Vulnerabilities > Schneider Electric

DATE CVE VULNERABILITY TITLE RISK
2024-07-11 CVE-2024-6407 Unspecified vulnerability in Schneider-Electric Whc-5918A Firmware
CWE-200: Information Exposure vulnerability exists that could cause disclosure of credentials when a specially crafted message is sent to the device.
network
low complexity
schneider-electric
7.5
2024-07-11 CVE-2024-2602 Path Traversal vulnerability in Schneider-Electric Foxrtu Station
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could result in remote code execution when an authenticated user executes a saved project file that has been tampered by a malicious actor.
local
low complexity
schneider-electric CWE-22
7.8
2024-07-11 CVE-2024-5679 Out-of-bounds Write vulnerability in Schneider-Electric Ecostruxure Foxboro DCS Control Core Services
CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, or kernel memory leak when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
local
low complexity
schneider-electric CWE-787
7.1
2024-07-11 CVE-2024-5680 Improper Validation of Array Index vulnerability in Schneider-Electric Ecostruxure Foxboro DCS Control Core Services
CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
local
low complexity
schneider-electric CWE-129
5.5
2024-07-11 CVE-2024-5681 Improper Input Validation vulnerability in Schneider-Electric Ecostruxure Foxboro DCS Control Core Services
CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service, privilege escalation, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
local
low complexity
schneider-electric CWE-20
7.8
2024-07-11 CVE-2024-6528 Cross-site Scripting vulnerability in Schneider-Electric products
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a vulnerability leading to a cross-site scripting condition where attackers can have a victim’s browser run arbitrary JavaScript when they visit a page containing the injected payload.
network
low complexity
schneider-electric CWE-79
6.1
2024-06-12 CVE-2024-0865 Use of Hard-coded Credentials vulnerability in Schneider-Electric Ecostruxure IT Gateway
CWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege escalation when logged in as a non-administrative user.
local
low complexity
schneider-electric CWE-798
7.8
2024-06-12 CVE-2024-37037 Path Traversal vulnerability in Schneider-Electric Sage RTU Firmware
CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability exists that could allow an authenticated user with access to the device’s web interface to corrupt files and impact device functionality when sending a crafted HTTP request.
network
low complexity
schneider-electric CWE-22
8.1
2024-06-12 CVE-2024-37038 Incorrect Default Permissions vulnerability in Schneider-Electric Sage RTU Firmware
CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perform unauthorized file and firmware uploads when crafting custom web requests.
network
low complexity
schneider-electric CWE-276
8.8
2024-06-12 CVE-2024-37039 Unchecked Return Value vulnerability in Schneider-Electric Sage RTU Firmware
CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request.
network
low complexity
schneider-electric CWE-252
7.5