Vulnerability index

Browse CVEs

689 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mcsesp083f23g0 Firmware CRITICAL 9.8
CVE-2021-22731

Weak Password Recovery Mechanism for Forgotten Password vulnerability exists on Modicon Managed Switch MCSESM* and MCSESP* V8.21 and prior which coul…

Fix: 8.22+
Fix from $2,300 2021-05-26
Vijeo Designer HIGH 7.8
CVE-2021-22705

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service or unauthorized acces…

Fix: 2.0 / 6.2.11+
Fix from $1,950 2021-05-26
Spacelynk Firmware HIGH 7.8
CVE-2021-22732

Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a code execution issue…

Fix: after 2.6.0
Fix from $1,950 2021-05-26
Spacelynk Firmware HIGH 7.8
CVE-2021-22733

Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause shell access when unau…

Fix: after 2.6.0
Fix from $1,950 2021-05-26
Modicon M241 Firmware HIGH 7.5
CVE-2021-22699

Improper Input Validation vulnerability exists in Modicon M241/M251 logic controllers firmware prior to V5.1.9.1 that could cause denial of service w…

Fix: 5.1.9.1+
Fix from $1,950 2021-05-26
C Bus Toolkit HIGH 8.8
CVE-2021-22717EPSS 39%

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) th…

Fix: after 1.15.7
Fix from $1,950 2021-04-13
C Bus Toolkit HIGH 8.8
CVE-2021-22719EPSS 41%

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) th…

Fix: after 1.15.7
Fix from $1,950 2021-04-13
C Bus Toolkit HIGH 7.8
CVE-2021-22716

A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could allow remote code execution when an unprivileged use…

Fix: after 1.15.7
Fix from $1,950 2021-04-13
C Bus Toolkit HIGH 7.8
CVE-2021-22718EPSS 27%

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) th…

Fix: after 1.15.7
Fix from $1,950 2021-04-13
C Bus Toolkit HIGH 7.2
CVE-2021-22720EPSS 31%

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) th…

Fix: after 1.15.7
Fix from $1,950 2021-04-13
Powerlogic Ion7400 Firmware CRITICAL 9.8
CVE-2021-22714

A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION7400, PM8000 and ION9000 (All…

Fix: 3.0.0+
Fix from $2,300 2021-03-11
Interactive Graphical Scada System HIGH 7.8
CVE-2021-22709

A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) D…

Fix: after 15.0.0.21041
Fix from $1,950 2021-03-11
Interactive Graphical Scada System HIGH 7.8
CVE-2021-22710

A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) D…

Fix: after 15.0.0.21041
Fix from $1,950 2021-03-11
Interactive Graphical Scada System HIGH 7.8
CVE-2021-22711

A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) D…

Fix: after 15.0.0.21041
Fix from $1,950 2021-03-11
Interactive Graphical Scada System HIGH 7.8
CVE-2021-22712

A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) D…

Fix: after 15.0.0.21041
Fix from $1,950 2021-03-11
Powerlogic Ion8650 Firmware HIGH 7.5
CVE-2021-22713

A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION8650, ION8800, ION7650, ION77…

Fix: 4.40.1 / 372+
Fix from $1,950 2021-03-11
Powerlogic Ion7400 Firmware HIGH 7.5
CVE-2021-22702

A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION7700/73xx, ION83xx/84xx/85xx/8600,…

Fix: 3.0.0+
Fix from $1,950 2021-02-19
Powerlogic Ion7400 Firmware HIGH 7.5
CVE-2021-22703

A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8…

Fix: 3.0.0+
Fix from $1,950 2021-02-19
Ecostruxure Power Build Rapsody HIGH 7.8
CVE-2021-22697

A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior)…

Fix: after 2.1.13
Fix from $1,950 2021-01-26
Ecostruxure Power Build Rapsody HIGH 7.8
CVE-2021-22698

A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior)…

Fix: after 2.1.13
Fix from $1,950 2021-01-26
Ecostruxure Operator Terminal Expert CRITICAL 9.8
CVE-2020-28221

A CWE-20: Improper Input Validation vulnerability exists in EcoStruxure™ Operator Terminal Expert and Pro-face BLUE (version details in the notificat…

Patch available
Fix from $2,300 2021-01-26
Modicon M340 Bmxp341000 Firmware CRITICAL 9.8
CVE-2020-7540

A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Mod…

Fix: 3.3 / 3.30+
Fix from $2,300 2020-12-11
Ecostruxure Control Expert HIGH 8.6
CVE-2020-7560

A CWE-123: Write-what-where Condition vulnerability exists in EcoStruxure™ Control Expert (all versions) and Unity Pro (former name of EcoStruxure™ C…

Mitigation only
Fix from $1,950 2020-12-11
Modicon M340 Bmxp341000 Firmware HIGH 7.5
CVE-2020-7535

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal' Vulnerability Type) vulnerability exists in the Web Server on…

Fix: 3.4 / 3.30+
Fix from $1,950 2020-12-11
Modicon M340 Bmxp341000 Firmware HIGH 7.5
CVE-2020-7536

A CWE-754:Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M340 CPUs (BMXP34* versions prior to V3.30) Modicon M3…

Fix: 3.4 / 3.30+
Fix from $1,950 2020-12-11
Modicon M580 Bmep584040 Firmware HIGH 7.5
CVE-2020-7537

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Legacy Controllers Modicon Quantu…

Fix: 3.20+
Fix from $1,950 2020-12-11
Modicon M340 Bmxp341000 Firmware HIGH 7.5
CVE-2020-7539

A CWE-754 Improper Check for Unusual or Exceptional Conditions vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum …

Fix: 3.3 / 3.30+
Fix from $1,950 2020-12-11
Modicon M580 Bmep584040 Firmware HIGH 7.5
CVE-2020-7542

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Legacy Controllers Modicon Quantu…

Fix: 3.20+
Fix from $1,950 2020-12-11
Modicon M580 Bmep584040 Firmware HIGH 7.5
CVE-2020-7543

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Legacy Controllers Modicon Quantu…

Fix: 3.20+
Fix from $1,950 2020-12-11
Modicon M340 Bmxp341000 Firmware MEDIUM 5.3
CVE-2020-7541

A CWE-425: Direct Request ('Forced Browsing') vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premi…

Fix: 3.3 / 3.30+
Fix from $1,600 2020-12-11