Vulnerabilities > Schneider Electric > Ecostruxure Control Expert > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-01-31 CVE-2022-45789 Authentication Bypass by Capture-replay vulnerability in Schneider-Electric products
A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session.
network
low complexity
schneider-electric CWE-294
critical
9.8
2023-01-30 CVE-2022-45788 Improper Check for Unusual or Exceptional Conditions vulnerability in Schneider-Electric products
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when a malicious project file is loaded onto the controller.
network
low complexity
schneider-electric CWE-754
critical
9.8
2022-04-14 CVE-2022-26507 Out-of-bounds Write vulnerability in multiple products
A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7.
network
low complexity
att schneider-electric CWE-787
critical
9.8
2022-04-13 CVE-2021-22797 Path Traversal vulnerability in Schneider-Electric products
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be deployed in an unauthorized location and may result in code execution on the engineering workstation when a malicious project file is loaded in the engineering software.
network
schneider-electric CWE-22
critical
9.3