These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2025-2441 is a medium-severity Schneider Electric vulnerability affecting Trio™ Q Licensed Data Radio devices prior to firmware version 2.7.2. According to the CISA CSAF advisory, a malicious user with physical access can place the radio into factory default mode, where the product does not correctly initialize all data, creating a risk of confidentiality loss. Schneider Electric provides a fixed firm [truncated]
CVE-2025-2440 is a medium-severity issue in Schneider Electric's Trio™ Q Licensed Data Radio. According to the CISA advisory, sensitive information may be stored insecurely in a way that could lead to unauthorized access to confidential data if an attacker has physical access, advanced knowledge of the file system, and can place the radio into factory default mode. Schneider Electric states that firmware [truncated]
CVE-2025-2223 affects Schneider Electric ConneXium Network Manager. According to the CISA CSAF advisory and Schneider Electric security notice, a malicious project file loaded by a user from the local system can trigger improper input validation and potentially impact the confidentiality, integrity, and availability of the engineering workstation. Schneider Electric also states the product has reached end [truncated]
CVE-2025-2222 is a CVSS 7.5 information-disclosure issue affecting Schneider Electric ConneXium Network Manager v2.0.01. The advisory describes a CWE-552 condition over HTTPS that could expose information and, in a man-in-the-middle scenario, create a path toward privilege escalation. Schneider Electric says the product is end-of-life, the webserver is disabled by default, and customers should apply the p [truncated]
CVE-2025-0813 is a medium-severity authentication bypass affecting Schneider Electric EcoStruxure Power Automation System User Interface (EPAS-UI) versions 2.1 through 2.9. The issue is specifically tied to an attacker who has physical access to the EPAS-UI computer and can reboot the workstation and interrupt the normal boot process. Schneider Electric states that version 2.10 includes a fix, and CISA pu [truncated]
CVE-2025-2002 is a medium-severity information disclosure issue in Schneider Electric EcoStruxure Panel Server. According to the advisory, FTP server credentials can be exposed when FTP is deployed, the device is placed into debug mode by an administrative user, and debug files are exported from the device. Schneider Electric provides a fix in EcoStruxure Panel Server firmware v2.1 or later, with EcoStrux [truncated]
CVE-2025-1960 is a critical Schneider Electric WebHMI issue tied to insecure default credentials (CWE-1188). According to the advisory, if the system's default password credentials are not changed on first use, an attacker could execute unauthorized commands. The advisory also says the default username is not displayed correctly in the WebHMI interface, which can make first-use hardening easier to miss. S [truncated]
CVE-2021-29999 is covered in CISA advisory ICSA-25-058-01 for Schneider Electric communication modules used with Modicon M580 and Quantum controllers. The source advisory ties the issue to a potential stack overflow in the Wind River VxWorks DHCP server through Version 6.8 and maps it to multiple Schneider Electric products with fixed firmware thresholds. Because the CVSS vector is 9.8 (network reachable, [truncated]
CVE-2025-1070 is a HIGH-severity vulnerability in Schneider Electric’s ASCO 5310 Single-Channel Remote Annunciator and ASCO 5350 Eight Channel Remote Annunciator. CISA and Schneider Electric describe it as a CWE-434 unrestricted upload of a file with a dangerous type, which could render the device inoperable when a malicious file is downloaded. The advisory was published on 2025-02-11. At publication, Sch [truncated]
CVE-2025-1060 is a high-severity information exposure issue affecting Schneider Electric ASCO 5310 Single-Channel Remote Annunciator and ASCO 5350 Eight Channel Remote Annunciator devices. The advisory states that sensitive data could be exposed if an attacker sniffs network traffic. Schneider Electric’s guidance focuses on reducing exposure until a remediation plan is available for future versions. From [truncated]
CVE-2025-1058 is a high-severity firmware integrity issue affecting Schneider Electric ASCO 5310 Single-Channel Remote Annunciator and ASCO 5350 Eight Channel Remote Annunciator, all versions listed in the advisory. The issue is described as CWE-494: Download of Code Without Integrity Check, and malicious firmware could render the device inoperable. Schneider Electric’s notice says a remediation plan is b [truncated]
CVE-2025-0815 is a Medium-severity Schneider Electric issue affecting the Enerlin'X IFE interface and Enerlin'X eIFE, both listed as all versions in the CISA CSAF advisory ICSA-25-079-02. The problem is described as a CWE-20 improper input validation weakness that could allow a denial-of-service condition when malicious ICMPv6 packets are sent to the device. The advisory does not describe a patch in the s [truncated]
CVE-2025-0814 is a medium-severity improper input validation issue in Schneider Electric Enerlin'X IFE and eIFE devices. According to the advisory, malicious IEC61850-MMS packets can trigger a denial-of-service condition in the product’s network services. The breaker’s core functionality remains intact during the attack, but communications and management services may be disrupted until the device is recov [truncated]
CVE-2025-0327 is a high-severity privilege management issue in Schneider Electric EcoStruxure™ Process Expert. According to the CISA CSAF advisory and Schneider Electric notice, a local attacker with standard privileges can modify the executable path of two Windows services; after those services are restarted, the issue can impact confidentiality, integrity, and availability on the engineering workstation.
