Vulnerabilities > Schneider Electric > High

DATE CVE VULNERABILITY TITLE RISK
2018-03-09 CVE-2018-7239 Untrusted Search Path vulnerability in Schneider-Electric products
A DLL hijacking vulnerability exists in Schneider Electric's SoMove Software and associated DTM software components in all versions prior to 2.6.2 which could allow an attacker to execute arbitrary code.
local
low complexity
schneider-electric CWE-426
7.8
2018-03-09 CVE-2018-7236 Improper Authentication vulnerability in Schneider-Electric products
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could enable SSH service due to lack of authentication for /login/bin/set_param could enable SSH service.
network
low complexity
schneider-electric CWE-287
8.1
2018-03-09 CVE-2018-7235 Improper Input Validation vulnerability in Schneider-Electric products
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow arbitrary system file download due to lack of validation of the shell meta characters with the value of 'system.download.sd_file'
network
low complexity
schneider-electric CWE-20
7.5
2018-03-09 CVE-2018-7234 Improper Certificate Validation vulnerability in Schneider-Electric products
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow arbitrary system file download due to lack of validation of SSL certificate.
network
low complexity
schneider-electric CWE-295
7.5
2018-03-09 CVE-2018-7230 XXE vulnerability in Schneider-Electric products
A XML external entity (XXE) vulnerability exists in the import.cgi of the web interface component of the Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67.
network
low complexity
schneider-electric CWE-611
8.8
2018-02-12 CVE-2017-9970 Unrestricted Upload of File with Dangerous Type vulnerability in Schneider-Electric Struxureon Gateway 1.1.3
A remote code execution vulnerability exists in Schneider Electric's StruxureOn Gateway versions 1.1.3 and prior.
network
low complexity
schneider-electric CWE-434
7.2
2018-02-12 CVE-2017-9967 Unspecified vulnerability in Schneider-Electric Interactive Graphical Scada System 10.0/12.0/9.0
A security misconfiguration vulnerability exists in Schneider Electric's IGSS SCADA Software versions 12 and prior.
local
low complexity
schneider-electric
7.8
2018-02-12 CVE-2017-9963 Cross-Site Request Forgery (CSRF) vulnerability in Schneider-Electric Powerscada Anywhere 1.0
A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for multiple state-changing requests.
network
low complexity
schneider-electric CWE-352
8.1
2018-01-18 CVE-2018-2637 Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JMX). 7.4
2018-01-18 CVE-2018-2633 Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). 8.3