Vulnerabilities > Schneider Electric > High

DATE CVE VULNERABILITY TITLE RISK
2020-12-11 CVE-2020-7535 Unspecified vulnerability in Schneider-Electric products
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal' Vulnerability Type) vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause disclosure of information when sending a specially crafted request to the controller over HTTP.
network
low complexity
schneider-electric
7.5
2020-12-11 CVE-2020-28219 Unspecified vulnerability in Schneider-Electric products
A CWE-522: Insufficiently Protected Credentials vulnerability exists in EcoStruxure Geo SCADA Expert 2019 (Original release and Monthly Updates to September 2020, from 81.7268.1 to 81.7578.1) and EcoStruxure Geo SCADA Expert 2020 (Original release and Monthly Updates to September 2020, from 83.7551.1 to 83.7578.1), that could cause exposure of credentials to server-side users when web users are logged in to Virtual ViewX.
local
low complexity
schneider-electric
7.8
2020-12-11 CVE-2020-28217 Unspecified vulnerability in Schneider-Electric Easergy T300 Firmware 1.5.2/2.7
A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to read network traffic over HTTP protocol.
network
low complexity
schneider-electric
7.5
2020-12-11 CVE-2020-28216 Unspecified vulnerability in Schneider-Electric Easergy T300 Firmware 1.5.2/2.7
A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to read network traffic over HTTP protocol.
network
low complexity
schneider-electric
7.5
2020-12-01 CVE-2020-7547 Unspecified vulnerability in Schneider-Electric products
A CWE-284: Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow a user the ability to perform actions via the web interface at a higher privilege level.
network
low complexity
schneider-electric
8.8
2020-12-01 CVE-2020-7545 Unspecified vulnerability in Schneider-Electric products
A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow for arbitrary code execution on the server when an authorized user access an affected webpage.
network
low complexity
schneider-electric
7.2
2020-11-19 CVE-2020-7572 Unspecified vulnerability in Schneider-Electric Webreports 1.9/3.1
A CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to inject arbitrary XML code and obtain disclosure of confidential data, denial of service, server side request forgery due to improper configuration of the XML parser.
network
low complexity
schneider-electric
8.8
2020-11-19 CVE-2020-7569 Unspecified vulnerability in Schneider-Electric Webreports 1.9/3.1
A CWE-434 Unrestricted Upload of File with Dangerous Type vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to upload arbitrary files due to incorrect verification of user supplied files and achieve remote code execution.
network
low complexity
schneider-electric
8.8
2020-11-19 CVE-2020-7566 Unspecified vulnerability in Schneider-Electric Modicon M221 Firmware
A CWE-334: Small Space of Random Values vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to break the encryption keys when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller.
low complexity
schneider-electric
7.3
2020-11-19 CVE-2020-7565 Unspecified vulnerability in Schneider-Electric Modicon M221 Firmware
A CWE-326: Inadequate Encryption Strength vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to break the encryption key when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller.
low complexity
schneider-electric
7.3