Schneider-Electric Citectscada vulnerabilities
5 known vulnerabilities affecting schneider-electric/citectscada.
Total CVEs
5
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2019-10981HIGHCVSS 7.8v7.30v7.402019-05-31
CVE-2019-10981 [HIGH] CWE-522 CVE-2019-10981: In Vijeo Citect 7.30 and 7.40, and CitectSCADA 7.30 and 7.40, a vulnerability has been identified th
In Vijeo Citect 7.30 and 7.40, and CitectSCADA 7.30 and 7.40, a vulnerability has been identified that may allow an authenticated local user access to Citect user credentials.
nvd
CVE-2013-2824HIGHCVSS 7.8v7.20v7.302014-02-26
CVE-2013-2824 [HIGH] CVE-2013-2824: Schneider Electric StruxureWare SCADA Expert Vijeo Citect 7.40, Vijeo Citect 7.20 through 7.30SP1, C
Schneider Electric StruxureWare SCADA Expert Vijeo Citect 7.40, Vijeo Citect 7.20 through 7.30SP1, CitectSCADA 7.20 through 7.30SP1, StruxureWare PowerSCADA Expert 7.30 through 7.30SR1, and PowerLogic SCADA 7.20 through 7.20SR1 do not properly handle exceptions, which allows remote attackers to cause a denial of service via a crafted packet.
nvd
CVE-2013-2796MEDIUMCVSS 6.9≤ 7.20v7.102013-08-09
CVE-2013-2796 [MEDIUM] CWE-264 CVE-2013-2796: Schneider Electric Vijeo Citect 7.20 and earlier, CitectSCADA 7.20 and earlier, and PowerLogic SCADA
Schneider Electric Vijeo Citect 7.20 and earlier, CitectSCADA 7.20 and earlier, and PowerLogic SCADA 7.20 and earlier allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML document containing an external entity declaration in conjunction with an enti
nvd
CVE-2013-3075CRITICALCVSS 10.0PoCv7.102013-04-19
CVE-2013-3075 [CRITICAL] CWE-119 CVE-2013-3075: Multiple buffer overflows in ActUWzd.dll 1.0.0.1 in Mitsubishi MX Component 3, as distributed in Cit
Multiple buffer overflows in ActUWzd.dll 1.0.0.1 in Mitsubishi MX Component 3, as distributed in Citect CitectFacilities 7.10 and CitectScada 7.10r1, allow remote attackers to execute arbitrary code via a long string, as demonstrated by a long WzTitle property value to a certain ActiveX control.
nvd
CVE-2011-5163MEDIUMCVSS 4.6≤ 7.102012-09-15
CVE-2011-5163 [MEDIUM] CWE-119 CVE-2011-5163: Buffer overflow in an unspecified third-party component in the Batch module for Schneider Electric C
Buffer overflow in an unspecified third-party component in the Batch module for Schneider Electric CitectSCADA before 7.20 and Mitsubishi MX4 SCADA before 7.20 allows local users to execute arbitrary code via a long string in a login sequence.
nvd