Vulnerabilidades em Schneider Electric

314 resultados
Análise Vexday

Com 302 CVEs catalogadas e 34 de severidade crítica, o portfólio de vulnerabilidades da Schneider Electric representa uma superfície de ataque relevante, especialmente em ambientes de tecnologia operacional e infraestrutura crítica. A taxa de exploração ativa está abaixo da média geral do catálogo, com nenhuma entrada confirmada no CISA KEV, e a ausência de PoCs públicas conhecidas reduz o risco imediato de exploração em massa. No entanto, o destaque vai para CVE-2022-34753, que registra EPSS de 0,71 — indicando probabilidade estatisticamente elevada de exploração — e está associada ao tipo de falha mais recorrente no conjunto, CWE-22 (Path Traversal), uma classe que frequentemente permite acesso não autorizado a arquivos e diretórios sensíveis. As 18 CVEs surgidas nos últimos 90 dias sinalizam ritmo contínuo de descoberta, o que exige monitoramento ativo por equipes responsáveis por ativos Schneider Electric.

CVE-2024-2602HIGHCWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could result in remote codeEPSS 0.3%CVE-2022-34763MEDIUMA CWE-345: Insufficient Verification of Data Authenticity vulnerability exists that could cause loading of unauthorized firmware images due EPSS 0.3%CVE-2024-12476HIGHCWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure, impacts workstaEPSS 0.3%CVE-2025-6788MEDIUMA CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that exposes TGML diagram resources to the wrong control sphere, providEPSS 0.3%CVE-2026-2402MEDIUMCWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to gain access to the usEPSS 0.3%CVE-2026-4832MEDIUMCWE-798 Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to sensitive device information when an unauEPSS 0.3%CVE-2025-0813HIGHCWE-287: Improper Authentication vulnerability exists that could cause an Authentication Bypass when an unauthorized user without permissionEPSS 0.3%CVE-2022-22732LOWA CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause all remote domains to access the resources (data) suppEPSS 0.3%CVE-2022-32512MEDIUMA CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause remote code executiEPSS 0.3%CVE-2022-41671HIGHA CWE-89: Improper Neutralization of Special Elements used in SQL Command (‘SQL Injection’) vulnerability exists that allows adversaries witEPSS 0.3%CVE-2024-6528MEDIUMCWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a vulneraEPSS 0.3%CVE-2025-8449MEDIUMCWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service when an authenticated user sends a specEPSS 0.3%CVE-2025-5742MEDIUMCWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when an authenticated userEPSS 0.3%CVE-2025-2442MEDIUMCWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could potentially lead to unauthorized access whicEPSS 0.2%CVE-2022-32516HIGHA CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could cause system’s configurations override and cause a reboot loop EPSS 0.2%CVE-2025-1060HIGHCWE-319: Cleartext Transmission of Sensitive Information vulnerability exists that could result in the exposure of data when network trafficEPSS 0.2%CVE-2026-2405MEDIUMCWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting zip file creation and denial of seEPSS 0.2%CVE-2023-27977MEDIUMA CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause access to delete files inEPSS 0.2%CVE-2023-27979MEDIUMA CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could allow the renaming of files in EPSS 0.2%CVE-2025-1058HIGHCWE-494: Download of Code Without Integrity Check vulnerability exists that could render the device inoperable when malicious firmware is doEPSS 0.2%