Vulnerability index

Browse CVEs

689 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Easergy Studio HIGH 7.8
CVE-2024-2747

CWE-428: Unquoted search path or element vulnerability exists in Easergy Studio, which could cause privilege escalation when a valid user replaces a …

Fix: after 9.3.3
Fix from $1,950 2024-06-12
Ecostruxure It Gateway HIGH 7.8
CVE-2024-0865

CWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege escalation when logged in as a non-administrative user.

Fix: 1.21.0+
Fix from $1,950 2024-06-12
Sage Rtu Firmware HIGH 7.5
CVE-2024-5560

CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service of the device’s web interface when an attacker sends a specially …

Patch available
Fix from $1,950 2024-06-12
Spacelogic As B Firmware MEDIUM 6.4
CVE-2024-5558

CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists that could cause escalation of privileges when an attacker abuses a l…

Fix: 6.0.1+
Fix from $1,600 2024-06-12
Sage Rtu Firmware HIGH 8.8
CVE-2024-37038

CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perfo…

Patch available
Fix from $1,950 2024-06-12
Sage Rtu Firmware HIGH 8.1
CVE-2024-37040

CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability exists that could allow a user with access to the devic…

Patch available
Fix from $1,950 2024-06-12
Sage Rtu Firmware HIGH 7.5
CVE-2024-37039

CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP…

Patch available
Fix from $1,950 2024-06-12
Sage Rtu Firmware CRITICAL 9.8
CVE-2024-37036

CWE-787: Out-of-bounds Write vulnerability exists that could result in an authentication bypass when sending a malformed POST request and particular …

No fix yet
Fix from $2,300 2024-06-12
Sage Rtu Firmware HIGH 8.1
CVE-2024-37037

CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability exists that could allow an authenticated user wi…

Patch available
Fix from $1,950 2024-06-12
Evlink Home Firmware MEDIUM 6.5
CVE-2024-5313

CWE-668: Exposure of the Resource Wrong Sphere vulnerability exists that exposes a SSH interface over the product network interface. This does not al…

Mitigation only
Fix from $1,600 2024-06-12
Modicon M340 Firmware MEDIUM 6.5
CVE-2024-5056

CWE-552: Files or Directories Accessible to External Parties vulnerability exists which may prevent user to update the device firmware and prevent pr…

Mitigation only
Fix from $1,600 2024-06-12
Modicon M340 Bmxp341000 Firmware HIGH 8.1
CVE-2023-6408

CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a denial of s…

Fix: 3.60+
Fix from $1,950 2024-02-14
Ecostruxure Control Expert HIGH 7.7
CVE-2023-6409

CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to a project file protected with application passwor…

Fix: 16.0 / 2023+
Fix from $1,950 2024-02-14
Ecostruxure Control Expert HIGH 7.1
CVE-2023-27975

CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized access to the project file in EcoStruxure Control Ex…

Fix: 16.0 / 2023+
Fix from $1,950 2024-02-14
Easergy Studio HIGH 7.8
CVE-2023-7032

A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker logged in with a user level account to gain higher pri…

Fix: after 9.3.5
Fix from $1,950 2024-01-09
Easy Ups Online Monitoring Software HIGH 7.1
CVE-2023-6407

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file deletio…

Fix: 2.6-ga-01-23248+
Fix from $1,950 2023-12-14
Eb450 Firmware MEDIUM 6.1
CVE-2023-5629

A CWE-601:URL Redirection to Untrusted Site (‘Open Redirect’) vulnerability exists that could cause disclosure of information through phishing attemp…

No fix yet
Fix from $1,600 2023-12-14
Ecostruxure Power Monitoring Expert MEDIUM 6.1
CVE-2023-5986

A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting att…

Mitigation only
Fix from $1,600 2023-11-15
Ecostruxure Power Monitoring Expert MEDIUM 6.1
CVE-2023-5987

A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability that could cause a vulnerability leading to…

Patch available
Fix from $1,600 2023-11-15
Galaxy Vl Firmware MEDIUM 5.3
CVE-2023-6032

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause a file system enumerat…

Mitigation only
Fix from $1,600 2023-11-15
Ecostruxure Power Monitoring Expert CRITICAL 9.8
CVE-2023-5391

A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by se…

No fix yet
Fix from $2,300 2023-10-04
Spacelogic C Bus Toolkit CRITICAL 9.8
CVE-2023-5399EPSS 39%

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause tampering of files on …

Fix: 1.16.4+
Fix from $2,300 2023-10-04
C Bus Toolkit CRITICAL 9.8
CVE-2023-5402

A CWE-269: Improper Privilege Management vulnerability exists that could cause a remote code execution when the transfer command is used over the net…

Fix: after 1.16.3
Fix from $2,300 2023-10-04
Interactive Graphical Scada System HIGH 7.8
CVE-2023-4516

A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allow a local attacker to change u…

Fix: after 16.0.0.23211
Fix from $1,950 2023-09-14
Pro Face Gp Pro Ex MEDIUM 5.3
CVE-2023-3953

A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause memory corruption when an au…

Fix: 4.09.500+
Fix from $1,600 2023-08-09
Accutech Manager HIGH 7.8
CVE-2023-29414

A CWE-120: Buffer Copy without Checking Size of Input (Classic Buffer Overflow) vulnerability exists that could cause user privilege escalation if a …

Fix: after 2.7
Fix from $1,950 2023-07-12
Struxureware Data Center Expert HIGH 7.2
CVE-2023-37199

A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on…

Fix: after 7.9.3
Fix from $1,950 2023-07-12
Struxureware Data Center Expert HIGH 8.8
CVE-2023-37196

A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a …

Fix: after 7.9.3
Fix from $1,950 2023-07-12
Struxureware Data Center Expert HIGH 8.8
CVE-2023-37197

A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a …

Fix: after 7.9.3
Fix from $1,950 2023-07-12
Struxureware Data Center Expert HIGH 7.2
CVE-2023-37198

A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on…

Fix: after 7.9.3
Fix from $1,950 2023-07-12