Known Vulnerabilities for products from Schneider-electric

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Schneider-electric".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Additional devices specifications by Schneider-electric can be found at device.report : Schneider-electric

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-2405 json CWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting zip file creation a... Not Provided 2026-04-14 2026-04-22
CVE-2026-2404 json CWE-116 Improper Encoding or Escaping of Output vulnerability exists that could cause log injection and forged log when an at... Not Provided 2026-04-14 2026-04-22
CVE-2026-2403 json CWE-1284 Improper Validation of Specified Quantity in Input vulnerability exists that could cause Event and Data Log truncati... Not Provided 2026-04-14 2026-04-22
CVE-2026-2402 json CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to gain a... Not Provided 2026-04-14 2026-04-22
CVE-2026-2401 json CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information to b... Not Provided 2026-04-14 2026-04-22
CVE-2026-2400 json CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists that could cause application user cr... Not Provided 2026-04-14 2026-04-22
CVE-2026-2399 json CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause c... Not Provided 2026-04-14 2026-04-22
CVE-2023-37199 json A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execut... 7.2 - HIGH 2023-07-12 2023-07-20
CVE-2023-37198 json A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code ex... 7.2 - HIGH 2023-07-12 2023-07-19
CVE-2023-37197 json A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability... 8.8 - HIGH 2023-07-12 2023-07-19
CVE-2023-37196 json A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability e... 8.8 - HIGH 2023-07-12 2023-07-19
CVE-2023-29414 json A CWE-120: Buffer Copy without Checking Size of Input (Classic Buffer Overflow) vulnerability exists that could cause user p... 7.8 - HIGH 2023-07-12 2023-07-19
CVE-2023-29413 json A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause Denial-of-Service when accesse... 7.5 - HIGH 2023-04-18 2023-04-28
CVE-2023-29412 json A CWE-78: Improper Handling of Case Sensitivity vulnerability exists that could cause remote code execution when manipulat... 9.8 - CRITICAL 2023-04-18 2023-04-28
CVE-2023-29411 json A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative cred... 9.8 - CRITICAL 2023-04-18 2023-04-28
CVE-2023-29410 json A CWE-20: Improper Input Validation vulnerability exists that could allow an authenticated attacker to gain the same privile... 8.8 - HIGH 2023-04-18 2023-04-28
CVE-2023-28004 json A CWE-129: Improper validation of an array index vulnerability exists where a specially crafted Ethernet request could res... 9.8 - CRITICAL 2023-04-18 2023-04-28
CVE-2023-28003 json A CWE-613: Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain unauthorized acce... 8.8 - HIGH 2023-04-18 2023-05-01
CVE-2023-27984 json A CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro to be executed, potential... 8.8 - HIGH 2023-03-21 2023-03-24
CVE-2023-27983 json A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allo... 5.3 - MEDIUM 2023-03-21 2023-03-28

Known software with vulnerabilities from Schneider-electric

Type Vendor Product Version
HardwareSchneider-electric140cpu31110-
HardwareSchneider-electric140cpu31110c-
Operating
System
Schneider-electric140cpu31110c Firmware-
Operating
System
Schneider-electric140cpu31110 Firmware-
HardwareSchneider-electric140cpu43412u-
HardwareSchneider-electric140cpu43412uc-
Operating
System
Schneider-electric140cpu43412uc Firmware-
Operating
System
Schneider-electric140cpu43412u Firmware-
HardwareSchneider-electric140cpu65150-
HardwareSchneider-electric140cpu65150c-
Operating
System
Schneider-electric140cpu65150c Firmware-
Operating
System
Schneider-electric140cpu65150 Firmware-
HardwareSchneider-electric140cpu65160-
HardwareSchneider-electric140cpu65160c-
Operating
System
Schneider-electric140cpu65160c Firmware-
HardwareSchneider-electric140cpu65160s-
Operating
System
Schneider-electric140cpu65160s Firmware-
Operating
System
Schneider-electric140cpu65160 Firmware-
HardwareSchneider-electric140cpu65260-
HardwareSchneider-electric140cpu65260c-