Schneider-electric
Schneider-electric Pro-face Blue: vulnerabilidades y CVE
Schneider-electric Pro-face Blue tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-1049 | Alta (7.8) | 0.60% | — | 14 jun 2023 | A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause execution of malicious code when an unsuspicious user loads a project file from the local filesystem into the HMI. |
| CVE-2022-41671 | Alta (7.8) | 0.26% | — | 4 nov 2022 | A CWE-89: Improper Neutralization of Special Elements used in SQL Command (‘SQL Injection’) vulnerability exists that allows adversaries with local user privileges to craft a malicious SQL query and execute as part of… |
| CVE-2022-41670 | Alta (7.8) | 0.20% | — | 4 nov 2022 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in the SGIUtility component that allows adversaries with local user privileges to load malicious DLL which… |
| CVE-2022-41669 | Alta (7.8) | 0.11% | — | 4 nov 2022 | A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in the SGIUtility component that allows adversaries with local user privileges to load a malicious DLL which could result in execution of… |
| CVE-2022-41668 | Alta (7.8) | 0.21% | — | 4 nov 2022 | A CWE-704: Incorrect Project Conversion vulnerability exists that allows adversaries with local user privileges to load a project file from an adversary-controlled network share which could result in execution of… |
| CVE-2022-41667 | Alta (7.8) | 0.23% | — | 4 nov 2022 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that allows adversaries with local user privileges to load a malicious DLL which could lead to execution of… |
| CVE-2022-41666 | Alta (7.8) | 0.14% | — | 4 nov 2022 | A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that allows adversaries with local user privileges to load a malicious DLL which could lead to execution of malicious code. Affected… |
| CVE-2020-28221 | Crítica (9.8) | 2.1% | — | 26 ene 2021 | A CWE-20: Improper Input Validation vulnerability exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE (version details in the notification) that could cause arbitrary code execution when the Ethernet… |
Otros productos de Schneider-electric
Struxureware Data Center Expert · 49Interactive Graphical Scada System · 43Modicon M580 Firmware · 41Modicon M340 Firmware · 39Modicon M340 Bmxp342020 Firmware · 32Modicon M340 Bmxp3420302 Firmware · 28Modicon M340 Bmxp341000 Firmware · 27Ecostruxure Control Expert · 26Modicon M340 Bmxp342000 Firmware · 25Modicon Quantum Firmware · 25Modicon M340 Bmxp3420102 Firmware · 25Easergy T300 Firmware · 24