Vulnerabilities > Schneider Electric > Lss5500Shac Firmware > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-01-30 CVE-2022-32514 Unspecified vulnerability in Schneider-Electric products
A CWE-287: Improper Authentication vulnerability exists that could allow an attacker to gain control of the device when logging into a web page.
network
low complexity
schneider-electric
critical
9.8
2023-01-30 CVE-2022-32513 Unspecified vulnerability in Schneider-Electric products
A CWE-521: Weak Password Requirements vulnerability exists that could allow an attacker to gain control of the device when the attacker brute forces the password.
network
low complexity
schneider-electric
critical
9.8