Vulnerabilities > Schneider Electric

DATE CVE VULNERABILITY TITLE RISK
2017-09-26 CVE-2017-9958 Incorrect Permission Assignment for Critical Resource vulnerability in Schneider-Electric U.Motion Builder 1.2.1
An improper access control vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an improper handling of the system configuration can allow an attacker to execute arbitrary code under the context of root.
local
low complexity
schneider-electric CWE-732
7.8
2017-09-26 CVE-2017-9957 Use of Hard-coded Credentials vulnerability in Schneider-Electric U.Motion Builder 1.2.1
A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the web service contains a hidden system account with a hardcoded password.
network
low complexity
schneider-electric CWE-798
critical
9.8
2017-09-26 CVE-2017-9956 Use of Hard-coded Credentials vulnerability in Schneider-Electric U.Motion Builder 1.2.1
An authentication bypass vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system contains a hard-coded valid session.
network
low complexity
schneider-electric CWE-798
7.3
2017-09-26 CVE-2017-7974 Path Traversal vulnerability in Schneider-Electric U.Motion Builder 1.2.1
A path traversal information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauthenticated user can execute arbitrary code and exfiltrate files.
network
low complexity
schneider-electric CWE-22
critical
9.8
2017-09-26 CVE-2017-7973 SQL Injection vulnerability in Schneider-Electric U.Motion Builder 1.2.1
A SQL injection vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauthenticated user can use calls to various paths allowing performance of arbitrary SQL commands against the underlying database.
network
low complexity
schneider-electric CWE-89
critical
9.8
2017-09-26 CVE-2017-7972 Unspecified vulnerability in Schneider-Electric Citect Anywhere and Powerscada Anywhere
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the ability to escape out of remote PowerSCADA Anywhere applications and launch other processes.
low complexity
schneider-electric
5.5
2017-09-26 CVE-2017-7971 Improper Certificate Validation vulnerability in Schneider-Electric Citect Anywhere and Powerscada Anywhere
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the use of outdated cipher suites and improper verification of peer SSL Certificate.
network
low complexity
schneider-electric CWE-295
6.5
2017-09-26 CVE-2017-7970 Unspecified vulnerability in Schneider-Electric Citect Anywhere and Powerscada Anywhere
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the ability to specify Arbitrary Server Target Nodes in connection requests to the Secure Gateway and Server components.
low complexity
schneider-electric
6.5
2017-09-26 CVE-2017-7969 Cross-Site Request Forgery (CSRF) vulnerability in Schneider-Electric Citect Anywhere and Powerscada Anywhere
A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for multiple state-changing requests.
network
low complexity
schneider-electric CWE-352
8.8
2017-07-07 CVE-2017-9631 NULL Pointer Dereference vulnerability in Schneider-Electric Wonderware Archestra Logger 2017.426.2307.1
A Null Pointer Dereference issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.2307.1 and prior.
network
low complexity
schneider-electric CWE-476
7.5