Vulnerability index

Browse CVEs

62 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

System Platform HIGH 7.2
CVE-2021-32977

AVEVA System Platform versions 2017 through 2020 R2 P01 does not verify, or incorrectly verifies, the cryptographic signature for data.

Fix: 2020+
Fix from $1,950 2022-04-04
System Platform HIGH 7.2
CVE-2021-32981

AVEVA System Platform versions 2017 through 2020 R2 P01 uses external input to construct a pathname that is intended to identify a file or directory …

Fix: 2020+
Fix from $1,950 2022-04-04
Suitelink CRITICAL 9.8
CVE-2021-32959

Heap-based buffer overflow in SuiteLink server while processing commands 0x05/0x06

Fix: 3.2.002+
Fix from $2,300 2021-09-23
Suitelink HIGH 7.5
CVE-2021-32963

Null pointer dereference in SuiteLink server while processing commands 0x03/0x10

Fix: 3.2.002+
Fix from $1,950 2021-09-23
Suitelink HIGH 7.5
CVE-2021-32971

Null pointer dereference in SuiteLink server while processing command 0x07

Fix: 3.2.002+
Fix from $1,950 2021-09-23
Suitelink HIGH 7.5
CVE-2021-32979

Null pointer dereference in SuiteLink server while processing commands 0x04/0x0a

Fix: 3.2.002+
Fix from $1,950 2021-09-23
Suitelink HIGH 7.5
CVE-2021-32987

Null pointer dereference in SuiteLink server while processing command 0x0b

Fix: 3.2.002+
Fix from $1,950 2021-09-23
Suitelink HIGH 7.5
CVE-2021-32999

Improper handling of exceptional conditions in SuiteLink server while processing command 0x01

Fix: 3.2.002+
Fix from $1,950 2021-09-23
Intouch 2017 MEDIUM 5.5
CVE-2021-32942

The vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowViewer) if an authorized, privi…

Patch available
Fix from $1,600 2021-06-09
Edna Enterprise Data Historian CRITICAL 9.8
CVE-2020-13499

An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially …

No fix yet
Fix from $2,300 2020-09-24
Edna Enterprise Data Historian CRITICAL 9.8
CVE-2020-13500

SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially cra…

No fix yet
Fix from $2,300 2020-09-24
Edna Enterprise Data Historian CRITICAL 9.8
CVE-2020-13501

An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially …

No fix yet
Fix from $2,300 2020-09-24
Edna Enterprise Data Historian CRITICAL 9.8
CVE-2020-13504

Parameter AttFilterValue in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted SOAP web requests can cause …

No fix yet
Fix from $2,300 2020-09-24
Edna Enterprise Data Historian CRITICAL 9.8
CVE-2020-13505

Parameter psClass in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted SOAP web requests can cause SQL inj…

No fix yet
Fix from $2,300 2020-09-24
Iec870ip Firmware HIGH 7.5
CVE-2019-13537

The IEC870IP driver for AVEVA’s Vijeo Citect and Citect SCADA and Schneider Electric’s Power SCADA Operation has a buffer overflow vulnerability that…

Fix: after 4.14.02
Fix from $1,950 2020-01-14
Wonderware System Platform HIGH 8.8
CVE-2019-6525

AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of system processes and inter-node…

Fix: 2017+
Fix from $1,950 2019-04-11
Indusoft Web Studio CRITICAL 9.8
CVE-2019-6543EPSS 17%

AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update…

No fix yet
Fix from $2,300 2019-02-13
Indusoft Web Studio HIGH 7.5
CVE-2019-6545EPSS 14%

AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update…

No fix yet
Fix from $1,950 2019-02-13
Indusoft Web Studio CRITICAL 9.8
CVE-2018-17914

InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. This vulnerability…

No fix yet
Fix from $2,300 2018-11-02
Indusoft Web Studio CRITICAL 9.8
CVE-2018-17916

InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. A remote attacker …

No fix yet
Fix from $2,300 2018-11-02
Intouch 2014 CRITICAL 9.8
CVE-2018-10628EPSS 5%

AVEVA InTouch 2014 R2 SP1 and prior, InTouch 2017, InTouch 2017 Update 1, and InTouch 2017 Update 2 allow an unauthenticated user to send a specially…

Patch available
Fix from $2,300 2018-07-24
Indusoft Web Studio CRITICAL 9.8
CVE-2018-10620

AVEVA InduSoft Web Studio v8.1 and v8.1SP1, and InTouch Machine Edition v2017 8.1 and v2017 8.1 SP1 a remote user could send a carefully crafted pack…

No fix yet
Fix from $2,300 2018-07-19
Clearscada HIGH 7.5
CVE-2017-6021

In Schneider Electric ClearSCADA 2014 R1 (build 75.5210) and prior, 2014 R1.1 (build 75.5387) and prior, 2015 R1 (build 76.5648) and prior, and 2015 …

Fix: after 2010
Fix from $1,950 2018-05-14
Clearscada HIGH 7.5
CVE-2017-9962

Schneider Electric's ClearSCADA versions released prior to August 2017 are susceptible to a memory allocation vulnerability, whereby malformed reques…

Fix: after 2010
Fix from $1,950 2017-09-26
Wonderware Intouch Access Anywhere CRITICAL 9.8
CVE-2017-5158

An Information Exposure issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. Credentials may be e…

Fix: after 11.5.2
Fix from $2,300 2017-04-20
Wonderware Intouch Access Anywhere HIGH 8.8
CVE-2017-5156

A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The client requ…

Fix: after 11.5.2
Fix from $1,950 2017-04-20
Wonderware Intouch Access Anywhere MEDIUM 5.3
CVE-2017-5160

An Inadequate Encryption Strength issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The softwa…

Fix: after 11.5.2
Fix from $1,600 2017-04-20
Aveva Edge MEDIUM 5.0
CVE-2015-0997

Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 provide an HMI user int…

Fix: 7.1 / 7.1.3.4+
Fix from $1,600 2015-03-29
Clearscada MEDIUM 5.0
CVE-2014-5412

Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allows remote attackers to read database records by leveraging access…

Mitigation only
Fix from $1,600 2014-09-18
Clearscada MEDIUM 5.0
CVE-2014-5413

Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 uses the MD5 algorithm for an X.509 certificate, which makes it easie…

Mitigation only
Fix from $1,600 2014-09-18