Vulnerabilidades em Schneider Electric SE

118 resultados
Análise Vexday

Com 118 CVEs catalogadas e nenhuma atualmente registrada no CISA KEV, a taxa de exploração ativa da Schneider Electric SE está abaixo da média geral do catálogo, o que indica pressão ofensiva relativamente contida no momento. Ainda assim, a CVE mais perigosa identificada, CVE-2018-7836, apresenta um score EPSS de 0,3198 — o valor mais alto observado no conjunto —, sinalizando probabilidade não negligenciável de exploração que justifica atenção mesmo em ausência de confirmação ativa. O tipo de falha mais recorrente, CWE-754 (verificação inadequada de condições excepcionais), sugere padrões de desenvolvimento que podem facilitar comportamentos inesperados em ambientes de tecnologia operacional, onde robustez é crítica. Com duas vulnerabilidades de severidade crítica e uma PoC pública disponível, equipes de segurança devem priorizar a revisão desses itens antes que o cenário de exploração se altere.

CVE-2017-6021In Schneider Electric ClearSCADA 2014 R1 (build 75.5210) and prior, 2014 R1.1 (build 75.5387) and prior, 2015 R1 (build 76.5648) and prior, EPSS 1.7%CVE-2018-7235A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow arbitrarEPSS 1.6%CVE-2019-6856HIGHA CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, ModiconEPSS 1.6%CVE-2019-6857HIGHA CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, ModiconEPSS 1.6%CVE-2017-9966A privilege escalation vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2.0 and prior. By replacing certainEPSS 1.6%CVE-2017-9957A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the web service contains a hiddenEPSS 1.6%CVE-2019-6829HIGHA CWE-248: Uncaught Exception vulnerability exists in Modicon M580 (firmware version prior to V2.90) and Modicon M340 (firmware version prioEPSS 1.6%CVE-2018-7230A XML external entity (XXE) vulnerability exists in the import.cgi of the web interface component of the Schneider Electric's Pelco Sarix PrEPSS 1.6%CVE-2018-7783Schneider Electric SoMachine Basic prior to v1.6 SP1 suffers from an XML External Entity (XXE) vulnerability using the DTD parameter entitieEPSS 1.6%CVE-2019-6828A CWE-248: Uncaught Exception vulnerability exists Modicon M580 (firmware version prior to V2.90), Modicon M340 (firmware version prior to VEPSS 1.5%CVE-2018-7760An authorization bypass vulnerability exists in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200. RequestEPSS 1.5%CVE-2017-7973A SQL injection vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauthenticated EPSS 1.5%CVE-2019-6832A CWE-287: Authentication vulnerability exists in spaceLYnk (all versions before 2.4.0) and Wiser for KNX (all versions before 2.4.0 - formeEPSS 1.5%CVE-2018-7771The vulnerability exists within processing of editscript.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A dirEPSS 1.4%CVE-2019-6831A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in BMXNOR0200H Ethernet / Serial RTU module (all firmwaEPSS 1.4%CVE-2018-7794HIGHA CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, ModiconEPSS 1.4%CVE-2018-7779In Schneider Electric Wiser for KNX V2.1.0 and prior, homeLYnk V2.0.1 and prior; and spaceLYnk V2.1.0 and prior, weak and unprotected FTP acEPSS 1.4%CVE-2018-7833An Improper Check for Unusual or Exceptional Conditions vulnerability exists in the embedded web servers in all Modicon M340, Premium, QuantEPSS 1.4%CVE-2018-7236A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could enable SSH serEPSS 1.3%CVE-2018-7763The vulnerability exists within css.inc.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The 'css' parameter coEPSS 1.3%