1 Studio MEDIUM 6.6
CVE-2013-0687

The installer routine in Schneider Electric MiCOM S1 Studio uses world-writable permissions for executable files, which allows local users to modify …

Mitigation only
Fix from $1,600 2013-04-18
Magelis Xbt Hmi HIGH 10.0
CVE-2013-2762

The Schneider Electric Magelis XBT HMI controller has a default password for authentication of configuration uploads, which makes it easier for remot…

Mitigation only
Fix from $1,950 2013-04-04
Modicon Quantum Plc HIGH 8.5
CVE-2013-0664

The FactoryCast service on the Schneider Electric Quantum 140NOE77111 and 140NWM10000, M340 BMXNOE0110x, and Premium TSXETY5103 PLC modules allows re…

Mitigation only
Fix from $1,950 2013-04-04
Modicon M340 Bmx Noc 0401 Firmware MEDIUM 5.0
CVE-2013-2763

The Schneider Electric M340 PLC modules allow remote attackers to cause a denial of service (resource consumption) via unspecified vectors. NOTE: th…

Mitigation only
Fix from $1,600 2013-04-04
Modicon Quantum Plc MEDIUM 6.8
CVE-2013-0663EPSS 6%

Cross-site request forgery (CSRF) vulnerability on the Schneider Electric Quantum 140NOE77111, 140NOE77101, and 140NWM10000; M340 BMXNOC0401, BMXNOE0…

No fix yet
Fix from $1,600 2013-04-04
Software Update Utility HIGH 9.3
CVE-2013-0655

The client in Schneider Electric Software Update (SESU) Utility 1.0.x and 1.1.x does not ensure that updates have a valid origin, which allows man-in…

Mitigation only
Fix from $1,950 2013-01-21
Modicon Quantum Plc CRITICAL 9.8
CVE-2012-0931

Schneider Electric Modicon Quantum PLC does not perform authentication between the Unity software and PLC, which allows remote attackers to cause a d…

Mitigation only
Fix from $2,300 2012-01-28
Modicon Quantum Plc HIGH 7.5
CVE-2012-0929

Multiple buffer overflows in Schneider Electric Modicon Quantum PLC allow remote attackers to cause a denial of service via malformed requests to the…

Mitigation only
Fix from $1,950 2012-01-28
Modicon Quantum Plc MEDIUM 6.1
CVE-2012-0930

Cross-site scripting (XSS) vulnerability in Schneider Electric Modicon Quantum PLC allows remote attackers to inject arbitrary web script or HTML via…

Mitigation only
Fix from $1,600 2012-01-28