Schneider-electric
Schneider-electric Ecostruxure Control Expert: vulnerabilidades y CVE
Schneider-electric Ecostruxure Control Expert tiene 26 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 7 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE26
Últimos 12 meses0
Críticas7
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-6409 | Alta (7.7) | 0.23% | — | 14 feb 2024 | CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to a project file protected with application password when opening the file with EcoStruxure Control Expert. |
| CVE-2023-6408 | Alta (8.1) | 0.32% | — | 14 feb 2024 | CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a denial of service and loss of confidentiality, integrity of controllers when… |
| CVE-2023-27975 | Alta (7.1) | 0.15% | — | 14 feb 2024 | CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized access to the project file in EcoStruxure Control Expert when a local user tampers with the memory of the engineering… |
| CVE-2023-27976 | Alta (8.8) | 0.84% | — | 18 abr 2023 | A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause remote code execution when a valid user visits a malicious link provided through the web endpoints. Affected Products: EcoStruxure… |
| CVE-2023-1548 | Media (5.5) | 0.15% | — | 18 abr 2023 | A CWE-269: Improper Privilege Management vulnerability exists that could cause a local user to perform a denial of service through the console server service that is part of EcoStruxure Control Expert. Affected… |
| CVE-2022-45789 | Crítica (9.8) | 1.5% | — | 31 ene 2023 | A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session. Affected Products:… |
| CVE-2022-45788 | Crítica (9.8) | 1.2% | — | 30 ene 2023 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when a malicious project file is… |
| CVE-2022-37302 | Media (5.5) | 0.20% | — | 13 sept 2022 | A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a crash of the Control Expert software when an incorrect project file is opened. Affected… |
| CVE-2022-37300 | Crítica (9.8) | 0.77% | — | 12 sept 2022 | A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode to the controller when communicating over Modbus. Affected Products:… |
| CVE-2022-26507 | Crítica (9.8) | 2.4% | — | 14 abr 2022 | A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any of: CVE-2021-21810, CVE-2021-21811,… |
| CVE-2021-22797 | Alta (7.8) | 26% | — | 13 abr 2022 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be deployed in an unauthorized location and may result in code execution… |
| CVE-2022-24323 | Media (5.9) | 0.86% | — | 9 mar 2022 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause a disruption of communication between the Modicon controller and the engineering software, when an attacker is able… |
| CVE-2022-24322 | Media (5.9) | 0.64% | — | 9 mar 2022 | A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a disruption of communication between the Modicon controller and the engineering software when an… |
| CVE-2021-22782 | Media (5.5) | 0.11% | — | 14 jul 2021 | Missing Encryption of Sensitive Data vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all… |
| CVE-2021-22781 | Media (5.5) | 0.24% | — | 14 jul 2021 | Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all… |
| CVE-2021-22780 | Alta (7.1) | 0.22% | — | 14 jul 2021 | Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all… |
| CVE-2021-22779 | Crítica (9.1) | 1.0% | — | 14 jul 2021 | Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Control Expert V15.0 SP1, EcoStruxure Process… |
| CVE-2021-22778 | Alta (7.1) | 0.22% | — | 14 jul 2021 | Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all… |
| CVE-2020-7560 | Alta (8.6) | 1.4% | — | 11 dic 2020 | A CWE-123: Write-what-where Condition vulnerability exists in EcoStruxure™ Control Expert (all versions) and Unity Pro (former name of EcoStruxure™ Control Expert) (all versions), that could cause a crash of the… |
| CVE-2020-7559 | Alta (7.5) | 1.9% | — | 19 nov 2020 | A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause a crash of the PLC… |
| CVE-2020-7538 | Alta (7.5) | 1.3% | — | 19 nov 2020 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause a crash of the PLC simulator present… |
| CVE-2020-28213 | Alta (8.8) | 1.2% | — | 19 nov 2020 | A CWE-494: Download of Code Without Integrity Check vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution when sending… |
| CVE-2020-28212 | Crítica (9.8) | 2.8% | — | 19 nov 2020 | A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause unauthorized command execution… |
| CVE-2020-28211 | Alta (7.8) | 0.33% | — | 19 nov 2020 | A CWE-863: Incorrect Authorization vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause bypass of authentication when overwriting memory using a debugger. |
| CVE-2020-7475 | Crítica (9.8) | 1.6% | — | 23 mar 2020 | A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix),… |
| CVE-2019-6855 | Alta (7.3) | 0.95% | — | 6 ene 2020 | Incorrect Authorization vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20) , and Modicon M580 (all versions… |
Otros productos de Schneider-electric
Struxureware Data Center Expert · 49Interactive Graphical Scada System · 43Modicon M580 Firmware · 41Modicon M340 Firmware · 39Modicon M340 Bmxp342020 Firmware · 32Modicon M340 Bmxp3420302 Firmware · 28Modicon M340 Bmxp341000 Firmware · 27Modicon M340 Bmxp342000 Firmware · 25Modicon M340 Bmxp3420102 Firmware · 25Modicon Quantum Firmware · 25Easergy T300 Firmware · 24U.motion Builder · 24