Vulnerabilities > Schneider Electric > High

DATE CVE VULNERABILITY TITLE RISK
2020-11-19 CVE-2020-7544 Unspecified vulnerability in Schneider-Electric Operator Terminal Expert Runtime 3.1
A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD) that could cause privilege escalation on the workstation when interacting directly with a driver installed by the runtime software of EcoStruxureª Operator Terminal Expert.
local
low complexity
schneider-electric
7.8
2020-11-19 CVE-2020-7538 Unspecified vulnerability in Schneider-Electric Ecostruxure Control Expert
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause a crash of the PLC simulator present in EcoStruxureª Control Expert software when receiving a specially crafted request over Modbus.
network
low complexity
schneider-electric
7.5
2020-11-19 CVE-2020-28213 Unspecified vulnerability in Schneider-Electric Ecostruxure Control Expert
A CWE-494: Download of Code Without Integrity Check vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when sending specially crafted requests over Modbus.
network
low complexity
schneider-electric
8.8
2020-11-19 CVE-2020-28211 Unspecified vulnerability in Schneider-Electric Ecostruxure Control Expert
A CWE-863: Incorrect Authorization vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause bypass of authentication when overwriting memory using a debugger.
local
low complexity
schneider-electric
7.8
2020-11-19 CVE-2020-28209 Unspecified vulnerability in Schneider-Electric Enterprise Server Installer 1.9/3.1
A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installer V1.9 - V3.1 and Enterprise Central installer V2.0 - V3.1 that could cause any local Windows user who has write permission on at least one of the subfolders of the Connect Agent service binary path, being able to gain the privilege of the user who started the service.
local
high complexity
schneider-electric
7.0
2020-11-18 CVE-2020-7564 Unspecified vulnerability in Schneider-Electric products
A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause write access and the execution of commands when uploading a specially crafted file on the controller over FTP.
network
low complexity
schneider-electric
8.8
2020-11-18 CVE-2020-7563 Unspecified vulnerability in Schneider-Electric products
A CWE-787: Out-of-bounds Write vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause corruption of data, a crash, or code execution when uploading a specially crafted file on the controller over FTP.
network
low complexity
schneider-electric
8.8
2020-11-18 CVE-2020-7562 Unspecified vulnerability in Schneider-Electric products
A CWE-125: Out-of-Bounds Read vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) which could cause a segmentation fault or a buffer overflow when uploading a specially crafted file on the controller over FTP.
network
low complexity
schneider-electric
8.1
2020-09-16 CVE-2020-7532 Deserialization of Untrusted Data vulnerability in Schneider-Electric Scadapack X70 Security Administrator 1.2.0
A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack x70 Security Administrator (V1.2.0 and prior) which could allow arbitrary code execution when an attacker builds a custom .SDB file containing a malicious serialized buffer.
local
low complexity
schneider-electric CWE-502
7.8
2020-09-16 CVE-2020-7531 Unspecified vulnerability in Schneider-Electric Scadapack 7X Remote Connect 3.6.3.574
A CWE-284 Improper Access Control vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place executables in a specific folder and run code whenever RemoteConnect is executed by the user.
local
low complexity
schneider-electric
7.8