Vulnerability index

Browse CVEs

689 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Interactive Graphical Scada System HIGH 7.8
CVE-2020-7558

A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when mali…

Fix: after 14.0.0.20247
Fix from $1,950 2020-11-19
Ecostruxure Control Expert HIGH 7.5
CVE-2020-7538

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) …

Patch available
Fix from $1,950 2020-11-19
Ecostruxure Control Expert HIGH 7.5
CVE-2020-7559

A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in PLC Simulator on EcoStruxureª Control Exper…

Patch available
Fix from $1,950 2020-11-19
Modicon M221 Firmware HIGH 7.3
CVE-2020-7565

A CWE-326: Inadequate Encryption Strength vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to break …

Mitigation only
Fix from $1,950 2020-11-19
Ecostruxure Control Expert CRITICAL 9.8
CVE-2020-28212

A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity …

Patch available
Fix from $2,300 2020-11-19
Ecostruxure Control Expert HIGH 8.8
CVE-2020-28213

A CWE-494: Download of Code Without Integrity Check vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all version…

Patch available
Fix from $1,950 2020-11-19
Ecostruxure Control Expert HIGH 7.8
CVE-2020-28211

A CWE-863: Incorrect Authorization vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cau…

Patch available
Fix from $1,950 2020-11-19
Enterprise Server Installer HIGH 7.0
CVE-2020-28209

A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installer V1.9 - V3.1 and Enterprise …

Fix: after 3.1
Fix from $1,950 2020-11-19
Ecostruxure Building Operation MEDIUM 6.1
CVE-2020-28210

A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability exists in EcoStruxure Building Operation We…

Fix: after 3.1
Fix from $1,600 2020-11-19
Modicon Tsxety4103 Firmware HIGH 8.8
CVE-2020-7563

A CWE-787: Out-of-bounds Write vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Co…

Mitigation only
Fix from $1,950 2020-11-18
Modicon Tsxety4103 Firmware HIGH 8.8
CVE-2020-7564

A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in the Web Server on Modicon M340, Modicon Qua…

Mitigation only
Fix from $1,950 2020-11-18
Modicon Tsxety4103 Firmware HIGH 8.1
CVE-2020-7562

A CWE-125: Out-of-Bounds Read vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Com…

Mitigation only
Fix from $1,950 2020-11-18
Scadapack 7x Remote Connect HIGH 8.8
CVE-2020-7530

A CWE-285 Improper Authorization vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows improper access to executabl…

Fix: after 3.6.3.574
Fix from $1,950 2020-09-16
Scadapack 7x Remote Connect HIGH 7.8
CVE-2020-7528

A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which could allow arbitrary co…

Fix: after 3.6.3.574
Fix from $1,950 2020-09-16
Scadapack 7x Remote Connect HIGH 7.8
CVE-2020-7531

A CWE-284 Improper Access Control vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place execut…

Fix: after 3.6.3.574
Fix from $1,950 2020-09-16
Scadapack X70 Security Administrator HIGH 7.8
CVE-2020-7532

A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack x70 Security Administrator (V1.2.0 and prior) which could allow arbitra…

Fix: after 1.2.0
Fix from $1,950 2020-09-16
Scadapack 7x Remote Connect MEDIUM 5.5
CVE-2020-7529

A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Transversal') vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3…

Fix: after 3.6.3.574
Fix from $1,600 2020-09-16
Apc Easy Ups Online Software CRITICAL 9.8
CVE-2020-7521

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line Software (V2.…

Fix: after 2.0
Fix from $2,300 2020-08-31
Apc Easy Ups Online Software CRITICAL 9.8
CVE-2020-7522

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line Software (V2.…

Fix: after 2.0
Fix from $2,300 2020-08-31
Modbus Driver Suite HIGH 7.8
CVE-2020-7523

Improper Privilege Management vulnerability exists in Schneider Electric Modbus Serial Driver (see security notification for versions) which could ca…

Fix: 2.20_ie_30 / 3.20_ie_30+
Fix from $1,950 2020-08-31
Somove HIGH 7.8
CVE-2020-7527

Incorrect Default Permission vulnerability exists in SoMove (V2.8.1) and prior which could cause elevation of privilege and provide full access contr…

Fix: after 2.8.1
Fix from $1,950 2020-08-31
Modicon M218 Firmware HIGH 7.5
CVE-2020-7524

Out-of-bounds Write vulnerability exists in Modicon M218 Logic Controller (V5.0.0.7 and prior) which could cause Denial of Service when sending speci…

Fix: after 5.0.0.7
Fix from $1,950 2020-08-31
Spacelynk Firmware HIGH 7.5
CVE-2020-7525

Improper Restriction of Excessive Authentication Attempts vulnerability exists in all hardware versions of spaceLYnk and Wiser for KNX (formerly home…

Fix: 2.5.1+
Fix from $1,950 2020-08-31
Easergy Builder HIGH 7.8
CVE-2020-7514

A CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an …

Fix: after 1.4.7.2
Fix from $1,950 2020-07-23
Easergy Builder HIGH 7.8
CVE-2020-7515

A CWE-321: Use of hard-coded cryptographic key stored in cleartext vulnerability exists in Easergy Builder V1.4.7.2 and prior which could allow an at…

Fix: after 1.4.7.2
Fix from $1,950 2020-07-23
Easergy Builder HIGH 7.8
CVE-2020-7516

A CWE-316: Cleartext Storage of Sensitive Information in Memory vulnerability exists in Easergy Builder V1.4.7.2 and prior which could allow an attac…

Fix: after 1.4.7.2
Fix from $1,950 2020-07-23
Tricon Tcm 4351 Firmware HIGH 7.5
CVE-2020-7491

**VERSION NOT SUPPORTED WHEN ASSIGNED** A legacy debug port account in TCMs installed in Tricon system versions 10.2.0 through 10.5.3 is visible on t…

Fix: 10.5.4+
Fix from $1,950 2020-07-23
Easergy Builder HIGH 7.5
CVE-2020-7518

A CWE-20: Improper input validation vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to modify proje…

Fix: after 1.4.7.2
Fix from $1,950 2020-07-23
Easergy Builder HIGH 7.5
CVE-2020-7519

A CWE-521: Weak Password Requirements vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to compromise…

Fix: after 1.4.7.2
Fix from $1,950 2020-07-23
Easergy Builder MEDIUM 5.5
CVE-2020-7517

A CWE-312: Cleartext Storage of Sensitive Information vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attack…

Fix: after 1.4.7.2
Fix from $1,600 2020-07-23