Known vulnerabilities in EcoStruxure Power SCADA Operation with Advanced Reports
Vendor:
Schneider Electric
Software CPE:
cpe:2.3:a:schneider_electric:ecostruxure_power_scada_operation_with_advanced_reports:*:*:*:*:*:*:*:*
Total vulnerabilities:
2
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (2)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU103599 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2024-8401 |
CWE-79 | Low | - | 04.02.2025 |
SB2025020453 |
||
| #VU82203 - Deserialization of Untrusted Data CVE-2023-5391 |
CWE-502 | High | 2021 hotfix 145271, 2022 hotfix 145271 | 18.10.2023 |
SB2023101845 |