Vulnerabilities > Schneider Electric > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-01-30 CVE-2022-32515 Unspecified vulnerability in Schneider-Electric Conext Combox Firmware
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause brute force attacks to take over the admin account when the product does not implement a rate limit mechanism on the admin authentication form.
network
low complexity
schneider-electric
critical
9.8
2023-01-30 CVE-2022-32518 Unspecified vulnerability in Schneider-Electric Data Center Expert
A CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in unwanted access to a DCE instance when performed over a network by a malicious third-party.
network
low complexity
schneider-electric
critical
9.8
2023-01-30 CVE-2022-32519 Insufficiently Protected Credentials vulnerability in Schneider-Electric Data Center Expert
A CWE-257: Storing Passwords in a Recoverable Format vulnerability exists that could result in unwanted access to a DCE instance when performed over a network by a malicious third-party.
network
low complexity
schneider-electric CWE-522
critical
9.8
2023-01-30 CVE-2022-32520 Unspecified vulnerability in Schneider-Electric Data Center Expert
A CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in unwanted access to a DCE instance when performed over a network by a malicious third-party.
network
low complexity
schneider-electric
critical
9.8
2023-01-30 CVE-2022-32522 Unspecified vulnerability in Schneider-Electric Interactive Graphical Scada System
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted mathematically reduced data request messages.
network
low complexity
schneider-electric
critical
9.8
2023-01-30 CVE-2022-32523 Unspecified vulnerability in Schneider-Electric Interactive Graphical Scada System
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted online data request messages.
network
low complexity
schneider-electric
critical
9.8
2023-01-30 CVE-2022-32524 Unspecified vulnerability in Schneider-Electric Interactive Graphical Scada System
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted time reduced data messages.
network
low complexity
schneider-electric
critical
9.8
2023-01-30 CVE-2022-32525 Unspecified vulnerability in Schneider-Electric Interactive Graphical Scada System
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted alarm data messages.
network
low complexity
schneider-electric
critical
9.8
2023-01-30 CVE-2022-32526 Classic Buffer Overflow vulnerability in Schneider-Electric Interactive Graphical Scada System
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted setting value messages.
network
low complexity
schneider-electric CWE-120
critical
9.8
2023-01-30 CVE-2022-32527 Unspecified vulnerability in Schneider-Electric Interactive Graphical Scada System
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted alarm cache data messages.
network
low complexity
schneider-electric
critical
9.8