Vulnerabilidades em Schneider Electric SE

118 resultados
Análise Vexday

Com 118 CVEs catalogadas e nenhuma atualmente registrada no CISA KEV, a taxa de exploração ativa da Schneider Electric SE está abaixo da média geral do catálogo, o que indica pressão ofensiva relativamente contida no momento. Ainda assim, a CVE mais perigosa identificada, CVE-2018-7836, apresenta um score EPSS de 0,3198 — o valor mais alto observado no conjunto —, sinalizando probabilidade não negligenciável de exploração que justifica atenção mesmo em ausência de confirmação ativa. O tipo de falha mais recorrente, CWE-754 (verificação inadequada de condições excepcionais), sugere padrões de desenvolvimento que podem facilitar comportamentos inesperados em ambientes de tecnologia operacional, onde robustez é crítica. Com duas vulnerabilidades de severidade crítica e uma PoC pública disponível, equipes de segurança devem priorizar a revisão desses itens antes que o cenário de exploração se altere.

CVE-2018-7764The vulnerability exists within runscript.php applet in Schneider Electric U.motion Builder software versions prior to v1.3.4. There is a diEPSS 1.3%CVE-2018-7762A vulnerability exists in the web services to process SOAP requests in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PEPSS 1.3%CVE-2018-7759A buffer overflow vulnerability exists in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200. The buffer ovEPSS 1.3%CVE-2019-6811An Improper Check for Unusual or Exceptional Conditions (CWE-754) vulnerability exists in Modicon Quantum 140 NOE771x1 version 6.9 and earliEPSS 1.3%CVE-2018-7770The vulnerability exists within processing of sendmail.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The appEPSS 1.3%CVE-2018-7245An improper authorization vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS andEPSS 1.3%CVE-2018-7806Data Center Operation allows for the upload of a zip file from its user interface to the server. A carefully crafted, malicious file could bEPSS 1.3%CVE-2018-7807Data Center Expert, versions 7.5.0 and earlier, allows for the upload of a zip file from its user interface to the server. A carefully craftEPSS 1.3%CVE-2018-7814A Stack-based Buffer Overflow (CWE-121) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0) which could cEPSS 1.2%CVE-2019-6826A CWE-426: Untrusted Search Path vulnerability exists in SoMachine HVAC v2.4.1 and earlier versions, which could cause arbitrary code executEPSS 1.2%CVE-2018-7227A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow retrieviEPSS 1.2%CVE-2018-7837An Improper Restriction of XML External Entity Reference ('XXE') vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 softwarEPSS 1.2%CVE-2018-7780In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, a buffer overflow vulnerabiliEPSS 1.2%CVE-2019-6840A Format String: CWE-134 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server PluEPSS 1.1%CVE-2018-7815A Type Confusion (CWE-843) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0) on c3core.dll which could EPSS 1.1%CVE-2018-7813A Type Confusion (CWE-843) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0) on pcwin.dll which could cEPSS 1.1%CVE-2019-6830A CWE-248: Uncaught Exception vulnerability exists IN Modicon M580 all versions prior to V2.80, which could cause a possible denial of serviEPSS 1.1%CVE-2018-7787In Schneider Electric U.motion Builder software versions prior to v1.3.4, this vulnerability is due to improper validation of input of conteEPSS 1.1%CVE-2017-9956An authentication bypass vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the systemEPSS 1.1%CVE-2018-7244An information disclosure vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS andEPSS 1.1%