Vulnerabilities > Schneider Electric > High

DATE CVE VULNERABILITY TITLE RISK
2024-11-13 CVE-2024-9409 Unspecified vulnerability in Schneider-Electric products
CWE-400: An Uncontrolled Resource Consumption vulnerability exists that could cause the device to become unresponsive resulting in communication loss when a large amount of IGMP packets is present in the network.
network
low complexity
schneider-electric
7.5
2024-10-08 CVE-2024-8422 Use After Free vulnerability in Schneider-Electric Zelio Soft 2
CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when application user opens a malicious Zelio Soft 2 project file.
local
low complexity
schneider-electric CWE-416
7.8
2024-09-11 CVE-2024-8306 Unspecified vulnerability in Schneider-Electric products
CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and availability of the workstation when non-admin authenticated user tries to perform privilege escalation by tampering with the binaries.
local
low complexity
schneider-electric
7.8
2024-07-11 CVE-2024-6407 Unspecified vulnerability in Schneider-Electric Whc-5918A Firmware
CWE-200: Information Exposure vulnerability exists that could cause disclosure of credentials when a specially crafted message is sent to the device.
network
low complexity
schneider-electric
7.5
2024-07-11 CVE-2024-2602 Unspecified vulnerability in Schneider-Electric Foxrtu Station
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could result in remote code execution when an authenticated user executes a saved project file that has been tampered by a malicious actor.
local
low complexity
schneider-electric
7.8
2024-07-11 CVE-2024-5679 Unspecified vulnerability in Schneider-Electric Ecostruxure Foxboro DCS Control Core Services
CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, or kernel memory leak when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
local
low complexity
schneider-electric
7.1
2024-07-11 CVE-2024-5681 Unspecified vulnerability in Schneider-Electric Ecostruxure Foxboro DCS Control Core Services
CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service, privilege escalation, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
local
low complexity
schneider-electric
7.8
2024-06-12 CVE-2024-0865 Unspecified vulnerability in Schneider-Electric Ecostruxure IT Gateway
CWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege escalation when logged in as a non-administrative user.
local
low complexity
schneider-electric
7.8
2024-06-12 CVE-2024-2747 Unspecified vulnerability in Schneider-Electric Easergy Studio
CWE-428: Unquoted search path or element vulnerability exists in Easergy Studio, which could cause privilege escalation when a valid user replaces a trusted file name on the system and reboots the machine.
local
low complexity
schneider-electric
7.8
2024-06-12 CVE-2024-37037 Unspecified vulnerability in Schneider-Electric Sage RTU Firmware
CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability exists that could allow an authenticated user with access to the device’s web interface to corrupt files and impact device functionality when sending a crafted HTTP request.
network
low complexity
schneider-electric
8.1