<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_se</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:36:29 +0000</lastBuildDate>
    <item>
      <title>SEVD-2015-344-01 — GoAhead Web Server vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2015-344-01</link>
      <description>&lt;p&gt;Schneider Electric is aware of a proof of concept exploit available for this vulnerability. It is &#13;
imperative that customers upgrade the firmware for the affected products.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of a proof of concept exploit available for this vulnerability. It is &#13;
imperative that customers upgrade the firmware for the affected products.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2015-344-01</guid>
      <pubDate>Tue, 15 Dec 2015 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SEVD-2018-081-01 — Embedded FTP Servers for Modicon PAC Controllers</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2018-081-01</link>
      <description>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in the FTP servers of its Modicon PAC controllers.&#13;
&#13;
Modicon PACs (Programmable Automation Controllers) control and monitor industrial operations in a sustainable, flexible, efficient, and protected way. Our PLCs and PACs supply edge technology, augmenting it with Ethernet connectivity, built-in cybersecurity, and processing power needed to handle Big Data analysis and protect against new vulnerabilities among connected industrial assets, across devices or into the cloud.&#13;
&#13;
Failure to address these vulnerabilities could result in unauthorized access to your PLC and a denial of service or other malicious activity.&#13;
&#13;
March 2023 Update: Remediation for the Modicon M580 CPU is available for download&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in the FTP servers of its Modicon PAC controllers.&#13;
&#13;
Modicon PACs (Programmable Automation Controllers) control and monitor industrial operations in a sustainable, flexible, efficient, and protected way. Our PLCs and PACs supply edge technology, augmenting it with Ethernet connectivity, built-in cybersecurity, and processing power needed to handle Big Data analysis and protect against new vulnerabilities among connected industrial assets, across devices or into the cloud.&#13;
&#13;
Failure to address these vulnerabilities could result in unauthorized access to your PLC and a denial of service or other malicious activity.&#13;
&#13;
March 2023 Update: Remediation for the Modicon M580 CPU is available for download&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2018-081-01</guid>
      <pubDate>Thu, 22 Mar 2018 03:39:21 +0000</pubDate>
    </item>
    <item>
      <title>SEVD-2018-095-01 — Security Notification - U.motion Builder software</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2018-095-01</link>
      <description>&lt;p&gt;Schneider Electric is aware of an exploit that targets Schneider Electric’s U.motion Builder &#13;
software. It is imperative customers cease using U.motion Builder software and remove it from &#13;
their systems immediately.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of an exploit that targets Schneider Electric’s U.motion Builder &#13;
software. It is imperative customers cease using U.motion Builder software and remove it from &#13;
their systems immediately.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2018-095-01</guid>
      <pubDate>Thu, 05 Apr 2018 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SEVD-2019-134-11 — Multiple Vulnerabilities in Modicon Controller Products</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2019-134-11</link>
      <description>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in its Modicon Controller products. &#13;
The [Modicon Programmable Automation controllers](https://www.se.com/ww/en/product-subcategory/3950-pac-programmable-automation-controllers/) are used for complex networked communication, display &#13;
and control applications  &#13;
Failure to apply the mitigations or remediations provided below may risk execution of unsolicited command on &#13;
the PLC which could result in a loss of availability of the controller.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in its Modicon Controller products. &#13;
The [Modicon Programmable Automation controllers](https://www.se.com/ww/en/product-subcategory/3950-pac-programmable-automation-controllers/) are used for complex networked communication, display &#13;
and control applications  &#13;
Failure to apply the mitigations or remediations provided below may risk execution of unsolicited command on &#13;
the PLC which could result in a loss of availability of the controller.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2019-134-11</guid>
      <pubDate>Tue, 14 May 2019 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SESB-2019-214-01 — Wind River VxWorks Vulnerabilities (URGENT/11)</title>
      <link>https://cve.radiocsirt.org/vuln/sesb-2019-214-01</link>
      <description>&lt;p&gt;Wind River&amp;#39;s VxWorks TCP/IP Stack vulnerabilities have wide-ranging impact across multiple IT and &#13;
industrial applications. We are working closely with Wind River to understand and assess how these &#13;
vulnerabilities impact Schneider Electric offers and our customers’ operations. We downloaded Wind &#13;
River’s patches as soon as they were made available to us, and we have quickly instituted a &#13;
remediation plan to evolve all current and future products that rely on the Wind River platform to &#13;
embed these fixes. &#13;
We will continue to monitor and will respond further if new information becomes available. In the &#13;
meantime, customers should immediately make sure they have implemented cybersecurity best &#13;
practices across their operations to protect themselves from these vulnerabilities. Where appropriate &#13;
