Product:

Ecostruxure_control_expert

(Schneider\-Electric)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 23
Date Id Summary Products Score Patch Annotated
2022-04-14 CVE-2022-26507 A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any of: CVE-2021-21810, CVE-2021-21811, CVE-2021-21812, CVE-2021-21815, CVE-2021-21825, CVE-2021-21826, CVE-2021-21828, CVE-2021-21829, or CVE-2021-21830. NOTE: This vulnerability only affects products that are no longer supported by the maintainer Xmill, Ecostruxure_control_expert, Ecostruxure_process_expert, Remoteconnect 9.8
2023-01-30 CVE-2022-45788 A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when a malicious project file is loaded onto the controller. Affected Products: EcoStruxure Control Expert (All Versions), EcoStruxure Process Expert (All Versions), Modicon M340 CPU - part numbers BMXP34* (All Versions), Modicon M580 CPU - part numbers BMEP* and BMEH* (All Versions), Modicon M580 CPU Safety... Ecostruxure_control_expert, Ecostruxure_process_expert, Modicon_m340_bmxp341000_firmware, Modicon_m340_bmxp342000_firmware, Modicon_m340_bmxp3420102_firmware, Modicon_m340_bmxp342010_firmware, Modicon_m340_bmxp342020_firmware, Modicon_m340_bmxp342020h_firmware, Modicon_m340_bmxp3420302_firmware, Modicon_m340_bmxp3420302h_firmware, Modicon_m340_bmxp342030_firmware, Modicon_m340_bmxp342030h_firmware, Modicon_m580_bmeh582040_firmware, Modicon_m580_bmeh582040c_firmware, Modicon_m580_bmeh582040s_firmware, Modicon_m580_bmeh584040_firmware, Modicon_m580_bmeh584040c_firmware, Modicon_m580_bmeh584040s_firmware, Modicon_m580_bmeh586040_firmware, Modicon_m580_bmeh586040c_firmware, Modicon_m580_bmeh586040s_firmware, Modicon_m580_bmep581020_firmware, Modicon_m580_bmep581020h_firmware, Modicon_m580_bmep582020_firmware, Modicon_m580_bmep582020h_firmware, Modicon_m580_bmep582040_firmware, Modicon_m580_bmep582040h_firmware, Modicon_m580_bmep582040s_firmware, Modicon_m580_bmep583020_firmware, Modicon_m580_bmep583040_firmware, Modicon_m580_bmep584020_firmware, Modicon_m580_bmep584040_firmware, Modicon_m580_bmep584040s_firmware, Modicon_m580_bmep585040_firmware, Modicon_m580_bmep585040c_firmware, Modicon_m580_bmep586040_firmware, Modicon_m580_bmep586040c_firmware, Modicon_mc80_bmkc8020301_firmware, Modicon_mc80_bmkc8020310_firmware, Modicon_mc80_bmkc8030311_firmware, Modicon_momentum_171cbu78090_firmware, Modicon_momentum_171cbu98090_firmware, Modicon_momentum_171cbu98091_firmware, Modicon_premium_tsxp57_1634m_firmware, Modicon_premium_tsxp57_2634m_firmware, Modicon_premium_tsxp57_2834m_firmware, Modicon_premium_tsxp57_454m_firmware, Modicon_premium_tsxp57_4634m_firmware, Modicon_premium_tsxp57_554m_firmware, Modicon_premium_tsxp57_5634m_firmware, Modicon_premium_tsxp57_6634m_firmware, Modicon_quantum_140cpu65150_firmware, Modicon_quantum_140cpu65150c_firmware, Modicon_quantum_140cpu65160_firmware, Modicon_quantum_140cpu65160c_firmware 9.8
2023-01-31 CVE-2022-45789 A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session. Affected Products: EcoStruxure Control Expert (All Versions), EcoStruxure Process Expert (All Versions), Modicon M340 CPU - part numbers BMXP34* (All Versions), Modicon M580 CPU - part numbers BMEP* and BMEH* (All Versions), Modicon M580 CPU Safety - part numbers BMEP58*S and BMEH58*S (All Versions) Ecostruxure_control_expert, Ecostruxure_process_expert, Modicon_m340_bmxp341000_firmware, Modicon_m340_bmxp342000_firmware, Modicon_m340_bmxp3420102_firmware, Modicon_m340_bmxp342010_firmware, Modicon_m340_bmxp342020_firmware, Modicon_m340_bmxp342020h_firmware, Modicon_m340_bmxp3420302_firmware, Modicon_m340_bmxp3420302h_firmware, Modicon_m340_bmxp342030_firmware, Modicon_m340_bmxp342030h_firmware, Modicon_m580_bmeh582040_firmware, Modicon_m580_bmeh582040c_firmware, Modicon_m580_bmeh582040s_firmware, Modicon_m580_bmeh584040_firmware, Modicon_m580_bmeh584040c_firmware, Modicon_m580_bmeh584040s_firmware, Modicon_m580_bmeh586040_firmware, Modicon_m580_bmeh586040c_firmware, Modicon_m580_bmeh586040s_firmware, Modicon_m580_bmep581020_firmware, Modicon_m580_bmep581020h_firmware, Modicon_m580_bmep582020_firmware, Modicon_m580_bmep582020h_firmware, Modicon_m580_bmep582040_firmware, Modicon_m580_bmep582040h_firmware, Modicon_m580_bmep582040s_firmware, Modicon_m580_bmep583020_firmware, Modicon_m580_bmep583040_firmware, Modicon_m580_bmep584020_firmware, Modicon_m580_bmep584040_firmware, Modicon_m580_bmep584040s_firmware, Modicon_m580_bmep585040_firmware, Modicon_m580_bmep585040c_firmware, Modicon_m580_bmep586040_firmware, Modicon_m580_bmep586040c_firmware 9.8
