Vulnerability index

Browse CVEs

689 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Modicon M221 Firmware HIGH 7.5
CVE-2018-7789

An Improper Check for Unusual or Exceptional Conditions vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versio…

Fix: 1.6.2.0+
Fix from $1,950 2018-08-29
Powerlogic Pm5560 Firmware MEDIUM 5.4
CVE-2018-7795

A Cross Protocol Injection vulnerability exists in Schneider Electric's PowerLogic (PM5560 prior to FW version 2.5.4) product. The vulnerability make…

Fix: 2.5.4+
Fix from $1,600 2018-08-29
Evlink Charging Station Firmware CRITICAL 9.8
CVE-2018-7778

In Schneider Electric Evlink Charging Station versions prior to v3.2.0-12_v1, the Web Interface has an issue that may allow a remote attacker to gain…

Fix: 3.2.0-12_v1+
Fix from $2,300 2018-07-03
Imps110 1 Firmware CRITICAL 9.8
CVE-2018-7780

In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, a buffer overflow vulnerability exist …

Fix: 3.29.69+
Fix from $2,300 2018-07-03
U.motion CRITICAL 9.8
CVE-2018-7784

In Schneider Electric U.motion Builder software versions prior to v1.3.4, this exploit occurs when the submitted data of an input string is evaluated…

Fix: 1.3.4+
Fix from $2,300 2018-07-03
U.motion Builder CRITICAL 9.8
CVE-2018-7785

In Schneider Electric U.motion Builder software versions prior to v1.3.4, a remote command injection allows authentication bypass.

Fix: 1.3.4+
Fix from $2,300 2018-07-03
U.motion Builder HIGH 8.8
CVE-2018-7774

The vulnerability exists within processing of localize.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying S…

Fix: 1.3.4+
Fix from $1,950 2018-07-03
U.motion Builder HIGH 8.8
CVE-2018-7777EPSS 32%

The vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Electric U.motion Builder softwa…

Fix: 1.3.4+
Fix from $1,950 2018-07-03
Imps110 1 Firmware HIGH 8.8
CVE-2018-7781

In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, by sending a specially crafted request…

Fix: 3.29.69+
Fix from $1,950 2018-07-03
Imps110 1 Firmware HIGH 8.8
CVE-2018-7782

In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, authenticated users can view passwords…

Fix: 3.29.69+
Fix from $1,950 2018-07-03
Homelynk Firmware HIGH 7.5
CVE-2018-7779

In Schneider Electric Wiser for KNX V2.1.0 and prior, homeLYnk V2.0.1 and prior; and spaceLYnk V2.1.0 and prior, weak and unprotected FTP access coul…

Fix: after 2.1.0
Fix from $1,950 2018-07-03
Somachine Basic HIGH 7.5
CVE-2018-7783

Schneider Electric SoMachine Basic prior to v1.6 SP1 suffers from an XML External Entity (XXE) vulnerability using the DTD parameter entities techniq…

Fix: after 1.6
Fix from $1,950 2018-07-03
U.motion Builder MEDIUM 6.1
CVE-2018-7786

In Schneider Electric U.motion Builder software versions prior to v1.3.4, a cross site scripting (XSS) vulnerability exists which could allow injecti…

Fix: 1.3.4+
Fix from $1,600 2018-07-03
U.motion Builder MEDIUM 5.3
CVE-2018-7787

In Schneider Electric U.motion Builder software versions prior to v1.3.4, this vulnerability is due to improper validation of input of context parame…

Fix: 1.3.4+
Fix from $1,600 2018-07-03
U.motion Builder HIGH 8.8
CVE-2018-7765

The vulnerability exists within processing of track_import_export.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The u…

Fix: 1.3.4+
Fix from $1,950 2018-07-03
U.motion Builder HIGH 8.8
CVE-2018-7766

The vulnerability exists within processing of track_getdata.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underly…

Fix: 1.3.4+
Fix from $1,950 2018-07-03
U.motion Builder HIGH 8.8
CVE-2018-7767

The vulnerability exists within processing of editobject.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying…

Fix: 1.3.4+
Fix from $1,950 2018-07-03
U.motion Builder HIGH 8.8
CVE-2018-7768

The vulnerability exists within processing of loadtemplate.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlyi…

Fix: 1.3.4+
Fix from $1,950 2018-07-03
U.motion Builder HIGH 8.8
CVE-2018-7769

The vulnerability exists within processing of xmlserver.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying …

Fix: 1.3.4+
Fix from $1,950 2018-07-03
U.motion Builder HIGH 8.8
CVE-2018-7772

The vulnerability exists within processing of applets which are exposed on the web service in Schneider Electric U.motion Builder software versions p…

Fix: 1.3.4+
Fix from $1,950 2018-07-03
U.motion Builder HIGH 8.8
CVE-2018-7773

The vulnerability exists within processing of nfcserver.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying …

Fix: 1.3.4+
Fix from $1,950 2018-07-03
U.motion Builder HIGH 8.0
CVE-2018-7771

The vulnerability exists within processing of editscript.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A directory tr…

Fix: 1.3.4+
Fix from $1,950 2018-07-03
U.motion MEDIUM 6.5
CVE-2018-7770

The vulnerability exists within processing of sendmail.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The applet allow…

Fix: 1.3.4+
Fix from $1,600 2018-07-03
Triconex Tricon Mp 3008 Firmware HIGH 8.1
CVE-2018-8872

In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, system calls read directly from memory addresses within the control …

Fix: after 10.4
Fix from $1,950 2018-05-04
Triconex Tricon Mp 3008 Firmware MEDIUM 6.7
CVE-2018-7522

In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, when a system call is made, registers are stored to a fixed memory l…

Fix: after 10.0-10.4
Fix from $1,600 2018-05-04
Bmxnor0200 Firmware CRITICAL 9.8
CVE-2018-7241

Hard coded accounts exist in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, and BMXNOR0200 controllers in all versions of the c…

Mitigation only
Fix from $2,300 2018-04-18
Bmxnor0200 Firmware CRITICAL 9.8
CVE-2018-7242

Vulnerable hash algorithms exists in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, and BMXNOR0200 controllers in all versions …

Mitigation only
Fix from $2,300 2018-04-18
66074 Mge Network Management Card Transverse CRITICAL 9.8
CVE-2018-7243

An authorization bypass vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. T…

Mitigation only
Fix from $2,300 2018-04-18
66074 Mge Network Management Card Transverse CRITICAL 9.8
CVE-2018-7246

A cleartext transmission of sensitive information vulnerability exists in Schneider Electric's 66074 MGE Network Management Card Transverse installed…

Mitigation only
Fix from $2,300 2018-04-18
Bmxnor0200 Firmware CRITICAL 9.8
CVE-2018-7760

An authorization bypass vulnerability exists in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200. Requests to CGI …

Mitigation only
Fix from $2,300 2018-04-18