Vulnerabilities > Schneider Electric

DATE CVE VULNERABILITY TITLE RISK
2017-02-13 CVE-2016-5809 Cross-Site Request Forgery (CSRF) vulnerability in Schneider-Electric products
An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series, ION8650 series, ION8800 series, and PM5XXX series.
network
low complexity
schneider-electric CWE-352
8.8
2016-07-15 CVE-2016-4529 Unspecified vulnerability in Schneider-Electric Somachine Hvac Firmware 2.0.2
An unspecified ActiveX control in Schneider Electric SoMachine HVAC Programming Software for M171/M172 Controllers before 2.1.0 allows remote attackers to execute arbitrary code via unknown vectors, related to the INTERFACESAFE_FOR_UNTRUSTED_CALLER (aka safe for scripting) flag.
network
low complexity
schneider-electric
7.3
2016-07-15 CVE-2016-4520 Unspecified vulnerability in Schneider-Electric Pelco Digital Sentry Video Management System Firmware 7.6.32.9203
Schneider Electric Pelco Digital Sentry Video Management System with firmware before 7.14 has hardcoded credentials, which allows remote attackers to obtain access, and consequently execute arbitrary code, via unspecified vectors.
network
low complexity
schneider-electric
critical
9.8
2016-06-26 CVE-2016-4513 Cross-site Scripting vulnerability in Schneider-Electric Powerlogic Pm8Ecc Firmware 2.60
Cross-site scripting (XSS) vulnerability in the Schneider Electric PowerLogic PM8ECC module before 2.651 for PowerMeter 800 devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
schneider-electric CWE-79
6.1
2016-04-06 CVE-2016-2292 Out-of-bounds Write vulnerability in Schneider-Electric products
Stack-based buffer overflow in Pro-face GP-Pro EX EX-ED before 4.05.000, PFXEXEDV before 4.05.000, PFXEXEDLS before 4.05.000, and PFXEXGRPLS before 4.05.000 allows remote attackers to execute arbitrary code via unspecified vectors.
network
low complexity
schneider-electric CWE-787
6.5
2016-04-06 CVE-2016-2291 Out-of-bounds Read vulnerability in Schneider-Electric products
Pro-face GP-Pro EX EX-ED before 4.05.000, PFXEXEDV before 4.05.000, PFXEXEDLS before 4.05.000, and PFXEXGRPLS before 4.05.000 allow remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via unspecified vectors.
network
low complexity
schneider-electric CWE-125
6.5
2016-04-06 CVE-2016-2290 Out-of-bounds Write vulnerability in Schneider-Electric products
Heap-based buffer overflow in Pro-face GP-Pro EX EX-ED before 4.05.000, PFXEXEDV before 4.05.000, PFXEXEDLS before 4.05.000, and PFXEXGRPLS before 4.05.000 allows remote attackers to execute arbitrary code via unspecified vectors.
network
low complexity
schneider-electric CWE-787
8.8
2016-04-06 CVE-2015-7921 Credentials Management vulnerability in Schneider-Electric products
The FTP server in Pro-face GP-Pro EX EX-ED before 4.05.000, PFXEXEDV before 4.05.000, PFXEXEDLS before 4.05.000, and PFXEXGRPLS before 4.05.000 has hardcoded credentials, which makes it easier for remote attackers to bypass authentication by leveraging knowledge of these credentials.
network
low complexity
schneider-electric CWE-255
critical
9.1
2016-03-12 CVE-2015-6485 Information Exposure vulnerability in Schneider-Electric Telvent RTU Firmware C3413500001D3/C3414500S02J1
Schneider Electric Telvent Sage 2300 RTUs with firmware before C3413-500-S01, and LANDAC II-2, Sage 1410, Sage 1430, Sage 1450, Sage 2400, and Sage 3030M RTUs with firmware before C3414-500-S02J2, allow remote attackers to obtain sensitive information from device memory by reading a padding field of an Ethernet packet.
network
low complexity
schneider-electric CWE-200
5.3
2016-03-02 CVE-2016-2278 Improper Access Control vulnerability in Schneider-Electric products
Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows remote authenticated administrators to execute arbitrary OS commands by defeating an msh (aka Minimal Shell) protection mechanism.
network
low complexity
schneider-electric CWE-284
7.2