Known vulnerabilities in EcoStruxure Power Operation 2024 CU1

Version: 2024 CU1
Software CPE: cpe:2.3:a:schneider_electric:ecostruxure_power_operation:*:*:*:*:*:*:*:*
Total vulnerabilities: 7
Public exploits: 2
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting EcoStruxure Power Operation version 2024 CU1 EcoStruxure Power Operation 2024 CU1 is affected by 7 vulnerabilities: 1 critical, 3 high, 3 medium Critical High Medium Low

Vulnerabilities (7)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU88063 - Memory corruption
CVE-2024-28219
CWE-119 Medium
No
No
2024 CU2 03.04.2024 SB2024040318
SB2024040320
SB2024040844
and 28 more
#VU85743 - Improper Control of Generation of Code ('Code Injection')
CVE-2023-50447
CWE-94 High
No
No
2024 CU2 24.01.2024 SB2024012413
SB2024012417
SB2024012465
and 34 more
#VU81728 - Resource exhaustion
CVE-2023-44487
CWE-400 High
Public exploit available
Exploited
2024 CU2 10.10.2023 SB2023101023
SB2023101024
SB2023101037
and 650 more
#VU81244 - Heap-based Buffer Overflow
CVE-2023-5217
CWE-122 Critical
Public exploit available
Exploited
2024 CU2 27.09.2023 SB2023092804
SB2023092847
SB2023092851
and 101 more
#VU78293 - Missing release of memory after effective lifetime
CVE-2023-35945
CWE-401 Medium
No
No
2024 CU2 16.07.2023 SB2023071620
SB2023080913
SB2023081405
and 18 more
#VU69498 - Resource Management Errors
CVE-2022-45198
CWE-399 Medium
No
No
2024 CU2 22.11.2022 SB2022112230
SB2022112234
SB2022121360
and 3 more
#VU60003 - Exposed Dangerous Method or Function
CVE-2022-22817
CWE-749 High
No
No
2024 CU2 25.01.2022 SB2022012523
SB2022012526
SB2022022226
and 26 more