Se develops industrial automation and control products spanning software platforms such as EcoStruxure OPC UA Server Expert and Operator Terminal Expert, along with networked devices including the RENF22R2MMW fault detection units. Observed vulnerabilities cluster around authentication bypass, command argument injection, and XML entity reference handling—weaknesses characteristic of industrial software interfaces where external input trust and protocol parsing are critical surfaces. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Se over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-0568HIGH
CWE-287: Improper Authentication vulnerability exists that could cause unauthorized tampering
of device configuration over NFC communication.
| Feb 14, 2024 | 8.8 | 25 | NO | NO |
CVE-2020-7496HIGH A CWE-88: Argument Injection or Modification vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)which could cause | Jun 16, 2020 | 7.8 | 25 | NO | NO |
CVE-2023-37200MEDIUM
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that
could cause loss of confidentiality when replacing a project file on the local filesyste | Jul 12, 2023 | 5.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Se.
Media articles that mention a CVE ID that affects a product developed by Se — matched by CVE ID, not by vendor name.