Vulnerabilities > Schneider Electric > Scada Expert Vijeo Citect

DATE CVE VULNERABILITY TITLE RISK
2019-05-31 CVE-2019-10981 Credentials Management vulnerability in Schneider-Electric Citectscada and Scada Expert Vijeo Citect
In Vijeo Citect 7.30 and 7.40, and CitectSCADA 7.30 and 7.40, a vulnerability has been identified that may allow an authenticated local user access to Citect user credentials.
local
low complexity
schneider-electric CWE-255
2.1
2019-03-25 CVE-2015-1014 Uncontrolled Search Path Element vulnerability in Schneider-Electric OPC Factory Server 3.5
A successful exploit of these vulnerabilities requires the local user to load a crafted DLL file in the system directory on servers running Schneider Electric OFS v3.5 with version v7.40 of SCADA Expert Vijeo Citect/CitectSCADA, OFS v3.5 with version v7.30 of Vijeo Citect/CitectSCADA, and OFS v3.5 with version v7.20 of Vijeo Citect/CitectSCADA..
4.4