Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Schneider Electric

First CVE: Apr 1, 2014Active for: 12 yearsTotal CVEs: 784

Schneider Electric operates one of the broadest portfolios in industrial control systems and energy-management infrastructure, spanning SCADA platforms, programmable logic controllers, data-center management software, and enterprise networking products that underpin critical infrastructure worldwide. The vendor's vulnerability exposure reflects the heterogeneity of that portfolio: disclosures cluster across memory-safety issues such as buffer overflows and out-of-bounds writes, web-application weaknesses including cross-site scripting, and command-injection flaws that arise in products bridging operational technology and IT networks. Recurring affected products include the Modicon M340 and M580 programmable controllers, StruxureWare Data Center Expert, and Interactive Graphical SCADA System, representing both legacy embedded firmware and modern supervisory software. Defenders tracking this vendor should prioritize inventory of deployed control systems and apply patches according to operational constraints; live severity, exploitation status, and detailed exposure counts are shown alongside this summary.

FAUCET AI Generated
784
Total CVEs
More Total CVEs than 100% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.1%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Schneider Electric over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 16, 2011
14 years ago
Most Recent CVE
Jun 25, 2026
31 days ago

Self-Reporting Analysis

Of all the CVEs published by Schneider Electric as a CNA, 0.0% affect products that Schneider Electric develops as a vendor.

100.0%
Self-reported: 0 (0.0%)
Third-party: 726 (100.0%)

Of all the CVEs published that affect products developed by Schneider Electric, 0.0% are self-published by Schneider Electric as a CNA.

100.0%
Self-published: 0 (0.0%)
Other CNAs: 6 (100.0%)

Products(1,762 total)

Top CVEs

Signals from CVEs in this vendor scope (784 CVEs).

784 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-7841CRITICAL
A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper set of characters is entered.
May 22, 20199.897YESYES
CVE-2022-34753HIGH
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote root exploit when the command is c
Jul 13, 20228.877NOYES
CVE-2021-22707CRITICAL
A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versio
Jul 21, 20219.875NOYES
CVE-2019-6814CRITICAL
A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 which could cause impact to confidentiality, integrity, and av
May 22, 20199.871NOYES
CVE-2018-3639MEDIUM
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthori
May 22, 20185.565NOYES
CVE-2017-6019HIGH
An issue was discovered in Schneider Electric Conext ComBox, model 865-1058, all firmware versions prior to V3.03 BN 830. A series of rapid requests to the device may cause it to r
Apr 7, 20177.556NOYES
CVE-2018-7777HIGH
The vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A
Jul 3, 20188.854NOYES
CVE-2013-0657HIGH
Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA System (IGSS) 10 and earlier allows remote attackers to execute arbitrary code by sending TCP port-123
Jan 21, 201310.053NOYES
CVE-2013-0662HIGH
Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow remote attackers to execute arbitrary code via a large buff
Apr 1, 20149.352NOYES
CVE-2017-6026CRITICAL
A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware versions prior to Version 4.0.5.11, and Modicon M251, firmware
Jun 30, 20179.151NOYES
View all 784 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products784 CVEs
28%
51%
19%
Severity distribution among all CVEs352,713 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local158 (20.2%)
Network542 (69.1%)
Unknown57 (7.3%)
Physical10 (1.3%)
Adjacent Network17 (2.2%)
Attack Complexity
Low689 (87.9%)
High38 (4.8%)
Unknown57 (7.3%)
User Interaction
None531 (67.7%)
Unknown57 (7.3%)
Required196 (25.0%)
Privileges Required
Low147 (18.8%)
High44 (5.6%)
None536 (68.4%)
Unknown57 (7.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (784 CVEs).

CISA KEV
1 CVE
0.1% of CVEs· 99th percentile
Metasploit
2 CVEs
0.3% of CVEs· 97th percentile
Nuclei
5 CVEs
0.6% of CVEs· 95th percentile
ExploitDB
15 CVEs
1.9% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Schneider Electric.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Schneider Electric — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Schneider Electric's Products

View all 7 CNAs →

Top CWEs