Vulnerabilities > Schneider Electric > High

DATE CVE VULNERABILITY TITLE RISK
2020-01-06 CVE-2019-6854 Unspecified vulnerability in Schneider-Electric Clearscada 2017
A CWE-287: Improper Authentication vulnerability exists in a folder within EcoStruxure Geo SCADA Expert (ClearSCADA) -with initial releases before 1 January 2019- which could cause a low privilege user to delete or modify database, setting or certificate files.
local
low complexity
schneider-electric
7.8
2020-01-06 CVE-2018-7794 Improper Check for Unusual or Exceptional Conditions vulnerability in Schneider-Electric products
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium (see security notification for specific versions) which could cause a Denial of Service when reading data with invalid index using Modbus TCP.
network
low complexity
schneider-electric CWE-754
7.5
2019-11-20 CVE-2019-6852 Information Exposure vulnerability in Schneider-Electric products
A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communication modules, Quantum CPUs, Quantum communication modules - see security notification for specific versions), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an unsecure network.
network
low complexity
schneider-electric CWE-200
7.5
2019-10-29 CVE-2019-6851 Information Exposure vulnerability in Schneider-Electric products
A CWE-538: File and Directory Information Exposure vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions), which could cause the disclosure of information from the controller when using TFTP protocol.
network
low complexity
schneider-electric CWE-200
7.5
2019-10-29 CVE-2019-6850 Information Exposure vulnerability in Schneider-Electric products
A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure of sensitive information when reading specific registers with the REST API of the controller/communication module.
network
low complexity
schneider-electric CWE-200
7.5
2019-10-29 CVE-2019-6849 Information Exposure vulnerability in Schneider-Electric products
A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure of sensitive information when using specific Modbus services provided by the REST API of the controller/communication module.
network
low complexity
schneider-electric CWE-200
7.5
2019-10-29 CVE-2019-6848 Improper Handling of Exceptional Conditions vulnerability in Schneider-Electric products
A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 CPU (BMEx58*) and Modicon M580 communication module (BMENOC0311, BMENOC0321) (see notification for version info), which could cause a Denial of Service attack on the PLC when sending specific data on the REST API of the controller/communication module.
network
low complexity
schneider-electric CWE-755
8.6
2019-10-29 CVE-2019-6845 Cleartext Transmission of Sensitive Information vulnerability in Schneider-Electric products
A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions), which could cause the disclosure of information when transferring applications to the controller using Modbus TCP protocol.
network
low complexity
schneider-electric CWE-319
7.5
2019-09-17 CVE-2019-6839 Unrestricted Upload of File with Dangerous Type vulnerability in Schneider-Electric products
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could allow a user with low privileges to upload a rogue file.
network
low complexity
schneider-electric CWE-434
8.8
2019-09-17 CVE-2019-6836 Unspecified vulnerability in Schneider-Electric products
A CWE-863: Incorrect Authorization vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could allow the file system to access the wrong file.
network
low complexity
schneider-electric
7.5