Vulnerability index

Browse CVEs

689 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Opc Ua Module For M580 Firmware HIGH 7.5
CVE-2022-34762

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause unauthorized firmware …

Fix: after 1.10
Fix from $1,950 2022-07-13
Opc Ua Module For M580 Firmware HIGH 7.5
CVE-2022-34763

A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists that could cause loading of unauthorized firmware images due to improp…

Fix: after 1.10
Fix from $1,950 2022-07-13
Opc Ua Module For M580 Firmware HIGH 7.5
CVE-2022-34764

A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service when parsi…

Fix: after 1.10
Fix from $1,950 2022-07-13
Acti9 Powertag Link C \(a9xelc10 A\) Firmware MEDIUM 6.8
CVE-2022-34754

A CWE-269: Improper Privilege Management vulnerability exists that could allow elevated functionality when guessing credentials. Affected Products: A…

Fix: after 2.12.0
Fix from $1,600 2022-07-13
Easergy P5 Firmware MEDIUM 5.3
CVE-2022-34757

A CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists where weak cipher suites can be used for the SSH connection between …

Fix: after 01.401.102
Fix from $1,600 2022-07-13
Opc Ua Module For M580 Firmware MEDIUM 5.3
CVE-2022-34765

A CWE-73: External Control of File Name or Path vulnerability exists that could cause loading of unauthorized firmware images when user-controlled da…

Fix: after 1.10
Fix from $1,600 2022-07-13
Geo Scada Mobile HIGH 7.8
CVE-2022-32530

A CWE-668 Exposure of Resource to Wrong Sphere vulnerability exists that could cause users to be misled, hiding alarms, showing the wrong server conn…

Fix: 2020+
Fix from $1,950 2022-06-24
Wiser Smart Eer21000 Firmware CRITICAL 9.8
CVE-2022-30234

A CWE-798: Use of Hard-coded Credentials vulnerability exists that could allow arbitrary code to be executed when root level access is obtained. Affe…

Fix: after 4.5
Fix from $2,300 2022-06-02
Wiser Smart Eer21000 Firmware CRITICAL 9.8
CVE-2022-30235

A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow unauthorized access when an attacker uses …

Fix: after 4.5
Fix from $2,300 2022-06-02
Powerlogic Ion Setup Firmware HIGH 8.8
CVE-2022-30232

A CWE-20: Improper Input Validation vulnerability exists that could cause potential remote code execution when an attacker is able to intercept and m…

Fix: 3.2.22096.01+
Fix from $1,950 2022-06-02
Wiser Smart Eer21000 Firmware HIGH 8.8
CVE-2022-30238

A CWE-287: Improper Authentication vulnerability exists that could allow an attacker to take over the admin account when an attacker hijacks a sessio…

Fix: after 4.5
Fix from $1,950 2022-06-02
Wiser Smart Eer21000 Firmware HIGH 8.2
CVE-2022-30236

A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could allow unauthorized access when an attacker uses cross-domain a…

Fix: after 4.5
Fix from $1,950 2022-06-02
Wiser Smart Eer21000 Firmware HIGH 7.5
CVE-2022-30237

A CWE-311: Missing Encryption of Sensitive Data vulnerability exists that could allow authentication credentials to be recovered when an attacker bre…

Fix: after 4.5
Fix from $1,950 2022-06-02
Wiser Smart Eer21000 Firmware MEDIUM 6.5
CVE-2022-30233

A CWE-20: Improper Input Validation vulnerability exists that could allow the product to be maliciously manipulated when the user is tricked into per…

Fix: after 4.5
Fix from $1,600 2022-06-02
Struxureware Data Center Expert CRITICAL 9.8
CVE-2021-22794

A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution. …

Fix: after 7.8.1
Fix from $2,300 2022-04-13
Struxureware Data Center Expert CRITICAL 9.8
CVE-2021-22795

A CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code…

Fix: after 7.8.1
Fix from $2,300 2022-04-13
Software Update HIGH 7.8
CVE-2019-6834

A CWE-502: Deserialization of Untrusted Data vulnerability exists which could allow an attacker to execute arbitrary code on the targeted system with…

Fix: after 2.3.0
Fix from $1,950 2022-04-13
Ecostruxure Control Expert HIGH 7.8
CVE-2021-22797EPSS 26%

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be …

Fix: 15.1 / 2021+
Fix from $1,950 2022-04-13
Scadapack Workbench MEDIUM 5.5
CVE-2022-0221

A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could result in information disclosure when opening a mali…

Fix: after 6.6.8a
Fix from $1,600 2022-04-13
Epas Gtw Firmware CRITICAL 9.8
CVE-2020-25176EPSS 6%

Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in t…

Fix: 1.1.0+
Fix from $2,300 2022-03-18
Epas Gtw Firmware HIGH 8.8
CVE-2020-25178

ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communication protocol provides vario…

Fix: 1.1.0+
Fix from $1,950 2022-03-18
Epas Gtw Firmware MEDIUM 6.7
CVE-2020-25182

Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x searches for and loads DLLs as dynamic libraries. Uncontrolled loading of dynamic libraries …

Fix: 1.1.0+
Fix from $1,600 2022-03-18
Epas Gtw Firmware MEDIUM 6.5
CVE-2020-25180

Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged comm…

Fix: 1.1.0+
Fix from $1,600 2022-03-18
Epas Gtw Firmware MEDIUM 5.5
CVE-2020-25184

Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable f…

Fix: 1.1.0+
Fix from $1,600 2022-03-18
Ritto Wiser Door HIGH 7.6
CVE-2021-22783

A CWE-200: Information Exposure vulnerability exists which could allow a session hijack when the door panel is communicating with the door. Affected …

Mitigation only
Fix from $1,950 2022-03-09
Ecostruxure Control Expert MEDIUM 5.9
CVE-2022-24322

A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a disruption of communicatio…

Fix: 15.0+
Fix from $1,600 2022-03-09
Ecostruxure Control Expert MEDIUM 5.9
CVE-2022-24323

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause a disruption of communication between the Modic…

Fix: 15.0+
Fix from $1,600 2022-03-09
Smt Series 1015 Ups Firmware CRITICAL 9.8
CVE-2022-22805EPSS 12%

A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause remote code execution when an…

Fix: after 04.5
Fix from $2,300 2022-03-09
Smt Series 1015 Ups Firmware CRITICAL 9.8
CVE-2022-22806EPSS 12%

A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause an unauthenticated connection to the UPS when a malformed co…

Fix: after 04.5
Fix from $2,300 2022-03-09
Smt Series 1015 Ups Firmware CRITICAL 9.1
CVE-2022-0715EPSS 6%

A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leak…

Fix: after 04.5
Fix from $2,300 2022-03-09