Threats Tagged 'schneider-electric-cpcert'
View all threats tagged with 'schneider-electric-cpcert'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'schneider-electric-cpcert'
Click on any threat for detailed analysis and mitigation recommendations
CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorized credential modification, potentially leading to compromise of managed devices, when a local privileged attacker leverages weaknesses in the handling and protection of stored credentials within the application. Join the discussion | GCVE Database | 07/29/2026, 15:31:10 UTC Added: 07/14/2026, 09:20:09 UTC |
An out-of-bounds write vulnerability (CWE-787) exists in the IGSS Definition (Def.exe) module of Schneider Electric software. This vulnerability can be triggered by importing a malicious CGF file, potentially leading to data loss or arbitrary code execution. The affected versions include IGSS Definition module version 18.0.0.26124 and earlier. No patch or official remediation has been indicated in the provided data. No known exploits are reported in the wild. Join the discussion | GCVE Database | 07/29/2026, 12:37:47 UTC Added: 07/14/2026, 09:20:09 UTC |
CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuration functionality unavailable when malformed requests are received over exposed network interfaces. Join the discussion | GCVE Database | 06/25/2026, 15:02:28 UTC Added: 06/09/2026, 10:22:54 UTC |
CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenticated attacker accesses credentials stored within firmware or system files. With this credential an attacker could subsequently compromise the device if they have physical access to the device. Join the discussion | GCVE Database | 06/25/2026, 14:44:30 UTC Added: 06/09/2026, 10:22:54 UTC |
CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert user account submits crafted XML payloads to SOAP service endpoints. Join the discussion | GCVE Database | 06/09/2026, 14:41:56 UTC Added: 06/09/2026, 10:22:54 UTC |
We strongly recommend the following industry cybersecurity best practices. * Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network. * Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks. * Place all controllers in locked cabinets and never leave them in the “Program” mode. * Never connect programming software to any network other than the network intended for that device. * Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks. * Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation. * Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet. * When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices. For more information refer to the Schneider Electric [Recommended Cybersecurity Best Practices](https://www.se.com/us/en/download/document/7EN52-0390/) document. Join the discussion | CVE Database V5 | 05/12/2026, 12:24:22 UTC Added: 05/12/2026, 12:36:46 UTC |
0 We strongly recommend the following industry cybersecurity best practices. https://www.se.com/us/en/download/document/7EN52-0390/ * Locate control and safety system networks and remote devices behind firewalls and isolate them from the business network. * Install physical controls so no unauthorized personnel can access your industrial control and safety systems, components, peripheral equipment, and networks. * Place all controllers in locked cabinets and never leave them in the “Program” mode. * Never connect programming software to any network other than the network intended for that device. * Scan all methods of mobile data exchange with the isolated network such as CDs, USB drives, etc. before use in the terminals or any node connected to these networks. * Never allow mobile devices that have connected to any other network besides the intended network to connect to the safety or control networks without proper sanitation. * Minimize network exposure for all control system devices and systems and ensure that they are not accessible from the Internet. * When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). Recognize that VPNs may have vulnerabilities and should be updated to the most current version available. Also, understand that VPNs are only as secure as the connected devices. For more information refer to the Schneider Electric Recommended Cybersecurity Best Practices document. Join the discussion | GCVE Database | 01/14/2025, 00:00:00 UTC Added: 07/14/2026, 09:20:09 UTC |
Showing 1 to 7 of 7 results