Vulnerabilities in Schneider Electric

314 results
Vexday analysis

Com 302 CVEs catalogadas e 34 de severidade crítica, o portfólio de vulnerabilidades da Schneider Electric representa uma superfície de ataque relevante, especialmente em ambientes de tecnologia operacional e infraestrutura crítica. A taxa de exploração ativa está abaixo da média geral do catálogo, com nenhuma entrada confirmada no CISA KEV, e a ausência de PoCs públicas conhecidas reduz o risco imediato de exploração em massa. No entanto, o destaque vai para CVE-2022-34753, que registra EPSS de 0,71 — indicando probabilidade estatisticamente elevada de exploração — e está associada ao tipo de falha mais recorrente no conjunto, CWE-22 (Path Traversal), uma classe que frequentemente permite acesso não autorizado a arquivos e diretórios sensíveis. As 18 CVEs surgidas nos últimos 90 dias sinalizam ritmo contínuo de descoberta, o que exige monitoramento ativo por equipes responsáveis por ativos Schneider Electric.

CVE-2026-4832MEDIUMCWE-798 Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to sensitive device information when an unauEPSS 0.4%CVE-2025-2875HIGHCWE-610: Externally Controlled Reference to a Resource in Another Sphere vulnerability exists that could cause a loss of confidentiality wheEPSS 0.4%CVE-2023-0595MEDIUMA CWE-117: Improper Output Neutralization for Logs vulnerability exists that could cause the misinterpretation of log files when malicious pEPSS 0.4%CVE-2025-6438MEDIUMA CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause manipulation of SOAP API callsEPSS 0.4%CVE-2026-9650HIGHCWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when uEPSS 0.4%CVE-2023-5987MEDIUM A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability that could cause a vulnerability EPSS 0.4%CVE-2023-27982HIGHA CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause manipulation of dashboardEPSS 0.4%CVE-2023-5985MEDIUM A CWE-79 Improper Neutralization of Input During Web Page Generation vulnerability exists that could cause compromise of a user’s browserEPSS 0.4%CVE-2023-25551MEDIUM A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists on a DCE fileEPSS 0.4%CVE-2024-37040MEDIUMCWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability exists that could allow a user with access to EPSS 0.4%CVE-2023-25553MEDIUM A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists on a DCE enEPSS 0.4%CVE-2026-8045HIGHCWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side fiEPSS 0.4%CVE-2025-0814MEDIUMCWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the network services running on the product wheEPSS 0.4%CVE-2022-46680HIGH A CWE-319: Cleartext transmission of sensitive information vulnerability exists that could cause disclosure of sensitive information, deniaEPSS 0.4%CVE-2022-43376HIGH A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause codeEPSS 0.4%CVE-2024-37038HIGHCWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interfaceEPSS 0.4%CVE-2014-5407—Schneider Electric VAMPSET Stack-based Buffer OverflowEPSS 0.4%CVE-2021-22783HIGHA CWE-200: Information Exposure vulnerability exists which could allow a session hijack when the door panel is communicating with the door. EPSS 0.4%CVE-2024-5313MEDIUMCWE-668: Exposure of the Resource Wrong Sphere vulnerability exists that exposes a SSH interface over the product network interface. This doEPSS 0.4%CVE-2023-25556HIGH A CWE-287: Improper Authentication vulnerability exists that could allow a device to be compromised when a key of less than seven digits isEPSS 0.4%