Vulnerability index

Browse CVEs

689 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Custom Reports MEDIUM 5.3
CVE-2023-27983

A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow deletion of reports fr…

Fix: after 16.0.0.23040
Fix from $1,600 2023-03-21
Custom Reports MEDIUM 6.5
CVE-2023-27979

A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could allow the renaming of files in the IGSS …

Fix: after 16.0.0.23040
Fix from $1,600 2023-03-21
Custom Reports MEDIUM 5.3
CVE-2023-27977

A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause access to delete files in the IGSS…

Fix: after 16.0.0.23040
Fix from $1,600 2023-03-21
Custom Reports HIGH 8.8
CVE-2023-27984

A CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro to be executed, potentially leading to remote cod…

Fix: after 16.0.0.23040
Fix from $1,950 2023-03-21
Custom Reports HIGH 8.8
CVE-2023-27981

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Custom Reports that could cause a remote code execution…

Fix: after 16.0.0.23040
Fix from $1,950 2023-03-21
Custom Reports HIGH 7.8
CVE-2023-27978EPSS 6%

A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload dat…

Fix: after 16.0.0.23040
Fix from $1,950 2023-03-21
Custom Reports HIGH 8.8
CVE-2023-27982

A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause manipulation of dashboard files in…

Fix: after 16.0.0.23040
Fix from $1,950 2023-03-21
Custom Reports HIGH 8.8
CVE-2023-27980

A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow the creation of a mali…

Fix: after 16.0.0.23040
Fix from $1,950 2023-03-21
Clearscada MEDIUM 5.3
CVE-2023-0595

A CWE-117: Improper Output Neutralization for Logs vulnerability exists that could cause the misinterpretation of log files when malicious packets ar…

Mitigation only
Fix from $1,600 2023-02-24
Apc Easy Ups Online Monitoring Software HIGH 7.8
CVE-2022-42972

A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cause local privilege escalation when a local attack…

Fix: 2.5-ga / 2.5-gs+
Fix from $1,950 2023-02-01
Apc Easy Ups Online Monitoring Software HIGH 7.8
CVE-2022-42973

A CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause local privilege escalation when local attacker connects to the databas…

Fix: 2.5-ga / 2.5-gs+
Fix from $1,950 2023-02-01
Ecostruxure Power Commission HIGH 7.8
CVE-2022-4062

A CWE-285: Improper Authorization vulnerability exists that could cause unauthorized access to certain software functions when an attacker gets acces…

Fix: 2.26+
Fix from $1,950 2023-02-01
Interactive Graphical Scada System CRITICAL 9.8
CVE-2022-24324

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leading to remo…

Fix: 15.0.0.22074+
Fix from $2,300 2023-02-01
Interactive Graphical Scada System CRITICAL 9.8
CVE-2022-2329

A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to denial of service and potentia…

Fix: 15.0.0.22074+
Fix from $2,300 2023-02-01
Apc Easy Ups Online Monitoring Software CRITICAL 9.8
CVE-2022-42970

A CWE-306: Missing Authentication for Critical Function The software does not perform any authentication for functionality that requires a provable u…

Fix: 2.5-ga / 2.5-gs+
Fix from $2,300 2023-02-01
Apc Easy Ups Online Monitoring Software CRITICAL 9.8
CVE-2022-42971

A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution when the attacker uploads a ma…

Fix: 2.5-ga / 2.5-gs+
Fix from $2,300 2023-02-01
Modicon M340 Bmxp341000 Firmware HIGH 7.5
CVE-2021-22786

A CWE-200: Information Exposure vulnerability exists that could cause the exposure of sensitive information stored on the memory of the controller wh…

Fix: 3.40+
Fix from $1,950 2023-02-01
Ecostruxure Geo Scada Expert 2019 HIGH 7.5
CVE-2023-22610

A CWE-863: Incorrect Authorization vulnerability exists that could cause Denial of Service against the Geo SCADA server when specific messages are se…

Patch available
Fix from $1,950 2023-01-31
Ecostruxure Geo Scada Expert 2019 HIGH 7.5
CVE-2023-22611

A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information disclosure when specific mess…

Patch available
Fix from $1,950 2023-01-31
Ecostruxure Control Expert CRITICAL 9.8
CVE-2022-45789

A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller…

Fix: after 2020
Fix from $2,300 2023-01-31
Interactive Graphical Scada System CRITICAL 9.8
CVE-2022-32529

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to rem…

Fix: after 15.0.0.22170
Fix from $2,300 2023-01-30
Interactive Graphical Scada System CRITICAL 9.1
CVE-2022-32528

A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause access to manipulate and read specific files in the IGS…

Fix: after 15.0.0.22170
Fix from $2,300 2023-01-30
Ecostruxure Cybersecurity Admin Expert HIGH 8.3
CVE-2022-32748

A CWE-295: Improper Certificate Validation vulnerability exists that could cause the CAE software to give wrong data to end users when using CAE to c…

Fix: 2.4+
Fix from $1,950 2023-01-30
Ecostruxure Cybersecurity Admin Expert HIGH 8.1
CVE-2022-32747

A CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause legitimate users to be locked out of devices or facilitate backdoo…

Fix: 2.4+
Fix from $1,950 2023-01-30
5500ac2 Firmware CRITICAL 9.8
CVE-2022-32514

A CWE-287: Improper Authentication vulnerability exists that could allow an attacker to gain control of the device when logging into a web page. Affe…

Fix: 1.11.0+
Fix from $2,300 2023-01-30
Conext Combox Firmware CRITICAL 9.8
CVE-2022-32515

A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause brute force attacks to take over the admin…

Mitigation only
Fix from $2,300 2023-01-30
Data Center Expert CRITICAL 9.8
CVE-2022-32518

A CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in unwanted access to a DCE instance when performed over a net…

Fix: 7.9.0+
Fix from $2,300 2023-01-30
Data Center Expert CRITICAL 9.8
CVE-2022-32519

A CWE-257: Storing Passwords in a Recoverable Format vulnerability exists that could result in unwanted access to a DCE instance when performed over …

Fix: 7.9.0+
Fix from $2,300 2023-01-30
Data Center Expert CRITICAL 9.8
CVE-2022-32520

A CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in unwanted access to a DCE instance when performed over a net…

Fix: 7.9.0+
Fix from $2,300 2023-01-30
Interactive Graphical Scada System CRITICAL 9.8
CVE-2022-32522

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to rem…

Fix: after 15.0.0.22170
Fix from $2,300 2023-01-30