2023-04-18 CVE-2023-1548 A CWE-269: Improper Privilege Management vulnerability exists that could cause a local user to perform a denial of service through the console server service that is part of EcoStruxure Control Expert. Affected Products: EcoStruxure Control Expert (V15.1 and above) Ecostruxure_control_expert 5.5
2023-04-18 CVE-2023-27976 A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause remote code execution when a valid user visits a malicious link provided through the web endpoints. Affected Products: EcoStruxure Control Expert (V15.1 and above) Ecostruxure_control_expert 8.8
2022-09-12 CVE-2022-37300 A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode to the controller when communicating over Modbus. Affected Products: EcoStruxure Control Expert Including all Unity Pro versions (former name of EcoStruxure Control Expert) (V15.0 SP1 and prior), EcoStruxure Process Expert, Including all versions of EcoStruxure Hybrid DCS (former name of EcoStruxure Process Expert) (V2021 and prior), Modicon M340... Ecostruxure_control_expert, Ecostruxure_process_expert, Modicon_m340_bmxp341000_firmware, Modicon_m340_bmxp342000_firmware, Modicon_m340_bmxp3420102_firmware, Modicon_m340_bmxp342010_firmware, Modicon_m340_bmxp342020_firmware, Modicon_m340_bmxp342020h_firmware, Modicon_m340_bmxp3420302_firmware, Modicon_m340_bmxp3420302h_firmware, Modicon_m340_bmxp342030_firmware, Modicon_m340_bmxp342030h_firmware, Modicon_m580_bmeh582040_firmware, Modicon_m580_bmeh582040c_firmware, Modicon_m580_bmeh582040s_firmware, Modicon_m580_bmeh584040_firmware, Modicon_m580_bmeh584040c_firmware, Modicon_m580_bmeh584040s_firmware, Modicon_m580_bmeh586040_firmware, Modicon_m580_bmeh586040c_firmware, Modicon_m580_bmeh586040s_firmware, Modicon_m580_bmep581020_firmware, Modicon_m580_bmep581020h_firmware, Modicon_m580_bmep582020_firmware, Modicon_m580_bmep582020h_firmware, Modicon_m580_bmep582040_firmware, Modicon_m580_bmep582040h_firmware, Modicon_m580_bmep583020_firmware, Modicon_m580_bmep583040_firmware, Modicon_m580_bmep584020_firmware, Modicon_m580_bmep584040_firmware, Modicon_m580_bmep584040s_firmware, Modicon_m580_bmep585040_firmware, Modicon_m580_bmep585040c_firmware, Modicon_m580_bmep586040_firmware, Modicon_m580_bmep586040c_firmware 9.8
2022-09-13 CVE-2022-37302 A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a crash of the Control Expert software when an incorrect project file is opened. Affected Products: EcoStruxure Control Expert(V15.1 HF001 and prior). Ecostruxure_control_expert 5.5
2022-04-13 CVE-2021-22797 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be deployed in an unauthorized location and may result in code execution on the engineering workstation when a malicious project file is loaded in the engineering software. Affected Product: EcoStruxure Control Expert (V15.0 SP1 and prior, including former Unity Pro), EcoStruxure Process Expert (2020 and prior, including former HDCS), SCADAPack... Ecostruxure_control_expert, Ecostruxure_process_expert, Remoteconnect 7.8
2022-03-09 CVE-2022-24322 A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a disruption of communication between the Modicon controller and the engineering software when an attacker is able to intercept and manipulate specific Modbus response data. Affected Product: EcoStruxure Control Expert (V15.0 SP1 and prior) Ecostruxure_control_expert 5.9
2022-03-09 CVE-2022-24323 A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause a disruption of communication between the Modicon controller and the engineering software, when an attacker is able to intercept and manipulate specific Modbus response data. Affected Product: EcoStruxure Process Expert (V2021 and prior), EcoStruxure Control Expert (V15.0 SP1 and prior) Ecostruxure_control_expert, Ecostruxure_process_expert 5.9