Vulnerabilities > Schneider Electric > Critical

DATE CVE VULNERABILITY TITLE RISK
2018-04-18 CVE-2018-7242 Inadequate Encryption Strength vulnerability in Schneider-Electric products
Vulnerable hash algorithms exists in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, and BMXNOR0200 controllers in all versions of the communication modules.
network
low complexity
schneider-electric CWE-326
critical
9.8
2018-04-18 CVE-2018-7241 Use of Hard-coded Credentials vulnerability in Schneider-Electric products
Hard coded accounts exist in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, and BMXNOR0200 controllers in all versions of the communication modules.
network
low complexity
schneider-electric CWE-798
critical
9.8
2018-03-09 CVE-2018-7238 Classic Buffer Overflow vulnerability in Schneider-Electric products
A buffer overflow vulnerability exist in the web-based GUI of Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow an unauthenticated, remote attacker to execute arbitrary code.
network
low complexity
schneider-electric CWE-120
critical
9.8
2018-03-09 CVE-2018-7237 Improper Input Validation vulnerability in Schneider-Electric products
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow a remote attacker to delete arbitrary system file due to lack of validation of the /login/bin/set_param to the file name with the value of 'system.delete.sd_file'
network
low complexity
schneider-electric CWE-20
critical
9.1
2018-03-09 CVE-2018-7233 Improper Input Validation vulnerability in Schneider-Electric products
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow execution of commands due to lack of validation of the shell meta characters with the value of 'model_name' or 'mac_address'.
network
low complexity
schneider-electric CWE-20
critical
9.8
2018-03-09 CVE-2018-7232 Improper Input Validation vulnerability in Schneider-Electric products
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow execution of commands due to lack of validation of the shell meta characters with the value of 'network.ieee8021x.delete_certs'.
network
low complexity
schneider-electric CWE-20
critical
9.8
2018-03-09 CVE-2018-7231 Improper Input Validation vulnerability in Schneider-Electric products
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow execution of commands due to lack of validation of the shell meta characters with the value of 'system.opkg.remove'.
network
low complexity
schneider-electric CWE-20
critical
9.8
2018-03-09 CVE-2018-7229 Use of Hard-coded Credentials vulnerability in Schneider-Electric products
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow an unauthenticated, remote attacker to bypass authentication and gain administrator privileges because the use of hardcoded credentials.
network
low complexity
schneider-electric CWE-798
critical
9.8
2018-03-09 CVE-2018-7228 Improper Authentication vulnerability in Schneider-Electric products
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow an unauthenticated, remote attacker to bypass authentication and get the administrator privileges.
network
low complexity
schneider-electric CWE-287
critical
9.8
2017-11-13 CVE-2017-14024 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Schneider-Electric Wonderware Indusoft web Studio and Wonderware Intouch
A Stack-based Buffer Overflow issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 Patch 1 and prior versions, and InTouch Machine Edition v8.0 SP2 Patch 1 and prior versions.
network
low complexity
schneider-electric CWE-119
critical
9.8