Vulnerability index

Browse CVEs

689 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Connexium Network Manager CRITICAL 9.8
CVE-2021-22801

A CWE-269: Improper Privilege Management vulnerability exists that could cause an arbitrary command execution when the software is configured with sp…

Mitigation only
Fix from $2,300 2022-02-11
Interactive Graphical Scada System Data Collector CRITICAL 9.8
CVE-2021-22802EPSS 20%

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution due to missing length check on …

Fix: after 15.0.0.21243
Fix from $2,300 2022-02-11
Interactive Graphical Scada System Data Collector CRITICAL 9.8
CVE-2021-22803

A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could lead to remote code execution through a number of paths, w…

Fix: after 15.0.0.21243
Fix from $2,300 2022-02-11
Interactive Graphical Scada System Data Collector CRITICAL 9.1
CVE-2021-22805

A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user …

Fix: after 15.0.0.21243
Fix from $2,300 2022-02-11
Interactive Graphical Scada System Data Collector CRITICAL 9.1
CVE-2021-22823EPSS 21%

A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user …

Fix: after 15.0.0.21320
Fix from $2,300 2022-02-11
C Gate Server HIGH 7.8
CVE-2021-22796

A CWE-287: Improper Authentication vulnerability exists that could allow remote code execution when a malicious file is uploaded. Affected Product: C…

Fix: after 2.11.7
Fix from $1,950 2022-02-11
Modicon M340 Bmxp342020 Firmware HIGH 7.5
CVE-2021-22787

A CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted …

Fix: 3.40+
Fix from $1,950 2022-02-11
Modicon M340 Bmxp342020 Firmware HIGH 7.5
CVE-2021-22788

A CWE-787: Out-of-bounds Write vulnerability exists that could cause denial of service when an attacker sends a specially crafted HTTP request to the…

Fix: 3.40+
Fix from $1,950 2022-02-11
Conext Combox Firmware HIGH 7.5
CVE-2021-22798

A CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause Sensitive data such as login credentials being exposed when a N…

Mitigation only
Fix from $1,950 2022-02-11
Modicon M218 Firmware HIGH 7.5
CVE-2021-22800

A CWE-20: Improper Input Validation vulnerability exists that could cause a Denial of Service when a crafted packet is sent to the controller over ne…

Fix: after 5.1.0.6
Fix from $1,950 2022-02-11
Interactive Graphical Scada System Data Collector HIGH 7.5
CVE-2021-22804

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause disclosure of arbitrary files being read …

Fix: after 15.0.0.21243
Fix from $1,950 2022-02-11
Spacelynk Firmware HIGH 7.5
CVE-2021-22806

A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could cause data exfiltration and unauthorized access when accessing…

Fix: after 2.6.1
Fix from $1,950 2022-02-11
Interactive Graphical Scada System Data Collector HIGH 7.5
CVE-2021-22824EPSS 14%

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in denial of service, due to missing length check on use…

Fix: after 15.0.0.21320
Fix from $1,950 2022-02-11
C Bus Toolkit HIGH 8.8
CVE-2021-22748

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could allow a remote code executio…

Fix: after 1.15.9
Fix from $1,950 2022-02-11
Modicon M340 Bmxp342020 Firmware HIGH 7.5
CVE-2021-22785

A CWE-200: Information Exposure vulnerability exists that could cause sensitive information of files located in the web root directory to leak when a…

Fix: 3.40+
Fix from $1,950 2022-02-11
Clearscada HIGH 7.5
CVE-2022-24318

A CWE-326: Inadequate Encryption Strength vulnerability exists that could cause non-encrypted communication with the server when outdated versions of…

Patch available
Fix from $1,950 2022-02-09
Clearscada HIGH 7.5
CVE-2022-24321

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause Denial of Service against the Geo SCADA server …

Patch available
Fix from $1,950 2022-02-09
Clearscada MEDIUM 5.9
CVE-2022-24319

A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and…

Patch available
Fix from $1,600 2022-02-09
Clearscada MEDIUM 5.9
CVE-2022-24320

A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communications between the client and…

Patch available
Fix from $1,600 2022-02-09
Spacelynk Firmware CRITICAL 9.8
CVE-2022-22810

A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to manipulate the admin after …

Fix: after 2.6.2
Fix from $2,300 2022-02-09
Easergy P141 Firmware CRITICAL 9.8
CVE-2022-22813

A CWE-798: Use of Hard-coded Credentials vulnerability exists. If an attacker were to obtain the TLS cryptographic key and take active control of the…

Mitigation only
Fix from $2,300 2022-02-09
Interactive Graphical Scada System Data Server CRITICAL 9.8
CVE-2022-24310

A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to denial of service and potentia…

Fix: after 15.0.0.22020
Fix from $2,300 2022-02-09
Interactive Graphical Scada System Data Server CRITICAL 9.8
CVE-2022-24311

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause modification of an existing file by inser…

Fix: after 15.0.0.22020
Fix from $2,300 2022-02-09
Interactive Graphical Scada System Data Server CRITICAL 9.8
CVE-2022-24312

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause modification of an existing file by addin…

Fix: after 15.0.0.22020
Fix from $2,300 2022-02-09
Interactive Graphical Scada System Data Server CRITICAL 9.8
CVE-2022-24313EPSS 45%

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leading to remo…

Fix: after 15.0.0.22020
Fix from $2,300 2022-02-09
Hmibscea53d1edb Firmware HIGH 8.8
CVE-2022-22808

A CWE-352: Cross-Site Request Forgery (CSRF) exists that could cause a remote attacker to gain unauthorized access to the product when conducting cro…

Fix: 4.0.0.13+
Fix from $1,950 2022-02-09
Spacelynk Firmware HIGH 8.1
CVE-2022-22811

A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could induce users to perform unintended actions, leading to the override of t…

Fix: after 2.6.2
Fix from $1,950 2022-02-09
Interactive Graphical Scada System Data Server HIGH 7.5
CVE-2022-24314EPSS 18%

A CWE-125: Out-of-bounds Read vulnerability exists that could cause memory leaks potentially resulting in denial of service when an attacker repeated…

Fix: after 15.0.0.22020
Fix from $1,950 2022-02-09
Interactive Graphical Scada System Data Server HIGH 7.5
CVE-2022-24315EPSS 19%

A CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service when an attacker repeatedly sends a specially crafted message. …

Fix: after 15.0.0.22020
Fix from $1,950 2022-02-09
Interactive Graphical Scada System Data Server HIGH 7.5
CVE-2022-24316

A CWE-665: Improper Initialization vulnerability exists that could cause information exposure when an attacker sends a specially crafted message. Aff…

Fix: after 15.0.0.22020
Fix from $1,950 2022-02-09