These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A CWE-290 Authentication Bypass by Spoofing vulnerability in Schneider Electric Modicon M340 CPU (part numbers BMXP34*, all versions since SV3.60) allows Man-in-the-Middle (MitM) attackers to bypass authentication during session establishment between the controller and engineering workstation. The root cause is the inherent lack of MitM protection in the Diffie-Hellman key exchange implementation used by [truncated]
CVE-2024-8933 is a HIGH severity vulnerability (CVSS 7.5) affecting Schneider Electric Modicon industrial controllers, published on November 12, 2024. The vulnerability stems from CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel. An attacker positioned within the logical network can intercept and retrieve password hashes during legitimate project file uploa [truncated]
A critical missing authorization vulnerability (CWE-862) in Schneider Electric EcoStruxure™ IT Gateway versions 1.21.0.6 through 1.23.0.4 allows unauthorized network access that could impact connected devices. The vulnerability was disclosed on November 12, 2024, with a CVSS 3.1 score of 9.8 (Critical). Schneider Electric has released version 1.23.1.10 to address this issue. Customers with automatic updat [truncated]
An Improper Input Validation vulnerability in Schneider Electric Zelio Soft 2 allows application crashes via specially crafted project files. The vulnerability requires local access and user interaction, with no confidentiality or integrity impact—only availability is affected at a low severity level.
A Use After Free vulnerability in Schneider Electric Zelio Soft 2 allows arbitrary code execution, denial-of-service, and loss of confidentiality and integrity when a user opens a malicious project file. The vulnerability was disclosed on October 10, 2024, with a CVSS 3.1 score of 7.8 (HIGH). Affected versions are prior to 5.4.2.2. Schneider Electric has released version 5.4.2.2 to address this issue, ava [truncated]
CVE-2024-9005 is a high-severity deserialization vulnerability in Schneider Electric EcoStruxure Power Monitoring Expert (PME). According to the advisory, unsafely deserialized data posted to the web server could allow remote code execution on the server. Schneider Electric provides a fix for PME 2022, while PME 2021 and prior are out of support and should be upgraded.
A privilege escalation vulnerability in Schneider Electric Easergy Studio allows authenticated non-administrative users to tamper with binaries to gain elevated privileges, potentially compromising workstation confidentiality, integrity, and availability. The vulnerability stems from improper privilege management (CWE-269) and requires local access with low privileges but no user interaction. Schneider El [truncated]
CVE-2024-8884 is a critical information exposure issue affecting Schneider Electric System Monitor applications in Harmony Industrial PC and Pro-face PS5000 legacy Industrial PC environments. According to the vendor and CISA CSAF source, an attacker with network access to the application over HTTP could expose credentials. Schneider Electric’s documented remediation is to uninstall the System Monitor appl [truncated]
A high-severity vulnerability (CVSS 8.5) in Schneider Electric EVlink Home Smart and Schneider Charge products exposes test credentials in cleartext within firmware binaries. The CWE-312 flaw allows local attackers with physical or logical access to extract sensitive authentication material from firmware images. Schneider Electric has released automatic firmware updates through the Wiser application and e [truncated]
CVE-2024-8401 is a stored cross-site scripting (XSS) vulnerability in Schneider Electric's EcoStruxure Power Monitoring Expert (PME) and related products. The flaw exists in the folder name modification functionality, where an authenticated attacker can inject malicious scripts through manipulated folder names. The vulnerability was published on September 10, 2024, with a CVSS 3.1 score of 5.4 (Medium sev [truncated]
A high-severity privilege escalation vulnerability in Schneider Electric Vijeo Designer allows authenticated non-admin users to tamper with binaries and gain unauthorized elevated access, risking full compromise of confidentiality, integrity, and availability on affected engineering workstations. The vulnerability stems from improper privilege management (CWE-269) where file system permissions permit low- [truncated]
A buffer overflow vulnerability in Schneider Electric Accutech Manager allows unauthenticated remote attackers to crash the application via specially crafted TCP requests to port 2536. The vulnerability stems from improper input validation (CWE-120) when handling network requests. Schneider Electric has released version 2.10.0 to address this issue. The affected product is Accutech Manager version 2.08.01 [truncated]
CVE-2024-6407 is a critical information exposure issue affecting Schneider Electric Wiser Home Controller WHC-5918A devices. According to the advisory, a specially crafted message sent to the device could disclose credentials. CISA’s CSAF record lists all versions of the product as affected and rates the issue CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Schneider Electric’s remediation notes state [truncated]
CVE-2024-5681 is a high-severity vulnerability in Schneider Electric's EcoStruxure™ Foxboro DCS Core Control Services, published on July 9, 2024. The flaw stems from improper input validation (CWE-20) in the Foxboro.sys driver, enabling a local attacker to craft malicious IOCTL calls that can trigger denial-of-service, privilege escalation, or potentially kernel-level code execution. The attack requires l [truncated]
CVE-2024-5680 is a high-severity local denial-of-service vulnerability in Schneider Electric's EcoStruxure™ Foxboro DCS Core Control Services, published on 2024-07-09. The flaw stems from CWE-129 (Improper Validation of Array Index) in the Foxboro.sys driver, where a malicious actor with local user access can trigger a DoS condition by crafting a script or program using an IOCTL call. The vulnerability af [truncated]
CVE-2024-5679 is a high-severity (CVSS 7.1) out-of-bounds write vulnerability (CWE-787) in the Foxboro.sys driver of Schneider Electric's EcoStruxure™ Foxboro DCS Core Control Services. Published on July 9, 2024, this vulnerability affects versions 9.5 through 9.8 of the distributed control system software used in industrial process automation environments. The flaw requires local user access to exploit, [truncated]
A path traversal vulnerability (CWE-22) in Schneider Electric FoxRTU Station prior to version 9.3.0 allows remote code execution when an authenticated user executes a saved project file that has been tampered with by a malicious actor. The vulnerability requires local access and user interaction, with a CVSS 3.1 score of 7.3 (HIGH). The attack vector involves a malicious actor gaining file write access to [truncated]
CVE-2024-5560 is a medium-severity denial-of-service issue affecting Schneider Electric Sage Series devices. According to the advisory, a specially crafted HTTP request can trigger an out-of-bounds read in the device’s web interface, potentially making that interface unavailable. Schneider Electric lists firmware C3414-500-S02K5_P9 as the fixed release for the affected Sage models.
