Browse all 25 CVE security advisories affecting SOCOMEC. AI-powered Chinese analysis, POCs, and references for each vulnerability.
SOCOMEC specializes in power management and electrical distribution solutions, primarily serving industrial, commercial, and residential sectors with uninterruptible power supplies (UPS) and energy monitoring systems. Security audits reveal a concerning history of twenty-five recorded Common Vulnerabilities and Exposures (CVEs), indicating persistent weaknesses in their product lifecycle. The most prevalent vulnerability classes involve remote code execution (RCE) and cross-site scripting (XSS), often stemming from insufficient input validation in web-based management interfaces. Additionally, several instances of privilege escalation have been documented, allowing unauthorized users to gain administrative control over critical infrastructure components. These flaws frequently reside in the embedded web servers and communication protocols used for device configuration. While no single catastrophic public breach has been widely reported, the accumulation of these CVEs suggests systemic issues in secure coding practices. Organizations deploying SOCOMEC equipment must prioritize network segmentation and regular firmware updates to mitigate the risk of exploitation within their operational technology environments.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2023-38255 | Socomec MOD3GP-SY-120K Cross-site Scripting — MODULYS GP (MOD3GP-SY-120K)CWE-79 | 6.5 | Medium | 2023-09-18 |
| CVE-2023-38582 | Socomec MOD3GP-SY-120K Cross-site Scripting — MODULYS GP (MOD3GP-SY-120K)CWE-79 | 6.3 | Medium | 2023-09-18 |
| CVE-2023-39446 | Socomec MOD3GP-SY-120K Cross-Site Request Forgery — MODULYS GP (MOD3GP-SY-120K)CWE-352 | 8.9 | High | 2023-09-18 |
| CVE-2023-39452 | Socomec MOD3GP-SY-120K Plaintext Storage of a Password — MODULYS GP (MOD3GP-SY-120K)CWE-256 | 7.5 | High | 2023-09-18 |
| CVE-2023-40221 | Socomec MOD3GP-SY-120K Code Injection — MODULYS GP (MOD3GP-SY-120K)CWE-94 | 8.8 | High | 2023-09-18 |
| CVE-2023-41084 | Socomec MOD3GP-SY-120K Reliance on Cookies without Validation and Integrity Checking — MODULYS GP (MOD3GP-SY-120K)CWE-565 | 10.0 | Critical | 2023-09-18 |
| CVE-2023-41965 | Socomec MOD3GP-SY-120K Insecure Storage of Sensitive Information — MODULYS GP (MOD3GP-SY-120K)CWE-921 | 7.5 | High | 2023-09-18 |
This page lists every published CVE security advisory associated with SOCOMEC. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.