Known Vulnerabilities for Ecostruxure Power Monitoring Expert by Schneider-electric
Listed below are 10 of the newest known vulnerabilities associated with "Ecostruxure Power Monitoring Expert" by "Schneider-electric".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-28003 json | A CWE-613: Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain unauthorized acce... | 8.8 - HIGH | 2023-04-18 | 2023-05-01 |
| CVE-2023-5987 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.1 - MEDIUM | 2023-11-15 | 2023-11-30 |
| CVE-2023-5986 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.1 - MEDIUM | 2023-11-15 | 2023-11-30 |
| CVE-2023-5391 json | A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code o... | 9.8 - CRITICAL | 2023-10-04 | 2024-02-01 |
| CVE-2022-22804 json | A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that coul... | 5.4 - MEDIUM | 2022-02-04 | 2022-02-10 |
| CVE-2022-22727 json | A CWE-20: Improper Input Validation vulnerability exists that could allow an unauthenticated attacker to view data, change se... | 8.8 - HIGH | 2022-02-04 | 2023-11-07 |
| CVE-2022-22726 json | A CWE-20: Improper Input Validation vulnerability exists that could allow arbitrary files on the server to be read by authent... | 6.5 - MEDIUM | 2022-02-04 | 2022-02-10 |
| CVE-2021-22827 json | A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits a pag... | 8.8 - HIGH | 2022-01-28 | 2023-11-07 |
| CVE-2021-22826 json | A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits a pag... | 8.8 - HIGH | 2022-01-28 | 2023-11-07 |
| CVE-2020-7547 json | A CWE-284: Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Softw... | 8.8 - HIGH | 2020-12-01 | 2022-09-03 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Schneider-electric | Ecostruxure Power Monitoring Expert | 8.0 | |||
| Application | Schneider-electric | Ecostruxure Power Monitoring Expert | 7.0 |