Vulnerability index

Browse CVEs

689 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Etg3000 Factorycast Hmi Gateway Firmware HIGH 7.8
CVE-2014-9197

The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access con…

Patch available
Fix from $1,950 2015-01-27
Wonderware Intouch Access Anywhere Server HIGH 10.0
CVE-2014-9190EPSS 6%

Stack-based buffer overflow in Schneider Electric Wonderware InTouch Access Anywhere Server 10.6 and 11.0 allows remote attackers to execute arbitrar…

Mitigation only
Fix from $1,950 2015-01-10
Proclima HIGH 10.0
CVE-2014-8511

Buffer overflow in an ActiveX control in Atx45.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via …

Fix: after 6.0.1
Fix from $1,950 2014-12-27
Stbnic2212 Firmware HIGH 10.0
CVE-2014-0754EPSS 9%

Directory traversal vulnerability in SchneiderWEB on Schneider Electric Modicon PLC Ethernet modules 140CPU65x Exec before 5.5, 140NOC78x Exec before…

Patch available
Fix from $1,950 2014-10-03
Opc Factory Server Tlxcdlfofs HIGH 7.8
CVE-2014-0789

Multiple buffer overflows in the OPC Automation 2.0 Server Object ActiveX control in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 3.5 and…

Fix: after 3.35
Fix from $1,950 2014-04-04
Concept HIGH 9.3
CVE-2013-0662EPSS 22%

Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow remote attackers to execute …

Fix: after 14.0
Fix from $1,950 2014-04-01
Ofs Test Client Tlxcdlfofs33 MEDIUM 6.9
CVE-2014-0774

Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 - 3.35, TLXCDSTOFS33 - 3.35, TLXCDLU…

Mitigation only
Fix from $1,600 2014-02-28
Floating License Manager MEDIUM 5.9
CVE-2014-0759

Unquoted Windows search path vulnerability in Schneider Electric Floating License Manager 1.0.0 through 1.4.0 allows local users to gain privileges v…

Mitigation only
Fix from $1,600 2014-02-28
Citectscada HIGH 7.8
CVE-2013-2824

Schneider Electric StruxureWare SCADA Expert Vijeo Citect 7.40, Vijeo Citect 7.20 through 7.30SP1, CitectSCADA 7.20 through 7.30SP1, StruxureWare Pow…

Patch available
Fix from $1,950 2014-02-26
Telvent Sage 3030 Firmware MEDIUM 5.0
CVE-2013-6143

The Schneider Electric Telvent SAGE 3030 RTU with firmware C3413-500-001D3_P4 and C3413-500-001F0_PB allows remote attackers to cause a denial of ser…

Mitigation only
Fix from $1,600 2014-01-31
Tburjr900 HIGH 9.3
CVE-2013-2782

Schneider Electric Trio J-Series License Free Ethernet Radio with firmware 3.6.0 through 3.6.3 uses the same AES encryption key across different cust…

Mitigation only
Fix from $1,950 2013-08-28
Citectscada MEDIUM 6.9
CVE-2013-2796

Schneider Electric Vijeo Citect 7.20 and earlier, CitectSCADA 7.20 and earlier, and PowerLogic SCADA 7.20 and earlier allow remote attackers to read …

Fix: after 7.20
Fix from $1,600 2013-08-09
Micom S1 Studio MEDIUM 6.6
CVE-2013-0687

The installer routine in Schneider Electric MiCOM S1 Studio uses world-writable permissions for executable files, which allows local users to modify …

Mitigation only
Fix from $1,600 2013-04-18
Magelis Xbt Hmi HIGH 10.0
CVE-2013-2762

The Schneider Electric Magelis XBT HMI controller has a default password for authentication of configuration uploads, which makes it easier for remot…

Mitigation only
Fix from $1,950 2013-04-04
Modicon Quantum Plc HIGH 8.5
CVE-2013-0664

