Vulnerabilidades em Schneider Electric

305 resultados
Análise Vexday

Com 302 CVEs catalogadas e 34 de severidade crítica, o portfólio de vulnerabilidades da Schneider Electric representa uma superfície de ataque relevante, especialmente em ambientes de tecnologia operacional e infraestrutura crítica. A taxa de exploração ativa está abaixo da média geral do catálogo, com nenhuma entrada confirmada no CISA KEV, e a ausência de PoCs públicas conhecidas reduz o risco imediato de exploração em massa. No entanto, o destaque vai para CVE-2022-34753, que registra EPSS de 0,71 — indicando probabilidade estatisticamente elevada de exploração — e está associada ao tipo de falha mais recorrente no conjunto, CWE-22 (Path Traversal), uma classe que frequentemente permite acesso não autorizado a arquivos e diretórios sensíveis. As 18 CVEs surgidas nos últimos 90 dias sinalizam ritmo contínuo de descoberta, o que exige monitoramento ativo por equipes responsáveis por ativos Schneider Electric.

CVE-2017-6030MEDIUMSchneider Electric Modicon PLCs Predictable Value Range from Previous ValuesEPSS 2.1%CVE-2022-2329CRITICALA CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to denial of service andEPSS 2.1%CVE-2021-22794CRITICALA CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code exEPSS 2.1%CVE-2014-9197Schneider Electric ETG3000 FactoryCast HMI Gateway Missing Authentication for Critical FunctionEPSS 2.0%CVE-2014-5399Schneider Electric Wonderware SQL InjectionEPSS 1.6%CVE-2014-5412Schneider Electric SCADA Expert ClearSCADA Improper AuthenticationEPSS 1.6%CVE-2022-34756HIGHA CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution or the crash of HTTPs EPSS 1.5%CVE-2014-5397Schneider Electric Wonderware Cross-site ScriptingEPSS 1.5%CVE-2014-0779Schneider Electric StruxureWare SCADA Expert ClearSCADA Improper Restriction of Operations within the Bounds of a Memory BufferEPSS 1.5%CVE-2022-45789HIGHA CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the cEPSS 1.4%CVE-2019-6852HIGHA CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium coEPSS 1.4%CVE-2023-29411CRITICAL A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leadinEPSS 1.3%CVE-2014-5411Schneider Electric SCADA Expert ClearSCADA Cross-site ScriptingEPSS 1.3%CVE-2022-32523CRITICALA CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leadiEPSS 1.3%CVE-2022-32529CRITICALA CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leadiEPSS 1.3%CVE-2022-32526CRITICALA CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leadiEPSS 1.3%CVE-2022-32527CRITICALA CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leadiEPSS 1.3%CVE-2022-32524CRITICALA CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leadiEPSS 1.3%CVE-2022-32525CRITICALA CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leadiEPSS 1.3%CVE-2023-29412CRITICALCWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remEPSS 1.2%