Vulnerability index

Browse CVEs

159 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Evlink City Evc1s22p4 Firmware CRITICAL 9.8
CVE-2021-22730

A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking…

Mitigation only
Fix from $2,300 2021-07-21
Evlink City Evc1s22p4 Firmware HIGH 8.1
CVE-2021-22726

A CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Pa…

Mitigation only
Fix from $1,950 2021-07-21
Evlink City Evc1s22p4 Firmware HIGH 7.2
CVE-2021-22708

A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0…

Mitigation only
Fix from $1,950 2021-07-21
Evlink City Evc1s22p4 Firmware MEDIUM 6.5
CVE-2021-22728

A CWE-200: Information Exposure vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / …

Mitigation only
Fix from $1,600 2021-07-21
Evlink City Evc1s22p4 Firmware MEDIUM 6.1
CVE-2021-22706

A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in EVlink City (EVC1S22P4 / EVC1S…

Mitigation only
Fix from $1,600 2021-07-21
Evlink City Evc1s22p4 Firmware MEDIUM 6.1
CVE-2021-22723

A CWE-79: Improper Neutralization of Input During Web Page Generation (Cross-siteScripting) through Cross-Site Request Forgery (CSRF) vulnerability e…

Mitigation only
Fix from $1,600 2021-07-21
Evlink City Evc1s22p4 Firmware MEDIUM 5.4
CVE-2021-22722

A CWE-79: Improper Neutralization of Input During Web Page Generation ('Stored Cross-site Scripting') vulnerability exists in EVlink City (EVC1S22P4 …

Mitigation only
Fix from $1,600 2021-07-21
Evlink City Evc1s22p4 Firmware MEDIUM 5.3
CVE-2021-22721

A CWE-200: Information Exposure vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / …

Mitigation only
Fix from $1,600 2021-07-21
Powerlogic Egx100 Firmware CRITICAL 9.8
CVE-2021-22765

A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that co…

Mitigation only
Fix from $2,300 2021-06-11
Powerlogic Egx100 Firmware CRITICAL 9.8
CVE-2021-22767

A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that co…

Mitigation only
Fix from $2,300 2021-06-11
Powerlogic Egx100 Firmware CRITICAL 9.8
CVE-2021-22768

A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that co…

Mitigation only
Fix from $2,300 2021-06-11
Powerlogic Egx100 Firmware HIGH 7.5
CVE-2021-22766

A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that co…

Mitigation only
Fix from $1,950 2021-06-11
Modicon X80 Bmxnor0200h Rtu Firmware MEDIUM 5.3
CVE-2021-22749

A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Modicon X80 BMXNOR0200H RTU SV1.70 IR22 and prior that …

Mitigation only
Fix from $1,600 2021-06-11
Ecostruxure Control Expert HIGH 8.6
CVE-2020-7560

A CWE-123: Write-what-where Condition vulnerability exists in EcoStruxure™ Control Expert (all versions) and Unity Pro (former name of EcoStruxure™ C…

Mitigation only
Fix from $1,950 2020-12-11
Modicon M221 Firmware MEDIUM 5.5
CVE-2020-28214

A CWE-760: Use of a One-Way Hash with a Predictable Salt vulnerability exists in Modicon M221 (all references, all versions), that could allow an att…

Mitigation only
Fix from $1,600 2020-12-11
Ecostruxure Energy Expert HIGH 8.8
CVE-2020-7547

A CWE-284: Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notifica…

Mitigation only
Fix from $1,950 2020-12-01
Ecostruxure Energy Expert HIGH 7.2
CVE-2020-7545

A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notificat…

Mitigation only
Fix from $1,950 2020-12-01
Ecostruxure Energy Expert MEDIUM 5.4
CVE-2020-7546

A CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SC…

Mitigation only
Fix from $1,600 2020-12-01
Modicon M221 Firmware HIGH 7.3
CVE-2020-7566

A CWE-334: Small Space of Random Values vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to break th…

Mitigation only
Fix from $1,950 2020-11-19
Modicon M221 Firmware MEDIUM 5.7
CVE-2020-7567

A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to …

Mitigation only
Fix from $1,600 2020-11-19
Modicon M221 Firmware HIGH 7.3
CVE-2020-7565

A CWE-326: Inadequate Encryption Strength vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to break …

Mitigation only
Fix from $1,950 2020-11-19
Modicon Tsxety4103 Firmware HIGH 8.8
CVE-2020-7563

A CWE-787: Out-of-bounds Write vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Co…

Mitigation only
Fix from $1,950 2020-11-18
Modicon Tsxety4103 Firmware HIGH 8.8
CVE-2020-7564

A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in the Web Server on Modicon M340, Modicon Qua…

Mitigation only
Fix from $1,950 2020-11-18
Modicon Tsxety4103 Firmware HIGH 8.1
CVE-2020-7562

A CWE-125: Out-of-Bounds Read vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Com…

Mitigation only
Fix from $1,950 2020-11-18
Os Loader CRITICAL 9.8
CVE-2020-7498

A CWE-798: Use of Hard-coded Credentials vulnerability exists in the Unity Loader and OS Loader Software (all versions). The fixed credentials are us…

Mitigation only
Fix from $2,300 2020-06-16
Ecostruxure Machine Expert CRITICAL 9.8
CVE-2020-7487

A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists which could allow the attacker to execute malicious code on the Modico…

Mitigation only
Fix from $2,300 2020-04-22
Bmx P34x Firmware HIGH 7.5
CVE-2019-6859

A CWE-798: Use of Hardcoded Credentials vulnerability exists in Modicon Controllers (All versions of the following CPUs and Communication Module prod…

Mitigation only
Fix from $1,950 2020-04-22
Ecostruxure Machine Expert HIGH 7.5
CVE-2020-7488

A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists which could leak sensitive information transmitted between the softwa…

Mitigation only
Fix from $1,950 2020-04-22
Tricon Tcm 4351 Firmware HIGH 7.5
CVE-2020-7486

**VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause TCM modules to reset when under high network load in TCM v10.4.x and in system v1…

Mitigation only
Fix from $1,950 2020-04-16
Andover Continuum 9680 Firmware CRITICAL 9.8
CVE-2020-7480

A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists in Andover Continuum (All versions), which could cause files…

Mitigation only
Fix from $2,300 2020-03-23