Schneider-electric

Ecostruxure Control Expert

26 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Veröffentlicht 14.02.2024 17:15:11
  • Zuletzt bearbeitet 11.12.2024 19:33:54

CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to a project file protected with application password when opening the file with EcoStruxure Control Expert.

  • EPSS 0.16%
  • Veröffentlicht 14.02.2024 17:15:11
  • Zuletzt bearbeitet 23.01.2025 19:39:42

CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a denial of service and loss of confidentiality, integrity of controllers when conducting a Man in the Middle att...

  • EPSS 0.07%
  • Veröffentlicht 14.02.2024 17:15:08
  • Zuletzt bearbeitet 11.12.2024 19:33:27

CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized access to the project file in EcoStruxure Control Expert when a local user tampers with the memory of the engineering workstation.

  • EPSS 0.43%
  • Veröffentlicht 18.04.2023 17:15:07
  • Zuletzt bearbeitet 21.11.2024 07:53:51

A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause remote code execution when a valid user visits a malicious link provided through the web endpoints. Affected Products: EcoStruxure Control Expert (V15.1 and above)

  • EPSS 0.02%
  • Veröffentlicht 18.04.2023 17:15:07
  • Zuletzt bearbeitet 21.11.2024 07:39:25

A CWE-269: Improper Privilege Management vulnerability exists that could cause a local user to perform a denial of service through the console server service that is part of EcoStruxure Control Expert. Affected Products: EcoStruxure Control Expert (...

  • EPSS 0.06%
  • Veröffentlicht 31.01.2023 06:15:07
  • Zuletzt bearbeitet 21.11.2024 07:29:43

A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session. Affected Products: EcoStruxure Control Expert (All V...

  • EPSS 0.29%
  • Veröffentlicht 30.01.2023 13:15:09
  • Zuletzt bearbeitet 21.11.2024 07:29:43

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when a malicious project file is loaded onto the controller. Aff...

  • EPSS 0.13%
  • Veröffentlicht 13.09.2022 10:15:10
  • Zuletzt bearbeitet 21.11.2024 07:14:42

A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a crash of the Control Expert software when an incorrect project file is opened. Affected Products: EcoStruxure Control Expert(V1...

  • EPSS 0.54%
  • Veröffentlicht 12.09.2022 18:15:08
  • Zuletzt bearbeitet 21.11.2024 07:14:42

A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode to the controller when communicating over Modbus. Affected Products: EcoStruxure Control Expert Includ...

  • EPSS 6.7%
  • Veröffentlicht 14.04.2022 13:15:11
  • Zuletzt bearbeitet 21.11.2024 06:54:04

A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any of: CVE-2021-21810, CVE-2021-21811, CVE-2021-21812, CVE-2021-21815, C...