Schneider Electric
First CVE: May 9, 2017Active for: 9 years
726
CVEs Published
More CVEs Published than 89% of tracked CNAs
72.6
Avg CVEs / Year
More Avg CVEs / Year than 88% of tracked CNAs
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked CNAs
0.1%
In CISA KEV
Higher KEV Rate than 79% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by Schneider Electric as a CNA, 0.0% affect products that Schneider Electric develops as a vendor.
100.0%
Self-reported: 0Third-party: 726
Of all the CVEs published that affect products developed by Schneider Electric, 0.0% are self-published by Schneider Electric as a CNA.
100.0%
Self-published: 0Published by other CNAs: 6
Trends Over Time
The number and severity of CVEs published by Schneider Electric over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 9, 2017
9 years ago
Most Recent CVE
Jun 25, 2026
29 days ago
Top CVEs
All CVEs published by Schneider Electric as a CNA, regardless of affected vendor or product.
726 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-7841CRITICAL A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper set of characters is entered. | May 22, 2019 | 9.8 | 97 | YES | YES |
CVE-2022-34753HIGH A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote root exploit when the command is c | Jul 13, 2022 | 8.8 | 77 | NO | YES |
CVE-2021-22707CRITICAL A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versio | Jul 21, 2021 | 9.8 | 75 | NO | YES |
CVE-2019-6814CRITICAL A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 which could cause impact to confidentiality, integrity, and av | May 22, 2019 | 9.8 | 71 | NO | YES |
CVE-2018-7777HIGH The vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A | Jul 3, 2018 | 8.8 | 54 | NO | YES |
CVE-2023-5399CRITICAL
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path
Traversal') vulnerability exists that could cause tampering of files on the personal computer
runn | Oct 4, 2023 | 9.8 | 49 | NO | NO |
CVE-2021-22719HIGH A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code ex | Apr 13, 2021 | 8.8 | 49 | NO | NO |
CVE-2018-7842CRITICAL A CWE-290: Authentication Bypass by Spoofing vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause an eleva | May 22, 2019 | 9.8 | 48 | NO | NO |
CVE-2018-7836CRITICAL An unrestricted Upload of File with Dangerous Type vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow upload and execution of malicious f | Dec 24, 2018 | 9.8 | 48 | NO | NO |
CVE-2022-24313CRITICAL A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leading to remote code execution when an attac | Feb 9, 2022 | 9.8 | 47 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA726 CVEs
27%
54%
18%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local165 (22.7%)
Network524 (72.2%)
Unknown0 (0.0%)
Physical14 (1.9%)
Adjacent Network20 (2.8%)
Attack Complexity
Low693 (95.5%)
High33 (4.5%)
Unknown0 (0.0%)
User Interaction
None530 (73.0%)
Unknown0 (0.0%)
Required186 (25.6%)
Privileges Required
Low167 (23.0%)
High50 (6.9%)
None509 (70.1%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (726 CVEs).
CISA KEV
1 CVE
0.1% of CVEs· 79th percentile
Metasploit
1 CVE
0.1% of CVEs· 79th percentile
Nuclei
5 CVEs
0.7% of CVEs· 78th percentile
ExploitDB
3 CVEs
0.4% of CVEs· 76th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Schneider Electric as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Schneider Electric as a CNA — matched by CVE ID, not by organization name.