Vulnerabilities
Vulnerable Software
Schneider-Electric:  Security Vulnerabilities
CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody.
CVSS Score
8.4
EPSS Score
0.002
Published
2026-01-15
CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rapsody.
CVSS Score
8.4
EPSS Score
0.004
Published
2026-01-15
CWE-400: An Uncontrolled Resource Consumption vulnerability exists that could cause the device to become unresponsive resulting in communication loss when a large amount of IGMP packets is present in the network.
CVSS Score
8.7
EPSS Score
0.008
Published
2024-11-13
CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access when enabled on the network and potentially impacting connected devices.
CVSS Score
10.0
EPSS Score
0.006
Published
2024-11-13
CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when application user opens a malicious Zelio Soft 2 project file.
CVSS Score
7.8
EPSS Score
0.002
Published
2024-10-08
CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and availability of the workstation when non-admin authenticated user tries to perform privilege escalation by tampering with the binaries.
CVSS Score
7.8
EPSS Score
0.002
Published
2024-09-11
CWE-200: Information Exposure vulnerability exists that could cause disclosure of credentials when a specially crafted message is sent to the device.
CVSS Score
9.8
EPSS Score
0.004
Published
2024-07-11
CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service, privilege escalation, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
CVSS Score
7.8
EPSS Score
0.002
Published
2024-07-11
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a vulnerability leading to a cross-site scripting condition where attackers can have a victim’s browser run arbitrary JavaScript when they visit a page containing the injected payload.
CVSS Score
5.4
EPSS Score
0.003
Published
2024-07-11
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could result in remote code execution when an authenticated user executes a saved project file that has been tampered by a malicious actor.
CVSS Score
7.3
EPSS Score
0.003
Published
2024-07-11


Contact Us

Shodan ® - All rights reserved