Vulnerabilities > Schneider Electric > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-03-18 CVE-2020-25182 Uncontrolled Search Path Element vulnerability in multiple products
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x searches for and loads DLLs as dynamic libraries.
6.7
2022-03-18 CVE-2020-25184 Insufficiently Protected Credentials vulnerability in multiple products
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable file.
5.5
2022-03-09 CVE-2022-24322 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Schneider-Electric Ecostruxure Control Expert 14.0/14.1/15.0
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a disruption of communication between the Modicon controller and the engineering software when an attacker is able to intercept and manipulate specific Modbus response data.
network
high complexity
schneider-electric CWE-119
5.9
2022-03-09 CVE-2022-24323 Improper Check for Unusual or Exceptional Conditions vulnerability in Schneider-Electric products
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause a disruption of communication between the Modicon controller and the engineering software, when an attacker is able to intercept and manipulate specific Modbus response data.
network
high complexity
schneider-electric CWE-754
5.9
2022-02-09 CVE-2022-22809 Unspecified vulnerability in Schneider-Electric products
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow modifications of the touch configurations in an unauthorized manner when an attacker attempts to modify the touch configurations.
network
low complexity
schneider-electric
5.3
2022-02-09 CVE-2022-22812 Unspecified vulnerability in Schneider-Electric products
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a web session compromise when an attacker injects and then executes arbitrary malicious JavaScript code inside the target browser.
network
low complexity
schneider-electric
6.1
2022-02-09 CVE-2022-24319 Improper Certificate Validation vulnerability in Schneider-Electric products
A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and Geo SCADA web server are intercepted.
network
high complexity
schneider-electric CWE-295
5.9
2022-02-09 CVE-2022-24320 Improper Certificate Validation vulnerability in Schneider-Electric products
A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and Geo SCADA database server are intercepted.
network
high complexity
schneider-electric CWE-295
5.9
2022-02-04 CVE-2022-22726 Unspecified vulnerability in Schneider-Electric Ecostruxure Power Monitoring Expert
A CWE-20: Improper Input Validation vulnerability exists that could allow arbitrary files on the server to be read by authenticated users through a limited operating system service account.
network
low complexity
schneider-electric
6.5
2022-02-04 CVE-2022-22804 Unspecified vulnerability in Schneider-Electric Ecostruxure Power Monitoring Expert
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could allow an authenticated attacker to view data, change settings, or impact availability of the software when the user visits a page containing the injected payload.
network
low complexity
schneider-electric
5.4