Vulnerability index

Browse CVEs

19 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Pi Asset Framework Client HIGH 7.8
CVE-2024-3467

There is a vulnerability in AVEVA PI Asset Framework Client that could allow malicious code to execute on the PI System Explorer environment under th…

Mitigation only
Fix from $1,950 2024-06-12
Platform Common Services HIGH 7.8
CVE-2023-6132

The vulnerability, if exploited, could allow a malicious entity with access to the file system to achieve arbitrary code execution and privilege esca…

Mitigation only
Fix from $1,950 2024-02-29
Aveva Plant Scada CRITICAL 9.8
CVE-2023-1256

The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an unauthen…

Mitigation only
Fix from $2,300 2023-03-16
Batch Management HIGH 7.8
CVE-2021-38410

AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled …

Mitigation only
Fix from $1,950 2022-07-27
Intouch Access Anywhere CRITICAL 9.9
CVE-2022-1467

Windows OS can be configured to overlay a “language bar” on top of any application. When this OS functionality is enabled, the OS language bar UI wil…

Mitigation only
Fix from $2,300 2022-05-23
System Platform MEDIUM 5.5
CVE-2022-0835

AVEVA System Platform 2020 stores sensitive information in cleartext, which may allow access to an attacker or a low-privileged user.

Mitigation only
Fix from $1,600 2022-04-11
Edna Enterprise Data Historian CRITICAL 9.8
CVE-2020-13499

An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially …

No fix yet
Fix from $2,300 2020-09-24
Edna Enterprise Data Historian CRITICAL 9.8
CVE-2020-13500

SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially cra…

No fix yet
Fix from $2,300 2020-09-24
Edna Enterprise Data Historian CRITICAL 9.8
CVE-2020-13501

An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially …

No fix yet
Fix from $2,300 2020-09-24
Edna Enterprise Data Historian CRITICAL 9.8
CVE-2020-13504

Parameter AttFilterValue in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted SOAP web requests can cause …

No fix yet
Fix from $2,300 2020-09-24
Edna Enterprise Data Historian CRITICAL 9.8
CVE-2020-13505

Parameter psClass in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted SOAP web requests can cause SQL inj…

No fix yet
Fix from $2,300 2020-09-24
Indusoft Web Studio CRITICAL 9.8
CVE-2019-6543EPSS 17%

AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update…

No fix yet
Fix from $2,300 2019-02-13
Indusoft Web Studio HIGH 7.5
CVE-2019-6545EPSS 14%

AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update…

No fix yet
Fix from $1,950 2019-02-13
Indusoft Web Studio CRITICAL 9.8
CVE-2018-17914

InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. This vulnerability…

No fix yet
Fix from $2,300 2018-11-02
Indusoft Web Studio CRITICAL 9.8
CVE-2018-17916

InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. A remote attacker …

No fix yet
Fix from $2,300 2018-11-02
Indusoft Web Studio CRITICAL 9.8
CVE-2018-10620

AVEVA InduSoft Web Studio v8.1 and v8.1SP1, and InTouch Machine Edition v2017 8.1 and v2017 8.1 SP1 a remote user could send a carefully crafted pack…

No fix yet
Fix from $2,300 2018-07-19
Clearscada MEDIUM 5.0
CVE-2014-5412

Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allows remote attackers to read database records by leveraging access…

Mitigation only
Fix from $1,600 2014-09-18
Clearscada MEDIUM 5.0
CVE-2014-5413

Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 uses the MD5 algorithm for an X.509 certificate, which makes it easie…

Mitigation only
Fix from $1,600 2014-09-18
Clearscada MEDIUM 6.8
CVE-2014-0779

The PLC driver in ServerMain.exe in the Kepware KepServerEX 4 component in Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R2 build 71.4…

Mitigation only
Fix from $1,600 2014-03-14