Vulnerabilities > Schneider Electric > Ecostruxure Control Expert > High

DATE CVE VULNERABILITY TITLE RISK
2020-11-19 CVE-2020-28211 Unspecified vulnerability in Schneider-Electric Ecostruxure Control Expert
A CWE-863: Incorrect Authorization vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause bypass of authentication when overwriting memory using a debugger.
local
low complexity
schneider-electric
7.8
2020-01-06 CVE-2019-6855 Incorrect Authorization vulnerability in Schneider-Electric products
Incorrect Authorization vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20) , and Modicon M580 (all versions prior to V3.10), which could cause a bypass of the authentication process between EcoStruxure Control Expert and the M340 and M580 controllers.
network
low complexity
schneider-electric CWE-863
7.3