Vulnerability index

Browse CVEs

689 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Interactive Graphical Scada System Data Server HIGH 7.5
CVE-2022-24317

A CWE-862: Missing Authorization vulnerability exists that could cause information exposure when an attacker sends a specific message. Affected Produ…

Fix: after 15.0.0.22020
Fix from $1,950 2022-02-09
Hmibscea53d1edb Firmware HIGH 7.4
CVE-2022-22807

A CWE-1021 Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause unintended modifications of the product setting…

Fix: 4.0.0.13+
Fix from $1,950 2022-02-09
Spacelynk Firmware MEDIUM 6.1
CVE-2022-22812

A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a web session co…

Fix: after 2.6.2
Fix from $1,600 2022-02-09
Spacelynk Firmware MEDIUM 5.3
CVE-2022-22809

A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow modifications of the touch configurations in an unautho…

Fix: after 2.6.2
Fix from $1,600 2022-02-09
Hmibmuhi29d2801 Firmware HIGH 7.8
CVE-2021-22817

A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to loca…

Mitigation only
Fix from $1,950 2022-02-09
Easergy P5 Firmware HIGH 8.8
CVE-2022-22723

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could lead to a buffer overflow causing program crashes and arbitrary…

Fix: 01.401.101+
Fix from $1,950 2022-02-04
Easergy P3 Firmware HIGH 8.8
CVE-2022-22725

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could lead to a buffer overflow causing program crashes and arbitrary…

Fix: 30.205+
Fix from $1,950 2022-02-04
Ecostruxure Power Monitoring Expert HIGH 8.8
CVE-2022-22727

A CWE-20: Improper Input Validation vulnerability exists that could allow an unauthenticated attacker to view data, change settings, impact availabil…

Fix: after 2020
Fix from $1,950 2022-02-04
Easergy P5 Firmware HIGH 7.5
CVE-2022-22722

A CWE-798: Use of Hard-coded Credentials vulnerability exists that could result in information disclosure. If an attacker were to obtain the SSH cryp…

Fix: 01.401.101+
Fix from $1,950 2022-02-04
Modicon M340 Bmxp341000 Firmware HIGH 7.5
CVE-2022-22724

A CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service on ports 80 (HTTP) and 502 (Modbus), when send…

Patch available
Fix from $1,950 2022-02-04
Ecostruxure Power Monitoring Expert MEDIUM 6.5
CVE-2022-22726

A CWE-20: Improper Input Validation vulnerability exists that could allow arbitrary files on the server to be read by authenticated users through a l…

Fix: after 2020
Fix from $1,600 2022-02-04
Ecostruxure Power Monitoring Expert MEDIUM 5.4
CVE-2022-22804

A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could allow an authenticated…

Fix: after 2020
Fix from $1,600 2022-02-04
Modicon M340 Bmxp342020 Firmware HIGH 8.8
CVE-2020-7534

A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could cause a leak of sensitive data or unauthorized a…

Patch available
Fix from $1,950 2022-02-04
Evlink City Evc1s22p4 Firmware CRITICAL 9.8
CVE-2021-22820

A CWE-614 Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain an unauthorized access over a hijacked sessio…

Fix: 3.4.0.2+
Fix from $2,300 2022-01-28
Ecostruxure Power Monitoring Expert HIGH 8.8
CVE-2021-22826

A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits a page containing the injecte…

Fix: after 9.0
Fix from $1,950 2022-01-28
Ecostruxure Power Monitoring Expert HIGH 8.8
CVE-2021-22827

A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits a page containing the injecte…

Fix: after 9.0
Fix from $1,950 2022-01-28
Evlink City Evc1s22p4 Firmware HIGH 8.6
CVE-2021-22821

A CWE-918 Server-Side Request Forgery (SSRF) vulnerability exists that could cause the station web server to forward requests to unintended network t…

Fix: 3.4.0.2+
Fix from $1,950 2022-01-28
Rack Power Distribution Unit With Network Management Card 2 Firmware HIGH 8.0
CVE-2021-22825

A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could allow an attacker to access the system with ele…

Fix: 1.2.0.2 / 7.0.6+
Fix from $1,950 2022-01-28
Scadapack 312e Firmware HIGH 7.5
CVE-2021-22816

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause a Denial of Service of the RTU when receiving a…

Fix: 8.19.1+
Fix from $1,950 2022-01-28
Evlink City Evc1s22p4 Firmware HIGH 7.5
CVE-2021-22818

A CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to …

Fix: 3.4.0.2+
Fix from $1,950 2022-01-28
Network Management Card 2 Firmware MEDIUM 6.1
CVE-2021-22811

A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause script execution…

Fix: after 6.9.8
Fix from $1,600 2022-01-28
Network Management Card 2 Firmware MEDIUM 6.1
CVE-2021-22812

A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause arbritrary scrip…

Fix: after 6.9.8
Fix from $1,600 2022-01-28
Network Management Card 2 Firmware MEDIUM 6.1
CVE-2021-22813

A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause arbritrary scrip…

Fix: after 6.9.8
Fix from $1,600 2022-01-28
Network Management Card 2 Firmware MEDIUM 6.1
CVE-2021-22814

A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists which could cause arbritrary scri…

Fix: after 6.9.8
Fix from $1,600 2022-01-28
Evlink City Evc1s22p4 Firmware MEDIUM 6.1
CVE-2021-22822

A CWE-79 Improper Neutralization of Input During Web Page Generation (�Cross-site Scripting�) vulnerability exists that could allow an attacker to im…

Fix: 3.4.0.2+
Fix from $1,600 2022-01-28
Network Management Card 2 Firmware MEDIUM 5.3
CVE-2021-22815

A CWE-200: Information Exposure vulnerability exists which could cause the troubleshooting archive to be accessed. Affected Products: 1-Phase Uninter…

Fix: after 6.9.8
Fix from $1,600 2022-01-28
Evc1s22p4 Firmware HIGH 8.8
CVE-2021-22724

A CVE-352 Cross-Site Request Forgery (CSRF) vulnerability exists that could allow an attacker to impersonate the user or carry out actions on their b…

Fix: 3.4.0.2+
Fix from $1,950 2022-01-28
Evc1s22p4 Firmware HIGH 8.8
CVE-2021-22725

A CVE-352 Cross-Site Request Forgery (CSRF) vulnerability exists that could allow an attacker to impersonate the user or carry out actions on their b…

Fix: 3.4.0.2+
Fix from $1,950 2022-01-28
Guicon HIGH 7.8
CVE-2021-22807

A CWE-787: Out-of-bounds Write vulnerability exists that could cause arbitrary code execution when a malicious *.gd1 configuration file is loaded int…

Fix: after 2.0
Fix from $1,950 2022-01-28
Guicon HIGH 7.8
CVE-2021-22808

A CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution when a malicious *.gd1 configuration file is loaded into the…

Fix: after 2.0
Fix from $1,950 2022-01-28