Vulnerability index

Browse CVEs

689 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Interactive Graphical Scada System CRITICAL 9.8
CVE-2022-32523

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to rem…

Fix: after 15.0.0.22170
Fix from $2,300 2023-01-30
Interactive Graphical Scada System CRITICAL 9.8
CVE-2022-32524

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to rem…

Fix: after 15.0.0.22170
Fix from $2,300 2023-01-30
Interactive Graphical Scada System CRITICAL 9.8
CVE-2022-32525

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to rem…

Fix: after 15.0.0.22170
Fix from $2,300 2023-01-30
Interactive Graphical Scada System CRITICAL 9.8
CVE-2022-32526

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to rem…

Fix: after 15.0.0.22170
Fix from $2,300 2023-01-30
Interactive Graphical Scada System CRITICAL 9.8
CVE-2022-32527

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to rem…

Fix: after 15.0.0.22170
Fix from $2,300 2023-01-30
Data Center Expert HIGH 8.8
CVE-2022-32521

A CWE 502: Deserialization of Untrusted Data vulnerability exists that could allow code to be remotely executed on the server when unsafely deseriali…

Fix: 7.9.0+
Fix from $1,950 2023-01-30
Conext Combox Firmware MEDIUM 6.5
CVE-2022-32516

A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could cause system’s configurations override and cause a reboot loop when the …

Mitigation only
Fix from $1,600 2023-01-30
Conext Combox Firmware MEDIUM 6.5
CVE-2022-32517

A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause an adversary to trick the interface user/admin…

Mitigation only
Fix from $1,600 2023-01-30
Ecostruxure Power Commission CRITICAL 9.8
CVE-2022-0223

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could allow an attacker to create …

Fix: 2.22+
Fix from $2,300 2023-01-30
Ecostruxure Power Commission CRITICAL 9.8
CVE-2022-22731

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in a function that could allow an attac…

Fix: 2.22+
Fix from $2,300 2023-01-30
5500ac2 Firmware CRITICAL 9.8
CVE-2022-32513

A CWE-521: Weak Password Requirements vulnerability exists that could allow an attacker to gain control of the device when the attacker brute forces …

Fix: 1.11.0+
Fix from $2,300 2023-01-30
Canbrass HIGH 7.8
CVE-2022-32512

A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause remote code execution when a…

Fix: 7.5.1+
Fix from $1,950 2023-01-30
Ecostruxure Power Commission HIGH 7.5
CVE-2022-22732

A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause all remote domains to access the resources (data) supplied by t…

Fix: 2.22+
Fix from $1,950 2023-01-30
Ecostruxure Control Expert CRITICAL 9.8
CVE-2022-45788

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of service and…

Fix: 2021+
Fix from $2,300 2023-01-30
Ecostruxure Machine Expert Hvac HIGH 7.5
CVE-2022-2988

A CWE-787: Out-of-bounds Write vulnerability exists that could cause sensitive information leakage when accessing a malicious web page from the commi…

Fix: 1.4.0 / 2.1.0+
Fix from $1,950 2023-01-30
Modicon M340 Bmxp341000 Firmware HIGH 7.5
CVE-2022-0222

A CWE-269: Improper Privilege Management vulnerability exists that could cause a denial of service of the Ethernet communication of the controller wh…

Fix: 3.50+
Fix from $1,950 2022-11-22
Modicon M340 Bmx P34 2010 Firmware HIGH 7.5
CVE-2022-37301

A CWE-191: Integer Underflow (Wrap or Wraparound) vulnerability exists that could cause a denial of service of the controller due to memory access vi…

Fix: 3.50 / 4.01+
Fix from $1,950 2022-11-22
Ecostruxure Operator Terminal Expert HIGH 7.8
CVE-2022-41671

A CWE-89: Improper Neutralization of Special Elements used in SQL Command (‘SQL Injection’) vulnerability exists that allows adversaries with local u…

Fix: 3.3+
Fix from $1,950 2022-11-04
Ecostruxure Operator Terminal Expert HIGH 7.8
CVE-2022-41670

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in the SGIUtility component that allows…

Fix: 3.3+
Fix from $1,950 2022-11-04
Ecostruxure Operator Terminal Expert HIGH 7.8
CVE-2022-41669

A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in the SGIUtility component that allows adversaries with local user …

Fix: 3.3+
Fix from $1,950 2022-11-04
Ecostruxure Operator Terminal Expert HIGH 7.8
CVE-2022-41668

A CWE-704: Incorrect Project Conversion vulnerability exists that allows adversaries with local user privileges to load a project file from an advers…

Fix: 3.3+
Fix from $1,950 2022-11-04
Ecostruxure Operator Terminal Expert HIGH 7.8
CVE-2022-41667

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that allows adversaries with local user…

Fix: 3.3+
Fix from $1,950 2022-11-04
Ecostruxure Operator Terminal Expert HIGH 7.8
CVE-2022-41666

A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that allows adversaries with local user privileges to load a malicio…

Fix: 3.3+
Fix from $1,950 2022-11-04
Ecostruxure Control Expert MEDIUM 5.5
CVE-2022-37302

A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a crash of the Control Exper…

Fix: 15.1+
Fix from $1,600 2022-09-13
Ecostruxure Control Expert CRITICAL 9.8
CVE-2022-37300

A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode t…

Fix: 3.50 / 15.1+
Fix from $2,300 2022-09-12
Easergy P5 Firmware CRITICAL 9.8
CVE-2022-34756

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution or the crash of HTTPs stack whi…

Fix: after 01.401.102
Fix from $2,300 2022-07-13
Spacelogic C Bus Home Controller Firmware HIGH 8.8
CVE-2022-34753EPSS 71%

A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote roo…

Fix: after 1.31.460
Fix from $1,950 2022-07-13
Opc Ua Module For M580 Firmware HIGH 7.5
CVE-2022-34759

A CWE-787: Out-of-bounds Write vulnerability exists that could cause a denial of service of the webserver due to improper parsing of the HTTP Headers…

Fix: after 1.10
Fix from $1,950 2022-07-13
Opc Ua Module For M580 Firmware HIGH 7.5
CVE-2022-34760

A CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability exists that could cause a denial of service of the webserver due to i…

Fix: after 1.10
Fix from $1,950 2022-07-13
Opc Ua Module For M580 Firmware HIGH 7.5
CVE-2022-34761

A CWE-476: NULL Pointer Dereference vulnerability exists that could cause a denial of service of the webserver when parsing JSON content type. Affect…

Fix: after 1.10
Fix from $1,950 2022-07-13