Vulnerabilities > Schneider Electric

DATE CVE VULNERABILITY TITLE RISK
2023-11-15 CVE-2023-5985 Unspecified vulnerability in Schneider-Electric Ion8650 Firmware and Ion8800 Firmware
A CWE-79 Improper Neutralization of Input During Web Page Generation vulnerability exists that could cause compromise of a user’s browser when an attacker with admin privileges has modified system values.
network
low complexity
schneider-electric
4.8
2023-11-15 CVE-2023-5986 Open Redirect vulnerability in Schneider-Electric Ecostruxure Power Monitoring Expert 2020/2021
A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting attack.
network
low complexity
schneider-electric CWE-601
6.1
2023-11-15 CVE-2023-5987 Unspecified vulnerability in Schneider-Electric Ecostruxure Power Monitoring Expert 2020/2021
A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability that could cause a vulnerability leading to a cross site scripting condition where attackers can have a victim’s browser run arbitrary JavaScript when they visit a page containing the injected payload.
network
low complexity
schneider-electric
6.1
2023-11-15 CVE-2023-6032 Unspecified vulnerability in Schneider-Electric Galaxy VL Firmware and Galaxy VS Firmware
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause a file system enumeration and file download when an attacker navigates to the Network Management Card via HTTPS.
network
low complexity
schneider-electric
5.3
2023-10-04 CVE-2023-5391 Unspecified vulnerability in Schneider-Electric products
A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by sending a specifically crafted packet to the application.
network
low complexity
schneider-electric
critical
9.8
2023-10-04 CVE-2023-5399 Unspecified vulnerability in Schneider-Electric Spacelogic C-Bus Toolkit 1.16.3
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause tampering of files on the personal computer running C-Bus when using the File Command.
network
low complexity
schneider-electric
critical
9.8
2023-10-04 CVE-2023-5402 Unspecified vulnerability in Schneider-Electric C-Bus Toolkit
A CWE-269: Improper Privilege Management vulnerability exists that could cause a remote code execution when the transfer command is used over the network.
network
low complexity
schneider-electric
critical
9.8
2023-09-14 CVE-2023-4516 Unspecified vulnerability in Schneider-Electric Interactive Graphical Scada System
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allow a local attacker to change update source, potentially leading to remote code execution when the attacker force an update containing malicious content.
local
low complexity
schneider-electric
7.8
2023-08-09 CVE-2023-3953 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Schneider-Electric Pro-Face Gp-Pro EX
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause memory corruption when an authenticated user opens a tampered log file from GP-Pro EX.
local
low complexity
schneider-electric CWE-119
5.3
2023-07-12 CVE-2023-29414 Unspecified vulnerability in Schneider-Electric Accutech Manager 2.00.1/2.00.2/2.7
A CWE-120: Buffer Copy without Checking Size of Input (Classic Buffer Overflow) vulnerability exists that could cause user privilege escalation if a local user sends specific string input to a local function call.
local
low complexity
schneider-electric
7.8