<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_se/10</id>
  <title>Most recent entries from csaf_se</title>
  <updated>2026-10-02T17:36:39.089361+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2015-344-01</id>
    <title>SEVD-2015-344-01 — GoAhead Web Server vulnerability</title>
    <updated>2020-06-09T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of a proof of concept exploit available for this vulnerability. It is 
imperative that customers upgrade the firmware for the affected products.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2015-344-01"/>
    <published>2015-12-15T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2018-081-01</id>
    <title>SEVD-2018-081-01 — Embedded FTP Servers for Modicon PAC Controllers</title>
    <updated>2024-08-13T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of multiple vulnerabilities in the FTP servers of its Modicon PAC controllers.

Modicon PACs (Programmable Automation Controllers) control and monitor industrial operations in a sustainable, flexible, efficient, and protected way. Our PLCs and PACs supply edge technology, augmenting it with Ethernet connectivity, built-in cybersecurity, and processing power needed to handle Big Data analysis and protect against new vulnerabilities among connected industrial assets, across devices or into the cloud.

Failure to address these vulnerabilities could result in unauthorized access to your PLC and a denial of service or other malicious activity.

March 2023 Update: Remediation for the Modicon M580 CPU is available for download</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2018-081-01"/>
    <published>2018-03-22T03:39:21+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2018-095-01</id>
    <title>SEVD-2018-095-01 — Security Notification - U.motion Builder software</title>
    <updated>2020-02-11T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of an exploit that targets Schneider Electric’s U.motion Builder 
software. It is imperative customers cease using U.motion Builder software and remove it from 
their systems immediately.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2018-095-01"/>
    <published>2018-04-05T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2019-134-11</id>
    <title>SEVD-2019-134-11 — Multiple Vulnerabilities in Modicon Controller Products</title>
    <updated>2026-09-08T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of multiple vulnerabilities in its Modicon Controller products. 
The [Modicon Programmable Automation controllers](https://www.se.com/ww/en/product-subcategory/3950-pac-programmable-automation-controllers/) are used for complex networked communication, display 
and control applications  
Failure to apply the mitigations or remediations provided below may risk execution of unsolicited command on 
the PLC which could result in a loss of availability of the controller.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2019-134-11"/>
    <published>2019-05-14T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sesb-2019-214-01</id>
    <title>SESB-2019-214-01 — Wind River VxWorks Vulnerabilities (URGENT/11)</title>
    <updated>2022-09-13T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Wind River's VxWorks TCP/IP Stack vulnerabilities have wide-ranging impact across multiple IT and 
industrial applications. We are working closely with Wind River to understand and assess how these 
vulnerabilities impact Schneider Electric offers and our customers’ operations. We downloaded Wind 
River’s patches as soon as they were made available to us, and we have quickly instituted a 
remediation plan to evolve all current and future products that rely on the Wind River platform to 
embed these fixes. 
We will continue to monitor and will respond further if new information becomes available. In the 
meantime, customers should immediately make sure they have implemented cybersecurity best 
practices across their operations to protect themselves from these vulnerabilities. Where appropriate 
this includes locating your industrial systems and remotely accessible devices behind firewalls; 
installing physical controls to prevent unauthorized access; and preventing mission-critical systems 
and devices from being accessed from outside networks.
Please subscribe to the Schneider Electric security notification service to be informed of updates to 
this disclosure, including details on affected products and remediations, as well as other important 
security notifications:
https://www.schneider-electric.com/en/work/support/cybersecurity/security-notifications.jsp
For additional information and support, please contact your Schneider Electric sales or service 
repr…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sesb-2019-214-01"/>
    <published>2019-08-02T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2019-225-01</id>
    <title>SEVD-2019-225-01 — Harmony (formerly known as Magelis) HMI Panels</title>
    <updated>2024-01-09T09:59:02+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of a vulnerability in the Harmony (formerly known as Magelis) HMI Panel products. Harmony HMI Panels are the main visible automation component that manage all vital machine features, including visualization, control, supervision, diagnostics, monitoring, and data logging.
Failure to apply the mitigations/remediations provided below may risk a temporary Denial of Service.
January 2024 Update: A fix is available for HMISCU series.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2019-225-01"/>
    <published>2019-08-13T09:59:02+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2019-281-02</id>
    <title>SEVD-2019-281-02 — Modicon Controllers</title>
    <updated>2024-08-13T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of multiple vulnerabilities in the Modicon Controller products.
March 2023 Update: Remediation for the Modicon M580 CPU is available for download</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2019-281-02"/>
    <published>2019-09-26T12:53:28+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2020-014-01</id>
    <title>SEVD-2020-014-01 — MSX Configurator</title>
    <updated>2020-01-14T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of a vulnerability in the MSX Configurator product.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2020-014-01"/>
    <published>2020-01-14T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2020-042-01</id>
    <title>SEVD-2020-042-01 — ProSoft Configurator for Modicon PMEPXM0100 (H)</title>
    <updated>2020-02-11T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of a vulnerability in the ProSoft Configurator for the PMEPXM0100
(H) module.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2020-042-01"/>
    <published>2020-02-11T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2020-070-01</id>
    <title>SEVD-2020-070-01 — IGSS (Interactive Graphical SCADA System)</title>
    <updated>2020-03-10T00:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of multiple vulnerabilities in the IGSS product.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2020-070-01"/>
    <published>2020-03-10T00:00:00+00:00</published>
  </entry>
</feed>