CVE-2024-10083 is an improper input validation issue in Schneider Electric’s Uni-Telway driver. According to the advisory, a local authenticated user can invoke a specific driver interface with crafted input and cause denial of service on an engineering workstation. The affected scope includes the Uni-Telway driver itself and several Schneider Electric products when that driver is installed: EcoStruxure C [truncated]
Schneider Electric Web Designer for Modicon is affected by an XML external entity (XXE) issue that can be triggered when a specially crafted XML project file is imported. CISA rates the issue 7.8 High. The advisory says the flaw can expose information, affect workstation integrity, and potentially lead to remote code execution on the compromised computer.
CVE-2024-10497 is a high-severity authorization bypass in Schneider Electric Power Logic. The issue can let an authenticated attacker modify values outside their assigned privileges by sending modified HTTPS requests to the device. Schneider Electric has published a fix for HDPM6000 v0.62.7 in v0.62.11 and newer, and CISA’s advisory also recommends restricting HTTPS access to the local network segment if [truncated]
CVE-2024-11425 is a high-severity denial-of-service issue in Schneider Electric Modicon M580 CPU firmware. According to the advisory, an unauthenticated attacker can send a crafted HTTPS packet to the web server and trigger a buffer size calculation error that can disrupt product availability. Schneider Electric lists fixed firmware in SV4.30 for the affected Modicon M580 CPU family and recommends network [truncated]
CVE-2024-12703 is a CWE-502 deserialization of untrusted data issue in Schneider Electric RemoteConnect and SCADAPack™ x70 Utilities. According to the CISA CSAF advisory ICSA-25-028-06, a non-admin authenticated user opening a malicious project file can trigger loss of confidentiality and integrity, with potential remote code execution on the workstation. The advisory was first published on 2025-01-14 and [truncated]
CVE-2024-12399 is a Schneider Electric Pro-face advisory for GP-Pro EX and Remote HMI. According to the CISA CSAF record, the issue is a CWE-924 message integrity weakness that could allow a man-in-the-middle attacker intercepting communications to cause partial loss of confidentiality, integrity, and availability of the HMI. The advisory was originally published on 2025-01-14 and later updated on 2025-09 [truncated]
CVE-2024-12142 is a HIGH-severity Schneider Electric OT/ICS vulnerability affecting Modicon M340 processors and related modules. According to the advisory, it can expose restricted web pages, allow web page modification, and cause denial of service when specific web pages are modified and restricted functions are invoked. Vendor fixes exist for some modules, while mitigations are provided for Modicon M340 [truncated]
A memory buffer boundary violation (CWE-119) in Schneider Electric EcoStruxure Power Build Rapsody allows local attackers to potentially execute arbitrary code when a malicious project file is opened. The vulnerability affects multiple localized versions of the engineering software used for electrical distribution design. CISA published advisory ICSA-25-023-05 on January 14, 2025, with a significant updat [truncated]
A cross-site scripting (XSS) vulnerability in Schneider Electric Modicon Controllers allows an attacker to inject arbitrary JavaScript that executes in a victim's browser when visiting a page containing the payload. The vulnerability was initially disclosed on December 19, 2024, and subsequently updated on October 21, 2025, to modify affected product versions for M258/LMC058 controllers and add specific m [truncated]
A critical improper input validation vulnerability (CWE-20) in Schneider Electric Modicon M241, M251, M258, and LMC058 controllers allows unauthenticated remote attackers to cause denial of service and compromise confidentiality and integrity via crafted Modbus packets. The vulnerability was disclosed on December 10, 2024, with vendor fixes released in phases: M241/M251 firmware 5.2.11.29 became available [truncated]
A high-severity vulnerability (CVSS 8.8) in Schneider Electric Harmony and Pro-face HMI products, published December 10, 2024, allows authenticated attackers to achieve complete device control by installing malicious code. The root cause is CWE-1104: Use of Unmaintained Third-Party Components. The attack requires network access and low-privilege authentication, with no user interaction needed. Affected pr [truncated]
A CWE-287 Improper Authentication vulnerability in Schneider Electric PowerChute Serial Shutdown versions v1.2.0.301 and prior allows an attacker on the local network to cause denial of access to the web interface by repeatedly requesting the /accessdenied URL. The vulnerability was published on December 10, 2024, with a CVSS 3.1 score of 5.3 (MEDIUM severity). The attack vector is network-based with low [truncated]
A buffer boundary violation (CWE-119) in Schneider Electric Modicon M340, MC80, and Momentum Unity M1E controllers allows potential arbitrary code execution. The attack requires a successful Man-in-the-Middle (MitM) position followed by a crafted Modbus command that tampers with a function call used to evaluate memory size. The vulnerability was disclosed on November 12, 2024, with firmware fixes becoming [truncated]
A buffer overflow vulnerability (CWE-119) in Schneider Electric Modicon M340, MC80, and Momentum Unity M1E controllers allows potential arbitrary code execution following a successful man-in-the-middle attack. An attacker positioned between communicating parties can intercept and inject crafted Modbus commands to tamper with authentication function calls, exploiting improper bounds checking in memory buff [truncated]
A CWE-20 Improper Input Validation vulnerability in Schneider Electric Modicon M340 CPU Controller firmware versions prior to SV3.65 allows an attacker to tamper with controller memory parameters after a successful Man-in-the-Middle (MitM) attack, followed by a Read Physical Memory operation. This results in loss of confidentiality of controller memory. The attack requires network access and high attack c [truncated]
A high-severity uncontrolled resource consumption vulnerability (CWE-400) in Schneider Electric PowerLogic PM5300 series power meters can cause device unresponsiveness and communication loss when the network contains a large volume of IGMP packets. The vulnerability was disclosed on November 12, 2024, with patches available for affected models.