Schneider Electric operates one of the broadest portfolios in industrial control systems and energy-management infrastructure, spanning SCADA platforms, programmable logic controllers, data-center management software, and enterprise networking products that underpin critical infrastructure worldwide. The vendor's vulnerability exposure reflects the heterogeneity of that portfolio: disclosures cluster across memory-safety issues such as buffer overflows and out-of-bounds writes, web-application weaknesses including cross-site scripting, and command-injection flaws that arise in products bridging operational technology and IT networks. Recurring affected products include the Modicon M340 and M580 programmable controllers, StruxureWare Data Center Expert, and Interactive Graphical SCADA System, representing both legacy embedded firmware and modern supervisory software. Defenders tracking this vendor should prioritize inventory of deployed control systems and apply patches according to operational constraints; live severity, exploitation status, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Schneider Electric over time
Of all the CVEs published by Schneider Electric as a CNA, 0.0% affect products that Schneider Electric develops as a vendor.
Of all the CVEs published that affect products developed by Schneider Electric, 0.0% are self-published by Schneider Electric as a CNA.
Signals from CVEs in this vendor scope (784 CVEs).
784 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-7841CRITICAL A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper set of characters is entered. | May 22, 2019 | 9.8 | 97 | YES | YES |
CVE-2022-34753HIGH A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote root exploit when the command is c | Jul 13, 2022 | 8.8 | 77 | NO | YES |
CVE-2021-22707CRITICAL A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versio | Jul 21, 2021 | 9.8 | 75 | NO | YES |
CVE-2019-6814CRITICAL A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 which could cause impact to confidentiality, integrity, and av | May 22, 2019 | 9.8 | 71 | NO | YES |
CVE-2018-3639MEDIUM Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthori | May 22, 2018 | 5.5 | 65 | NO | YES |
CVE-2017-6019HIGH An issue was discovered in Schneider Electric Conext ComBox, model 865-1058, all firmware versions prior to V3.03 BN 830. A series of rapid requests to the device may cause it to r | Apr 7, 2017 | 7.5 | 56 | NO | YES |
CVE-2018-7777HIGH The vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A | Jul 3, 2018 | 8.8 | 54 | NO | YES |
CVE-2013-0657HIGH Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA System (IGSS) 10 and earlier allows remote attackers to execute arbitrary code by sending TCP port-123 | Jan 21, 2013 | 10.0 | 53 | NO | YES |
CVE-2013-0662HIGH Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow remote attackers to execute arbitrary code via a large buff | Apr 1, 2014 | 9.3 | 52 | NO | YES |
CVE-2017-6026CRITICAL A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware versions prior to Version 4.0.5.11, and Modicon M251, firmware | Jun 30, 2017 | 9.1 | 51 | NO | YES |
Signals from CVEs in this vendor scope (784 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Schneider Electric.
Media articles that mention a CVE ID that affects a product developed by Schneider Electric — matched by CVE ID, not by vendor name.