The FactoryCast service on the Schneider Electric Quantum 140NOE77111 and 140NWM10000, M340 BMXNOE0110x, and Premium TSXETY5103 PLC modules allows re…

Mitigation only
Fix from $1,950 2013-04-04
Modicon M340 Bmx Noc 0401 Firmware MEDIUM 5.0
CVE-2013-2763

The Schneider Electric M340 PLC modules allow remote attackers to cause a denial of service (resource consumption) via unspecified vectors. NOTE: th…

Mitigation only
Fix from $1,600 2013-04-04
Modicon Quantum Plc MEDIUM 6.8
CVE-2013-0663EPSS 6%

Cross-site request forgery (CSRF) vulnerability on the Schneider Electric Quantum 140NOE77111, 140NOE77101, and 140NWM10000; M340 BMXNOC0401, BMXNOE0…

No fix yet
Fix from $1,600 2013-04-04
Accutech Manager HIGH 10.0
CVE-2013-0658EPSS 22%

Heap-based buffer overflow in RFManagerService.exe in Schneider Electric Accutech Manager 2.00.1 and earlier allows remote attackers to execute arbit…

Fix: after 2.00.1
Fix from $1,950 2013-02-15
Interactive Graphical Scada System HIGH 10.0
CVE-2013-0657EPSS 21%

Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA System (IGSS) 10 and earlier allows remote attackers to execute arbitra…

Fix: after 10.0
Fix from $1,950 2013-01-21
Software Update Utility HIGH 9.3
CVE-2013-0655

The client in Schneider Electric Software Update (SESU) Utility 1.0.x and 1.1.x does not ensure that updates have a valid origin, which allows man-in…

Mitigation only
Fix from $1,950 2013-01-21
Modicon Quantum Plc CRITICAL 9.8
CVE-2012-0931

Schneider Electric Modicon Quantum PLC does not perform authentication between the Unity software and PLC, which allows remote attackers to cause a d…

Mitigation only
Fix from $2,300 2012-01-28
Modicon Quantum Plc HIGH 7.5
CVE-2012-0929

Multiple buffer overflows in Schneider Electric Modicon Quantum PLC allow remote attackers to cause a denial of service via malformed requests to the…

Mitigation only
Fix from $1,950 2012-01-28
Modicon Quantum Plc MEDIUM 6.1
CVE-2012-0930

Cross-site scripting (XSS) vulnerability in Schneider Electric Modicon Quantum PLC allows remote attackers to inject arbitrary web script or HTML via…

Mitigation only
Fix from $1,600 2012-01-28
Quantum Ethernet Module 140noe77100 HIGH 10.0
CVE-2011-4860

The ComputePassword function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) generates th…

Fix: after 5.0
Fix from $1,950 2011-12-17
Quantum Ethernet Module 140noe77100 HIGH 10.0
CVE-2011-4861

The modbus_125_handler function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) allows re…

Fix: after 5.0
Fix from $1,950 2011-12-17
Quantum Ethernet Module 140cpu65150 HIGH 10.0
CVE-2011-4859

The Schneider Electric Quantum Ethernet Module, as used in the Quantum 140NOE771* and 140CPU65* modules, the Premium TSXETY* and TSXP57* modules, the…

Fix: after 5.0
Fix from $1,950 2011-12-17
Vijeo Historian HIGH 9.3
CVE-2011-4034EPSS 13%

Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earl…

Fix: after 4.30
Fix from $1,950 2011-12-02
Vijeo Historian MEDIUM 5.0
CVE-2011-4036

Directory traversal vulnerability in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.…

Fix: after 4.30
Fix from $1,600 2011-12-02
Monitor Pro HIGH 7.2
CVE-2011-3330

Buffer overflow in the UnitelWay Windows Device Driver, as used in Schneider Electric Unity Pro 6 and earlier, OPC Factory Server 3.34, Vijeo Citect …

Fix: after 7.20
Fix from $1,950 2011-11-04