Known vulnerabilities in EcoStruxure Operator Terminal Expert

Software CPE: cpe:2.3:a:schneider_electric:vijeo_xd:*:*:*:*:*:*:*:*
Total vulnerabilities: 9
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting EcoStruxure Operator Terminal Expert EcoStruxure Operator Terminal Expert is affected by 9 known vulnerabilities: 3 high, 1 medium, 5 low Critical High Medium Low

Vulnerabilities (9)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU77817 - Improper Control of Generation of Code ('Code Injection')
CVE-2023-1049
CWE-94 High
No
No
3.4 30.06.2023 SB2023063003
#VU58500 - Insufficient Entropy
CVE-2021-22799
CWE-331 Low
No
No
- 03.12.2021 SB2021120302
#VU48745 - Improper Privilege Management
CVE-2020-7544
CWE-269 Low
No
No
3.1 SP1B 19.11.2020 SB2020120206
#VU47730 - Use of Hard-coded Cryptographic Key
CWE-321 Medium
No
No
- 20.10.2020 SB2020102003
#VU27967 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2020-7497
CWE-22 Low
No
No
- 18.05.2020 SB2020051811
#VU27966 - Argument Injection or Modification
CVE-2020-7496
CWE-88 Low
No
No
3.1 SP1A 18.05.2020 SB2020051810
#VU27964 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2020-7495
CWE-22 Low
No
No
3.1 SP1A 18.05.2020 SB2020051810
#VU27963 - Uncontrolled Search Path Element
CVE-2020-7494
CWE-427 High
No
No
3.1 SP1A 18.05.2020 SB2020051810
#VU27962 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2020-7493
CWE-89 High
No
No
3.1 SP1A 18.05.2020 SB2020051810