Vulnerabilidades em Schneider ELectric

314 resultados
Análise Vexday

A Schneider Electric apresenta perfil de risco baixo com apenas 1 vulnerabilidade catalogada na base, sem registros de exploração ativa ou incidentes críticos. A fraqueza identificada (CWE-20 - validação imprópria de entrada) é de natureza genérica e a vulnerabilidade não foi publicada recentemente, indicando um risco estabilizado e de menor prioridade para monitoramento imediato.

CVE-2025-9997MEDIUMCWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause comEPSS 0.5%CVE-2023-7032HIGH A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker logged in with a user level account to gain EPSS 0.5%CVE-2025-50125MEDIUMA CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthenticated remote code execution when the serverEPSS 0.5%CVE-2024-6918HIGHCWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause a crash of the AccutecEPSS 0.5%CVE-2025-1070HIGHCWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could render the device inoperable when a malicious file EPSS 0.5%CVE-2025-6625HIGHCWE-20: Improper Input Validation vulnerability exists that could cause a Denial Of Service when specific crafted FTP command is sent to theEPSS 0.5%CVE-2022-32519HIGHA CWE-257: Storing Passwords in a Recoverable Format vulnerability exists that could result in unwanted access to a DCE instance when perforEPSS 0.5%CVE-2022-32528HIGH A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause access to manipulate and read specific files EPSS 0.5%CVE-2024-2050HIGH CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when an attacker injects EPSS 0.5%CVE-2025-1059HIGHCWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause communications to stop when malicious paEPSS 0.5%CVE-2014-0774Schneider Electric OFS Stack Buffer OverflowEPSS 0.5%CVE-2022-43378MEDIUM A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause the user to be tricked into peEPSS 0.5%CVE-2026-9716HIGHCWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuEPSS 0.5%CVE-2024-8531HIGHCWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could compromise the Data Center Expert software when anEPSS 0.5%CVE-2015-1014A successful exploit of these vulnerabilities requires the local user to load a crafted DLL file in the system directory on servers running EPSS 0.5%CVE-2025-13901MEDIUMCWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of Service on Machine Expert protocol wheEPSS 0.5%CVE-2025-54924HIGHCWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized access to sensitive data when an attacker senEPSS 0.5%CVE-2023-5986HIGH A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scrEPSS 0.5%CVE-2025-3116HIGHCWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated malicious user sends specialEPSS 0.5%CVE-2025-54925HIGHCWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized access to sensitive data when an attacker conEPSS 0.5%