Vulnerabilities > Schneider Electric > High

DATE CVE VULNERABILITY TITLE RISK
2020-06-16 CVE-2020-7502 Out-of-bounds Write vulnerability in Schneider-Electric Modicon M218 Firmware 4.3
A CWE-787: Out-of-bounds Write vulnerability exists in Modicon M218 Logic Controller (Firmware version 4.3 and prior), which may cause a Denial of Service when specific TCP/IP crafted packets are sent to the Modicon M218 Logic Controller.
network
low complexity
schneider-electric CWE-787
7.5
2020-06-16 CVE-2020-7501 Use of Hard-coded Credentials vulnerability in Schneider-Electric Vijeo Designer
A CWE-798: Use of Hard-coded Credentials vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 16 and prior) and Vijeo Designer (V6.2 SP9 and prior) which could cause unauthorized read and write when downloading and uploading project or firmware into Vijeo Designer Basic and Vijeo Designer.
network
low complexity
schneider-electric CWE-798
8.8
2020-06-16 CVE-2020-7494 Path Traversal vulnerability in Schneider-Electric Ecostruxure Operator Terminal Expert 3.0/3.1
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause malicious code execution when opening the project file.
local
low complexity
schneider-electric CWE-22
7.8
2020-06-16 CVE-2020-7493 SQL Injection vulnerability in Schneider-Electric Ecostruxure Operator Terminal Expert 3.0/3.1
A CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause malicious code execution when opening the project file.
local
low complexity
schneider-electric CWE-89
7.8
2020-05-14 CVE-2020-10626 Uncontrolled Search Path Element vulnerability in multiple products
In Fazecast jSerialComm, Version 2.2.2 and prior, an uncontrolled search path element vulnerability could allow a malicious DLL file with the same name of any resident DLLs inside the software installation to execute arbitrary code.
local
low complexity
fazecast schneider-electric CWE-427
7.8
2020-04-22 CVE-2020-7490 Untrusted Search Path vulnerability in Schneider-Electric Vijeo Designer
A CWE-426: Untrusted Search Path vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 15 and prior) and Vijeo Designer (V6.9 SP9 and prior), which could cause arbitrary code execution on the system running Vijeo Basic when a malicious DLL library is loaded by the Product.
local
low complexity
schneider-electric CWE-426
7.8
2020-04-22 CVE-2020-7488 Cleartext Transmission of Sensitive Information vulnerability in Schneider-Electric products
A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists which could leak sensitive information transmitted between the software and the Modicon M218, M241, M251, and M258 controllers.
network
low complexity
schneider-electric CWE-319
7.5
2020-04-22 CVE-2019-6859 Use of Hard-coded Credentials vulnerability in Schneider-Electric products
A CWE-798: Use of Hardcoded Credentials vulnerability exists in Modicon Controllers (All versions of the following CPUs and Communication Module product references listed in the Security Notifications), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an unsecure network.
network
low complexity
schneider-electric CWE-798
7.5
2020-04-16 CVE-2020-7486 Resource Exhaustion vulnerability in Schneider-Electric products
**VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause TCM modules to reset when under high network load in TCM v10.4.x and in system v10.3.x.
network
low complexity
schneider-electric CWE-400
7.5
2020-04-16 CVE-2020-7484 Unspecified vulnerability in Schneider-Electric Tristation 1131
**VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability with the former 'password' feature could allow a denial of service attack if the user is not following documented guidelines pertaining to dedicated TriStation connection and key-switch protection.
network
low complexity
schneider-electric
7.5