Schneider Electric

First CVE: May 9, 2017Active for: 9 years
726
CVEs Published
More CVEs Published than 89% of tracked CNAs
72.6
Avg CVEs / Year
More Avg CVEs / Year than 88% of tracked CNAs
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked CNAs
0.1%
In CISA KEV
Higher KEV Rate than 79% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by Schneider Electric as a CNA, 0.0% affect products that Schneider Electric develops as a vendor.

100.0%
Self-reported: 0Third-party: 726

Of all the CVEs published that affect products developed by Schneider Electric, 0.0% are self-published by Schneider Electric as a CNA.

100.0%
Self-published: 0Published by other CNAs: 6

Trends Over Time

The number and severity of CVEs published by Schneider Electric over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 9, 2017
9 years ago
Most Recent CVE
Jun 25, 2026
29 days ago

Top CVEs

All CVEs published by Schneider Electric as a CNA, regardless of affected vendor or product.

726 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper set of characters is entered.
May 22, 20199.897YESYES
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote root exploit when the command is c
Jul 13, 20228.877NOYES
A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versio
Jul 21, 20219.875NOYES
A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 which could cause impact to confidentiality, integrity, and av
May 22, 20199.871NOYES
The vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A
Jul 3, 20188.854NOYES
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause tampering of files on the personal computer runn
Oct 4, 20239.849NONO
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code ex
Apr 13, 20218.849NONO
A CWE-290: Authentication Bypass by Spoofing vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause an eleva
May 22, 20199.848NONO
An unrestricted Upload of File with Dangerous Type vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow upload and execution of malicious f
Dec 24, 20189.848NONO
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leading to remote code execution when an attac
Feb 9, 20229.847NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA726 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local165 (22.7%)
Network524 (72.2%)
Unknown0 (0.0%)
Physical14 (1.9%)
Adjacent Network20 (2.8%)
Attack Complexity
Low693 (95.5%)
High33 (4.5%)
Unknown0 (0.0%)
User Interaction
None530 (73.0%)
Unknown0 (0.0%)
Required186 (25.6%)
Privileges Required
Low167 (23.0%)
High50 (6.9%)
None509 (70.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (726 CVEs).

CISA KEV
1 CVE
0.1% of CVEs· 79th percentile
Metasploit
1 CVE
0.1% of CVEs· 79th percentile
Nuclei
5 CVEs
0.7% of CVEs· 78th percentile
ExploitDB
3 CVEs
0.4% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Schneider Electric as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Schneider Electric as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs