Vulnerabilities > Schneider Electric > Modicon M258 Firmware > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-07-11 CVE-2024-6528 Unspecified vulnerability in Schneider-Electric products
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a vulnerability leading to a cross-site scripting condition where attackers can have a victim’s browser run arbitrary JavaScript when they visit a page containing the injected payload.
network
low complexity
schneider-electric
6.1
2020-12-11 CVE-2020-28220 Unspecified vulnerability in Schneider-Electric Modicon M258 Firmware, Somachine and Somachine Motion
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Modicon M258 Firmware (All versions prior to V5.0.4.11) and SoMachine/SoMachine Motion software (All versions), that could cause a buffer overflow when the length of a file transferred to the webserver is not verified.
low complexity
schneider-electric
6.8