Vulnerabilidades em Schneider Electric

314 resultados
Análise Vexday

Com 302 CVEs catalogadas e 34 de severidade crítica, o portfólio de vulnerabilidades da Schneider Electric representa uma superfície de ataque relevante, especialmente em ambientes de tecnologia operacional e infraestrutura crítica. A taxa de exploração ativa está abaixo da média geral do catálogo, com nenhuma entrada confirmada no CISA KEV, e a ausência de PoCs públicas conhecidas reduz o risco imediato de exploração em massa. No entanto, o destaque vai para CVE-2022-34753, que registra EPSS de 0,71 — indicando probabilidade estatisticamente elevada de exploração — e está associada ao tipo de falha mais recorrente no conjunto, CWE-22 (Path Traversal), uma classe que frequentemente permite acesso não autorizado a arquivos e diretórios sensíveis. As 18 CVEs surgidas nos últimos 90 dias sinalizam ritmo contínuo de descoberta, o que exige monitoramento ativo por equipes responsáveis por ativos Schneider Electric.

CVE-2014-2381Schneider Electric Wonderware Inadequate Encryption StrengthEPSS 0.1%CVE-2022-32748HIGHA CWE-295: Improper Certificate Validation vulnerability exists that could cause the CAE software to give wrong data to end users when usingEPSS 0.1%CVE-2022-41666HIGHA CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that allows adversaries with local user privileges to load EPSS 0.1%CVE-2026-1226HIGHCWE‑94: Improper Control of Generation of Code vulnerability exists that could cause execution of untrusted or unintended code within the apEPSS 0.1%CVE-2025-11565HIGHCWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause elevated systemEPSS 0.1%CVE-2026-6332MEDIUMClear Text Storage of Sensitive Information on EcoStruxure™ Machine Expert HVACEPSS 0.1%CVE-2025-11567HIGHCWE-276: Incorrect Default Permissions vulnerability exists that could cause elevated system access when the target installation folder is nEPSS 0.1%CVE-2026-14354HIGHCWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorized credential modificEPSS 0.1%CVE-2022-41669HIGHA CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in the SGIUtility component that allows adversaries with loEPSS 0.1%CVE-2024-8070HIGHCWE-312: Cleartext Storage of Sensitive Information vulnerability exists that exposes test credentials in the firmware binaryEPSS 0.1%CVE-2026-1227HIGHCWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized disclosure of local files,EPSS 0.1%CVE-2024-5558MEDIUMCWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists that could cause escalation of privileges when an attacker aEPSS 0.1%CVE-2026-2401LOWCWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information to be exposed when EPSS 0.1%CVE-2025-13905HIGHCWE-276: Incorrect Default Permissions vulnerability exists that could cause privilege escalation through the reverse shell when one or moEPSS 0.1%