Vulnerabilidades em Schneider Electric

314 resultados
Análise Vexday

Com 302 CVEs catalogadas e 34 de severidade crítica, o portfólio de vulnerabilidades da Schneider Electric representa uma superfície de ataque relevante, especialmente em ambientes de tecnologia operacional e infraestrutura crítica. A taxa de exploração ativa está abaixo da média geral do catálogo, com nenhuma entrada confirmada no CISA KEV, e a ausência de PoCs públicas conhecidas reduz o risco imediato de exploração em massa. No entanto, o destaque vai para CVE-2022-34753, que registra EPSS de 0,71 — indicando probabilidade estatisticamente elevada de exploração — e está associada ao tipo de falha mais recorrente no conjunto, CWE-22 (Path Traversal), uma classe que frequentemente permite acesso não autorizado a arquivos e diretórios sensíveis. As 18 CVEs surgidas nos últimos 90 dias sinalizam ritmo contínuo de descoberta, o que exige monitoramento ativo por equipes responsáveis por ativos Schneider Electric.

CVE-2023-27982HIGHA CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause manipulation of dashboardEPSS 0.4%CVE-2023-5985MEDIUM A CWE-79 Improper Neutralization of Input During Web Page Generation vulnerability exists that could cause compromise of a user’s browserEPSS 0.4%CVE-2023-25551MEDIUM A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists on a DCE fileEPSS 0.4%CVE-2024-37040MEDIUMCWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability exists that could allow a user with access to EPSS 0.4%CVE-2023-25553MEDIUM A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists on a DCE enEPSS 0.4%CVE-2026-81861MEDIUMCWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of authentication information and unauthorized accEPSS 0.4%CVE-2025-0814MEDIUMCWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the network services running on the product wheEPSS 0.4%CVE-2022-43376HIGH A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause codeEPSS 0.4%CVE-2022-46680HIGH A CWE-319: Cleartext transmission of sensitive information vulnerability exists that could cause disclosure of sensitive information, deniaEPSS 0.4%CVE-2024-37038HIGHCWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interfaceEPSS 0.4%CVE-2014-5407Schneider Electric VAMPSET Stack-based Buffer OverflowEPSS 0.4%CVE-2021-22783HIGHA CWE-200: Information Exposure vulnerability exists which could allow a session hijack when the door panel is communicating with the door. EPSS 0.4%CVE-2026-0667CRITICALCWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service andEPSS 0.4%CVE-2024-5313MEDIUMCWE-668: Exposure of the Resource Wrong Sphere vulnerability exists that exposes a SSH interface over the product network interface. This doEPSS 0.4%CVE-2023-25556HIGH A CWE-287: Improper Authentication vulnerability exists that could allow a device to be compromised when a key of less than seven digits isEPSS 0.4%CVE-2025-13845HIGHCWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file)EPSS 0.4%CVE-2024-5056MEDIUMCWE-552: Files or Directories Accessible to External Parties vulnerability exists which may prevent user to update the device firmware and pEPSS 0.4%CVE-2024-12142HIGHCWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information disclosure of restrictEPSS 0.3%CVE-2024-9005HIGHCWE-502: Deserialization of Untrusted Data vulnerability exists that could allow code to be remotely executed on the server when unsafely deEPSS 0.3%CVE-2025-50123HIGHA CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote command execution by a priEPSS 0.3%