Vulnerabilities > Schneider Electric
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-07-11 | CVE-2024-6407 | Unspecified vulnerability in Schneider-Electric Whc-5918A Firmware CWE-200: Information Exposure vulnerability exists that could cause disclosure of credentials when a specially crafted message is sent to the device. | 7.5 |
2024-07-11 | CVE-2024-2602 | Path Traversal vulnerability in Schneider-Electric Foxrtu Station CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could result in remote code execution when an authenticated user executes a saved project file that has been tampered by a malicious actor. | 7.8 |
2024-07-11 | CVE-2024-5679 | Out-of-bounds Write vulnerability in Schneider-Electric Ecostruxure Foxboro DCS Control Core Services CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, or kernel memory leak when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver. | 7.1 |
2024-07-11 | CVE-2024-5680 | Improper Validation of Array Index vulnerability in Schneider-Electric Ecostruxure Foxboro DCS Control Core Services CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver. | 5.5 |
2024-07-11 | CVE-2024-5681 | Improper Input Validation vulnerability in Schneider-Electric Ecostruxure Foxboro DCS Control Core Services CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service, privilege escalation, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver. | 7.8 |
2024-07-11 | CVE-2024-6528 | Cross-site Scripting vulnerability in Schneider-Electric products CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a vulnerability leading to a cross-site scripting condition where attackers can have a victim’s browser run arbitrary JavaScript when they visit a page containing the injected payload. | 6.1 |
2024-06-12 | CVE-2024-0865 | Use of Hard-coded Credentials vulnerability in Schneider-Electric Ecostruxure IT Gateway CWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege escalation when logged in as a non-administrative user. | 7.8 |
2024-06-12 | CVE-2024-37037 | Path Traversal vulnerability in Schneider-Electric Sage RTU Firmware CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability exists that could allow an authenticated user with access to the device’s web interface to corrupt files and impact device functionality when sending a crafted HTTP request. | 8.1 |
2024-06-12 | CVE-2024-37038 | Incorrect Default Permissions vulnerability in Schneider-Electric Sage RTU Firmware CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perform unauthorized file and firmware uploads when crafting custom web requests. | 8.8 |
2024-06-12 | CVE-2024-37039 | Unchecked Return Value vulnerability in Schneider-Electric Sage RTU Firmware CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request. | 7.5 |