Known Vulnerabilities for Ecostruxure Control Expert by Schneider-electric
Listed below are 10 of the newest known vulnerabilities associated with "Ecostruxure Control Expert" by "Schneider-electric".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-24323 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause a disruption of communi... | 5.9 - MEDIUM | 2022-03-09 | 2022-03-12 |
| CVE-2022-24322 | A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a di... | 5.9 - MEDIUM | 2022-03-09 | 2022-03-12 |
| CVE-2021-22797 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause... | 7.8 - HIGH | 2022-04-13 | 2022-04-23 |
| CVE-2021-22782 | Missing Encryption of Sensitive Data vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, inc... | 5.5 - MEDIUM | 2021-07-14 | 2021-07-26 |
| CVE-2021-22781 | Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, inc... | 5.5 - MEDIUM | 2021-07-14 | 2021-07-26 |
| CVE-2021-22780 | Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, inc... | 7.1 - HIGH | 2021-07-14 | 2021-07-26 |
| CVE-2021-22779 | Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, includ... | 9.1 - CRITICAL | 2021-07-14 | 2021-07-26 |
| CVE-2021-22778 | Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, inc... | 7.1 - HIGH | 2021-07-14 | 2021-07-26 |
| CVE-2020-7538 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in PLC Simulator on EcoStruxureª Contro... | 7.5 - HIGH | 2020-11-19 | 2022-01-31 |
| CVE-2020-7475 | A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL,... | 9.8 - CRITICAL | 2020-03-23 | 2022-02-03 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Schneider-electric | Ecostruxure Control Expert | 14.0 | All | All | All |