<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 14:28:10 +0000</lastBuildDate>
    <item>
      <title>certfr-2021-avi-705 — De multiples vulnérabilités ont été découvertes dans les produits
Schneider. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-705</link>
      <description>certfr-2021-avi-705</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-705</guid>
    </item>
    <item>
      <title>EUVD-2026-23170</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-23170</link>
      <description>EUVD-2026-23170</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-23170</guid>
    </item>
    <item>
      <title>fkie_cve-2021-22797</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-22797</link>
      <description>&lt;p&gt;A CWE-22: Improper Limitation of a Pathname to a Restricted Directory (&amp;#39;Path Traversal) vulnerability exists that could cause malicious script to be deployed in an unauthorized location and may result in code execution on the engineering workstation when a malicious project file is loaded in the engineering software. Affected Product: EcoStruxure Control Expert (V15.0 SP1 and prior, including former Unity Pro), EcoStruxure Process Expert (2020 and prior, including former HDCS), SCADAPack RemoteConnect for x70 (All versions)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A CWE-22: Improper Limitation of a Pathname to a Restricted Directory (&amp;#39;Path Traversal) vulnerability exists that could cause malicious script to be deployed in an unauthorized location and may result in code execution on the engineering workstation when a malicious project file is loaded in the engineering software. Affected Product: EcoStruxure Control Expert (V15.0 SP1 and prior, including former Unity Pro), EcoStruxure Process Expert (2020 and prior, including former HDCS), SCADAPack RemoteConnect for x70 (All versions)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-22797</guid>
    </item>
    <item>
      <title>GHSA-qqgr-6jmg-cwgv</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qqgr-6jmg-cwgv</link>
      <description>&lt;p&gt;A CWE-22: Improper Limitation of a Pathname to a Restricted Directory (&amp;#39;Path Traversal) vulnerability exists that could cause malicious script to be deployed in an unauthorized location and may result in code execution on the engineering workstation when a malicious project file is loaded in the engineering software. Affected Product: EcoStruxure Control Expert (V15.0 SP1 and prior, including former Unity Pro), EcoStruxure Process Expert (2020 and prior, including former HDCS), SCADAPack RemoteConnect for x70 (All versions)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A CWE-22: Improper Limitation of a Pathname to a Restricted Directory (&amp;#39;Path Traversal) vulnerability exists that could cause malicious script to be deployed in an unauthorized location and may result in code execution on the engineering workstation when a malicious project file is loaded in the engineering software. Affected Product: EcoStruxure Control Expert (V15.0 SP1 and prior, including former Unity Pro), EcoStruxure Process Expert (2020 and prior, including former HDCS), SCADAPack RemoteConnect for x70 (All versions)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qqgr-6jmg-cwgv</guid>
    </item>
    <item>
      <title>gsd-2021-22797</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-22797</link>
      <description>gsd-2021-22797</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-22797</guid>
    </item>
    <item>
      <title>ICSA-21-259-02 — Schneider Electric EcoStruxure and SCADAPack</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-21-259-02</link>
      <description>&lt;p&gt;When a malicious project file is loaded on the engineering workstation software, it deploys a malicious script to execute arbitrary code in unauthorized locations.CVE-2021-22797has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When a malicious project file is loaded on the engineering workstation software, it deploys a malicious script to execute arbitrary code in unauthorized locations.CVE-2021-22797has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-21-259-02</guid>
    </item>
    <item>
      <title>SEVD-2021-257-01 — EcoStruxureTM Control Expert, EcoStruxureTM Process Expert, SCADAPack RemoteConnect™ for x70</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2021-257-01</link>
      <description>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in its EcoStruxure™ Control Expert, EcoStruxure™ Process Expert, SCADAPack RemoteConnect™ for x70 software products.&#13;
EcoStruxure™ Control Expert is the common programming, debugging and operating software for Modicon M340, M580, M580S, Premium, Momentum and Quantum ranges.   &#13;
EcoStruxure™ Process Expert is the next-generation process automation system to engineer, operate and maintain an entire plant, a Distributed Control System (DCS), designed especially for water, mining, cement, power generation, consumer packaged goods, chemical, and oil and gas applications.  &#13;
The SCADAPack RemoteConnect™ for x70 product is a Windows-based application based on EcoStruxure™ Control Expert software components that provides a programming and configuration environment for the SCADAPack x70 RTU series, which is comprised of the SCADAPack 470, 474, 570, 574 and 575 Smart RTUs.&#13;
Failure to apply the remediations provided below may risk a Denial of Service attack, which could cause a disruption of communication between the Modicon controller and the engineering software.&#13;
&#13;
June 2022 Update: Added SCADAPack RemoteConnect™ to the list of affected products, which is impacted on versions prior to R2.7.3 through the integration of EcoStruxure™ Control Expert.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in its EcoStruxure™ Control Expert, EcoStruxure™ Process Expert, SCADAPack RemoteConnect™ for x70 software products.&#13;
EcoStruxure™ Control Expert is the common programming, debugging and operating software for Modicon M340, M580, M580S, Premium, Momentum and Quantum ranges.   &#13;
EcoStruxure™ Process Expert is the next-generation process automation system to engineer, operate and maintain an entire plant, a Distributed Control System (DCS), designed especially for water, mining, cement, power generation, consumer packaged goods, chemical, and oil and gas applications.  &#13;
The SCADAPack RemoteConnect™ for x70 product is a Windows-based application based on EcoStruxure™ Control Expert software components that provides a programming and configuration environment for the SCADAPack x70 RTU series, which is comprised of the SCADAPack 470, 474, 570, 574 and 575 Smart RTUs.&#13;
Failure to apply the remediations provided below may risk a Denial of Service attack, which could cause a disruption of communication between the Modicon controller and the engineering software.&#13;
&#13;
June 2022 Update: Added SCADAPack RemoteConnect™ to the list of affected products, which is impacted on versions prior to R2.7.3 through the integration of EcoStruxure™ Control Expert.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2021-257-01</guid>
    </item>
  </channel>
</rss>
