Vulnerabilities in Schneider Electric

314 results
Vexday analysis

Com 302 CVEs catalogadas e 34 de severidade crítica, o portfólio de vulnerabilidades da Schneider Electric representa uma superfície de ataque relevante, especialmente em ambientes de tecnologia operacional e infraestrutura crítica. A taxa de exploração ativa está abaixo da média geral do catálogo, com nenhuma entrada confirmada no CISA KEV, e a ausência de PoCs públicas conhecidas reduz o risco imediato de exploração em massa. No entanto, o destaque vai para CVE-2022-34753, que registra EPSS de 0,71 — indicando probabilidade estatisticamente elevada de exploração — e está associada ao tipo de falha mais recorrente no conjunto, CWE-22 (Path Traversal), uma classe que frequentemente permite acesso não autorizado a arquivos e diretórios sensíveis. As 18 CVEs surgidas nos últimos 90 dias sinalizam ritmo contínuo de descoberta, o que exige monitoramento ativo por equipes responsáveis por ativos Schneider Electric.

CVE-2025-1960CRITICALCWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could cause an attacker to execute unauthorized coEPSS 0.5%CVE-2023-25552HIGH A CWE-862: Missing Authorization vulnerability exists that could allow viewing of unauthorized content, changes or deleting of content, oEPSS 0.5%CVE-2024-8935HIGHCWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss of confidentiality and integriEPSS 0.5%CVE-2024-8936HIGHCWE-20: Improper Input Validation vulnerability exists that could lead to loss of confidentiality of controller memory after a successful MaEPSS 0.5%CVE-2025-9997MEDIUMCWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause comEPSS 0.5%CVE-2026-6866HIGHInitialization of a Resource with an Insecure Default vulnerability on EcoStruxure™ Panel ServerEPSS 0.5%CVE-2023-7032HIGH A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker logged in with a user level account to gain EPSS 0.5%CVE-2025-50125MEDIUMA CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthenticated remote code execution when the serverEPSS 0.5%CVE-2024-6918HIGHCWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause a crash of the AccutecEPSS 0.5%CVE-2025-1070HIGHCWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could render the device inoperable when a malicious file EPSS 0.5%CVE-2022-32519HIGHA CWE-257: Storing Passwords in a Recoverable Format vulnerability exists that could result in unwanted access to a DCE instance when perforEPSS 0.5%CVE-2025-6625HIGHCWE-20: Improper Input Validation vulnerability exists that could cause a Denial Of Service when specific crafted FTP command is sent to theEPSS 0.5%CVE-2022-32528HIGH A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause access to manipulate and read specific files EPSS 0.5%CVE-2024-2050HIGH CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when an attacker injects EPSS 0.5%CVE-2014-0774—Schneider Electric OFS Stack Buffer OverflowEPSS 0.5%CVE-2025-1059HIGHCWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause communications to stop when malicious paEPSS 0.5%CVE-2022-43378MEDIUM A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause the user to be tricked into peEPSS 0.5%CVE-2026-9716HIGHCWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuEPSS 0.5%CVE-2024-8531HIGHCWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could compromise the Data Center Expert software when anEPSS 0.5%CVE-2015-1014—A successful exploit of these vulnerabilities requires the local user to load a crafted DLL file in the system directory on servers running EPSS 0.5%