this includes locating your industrial systems and remotely accessible devices behind firewalls; &#13;
installing physical controls to prevent unauthorized access; and preventing mission-critical systems &#13;
and devices from being accessed from outside networks.&#13;
Please subscribe to the Schneider Electric security notification service to be informed of updates to &#13;
this disclosure, including details on affected products and remediations, as well as other important &#13;
security notifications:&#13;
https://www.schneider-electric.com/en/work/support/cybersecurity/security-notifications.jsp&#13;
For additional information and support, please contact your Schneider Electric sales or service &#13;
repr…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Wind River&amp;#39;s VxWorks TCP/IP Stack vulnerabilities have wide-ranging impact across multiple IT and &#13;
industrial applications. We are working closely with Wind River to understand and assess how these &#13;
vulnerabilities impact Schneider Electric offers and our customers’ operations. We downloaded Wind &#13;
River’s patches as soon as they were made available to us, and we have quickly instituted a &#13;
remediation plan to evolve all current and future products that rely on the Wind River platform to &#13;
embed these fixes. &#13;
We will continue to monitor and will respond further if new information becomes available. In the &#13;
meantime, customers should immediately make sure they have implemented cybersecurity best &#13;
practices across their operations to protect themselves from these vulnerabilities. Where appropriate &#13;
this includes locating your industrial systems and remotely accessible devices behind firewalls; &#13;
installing physical controls to prevent unauthorized access; and preventing mission-critical systems &#13;
and devices from being accessed from outside networks.&#13;
Please subscribe to the Schneider Electric security notification service to be informed of updates to &#13;
this disclosure, including details on affected products and remediations, as well as other important &#13;
security notifications:&#13;
https://www.schneider-electric.com/en/work/support/cybersecurity/security-notifications.jsp&#13;
For additional information and support, please contact your Schneider Electric sales or service &#13;
repr…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sesb-2019-214-01</guid>
      <pubDate>Fri, 02 Aug 2019 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SEVD-2019-225-01 — Harmony (formerly known as Magelis) HMI Panels</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2019-225-01</link>
      <description>&lt;p&gt;Schneider Electric is aware of a vulnerability in the Harmony (formerly known as Magelis) HMI Panel products. Harmony HMI Panels are the main visible automation component that manage all vital machine features, including visualization, control, supervision, diagnostics, monitoring, and data logging.&#13;
Failure to apply the mitigations/remediations provided below may risk a temporary Denial of Service.&#13;
January 2024 Update: A fix is available for HMISCU series.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of a vulnerability in the Harmony (formerly known as Magelis) HMI Panel products. Harmony HMI Panels are the main visible automation component that manage all vital machine features, including visualization, control, supervision, diagnostics, monitoring, and data logging.&#13;
Failure to apply the mitigations/remediations provided below may risk a temporary Denial of Service.&#13;
January 2024 Update: A fix is available for HMISCU series.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2019-225-01</guid>
      <pubDate>Tue, 13 Aug 2019 09:59:02 +0000</pubDate>
    </item>
    <item>
      <title>SEVD-2019-281-02 — Modicon Controllers</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2019-281-02</link>
      <description>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in the Modicon Controller products.
March 2023 Update: Remediation for the Modicon M580 CPU is available for download&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in the Modicon Controller products.
March 2023 Update: Remediation for the Modicon M580 CPU is available for download&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2019-281-02</guid>
      <pubDate>Thu, 26 Sep 2019 12:53:28 +0000</pubDate>
    </item>
    <item>
      <title>SEVD-2020-014-01 — MSX Configurator</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2020-014-01</link>
      <description>&lt;p&gt;Schneider Electric is aware of a vulnerability in the MSX Configurator product.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of a vulnerability in the MSX Configurator product.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2020-014-01</guid>
      <pubDate>Tue, 14 Jan 2020 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SEVD-2020-042-01 — ProSoft Configurator for Modicon PMEPXM0100 (H)</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2020-042-01</link>
      <description>&lt;p&gt;Schneider Electric is aware of a vulnerability in the ProSoft Configurator for the PMEPXM0100&#13;
(H) module.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of a vulnerability in the ProSoft Configurator for the PMEPXM0100&#13;
(H) module.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2020-042-01</guid>
      <pubDate>Tue, 11 Feb 2020 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SEVD-2020-070-01 — IGSS (Interactive Graphical SCADA System)</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2020-070-01</link>
      <description>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in the IGSS product.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in the IGSS product.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2020-070-01</guid>
      <pubDate>Tue, 10 Mar 2020 00:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
