Vulnerabilidades em Schneider Electric SE

118 resultados
Análise Vexday

Com 118 CVEs catalogadas e nenhuma atualmente registrada no CISA KEV, a taxa de exploração ativa da Schneider Electric SE está abaixo da média geral do catálogo, o que indica pressão ofensiva relativamente contida no momento. Ainda assim, a CVE mais perigosa identificada, CVE-2018-7836, apresenta um score EPSS de 0,3198 — o valor mais alto observado no conjunto —, sinalizando probabilidade não negligenciável de exploração que justifica atenção mesmo em ausência de confirmação ativa. O tipo de falha mais recorrente, CWE-754 (verificação inadequada de condições excepcionais), sugere padrões de desenvolvimento que podem facilitar comportamentos inesperados em ambientes de tecnologia operacional, onde robustez é crítica. Com duas vulnerabilidades de severidade crítica e uma PoC pública disponível, equipes de segurança devem priorizar a revisão desses itens antes que o cenário de exploração se altere.

CVE-2018-7836An unrestricted Upload of File with Dangerous Type vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could aEPSS 26.1%CVE-2018-7777The vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Electric U.motion BuildEPSS 25.0%CVE-2018-7801A Code Injection vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could enable access with maximum privileges when a EPSS 6.3%CVE-2018-7817A Use After Free (CWE-416) vulnerability exists in Zelio Soft 2 v5.1 and prior versions which could cause remote code execution when openingEPSS 4.4%CVE-2017-9965An exposure of sensitive information vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2.0 and prior. Using EPSS 4.4%CVE-2018-7799A DLL hijacking vulnerability exists in Schneider Electric Software Update (SESU), all versions prior to V2.2.0, which could allow an attackEPSS 3.8%CVE-2018-7239A DLL hijacking vulnerability exists in Schneider Electric's SoMove Software and associated DTM software components in all versions prior toEPSS 3.8%CVE-2017-7974A path traversal information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in wEPSS 3.4%CVE-2018-7800A Hard-coded Credentials vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could enable an attacker to gain access to EPSS 3.3%CVE-2018-7241Hard coded accounts exist in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, and BMXNOR0200 controllers in all versionsEPSS 3.2%CVE-2018-7812An Information Exposure through Discrepancy vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and EPSS 3.2%CVE-2018-7811An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 whiEPSS 2.8%CVE-2018-7789MEDIUMAn Improper Check for Unusual or Exceptional Conditions vulnerability exists in Schneider Electric's Modicon M221 product (all references, aEPSS 2.8%CVE-2018-7238A buffer overflow vulnerability exist in the web-based GUI of Schneider Electric's Pelco Sarix Professional in all firmware versions prior tEPSS 2.8%CVE-2018-7240A vulnerability exists in Schneider Electric's Modicon Quantum in all versions of the communication modules which could allow arbitrary codeEPSS 2.8%CVE-2018-7243An authorization bypass vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MEPSS 2.6%CVE-2018-7785In Schneider Electric U.motion Builder software versions prior to v1.3.4, a remote command injection allows authentication bypass.EPSS 2.5%CVE-2018-7790CRITICALAn Information Management Error vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firEPSS 2.5%CVE-2017-7966A DLL Hijacking vulnerability in the programming software in Schneider Electric's SoMachine HVAC v2.1.0 allows a remote attacker to execute EPSS 2.4%CVE-2018-7795MEDIUMA Cross Protocol Injection vulnerability exists in Schneider Electric's PowerLogic (PM5560 prior to FW version 2.5.4) product. The vulnerabiEPSS 2.3%