Vulnerability index

Browse CVEs

89 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Esoms MEDIUM 5.3
CVE-2023-5515

The responses for web queries with certain parameters disclose internal path of resources. This information can be used to learn internal structure o…

Fix: after 6.3.13
Fix from $1,600 2023-11-01
Asset Suite HIGH 8.8
CVE-2023-4816

A vulnerability exists in the Equipment Tag Out authentication, when configured with Single Sign-On (SSO) with password validation in T214. This vuln…

Fix: after 9.6.3.11.1
Fix from $1,950 2023-09-11
Rtu500 Firmware HIGH 7.5
CVE-2022-4608

A vulnerability exists in HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be explo…

Mitigation only
Fix from $1,950 2023-07-26
Rtu500 Firmware HIGH 7.5
CVE-2022-2502

A vulnerability exists in the HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be e…

Mitigation only
Fix from $1,950 2023-07-26
Sdm600 HIGH 7.2
CVE-2022-3685

A vulnerability exists in the SDM600 software. The software operates at a privilege level that is higher than the minimum level required. An attacker…

Fix: 1.3+
Fix from $1,950 2023-03-28
Sdm600 CRITICAL 9.1
CVE-2022-3686

A vulnerability exists in a SDM600 endpoint. An attacker could exploit this vulnerability by running multiple parallel requests, the SDM600 web servi…

Fix: 1.2.23000.291+
Fix from $2,300 2023-03-28
Sdm600 HIGH 7.5
CVE-2022-3683

A vulnerability exists in the SDM600 API web services authorization validation implementation. An attacker who successfully exploits the vulnerabili…

Fix: 1.2.23000.291+
Fix from $1,950 2023-03-28
Sdm600 HIGH 7.5
CVE-2022-3684

A vulnerability exists in a SDM600 endpoint. An attacker could exploit this vulnerability by running multiple parallel requests, the SDM600 web servi…

Fix: 1.2.23000.291+
Fix from $1,950 2023-03-28
Sdm600 HIGH 8.8
CVE-2022-3682

A vulnerability exists in the SDM600 file permission validation. An attacker could exploit the vulnerability by gaining access to the system and upl…

Fix: 1.3.0.1339+
Fix from $1,950 2023-03-28
Sys600 Firmware HIGH 7.5
CVE-2022-3353

A vulnerability exists in the IEC 61850 communication stack that affects multiple Hitachi Energy products.  An attacker could exploit the vulnerabil…

Fix: 8.3.3+
Fix from $1,950 2023-02-21
Lumada Asset Performance Management HIGH 7.1
CVE-2022-2155

A vulnerability exists in the affected versions of Lumada APM’s User Asset Group feature due to a flaw in access control mechanism implementation on …

Fix: 6.4.0.1+
Fix from $1,950 2023-01-12
Foxman Un CRITICAL 9.8
CVE-2022-3927

The affected products store both public and private key that are used to sign and protect Custom Parameter Set (CPS) file from modification. An attac…

Mitigation only
Fix from $2,300 2023-01-05
Foxman Un CRITICAL 9.8
CVE-2022-3929

Communication between the client and the server application of the affected products is partially done using CORBA (Common Object Request Broker Arch…

Mitigation only
Fix from $2,300 2023-01-05
Foxman Un MEDIUM 5.5
CVE-2022-3928

Hardcoded credential is found in affected products' message queue. An attacker that manages to exploit this vulnerability will be able to access data…

Mitigation only
Fix from $1,600 2023-01-05
Foxman Un CRITICAL 9.8
CVE-2021-40342

In the DES implementation, the affected product versions use a default key for encryption. Successful exploitation allows an attacker to obtain sensi…

Mitigation only
Fix from $2,300 2023-01-05
Foxman Un MEDIUM 5.5
CVE-2021-40341

DES cipher, which has inadequate encryption strength, is used Hitachi Energy FOXMAN-UN to encrypt user credentials used to access the Network Element…

