Vulnerabilidades em Schneider ELectric
314 resultadosAnálise Vexday
A Schneider Electric apresenta perfil de risco baixo com apenas 1 vulnerabilidade catalogada na base, sem registros de exploração ativa ou incidentes críticos. A fraqueza identificada (CWE-20 - validação imprópria de entrada) é de natureza genérica e a vulnerabilidade não foi publicada recentemente, indicando um risco estabilizado e de menor prioridade para monitoramento imediato.
CVE-2024-12399MEDIUMCWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability
exists that could cause partEPSS 0.2%CVE-2024-9002HIGHCWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized
access, loss of confidentiality, integrity, and avEPSS 0.2%CVE-2026-2403MEDIUMCWE-1284 Improper Validation of Specified Quantity in Input vulnerability exists that could cause Event and Data Log truncation impacting loEPSS 0.2%CVE-2023-2161MEDIUM
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that
could cause unauthorized read access to the fileEPSS 0.2%CVE-2024-2747HIGHCWE-428: Unquoted search path or element vulnerability exists in Easergy Studio, which could
cause privilege escalation when a valid user reEPSS 0.2%CVE-2025-0327HIGHCWE-269: Improper Privilege Management vulnerability exists for two services (of which one managing audit
trail data and the other acting asEPSS 0.2%CVE-2022-4062HIGHA CWE-285: Improper Authorization vulnerability exists that could cause unauthorized access to certain software functions when an attacker gEPSS 0.2%CVE-2025-3899MEDIUMCWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability
exists in Certificates page on WeEPSS 0.2%CVE-2022-42973HIGHA CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause local privilege escalation when local attacker connects to thEPSS 0.2%CVE-2025-2002MEDIUMCWE-532: Insertion of Sensitive Information into Log Files vulnerability exists that could cause the disclosure
of FTP server credentials whEPSS 0.2%CVE-2025-13844HIGHCWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD fiEPSS 0.2%CVE-2023-2570HIGH
A CWE-129: Improper Validation of Array Index vulnerability exists that could cause local
denial-of-service, and potentially kernel execuEPSS 0.2%CVE-2026-12927HIGHCWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execution when a maliciousEPSS 0.2%CVE-2024-8518LOWCWE-20: Improper Input Validation vulnerability exists that could cause a crash of the Zelio Soft
2 application when a specially crafted proEPSS 0.2%CVE-2026-9651MEDIUMCWE-732 Incorrect Permission Assignment for Critical Resource vulnerability that could cause unauthorized disclosure of password hashes and EPSS 0.2%CVE-2024-10083MEDIUMCWE-20: Improper Input Validation vulnerability exists that could cause denial of service of engineering
workstation when specific driver inEPSS 0.2%CVE-2023-27975HIGH
CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized
access to the project file in EcoStruxure EPSS 0.1%CVE-2024-5679HIGHCWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, or
kernel memory leak when a malicious actor witEPSS 0.1%CVE-2023-1548MEDIUM
A CWE-269: Improper Privilege Management vulnerability exists that could cause a local user to
perform a denial of service through the consEPSS 0.1%CVE-2024-5680HIGHCWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service when a malicious actor with local EPSS 0.1%