Vulnerabilities > Schneider Electric

DATE CVE VULNERABILITY TITLE RISK
2019-05-22 CVE-2019-6815 Unspecified vulnerability in Schneider-Electric Modicon Quantum Firmware
In Modicon Quantum all firmware versions, CWE-264: Permissions, Privileges, and Access Control vulnerabilities could cause a denial of service or unauthorized modifications of the PLC configuration when using Ethernet/IP protocol.
network
low complexity
schneider-electric
critical
9.1
2019-05-22 CVE-2019-6814 Improper Authentication vulnerability in Schneider-Electric products
A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 which could cause impact to confidentiality, integrity, and availability when a remote attacker crafts a malicious request to the encoder webUI.
network
low complexity
schneider-electric CWE-287
critical
9.8
2019-05-22 CVE-2019-6812 Use of Hard-coded Credentials vulnerability in Schneider-Electric Bmx-Nor-0200H Firmware 1.7
A CWE-798 use of hardcoded credentials vulnerability exists in BMX-NOR-0200H with firmware versions prior to V1.7 IR 19 which could cause a confidentiality issue when using FTP protocol.
network
low complexity
schneider-electric CWE-798
7.2
2019-05-22 CVE-2018-7852 Improper Handling of Exceptional Conditions vulnerability in Schneider-Electric products
A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause denial of service when an invalid private command parameter is sent to the controller over Modbus.
network
low complexity
schneider-electric CWE-755
7.5
2019-05-22 CVE-2018-7851 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Schneider-Electric products
CWE-119: Buffer errors vulnerability exists in Modicon M580 with firmware prior to V2.50, Modicon M340 with firmware prior to V3.01, BMxCRA312xx with firmware prior to V2.40, All firmware versions of Modicon Premium and 140CRA312xxx when sending a specially crafted Modbus packet, which could cause a denial of service to the device that would force a restart to restore availability.
network
low complexity
schneider-electric CWE-119
6.5
2019-05-22 CVE-2018-7850 Unspecified vulnerability in Schneider-Electric products
A CWE-807: Reliance on Untrusted Inputs in a Security Decision vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause invalid information displayed in Unity Pro software.
network
low complexity
schneider-electric
5.3
2019-05-22 CVE-2018-7849 Improper Handling of Exceptional Conditions vulnerability in Schneider-Electric products
A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum and Modicon Premium which could cause a possible Denial of Service due to improper data integrity check when sending files the controller over Modbus.
network
low complexity
schneider-electric CWE-755
7.5
2019-05-22 CVE-2018-7848 Information Exposure vulnerability in Schneider-Electric products
A CWE-200: Information Exposure vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause the disclosure of SNMP information when reading files from the controller over Modbus
network
low complexity
schneider-electric CWE-200
7.5
2019-05-22 CVE-2018-7847 Improper Authentication vulnerability in Schneider-Electric products
A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause denial of service or potential code execution by overwriting configuration settings of the controller over Modbus.
network
low complexity
schneider-electric CWE-287
critical
9.8
2019-05-22 CVE-2018-7846 Exposure of Resource to Wrong Sphere vulnerability in Schneider-Electric products
A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum and Modicon Premium which could cause unauthorized access by conducting a brute force attack on Modbus protocol to the controller.
network
low complexity
schneider-electric CWE-668
critical
9.8