Vulnerabilities > Schneider Electric

DATE CVE VULNERABILITY TITLE RISK
2020-11-18 CVE-2020-7564 Classic Buffer Overflow vulnerability in Schneider-Electric products
A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause write access and the execution of commands when uploading a specially crafted file on the controller over FTP.
network
low complexity
schneider-electric CWE-120
8.8
2020-11-18 CVE-2020-7563 Out-of-bounds Write vulnerability in Schneider-Electric products
A CWE-787: Out-of-bounds Write vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause corruption of data, a crash, or code execution when uploading a specially crafted file on the controller over FTP.
network
low complexity
schneider-electric CWE-787
8.8
2020-11-18 CVE-2020-7562 Out-of-bounds Read vulnerability in Schneider-Electric products
A CWE-125: Out-of-Bounds Read vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause a segmentation fault or a buffer overflow when uploading a specially crafted file on the controller over FTP.
network
low complexity
schneider-electric CWE-125
8.1
2020-09-16 CVE-2020-7532 Deserialization of Untrusted Data vulnerability in Schneider-Electric Scadapack X70 Security Administrator 1.2.0
A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack x70 Security Administrator (V1.2.0 and prior) which could allow arbitrary code execution when an attacker builds a custom .SDB file containing a malicious serialized buffer.
local
low complexity
schneider-electric CWE-502
7.8
2020-09-16 CVE-2020-7531 Unspecified vulnerability in Schneider-Electric Scadapack 7X Remote Connect 3.6.3.574
A CWE-284 Improper Access Control vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place executables in a specific folder and run code whenever RemoteConnect is executed by the user.
local
low complexity
schneider-electric
7.8
2020-09-16 CVE-2020-7530 Unspecified vulnerability in Schneider-Electric Scadapack 7X Remote Connect 3.6.3.574
A CWE-285 Improper Authorization vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows improper access to executable code folders.
network
low complexity
schneider-electric
8.8
2020-09-16 CVE-2020-7529 Path Traversal vulnerability in Schneider-Electric Scadapack 7X Remote Connect 3.6.3.574
A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Transversal') vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place content in any unprotected folder on the target system using a crafted .RCZ file.
local
low complexity
schneider-electric CWE-22
5.5
2020-09-16 CVE-2020-7528 Deserialization of Untrusted Data vulnerability in Schneider-Electric Scadapack 7X Remote Connect 3.6.3.574
A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which could allow arbitrary code execution when an attacker builds a custom .PRJ file containing a malicious serialized buffer.
local
low complexity
schneider-electric CWE-502
7.8
2020-08-31 CVE-2020-7527 Incorrect Default Permissions vulnerability in Schneider-Electric Somove
Incorrect Default Permission vulnerability exists in SoMove (V2.8.1) and prior which could cause elevation of privilege and provide full access control to local system users to SoMove component and services when a SoMove installer script is launched.
local
low complexity
schneider-electric CWE-276
7.8
2020-08-31 CVE-2020-7525 Improper Restriction of Excessive Authentication Attempts vulnerability in Schneider-Electric Spacelynk Firmware and Wiser for KNX Firmware
Improper Restriction of Excessive Authentication Attempts vulnerability exists in all hardware versions of spaceLYnk and Wiser for KNX (formerly homeLYnk) which could allow an attacker to guess a password when brute force is used.
network
low complexity
schneider-electric CWE-307
7.5