Vulnerability index

Browse CVEs

689 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pro Face Gp Pro Ex HIGH 7.8
CVE-2017-9961

A vulnerability exists in Schneider Electric's Pro-Face GP Pro EX version 4.07.000 that allows an attacker to execute arbitrary code. Malicious code …

Mitigation only
Fix from $1,950 2017-09-26
U.motion Builder CRITICAL 9.8
CVE-2017-7973

A SQL injection vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauthenticated user can …

Fix: after 1.2.1
Fix from $2,300 2017-09-26
U.motion Builder CRITICAL 9.8
CVE-2017-7974

A path traversal information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an u…

Fix: after 1.2.1
Fix from $2,300 2017-09-26
U.motion Builder CRITICAL 9.8
CVE-2017-9957

A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the web service contains a hidden system a…

Fix: after 1.2.1
Fix from $2,300 2017-09-26
Powerscada Anywhere HIGH 8.8
CVE-2017-7969

A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with…

Patch available
Fix from $1,950 2017-09-26
U.motion Builder HIGH 7.8
CVE-2017-9958

An improper access control vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an improper handl…

Fix: after 1.2.1
Fix from $1,950 2017-09-26
U.motion Builder HIGH 7.3
CVE-2017-9956

An authentication bypass vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system contains…

Fix: after 1.2.1
Fix from $1,950 2017-09-26
Powerscada Anywhere MEDIUM 6.5
CVE-2017-7970

A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Cite…

Patch available
Fix from $1,600 2017-09-26
Powerscada Anywhere MEDIUM 6.5
CVE-2017-7971

A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Cite…

Patch available
Fix from $1,600 2017-09-26
Powerscada Anywhere MEDIUM 5.5
CVE-2017-7972

A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Cite…

Patch available
Fix from $1,600 2017-09-26
U.motion Builder MEDIUM 5.5
CVE-2017-9959

A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system accepts reboot in session from …

Fix: after 1.2.1
Fix from $1,600 2017-09-26
U.motion Builder MEDIUM 5.3
CVE-2017-9960

An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system respons…

Fix: after 1.2.1
Fix from $1,600 2017-09-26
Wonderware Archestra Logger CRITICAL 9.8
CVE-2017-9629EPSS 10%

A Stack-Based Buffer Overflow issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.2307.1 and prior. The stack-b…

Fix: after 2017.426.2307.1
Fix from $2,300 2017-07-07
Wonderware Archestra Logger HIGH 8.6
CVE-2017-9627

An Uncontrolled Resource Consumption issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.2307.1 and prior. The …

Mitigation only
Fix from $1,950 2017-07-07
Wonderware Archestra Logger HIGH 7.5
CVE-2017-9631

A Null Pointer Dereference issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.2307.1 and prior. The null point…

Fix: after 2017.426.2307.1
Fix from $1,950 2017-07-07
Modicon M241 Firmware CRITICAL 9.8
CVE-2017-6028

An Insufficiently Protected Credentials issue was discovered in Schneider Electric Modicon PLCs Modicon M241, all firmware versions, and Modicon M251…

Fix: after 4.0.3.20
Fix from $2,300 2017-06-30
Modbus Firmware CRITICAL 9.8
CVE-2017-6034EPSS 5%

An authentication bypass by capture-replay issue was discovered in Schneider Electric Modicon Modbus Protocol. Sensitive information is transmitted i…

No fix yet
Fix from $2,300 2017-06-30
Modicon M251 Firmware CRITICAL 9.1
CVE-2017-6026EPSS 32%

A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware versions prior to Version 4.0.5.…

Fix: after 4.0.3.20
Fix from $2,300 2017-06-30
Bmxnoc0401 Firmware HIGH 7.5
CVE-2017-6017

A Resource Exhaustion issue was discovered in Schneider Electric Modicon M340 PLC BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP3…

Mitigation only
Fix from $1,950 2017-06-30
Modicon M241 Firmware MEDIUM 6.5
CVE-2017-6030

A predictable value range from previous values issue was discovered in Schneider Electric Modicon PLCs Modicon M221, firmware versions prior to Versi…

Fix: after 4.0.3.20
Fix from $1,600 2017-06-30
Modbus Firmware MEDIUM 5.3
CVE-2017-6032

A Violation of Secure Design Principles issue was discovered in Schneider Electric Modicon Modbus Protocol. The Modicon Modbus protocol has a session…

Mitigation only
Fix from $1,600 2017-06-30
Somachine HIGH 8.8
CVE-2017-7966

A DLL Hijacking vulnerability in the programming software in Schneider Electric's SoMachine HVAC v2.1.0 allows a remote attacker to execute arbitrary…

Mitigation only
Fix from $1,950 2017-06-07
Somachine Hvac HIGH 7.3
CVE-2017-7965

A buffer overflow vulnerability exists in Programming Software executable AlTracePrint.exe, in Schneider Electric's SoMachine HVAC v2.1.0 for Modicon…

Mitigation only
Fix from $1,950 2017-06-07
Wonderware Indusoft Web Studio HIGH 7.8
CVE-2017-7968

An Incorrect Default Permissions issue was discovered in Schneider Electric Wonderware InduSoft Web Studio v8.0 Patch 3 and prior versions. Upon inst…

Fix: after 8.0
Fix from $1,950 2017-05-19
Wonderware Historian Client MEDIUM 6.6
CVE-2017-7907

An Improper XML Parser Configuration issue was discovered in Schneider Electric Wonderware Historian Client 2014 R2 SP1 and prior. An improperly rest…

Fix: after 2014_r2
Fix from $1,600 2017-05-19
Vampset MEDIUM 5.5
CVE-2017-7967

All versions of VAMPSET software produced by Schneider Electric, prior to V2.2.189, are susceptible to a memory corruption vulnerability when a corru…

Fix: after 2.2.185
Fix from $1,600 2017-05-09
Struxureware Data Center Expert MEDIUM 6.8
CVE-2017-8371

Schneider Electric StruxureWare Data Center Expert before 7.4.0 uses cleartext RAM storage for passwords, which might allow remote attackers to obtai…

Fix: after 7.3.1
Fix from $1,600 2017-04-30
Homelynk Controller Lss100100 Firmware CRITICAL 9.8
CVE-2017-7689EPSS 6%

A Command Injection vulnerability in Schneider Electric homeLYnk Controller exists in all versions before 1.5.0.

Fix: 1.5.0+
Fix from $2,300 2017-04-11
Interactive Graphical Scada System HIGH 7.8
CVE-2017-6033

A DLL Hijacking issue was discovered in Schneider Electric Interactive Graphical SCADA System (IGSS) Software, Version 12 and previous versions. The …

Fix: after 12.0
Fix from $1,950 2017-04-07
Conext Combox 865 1058 Firmware HIGH 7.5
CVE-2017-6019EPSS 37%

An issue was discovered in Schneider Electric Conext ComBox, model 865-1058, all firmware versions prior to V3.03 BN 830. A series of rapid requests …

Fix: after 3.03
Fix from $1,950 2017-04-07