Vulnerabilities in Schneider ELectric
314 resultsVexday analysis
A Schneider Electric apresenta perfil de risco baixo com apenas 1 vulnerabilidade catalogada na base, sem registros de exploração ativa ou incidentes críticos. A fraqueza identificada (CWE-20 - validação imprópria de entrada) é de natureza genérica e a vulnerabilidade não foi publicada recentemente, indicando um risco estabilizado e de menor prioridade para monitoramento imediato.
CVE-2024-10085HIGHCWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause denial of service of the OPC UA communicEPSS 0.3%CVE-2022-34757MEDIUMA CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists where weak cipher suites can be used for the SSH connectionEPSS 0.3%CVE-2023-28003MEDIUM
A CWE-613: Insufficient Session Expiration vulnerability exists that could allow an attacker to
maintain unauthorized access over a hijacEPSS 0.3%CVE-2023-6408HIGH
CWE-924: Improper Enforcement of Message Integrity During Transmission in a
Communication Channel vulnerability exists that could cause a dEPSS 0.3%CVE-2026-1286HIGHCWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote cEPSS 0.3%CVE-2022-32747HIGHA CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause legitimate users to be locked out of devices or facilitatEPSS 0.3%CVE-2026-4827HIGHInsufficient Entropy vulnerability on Multiple ProductsEPSS 0.3%CVE-2026-13348MEDIUMCWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized acEPSS 0.3%CVE-2022-30237HIGHA CWE-311: Missing Encryption of Sensitive Data vulnerability exists that could allow authentication credentials to be recovered when an attEPSS 0.3%CVE-2024-0568HIGH
CWE-287: Improper Authentication vulnerability exists that could cause unauthorized tampering
of device configuration over NFC communicatioEPSS 0.3%CVE-2023-5984HIGH
A CWE-494 Download of Code Without Integrity Check vulnerability exists that could allow
modified firmware to be uploaded when an authorizeEPSS 0.3%CVE-2024-12703HIGHCWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity
and potential remote cEPSS 0.3%CVE-2026-6865HIGHImproper Limitation of a Pathname to a Restricted Directory Vulnerability on Multiple ProductsEPSS 0.3%CVE-2024-8401MEDIUMCWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
vulnerability exists when an authenticated attaEPSS 0.3%CVE-2022-34754MEDIUMA CWE-269: Improper Privilege Management vulnerability exists that could allow elevated functionality when guessing credentials. Affected PrEPSS 0.3%CVE-2025-2222HIGHCWE-552: Files or Directories Accessible to External Parties vulnerability over https exists that could leak
information and potential priviEPSS 0.3%CVE-2025-3905MEDIUMCWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability
exists impacting PLC system variaEPSS 0.3%CVE-2024-8933HIGHCWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel
vulnerability exists that could cause retrEPSS 0.3%CVE-2026-6866HIGHInitialization of a Resource with an Insecure Default vulnerability on EcoStruxure™ Panel ServerEPSS 0.3%CVE-2023-5630MEDIUM
A CWE-494: Download of Code Without Integrity Check vulnerability exists that could allow a
privileged user to install an untrusted firmwEPSS 0.3%