Vulnerability index

Browse CVEs

689 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Andover Continuum 9680 Firmware CRITICAL 9.8
CVE-2020-7480

A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists in Andover Continuum (All versions), which could cause files…

Mitigation only
Fix from $2,300 2020-03-23
Ulti Zigbee Installation Toolkit HIGH 7.8
CVE-2020-7476

A CWE-426: Untrusted Search Path vulnerability exists in ZigBee Installation Kit (Versions prior to 1.0.1), which could cause execution of malicious …

Fix: 1.0.1+
Fix from $1,950 2020-03-23
Interactive Graphical Scada System HIGH 7.8
CVE-2020-7479

A CWE-306: Missing Authentication for Critical Function vulnerability exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which cou…

Fix: 14.0.0.20009+
Fix from $1,950 2020-03-23
140noe77101 Firmware HIGH 7.5
CVE-2020-7477

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Quantum Ethernet Network module 140NOE771x1 (Versions 7.0 and…

Fix: after 7.0
Fix from $1,950 2020-03-23
Interactive Graphical Scada System HIGH 7.5
CVE-2020-7478

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which cou…

Fix: 14.0.0.20009+
Fix from $1,950 2020-03-23
Andover Continuum 9680 Firmware MEDIUM 6.1
CVE-2020-7481

A CWE-79:Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists Andover Continuum (All versions), …

Mitigation only
Fix from $1,600 2020-03-23
Andover Continuum 9680 Firmware MEDIUM 6.1
CVE-2020-7482

A CWE-79:Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists Andover Continuum (All versions), …

Mitigation only
Fix from $1,600 2020-03-23
Ecostruxure Control Expert CRITICAL 9.8
CVE-2020-7475

A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability exists in…

Fix: 3.10 / 3.20+
Fix from $2,300 2020-03-23
Pmepxm0100 Prosoft Configurator HIGH 7.8
CVE-2020-7474

A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProSoft Configurator (v1.002 and prior), for the PMEPXM0100 (H) module, which cou…

Fix: after 1.002
Fix from $1,950 2020-03-23
Msx Configurator HIGH 7.8
CVE-2019-6858

A CWE-427:Uncontrolled Search Path Element vulnerability exists in MSX Configurator (Software Version prior to V1.0.8.1), which could cause privilege…

Fix: 1.0.8.1+
Fix from $1,950 2020-01-22
Clearscada HIGH 7.8
CVE-2019-6854

A CWE-287: Improper Authentication vulnerability exists in a folder within EcoStruxure Geo SCADA Expert (ClearSCADA) -with initial releases before 1 …

Mitigation only
Fix from $1,950 2020-01-06
Modicon M580 Firmware HIGH 7.5
CVE-2019-6856

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium …

Fix: 2.80 / 3.01+
Fix from $1,950 2020-01-06
Modicon M580 Firmware HIGH 7.5
CVE-2019-6857

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium …

Fix: 2.80 / 3.01+
Fix from $1,950 2020-01-06
Ecostruxure Control Expert HIGH 7.3
CVE-2019-6855

Incorrect Authorization vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M3…

Fix: 3.10 / 14.1+
Fix from $1,950 2020-01-06
Modicon M580 Firmware HIGH 7.5
CVE-2018-7794

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium …

Fix: 2.80 / 3.01+
Fix from $1,950 2020-01-06
Bmx P34x Firmware HIGH 7.5
CVE-2019-6852

A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communicati…

Mitigation only
Fix from $1,950 2019-11-20
Andover Continuum 9680 Firmware MEDIUM 6.1
CVE-2019-6853

A CWE-79: Failure to Preserve Web Page Structure vulnerability exists in Andover Continuum (models 9680, 5740 and 5720, bCX4040, bCX9640, 9900, 9940,…

Mitigation only
Fix from $1,600 2019-11-20
Modicon M580 Firmware HIGH 8.6
CVE-2019-6848EPSS 33%

A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 CPU (BMEx58*) and Modicon M580 communication module (BMEN…

Mitigation only
Fix from $1,950 2019-10-29
Modicon M580 Firmware HIGH 7.5
CVE-2019-6845

A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all…

Mitigation only
Fix from $1,950 2019-10-29
Modicon M580 Firmware HIGH 7.5
CVE-2019-6849

A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure …

Mitigation only
Fix from $1,950 2019-10-29
Modicon M580 Firmware HIGH 7.5
CVE-2019-6850

A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure …

Mitigation only
Fix from $1,950 2019-10-29
Modicon M580 Firmware HIGH 7.5
CVE-2019-6851EPSS 30%

A CWE-538: File and Directory Information Exposure vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmwar…

Mitigation only
Fix from $1,950 2019-10-29
Modicon M580 Firmware MEDIUM 6.5
CVE-2019-6846

A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all…

Mitigation only
Fix from $1,600 2019-10-29
Meg6501 0001 Firmware CRITICAL 9.8
CVE-2019-6840

A Format String: CWE-134 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG626…

Fix: 1.3.7+
Fix from $2,300 2019-09-17
Meg6501 0001 Firmware CRITICAL 9.1
CVE-2019-6837

A Server-Side Request Forgery (SSRF): CWE-918 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KN…

Fix: 1.3.7+
Fix from $2,300 2019-09-17
Meg6501 0001 Firmware HIGH 8.8
CVE-2019-6839

A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 …

Fix: 1.3.7+
Fix from $1,950 2019-09-17
Bmxnor0200h Firmware HIGH 8.6
CVE-2019-6831

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in BMXNOR0200H Ethernet / Serial RTU module (all firmware versio…

Mitigation only
Fix from $1,950 2019-09-17
Wiser For Knx Firmware HIGH 8.3
CVE-2019-6832

A CWE-287: Authentication vulnerability exists in spaceLYnk (all versions before 2.4.0) and Wiser for KNX (all versions before 2.4.0 - formerly known…

Fix: 2.4.0+
Fix from $1,950 2019-09-17
Somachine Hvac HIGH 7.8
CVE-2019-6826

A CWE-426: Untrusted Search Path vulnerability exists in SoMachine HVAC v2.4.1 and earlier versions, which could cause arbitrary code execution on th…

Fix: after 2.4.1
Fix from $1,950 2019-09-17
Modicon M340 Firmware HIGH 7.5
CVE-2019-6813

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in BMXNOR0200H Ethernet / Serial RTU module (all firmware versio…

Mitigation only
Fix from $1,950 2019-09-17