Vulnerability index

Browse CVEs

689 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ecostruxure Foxboro Dcs Control Core Services HIGH 7.8
CVE-2023-2569

A CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, elevation of privilege, and potentially kernel executio…

Mitigation only
Fix from $1,950 2023-06-14
Ecostruxure Foxboro Dcs Control Core Services HIGH 7.8
CVE-2023-2570

A CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service, and potentially kernel execution when a …

Mitigation only
Fix from $1,950 2023-06-14
Igss Dashboard HIGH 7.8
CVE-2023-3001EPSS 32%

A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload dat…

Fix: 16.0.0.23131+
Fix from $1,950 2023-06-14
Ecostruxure Operator Terminal Expert HIGH 7.8
CVE-2023-1049

A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause execution of malicious code when an unsuspi…

Fix: 3.3+
Fix from $1,950 2023-06-14
Powerlogic Ion9000 Firmware CRITICAL 9.8
CVE-2022-46680

A CWE-319: Cleartext transmission of sensitive information vulnerability exists that could cause disclosure of sensitive information, denial of servi…

Fix: 4.0.0+
Fix from $2,300 2023-05-22
Opc Factory Server MEDIUM 5.5
CVE-2023-2161

A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized read access to the file system wh…

Fix: 3.63+
Fix from $1,600 2023-05-16
Modicon M580 Firmware MEDIUM 6.5
CVE-2023-25620

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of service of the controller when a mali…

Fix: 3.51 / 4.10+
Fix from $1,600 2023-04-19
Modicon M580 Firmware HIGH 7.5
CVE-2023-25619

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause denial of service of the controller when commun…

Fix: 3.51 / 4.10+
Fix from $1,950 2023-04-19
Insighthome Firmware HIGH 8.8
CVE-2023-29410

A CWE-20: Improper Input Validation vulnerability exists that could allow an authenticated attacker to gain the same privilege as the application on …

Fix: 1.16+
Fix from $1,950 2023-04-18
Powerlogic Hdpm6000 Firmware CRITICAL 9.8
CVE-2023-28004

A CWE-129: Improper validation of an array index vulnerability exists where a specially crafted Ethernet request could result in denial of service or…

Fix: after 0.58.6
Fix from $2,300 2023-04-18
Apc Easy Ups Online Monitoring Software CRITICAL 9.8
CVE-2023-29411

A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to poten…

Fix: after 2.5-gs-01-22320
Fix from $2,300 2023-04-18
Apc Easy Ups Online Monitoring Software CRITICAL 9.8
CVE-2023-29412

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code …

Fix: after 2.5-gs-01-22320
Fix from $2,300 2023-04-18
Ecostruxure Power Monitoring Expert HIGH 8.8
CVE-2023-28003

A CWE-613: Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain unauthorized access over a hijacked session …

Fix: after 2022
Fix from $1,950 2023-04-18
Apc Easy Ups Online Monitoring Software HIGH 7.5
CVE-2023-29413

A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause Denial-of-Service when accessed by an unauthenticated u…

Fix: after 2.5-gs-01-22320
Fix from $1,950 2023-04-18
Struxureware Data Center Expert CRITICAL 9.8
CVE-2023-25549

A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows for remote code execution when using a parameter…

Fix: after 7.9.2
Fix from $2,300 2023-04-18
Struxureware Data Center Expert CRITICAL 9.8
CVE-2023-25550

A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows remote code execution via the “hostname” paramet…

Fix: after 7.9.2
Fix from $2,300 2023-04-18
Struxureware Data Center Expert HIGH 8.8
CVE-2023-25547

A CWE-863: Incorrect Authorization vulnerability exists that could allow remote code execution on upload and install packages when a hacker is using …

Fix: after 7.9.2
Fix from $1,950 2023-04-18
Struxureware Data Center Expert HIGH 8.1
CVE-2023-25552

A CWE-862: Missing Authorization vulnerability exists that could allow viewing of unauthorized content, changes or deleting of content, or performing…

Fix: after 7.9.2
Fix from $1,950 2023-04-18
Struxureware Data Center Expert HIGH 8.1
CVE-2023-25555

A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow a user tha…

Fix: after 7.9.2
Fix from $1,950 2023-04-18
Struxureware Data Center Expert HIGH 7.8
CVE-2023-25554

A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that allows a local privile…

Fix: after 7.9.2
Fix from $1,950 2023-04-18
Struxureware Data Center Expert MEDIUM 6.5
CVE-2023-25548

A CWE-863: Incorrect Authorization vulnerability exists that could allow access to device credentials on specific DCE endpoints not being properly se…

Fix: after 7.9.2
Fix from $1,600 2023-04-18
Struxureware Data Center Expert MEDIUM 6.1
CVE-2023-25551

A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists on a DCE file upload endpoint whe…

Fix: after 7.9.2
Fix from $1,600 2023-04-18
Struxureware Data Center Expert MEDIUM 6.1
CVE-2023-25553

A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists on a DCE endpoint through the log…

Fix: after 7.9.2
Fix from $1,600 2023-04-18
Netbotz 355 Firmware MEDIUM 6.5
CVE-2022-43378

A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause the user to be tricked into performing uninten…

Fix: after 4.7.0
Fix from $1,600 2023-04-18
Netbotz 355 Firmware HIGH 7.5
CVE-2022-43377

A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause account takeover when a brute force attack…

Fix: after 4.7.0
Fix from $1,950 2023-04-18
Easergy Builder Installer MEDIUM 6.7
CVE-2022-34755

A CWE-427 - Uncontrolled Search Path Element vulnerability exists that could allow an attacker with a local privileged account to place a specially c…

Fix: after 1.7.23
Fix from $1,600 2023-04-18
Netbotz 355 Firmware MEDIUM 6.1
CVE-2022-43376

A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause code and session…

Fix: after 4.7.0
Fix from $1,600 2023-04-18
Merten Instabus Tastermodul 1fach System M Firmware HIGH 8.8
CVE-2023-25556

A CWE-287: Improper Authentication vulnerability exists that could allow a device to be compromised when a key of less than seven digits is entered a…

Mitigation only
Fix from $1,950 2023-04-18
Ecostruxure Control Expert HIGH 8.8
CVE-2023-27976

A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause remote code execution when a valid user visits a malicious link…

No fix yet
Fix from $1,950 2023-04-18
Ecostruxure Control Expert MEDIUM 5.5
CVE-2023-1548

A CWE-269: Improper Privilege Management vulnerability exists that could cause a local user to perform a denial of service through the console server…

Mitigation only
Fix from $1,600 2023-04-18