Mitigation only
Fix from $1,600 2023-01-05
650connectivitypackage MEDIUM 5.5
CVE-2022-2513

A vulnerability exists in the Intelligent Electronic Device (IED) Connectivity Package (ConnPack) credential storage function in Hitachi Energy’s PCM…

Fix: after 2.11
Fix from $1,600 2022-11-22
Microscada Pro Sys600 HIGH 7.8
CVE-2022-3388

An input validation vulnerability exists in the Monitor Pro interface of MicroSCADA Pro and MicroSCADA X SYS600. An authenticated user can launch an …

Mitigation only
Fix from $1,950 2022-11-21
Microscada X Sys600 HIGH 7.5
CVE-2022-29492

Improper Input Validation vulnerability in the handling of a malformed IEC 104 TCP packet in the Hitachi Energy MicroSCADA X SYS600, MicroSCADA Pro S…

Fix: 10.4+
Fix from $1,950 2022-09-14
Microscada X Sys600 HIGH 7.5
CVE-2022-29922

Improper Input Validation vulnerability in the handling of a specially crafted IEC 61850 packet with a valid data item but with incorrect data type i…

Fix: 10.4+
Fix from $1,950 2022-09-14
Microscada X Sys600 HIGH 7.5
CVE-2022-2277

Improper Input Validation vulnerability exists in the Hitachi Energy MicroSCADA X SYS600's ICCP stack during the ICCP communication establishment cau…

Fix: after 10.3.1
Fix from $1,950 2022-09-14
Microscada X Sys600 HIGH 8.8
CVE-2022-29490

Improper Authorization vulnerability exists in the Workplace X WebUI of the Hitachi Energy MicroSCADA X SYS600 allows an authenticated user to execut…

Fix: after 10.3.1
Fix from $1,950 2022-09-12
Modular Switchgear Monitoring Firmware HIGH 8.8
CVE-2021-40335

A vulnerability exists in the HTTP web interface where the web interface does not sufficiently verify if a well-formed, valid, consistent request was…

Fix: after 2.2.0
Fix from $1,950 2022-07-25
Modular Switchgear Monitoring Firmware HIGH 8.8
CVE-2021-40336

A vulnerability exists in the http web interface where the web interface does not validate data in an HTTP header. This causes a possible HTTP respon…

Fix: after 2.2.0
Fix from $1,950 2022-07-25
Txpert Hub Coretec 4 Firmware MEDIUM 6.7
CVE-2021-35530

A vulnerability in the application authentication and authorization mechanism in Hitachi Energy's TXpert Hub CoreTec 4, that depends on a token valid…

Mitigation only
Fix from $1,600 2022-06-07
Txpert Hub Coretec 4 Firmware MEDIUM 6.7
CVE-2021-35531

Improper Input Validation vulnerability in a particular configuration setting field of Hitachi Energy TXpert Hub CoreTec 4 product, allows an attacke…

Mitigation only
Fix from $1,600 2022-06-07
Txpert Hub Coretec 4 Firmware MEDIUM 6.7
CVE-2021-35532

A vulnerability exists in the file upload validation part of Hitachi Energy TXpert Hub CoreTec 4 product. The vulnerability allows an attacker or mal…

Mitigation only
Fix from $1,600 2022-06-07
Ellipse Enterprise Asset Management MEDIUM 6.1
CVE-2021-27414

An attacker could trick a user of Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to and including 9.0.25 into visit…

Fix: 9.0.23+
Fix from $1,600 2022-03-11
Ellipse Enterprise Asset Management MEDIUM 5.4
CVE-2021-27416

An attacker could exploit this vulnerability in Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to and including 9.0…

Fix: 9.0.26+
Fix from $1,600 2022-03-11
Fox615 Firmware HIGH 7.5
CVE-2021-40334

Missing Handler vulnerability in the proprietary management protocol (port TCP 5558) of Hitachi Energy FOX61x, XCM20 allows an attacker that exploits…

Mitigation only
Fix from $1,950 2021-12-02