Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Schneider Electric — Vulnerabilities & Security Advisories 311

Browse all 311 CVE security advisories affecting Schneider Electric. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Schneider Electric operates as a global specialist in energy management and industrial automation, providing critical infrastructure solutions for data centers, buildings, and manufacturing facilities. Its extensive product portfolio, including programmable logic controllers and supervisory control and data acquisition systems, has historically been associated with a significant volume of vulnerabilities, currently totaling 287 Common Vulnerabilities and Exposures. These security flaws frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from legacy protocols or default configurations in industrial control interfaces. While the company has implemented various security patches and guidelines, the sheer scale of its connected ecosystem presents persistent attack surfaces. Notable incidents have highlighted risks in unpatched firmware and weak authentication mechanisms within its EcoStruxure platform, underscoring the critical need for rigorous network segmentation and continuous monitoring to mitigate potential disruptions to essential operational technology environments.

CVE ID Title CVSS Severity Published
CVE-2022-30233 Schneider Electric PowerLogic ION Setup 输入验证错误漏洞 — Wiser Smart CWE-20 6.5 Medium 2022-06-02
CVE-2022-30232 Schneider Electric PowerLogic ION Setup 输入验证错误漏洞 — Power Logic ION Setup CWE-20 8.0 High 2022-06-02
CVE-2022-0221 Schneider Electric SCADAPack 代码问题漏洞 — SCADAPack Workbench CWE-611 5.5 Medium 2022-03-28
CVE-2021-22797 Schneider Electric EcoStruxure Control Expert 路径遍历漏洞 — EcoStruxure Control Expert CWE-22 7.8 High 2022-03-28
CVE-2021-22795 Schneider Electric StruxureWare Data Center Expert 操作系统命令注入漏洞 — StruxureWare Data Center Expert CWE-78 9.1 Critical 2022-03-28
CVE-2021-22794 Schneider Electric StruxureWare Data Center Expert 路径遍历漏洞 — StruxureWare Data Center Expert CWE-22 9.1 Critical 2022-03-28
CVE-2019-6834 Schneider Electric Software Update 代码问题漏洞 — Software Update (SESU) – SUT Service component CWE-502 7.3 High 2022-03-28
CVE-2022-24323 Schneider Electric EcoStruxure Control Expert和Schneider Electric EcoStruxure Process Exper 代码问题漏洞 — EcoStruxure Process Expert CWE-754 5.3 Medium 2022-03-09
CVE-2022-24322 Schneider Electric EcoStruxure Control Experta 缓冲区错误漏洞 — EcoStruxure Control Expert CWE-119 5.3 Medium 2022-03-09
CVE-2021-22783 Schneider Electric Ritto Wiser Door 安全漏洞 — Ritto Wiser Door CWE-200 8.8 High 2022-03-09
CVE-2022-22806 Schneider Electric 多款产品授权问题漏洞 — SmartConnect CWE-294 9.8 - 2022-03-09
CVE-2022-22805 Schneider Electric 多款产品缓冲区错误漏洞 — SmartConnect CWE-120 9.8 - 2022-03-09
CVE-2022-0715 多款Schneider Electric产品数据伪造问题漏洞 — APC Smart-UPS CWE-287 9.1 - 2022-03-09
CVE-2022-22722 Schneider Electric Easergy P5 信任管理问题漏洞 — Easergy P5 CWE-798 7.4 - 2022-02-04
CVE-2021-22716 Schneider Electric C-Bus Toolkit 权限许可和访问控制问题漏洞 — C-Bus Toolkit CWE-732 7.8 High 2021-04-13
CVE-2019-6852 多款Schneider Electric产品信息泄露漏洞 — Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communication modules, Quantum CPUs, Quantum communication modules - see security notification for specific versions) CWE-200 7.5 - 2019-11-20
CVE-2019-6853 Schneider Electric Andover Continuum 跨站脚本漏洞 — Andover Continuum models 9680, 5740 and 5720, bCX4040, bCX9640, 9900, 9940, 9924 and 9702 CWE-79 6.1 - 2019-11-20
CVE-2015-1014 Schneider Electric OPC Factory Server 安全漏洞 — OFS v3.5 CWE-427 7.8 - 2019-03-25
CVE-2018-7522 Schneider Electric Triconex Tricon MP 3008 安全漏洞 — Triconex Tricon CWE-119 9.8 - 2018-05-04
CVE-2018-8872 Schneider Electric Triconex Tricon MP 3008 安全漏洞 — Triconex Tricon CWE-119 8.1 - 2018-05-04
CVE-2017-6030 Schneider Electric Modicon PLCs Predictable Value Range from Previous Values — Modicon M221 CWE-343 7.3 - 2017-06-30
CVE-2017-6034 Schneider Electric Modicon Modbus Protocol Authentication Bypass by Capture-replay — Modicon Modbus Protocol CWE-294 9.8 - 2017-06-30
CVE-2014-9200 Schneider Electric Device Type Managers (DTMs) Stack-based Buffer Overflow — Unity Pro CWE-121 7.8 - 2015-02-01
CVE-2014-9197 Schneider Electric ETG3000 FactoryCast HMI Gateway Missing Authentication for Critical Function — ETG3000 FactoryCast HMI Gateway CWE-306 5.3 - 2015-01-27
CVE-2014-9198 Schneider Electric ETG3000 FactoryCast HMI Gateway Use of Hard-coded Credentials — ETG3000 FactoryCast HMI Gateway CWE-798 9.8 - 2015-01-27
CVE-2014-9190 Schneider Electric Wonderware InTouch Access Anywhere Server Buffer Overflow — InTouch Access Anywhere Server CWE-121 9.8 - 2015-01-10
CVE-2014-9188 Schneider Electric ProClima Command Injection — ProClima CWE-77 9.8 - 2014-12-27
CVE-2014-0754 Schneider Electric — Ethernet modules for M340, Quantum and Premium PLC ranges 8.1 - 2014-10-03
CVE-2014-5411 Schneider Electric SCADA Expert ClearSCADA Cross-site Scripting — ClearSCADA CWE-79 5.4 - 2014-09-18
CVE-2014-5412 Schneider Electric SCADA Expert ClearSCADA Improper Authentication — ClearSCADA CWE-287 6.5 - 2014-09-18

This page lists every published CVE security advisory associated with Schneider Electric. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.