Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Boss Mini Firmware CRITICAL 9.8
CVE-2023-3643EPSS 75%

A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/do…

No fix yet
Fix from $2,300 2023-07-12
Pcoweb Card Web HIGH 7.5
CVE-2020-18329

An issue was discovered in Rehau devices that use a pCOWeb card BIOS v6.27, BOOT v5.00, web version v2.2, allows attackers to gain full unauthenticat…

Mitigation only
Fix from $1,950 2023-01-26
Boss Mini Firmware CRITICAL 9.9
CVE-2022-34827

Carel Boss Mini 1.5.0 has Improper Access Control.

No fix yet
Fix from $2,300 2022-11-18
Pcoweb Card Firmware HIGH 7.5
CVE-2022-37122EPSS 19%

Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 suffers from an unauthenticate…

No fix yet
Fix from $1,950 2022-08-31
Pcoweb Firmware CRITICAL 9.8
CVE-2019-13553

Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems is …

Mitigation only
Fix from $2,300 2019-10-25
Pcoweb Firmware HIGH 7.5
CVE-2019-13549

Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems doe…

Mitigation only
Fix from $1,950 2019-10-25
Pcoweb Card Firmware HIGH 8.8
CVE-2019-11369EPSS 8%

An issue was discovered in Carel pCOWeb prior to B1.2.4. In /config/pw_changeusers.html the device stores cleartext passwords, which may allow sensit…

No fix yet
Fix from $1,950 2019-06-03
Pcoweb Card Firmware MEDIUM 5.4
CVE-2019-11370

Stored XSS was discovered in Carel pCOWeb prior to B1.2.4, as demonstrated by the config/pw_snmp.html "System contact" field.

No fix yet
Fix from $1,600 2019-06-03
Pcoweb Card Firmware HIGH 7.5
CVE-2019-9484

The Glen Dimplex Deutschland GmbH implementation of the Carel pCOWeb configuration tool allows remote attackers to obtain access via an HTTP session …

Mitigation only
Fix from $1,950 2019-03-01
Plantvisor Enhanced HIGH 7.5
CVE-2016-0867

CAREL PlantVisorEnhanced allows remote attackers to bypass intended access restrictions via a direct file request.

Mitigation only
Fix from $1,950 2016-01-30
Plantvisor MEDIUM 5.0
CVE-2011-3487EPSS 7%

Directory traversal vulnerability in CarelDataServer.exe in Carel PlantVisor 2.4.4 and earlier allows remote attackers to read arbitrary files via a …

Fix: after 2.4.4
Fix from $1,600 2011-09-16