A medium-severity vulnerability (CVSS 6.1) in Schneider Electric PowerLogic P5 protective relays allows physical attackers to cause denial of service, device reboot, or gain full control of the relay by entering a specially crafted reset token at the device front panel. The root cause is CWE-327: Use of a Broken or Risky Cryptographic Algorithm. The vulnerability was disclosed on June 11, 2024, with an in [truncated]
CVE-2024-5056 affects Schneider Electric Modicon M340-related products and is described as a CWE-552 issue where files or directories are accessible to external parties. According to the advisory, this can prevent users from updating device firmware and can affect proper webserver behavior when specific files or directories are removed from the filesystem. The CISA CSAF record was originally published on [truncated]
CVE-2024-37040 is a medium-severity buffer overflow in Schneider Electric Sage RTU devices. A user with access to the device’s web interface can send a malformed HTTP request and cause a fault on the device. Schneider Electric lists firmware C3414-500-S02K5_P9 as the fix for affected Sage 1410, 1430, 1450, 2400, 3030 Magnum, and 4400 products.
CVE-2024-37039 is a Schneider Electric Sage RTU vulnerability where an unchecked return value can let a specially crafted HTTP request trigger denial of service on the device. The issue was published on 2024-06-11 and the advisory was updated on 2024-07-09 to add a direct remediation link.
CVE-2024-37038 affects multiple Schneider Electric Sage RTU products and is rated High (CVSS 7.5). According to the CISA CSAF advisory and Schneider Electric notice, an authenticated user with access to the device’s web interface could craft custom web requests to perform unauthorized file and firmware uploads. Schneider Electric states that firmware C3414-500-S02K5_P9 fixes the issue for the affected Sage families.
CVE-2024-37037 affects Schneider Electric Sage Series RTUs and can let an authenticated user with web-interface access corrupt files and disrupt device functionality by sending a crafted HTTP request. Schneider Electric’s remediation is firmware C3414-500-S02K5_P9 for affected Sage models.
CVE-2024-37036 is a critical Schneider Electric Sage vulnerability that CISA and Schneider Electric describe as a CWE-787 out-of-bounds write. Under particular configuration parameters, a malformed POST request can lead to authentication bypass. The affected products are Sage 1410, 1430, 1450, 2400, 3030 Magnum, and 4400 versions C3414-500-S02K5_P8 and earlier. Schneider Electric provides firmware C3414-5 [truncated]
A hard-coded credentials vulnerability (CWE-798) in Schneider Electric's EcoStruxure Control Expert and Process Expert engineering software allows unauthorized access to password-protected project files. The flaw exists because the software contains embedded credentials that can bypass application-level password protection when opening project files. This affects industrial control system programming envi [truncated]
CVE-2023-6408 is a critical vulnerability in Schneider Electric Modicon M340, M580, M580 Safety, MC80, and Momentum M1E PLCs, as well as EcoStruxure Control Expert and EcoStruxure Process Expert software. The flaw, classified as CWE-924 (Improper Enforcement of Message Integrity During Transmission in a Communication Channel), enables man-in-the-middle attackers to compromise controller confidentiality, i [truncated]
A CWE-522: Insufficiently Protected Credentials vulnerability in Schneider Electric EcoStruxure Control Expert and EcoStruxure Process Expert allows a local, authenticated user with low privileges to tamper with the memory of an engineering workstation and gain unauthorized access to project files. The vulnerability stems from inadequate protection of credentials within the application, enabling confident [truncated]
CVE-2023-28355 affects Schneider Electric devices using CODESYS Runtime, including HMISCU Controller. The issue is an integrity-verification weakness: the runtime checksum helps the development system compare the loaded project with the PLC application code running on the controller, but Schneider Electric says it is not sufficient to reliably detect code altered in memory or manipulated boot application files.
An authenticated remote attacker can exploit a stack-based out-of-bounds write in the CmpTraceMgr component used by affected CODESYS products in Festo Automation Suite to overwrite stack memory. The advisory says impact can include denial of service, memory corruption, or remote code execution, making this a high-priority issue for OT environments.