27 January 2021
From buffer overflow to switchboard setup errors: vulnerabilities in building operation software by Schneider Electric
Vulnerabilities in Schneider Electric’s low-voltage distribution system configuration software could enable attackers to upload arbitrary files defining electrical system parameters
26 January 2021
Twentieth for Ripple20: Vulnerability in embedded web server of I/O expansion modules for IoT
Sсhneider Electric has published an advisory on a critical vulnerability in the web server used in TM3 I/O expansion modules
26 January 2021
Critical vulnerability in Schneider Electric HMI configuration software
The vulnerability could cause a Windows local user privilege escalation when using EcoStruxure™ Operator Terminal Expert and Pro-face BLUE software and WinGP runtime environment by Schneider Electric.
26 January 2021
A classic that needs updating: fresh vulnerabilities in the software of Siemens SCALANCE X switches
DoS vulnerabilities have been disclosed in the integrated web server of Siemens SCALANCE X-200 / X-200IRT / X-300 switches. Measures proposed by the vendor do not prevent all possible attacks.
30 April 2020
Multiple vulnerabilities in ABB 800xA DCS
The vulnerabilities could allow attackers to remotely compromise hosts, cause denial-of-service conditions or elevate their privileges
17 April 2020
Dozens of Siemens industrial devices are affected by DoS vulnerabilities
Siemens industrial solutions are affected by SegmentSmack and FragmentSmack vulnerabilities, which could lead to device denial of service
13 April 2020
Multiple vulnerabilities in Advantech WebAccess/NMS
If exploited, the vulnerabilities could lead to arbitrary code execution, file manipulations, denial of service and the creation of an admin account
20 December 2019
Multiple vulnerabilities in WAGO PLCs
Nine vulnerabilities have been identified in WAGO PFC200 and PFC100 PLCs. They could lead to arbitrary code execution or cause denial of service
19 December 2019
Multiple vulnerabilities in Modicon controllers
If exploited, the vulnerabilities could result in denial of service. They can be fixed by updating device firmware
18 December 2019
Multiple vulnerabilities in SPPA-T3000 components
Vulnerabilities have been identified in SPPA-T3000 Application Server and MS3000 Migration Server. Some of the faults are critical and could allow attackers to execute arbitrary code on the server