Vulnerabilities > Schneider Electric

DATE CVE VULNERABILITY TITLE RISK
2022-02-04 CVE-2022-22723 Unspecified vulnerability in Schneider-Electric Easergy P5 Firmware
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could lead to a buffer overflow causing program crashes and arbitrary code execution when specially crafted packets are sent to the device over the network.
low complexity
schneider-electric
8.8
2022-02-04 CVE-2022-22724 Unspecified vulnerability in Schneider-Electric products
A CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service on ports 80 (HTTP) and 502 (Modbus), when sending a large number of TCP RST or FIN packets to any open TCP port of the PLC.
network
low complexity
schneider-electric
7.5
2022-02-04 CVE-2022-22725 Unspecified vulnerability in Schneider-Electric Easergy P3 Firmware
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could lead to a buffer overflow causing program crashes and arbitrary code execution when specially crafted packets are sent to the device over the network.
low complexity
schneider-electric
8.8
2022-02-04 CVE-2022-22726 Unspecified vulnerability in Schneider-Electric Ecostruxure Power Monitoring Expert
A CWE-20: Improper Input Validation vulnerability exists that could allow arbitrary files on the server to be read by authenticated users through a limited operating system service account.
network
low complexity
schneider-electric
6.5
2022-02-04 CVE-2022-22727 Unspecified vulnerability in Schneider-Electric Ecostruxure Power Monitoring Expert
A CWE-20: Improper Input Validation vulnerability exists that could allow an unauthenticated attacker to view data, change settings, impact availability of the software, or potentially impact a user?s local machine when the user clicks a specially crafted link.
network
low complexity
schneider-electric
8.8
2022-02-04 CVE-2022-22804 Unspecified vulnerability in Schneider-Electric Ecostruxure Power Monitoring Expert
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could allow an authenticated attacker to view data, change settings, or impact availability of the software when the user visits a page containing the injected payload.
network
low complexity
schneider-electric
5.4
2022-01-28 CVE-2021-22724 Cross-Site Request Forgery (CSRF) vulnerability in Schneider-Electric products
A CVE-352 Cross-Site Request Forgery (CSRF) vulnerability exists that could allow an attacker to impersonate the user or carry out actions on their behalf when crafted malicious parameters are submitted in POST requests sent to the charging station web server.
network
low complexity
schneider-electric CWE-352
8.8
2022-01-28 CVE-2021-22725 Cross-Site Request Forgery (CSRF) vulnerability in Schneider-Electric products
A CVE-352 Cross-Site Request Forgery (CSRF) vulnerability exists that could allow an attacker to impersonate the user or carry out actions on their behalf when crafted malicious parameters are submitted in POST requests sent to the charging station web server.
network
low complexity
schneider-electric CWE-352
8.8
2022-01-28 CVE-2021-22799 Insufficient Entropy vulnerability in Schneider-Electric Software Update 2.3.0/2.3.1/2.5.1
A CWE-331: Insufficient Entropy vulnerability exists that could cause unintended connection from an internal network to an external network when an attacker manages to decrypt the SESU proxy password from the registry.
local
low complexity
schneider-electric CWE-331
3.8
2022-01-28 CVE-2021-22807 Out-of-bounds Write vulnerability in Schneider-Electric Guicon 2.0
A CWE-787: Out-of-bounds Write vulnerability exists that could cause arbitrary code execution when a malicious *.gd1 configuration file is loaded into the GUIcon tool.
local
low complexity
schneider-electric CWE-787
7.8