AID
Automation
Information Directory
HomeCVE FeedBrands
AID
Automation Information Directory
CVE data sourced from NIST NVD · Documentation links from official sources
›
Home›CVE Feed
Security Intelligence

Global CVE Feed

Sourced from NIST NVD · Auto-synced every 6 hours

2,506
Total CVEs
493
CRIT
1247
HIGH
675
MED
58
LOW
1247 / 2506
CVE-2015-7937HIGH

Stack-based buffer overflow in the GoAhead Web Server on Schneider Electric Modicon M340 PLC BMXNOx and BMXPx devices allows remote attackers to execute arbitrary code via a long password in HTTP Basic Authentication data.

Dec 21, 2015
10.0
CVE-2015-6476HIGH

Advantech EKI-122x-BE devices with firmware before 1.65, EKI-132x devices with firmware before 1.98, and EKI-136x devices with firmware before 1.27 have hardcoded SSH keys, which makes it easier for remote attackers to obtain access via an SSH session.

Nov 7, 2015
10.0
CVE-2015-6459HIGH

Absolute path traversal vulnerability in the download feature in FileDownloadServlet in GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 allows remote attackers to read or delete arbitrary files via a full pathname.

Sep 18, 2015
10.0
CVE-2014-9208HIGH

Multiple stack-based buffer overflows in unspecified DLL files in Advantech WebAccess before 8.0.1 allow remote attackers to execute arbitrary code via unknown vectors.

Sep 11, 2015
10.0
CVE-2015-0984HIGH

Directory traversal vulnerability in the FTP server on Honeywell Excel Web XL1000C50 52 I/O, XL1000C100 104 I/O, XL1000C500 300 I/O, XL1000C1000 600 I/O, XL1000C50U 52 I/O UUKL, XL1000C100U 104 I/O UUKL, XL1000C500U 300 I/O UUKL, and XL1000C1000U 600 I/O UUKL controllers before 2.04.01 allows remote attackers to read files under the web root, and consequently obtain administrative login access, via a crafted pathname.

Mar 31, 2015
10.0
CVE-2014-8385HIGH

Buffer overflow on Advantech EKI-1200 gateways with firmware before 1.63 allows remote attackers to execute arbitrary code via unspecified vectors.

Feb 13, 2015
10.0
CVE-2015-1449HIGH

Buffer overflow in the integrated web server on Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware before SS4.4.4624.35, WIN70xx devices with firmware before BS4.4.4621.32, and WIN72xx devices with firmware before BS4.4.4621.32 allows remote attackers to execute arbitrary code via unspecified vectors.

Feb 2, 2015
10.0
CVE-2015-1448HIGH

The integrated management service on Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware before SS4.4.4624.35, WIN70xx devices with firmware before BS4.4.4621.32, and WIN72xx devices with firmware before BS4.4.4621.32 allows remote attackers to bypass authentication and perform administrative actions via unspecified vectors.

Feb 2, 2015
10.0
CVE-2014-9198HIGH

The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to obtain access via an FTP session.

Jan 27, 2015
10.0
CVE-2014-9197HIGH

The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request.

Jan 27, 2015
10.0
CVE-2014-9195HIGH

Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote attackers to execute arbitrary commands via protocol-compliant traffic.

Jan 17, 2015
10.0
CVE-2014-9190HIGH

Stack-based buffer overflow in Schneider Electric Wonderware InTouch Access Anywhere Server 10.6 and 11.0 allows remote attackers to execute arbitrary code via a request for a filename that does not exist.

Jan 10, 2015
10.0
CVE-2014-9188HIGH

Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8513 and CVE-2014-8514. NOTE: this may be clarified later based on details provided by researchers.

Dec 27, 2014
10.0
CVE-2014-8511HIGH

Buffer overflow in an ActiveX control in Atx45.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8512. NOTE: this may be clarified later based on details provided by researchers.

Dec 27, 2014
10.0
CVE-2014-8551HIGH

The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through SP2, and 8.1; and TIA Portal 13 before Update 6 allows remote attackers to execute arbitrary code via crafted packets.

Nov 26, 2014
10.0
CVE-2014-0754HIGH

Directory traversal vulnerability in SchneiderWEB on Schneider Electric Modicon PLC Ethernet modules 140CPU65x Exec before 5.5, 140NOC78x Exec before 1.62, 140NOE77x Exec before 6.2, BMXNOC0401 before 2.05, BMXNOE0100 before 2.9, BMXNOE0110x Exec before 6.0, TSXETC101 Exec before 2.04, TSXETY4103x Exec before 5.7, TSXETY5103x Exec before 5.9, TSXP57x ETYPort Exec before 5.7, and TSXP57x Ethernet Copro Exec before 5.5 allows remote attackers to visit arbitrary resources via a crafted HTTP request.

Oct 3, 2014
10.0
CVE-2013-6920HIGH

Siemens SINAMICS S/G controllers with firmware before 4.6.11 do not require authentication for FTP and TELNET sessions, which allows remote attackers to bypass intended access restrictions via TCP traffic to port (1) 21 or (2) 23.

Dec 7, 2013
10.0
CVE-2013-5944HIGH

The integrated web server on Siemens SCALANCE X-200 switches with firmware before 4.5.0 and X-200IRT switches with firmware before 5.1.0 does not properly enforce authentication requirements, which allows remote attackers to perform administrative actions via requests to the management interface.

Oct 3, 2013
10.0
CVE-2013-4652HIGH

Unspecified vulnerability in the command-line management interface on Siemens Scalance W7xx devices with firmware before 4.5.4 allows remote attackers to bypass authentication and execute arbitrary code via a (1) SSH or (2) TELNET connection.

Aug 1, 2013
10.0
CVE-2013-4781HIGH

core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Controller (SBC) before 2 R0.32.0, and 7 before 7 R1.7.0, allows remote attackers to execute arbitrary commands via unspecified vectors.

Jul 18, 2013
10.0
CVE-2013-2781HIGH

Use-after-free vulnerability in the server application in 3S CODESYS Gateway 2.3.9.27 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via unspecified vectors.

May 23, 2013
10.0
CVE-2012-4715HIGH

Buffer overflow in LogReceiver.exe in Rockwell Automation RSLinx Enterprise CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a UDP packet with a certain integer length value that is (1) too large or (2) too small, leading to improper handling by Logger.dll.

Apr 18, 2013
10.0
CVE-2013-2762HIGH

The Schneider Electric Magelis XBT HMI controller has a default password for authentication of configuration uploads, which makes it easier for remote attackers to bypass intended access restrictions via crafted configuration data.

Apr 4, 2013
10.0
CVE-2013-0659HIGH

The debugging feature on the Siemens CP 1604 and CP 1616 interface cards with firmware before 2.5.2 allows remote attackers to execute arbitrary code via a crafted packet to UDP port 17185.

Apr 1, 2013
10.0
CVE-2012-4708HIGH

Stack-based buffer overflow in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via a crafted packet.

Feb 24, 2013
10.0
CVE-2012-4707HIGH

3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors that trigger an out-of-bounds memory access.

Feb 24, 2013
10.0
CVE-2012-4705HIGH

Directory traversal vulnerability in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors involving a crafted pathname.

Feb 24, 2013
10.0
CVE-2012-4704HIGH

Array index error in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via a crafted packet.

Feb 24, 2013
10.0
CVE-2013-0658HIGH

Heap-based buffer overflow in RFManagerService.exe in Schneider Electric Accutech Manager 2.00.1 and earlier allows remote attackers to execute arbitrary code via a crafted HTTP request.

Feb 15, 2013
10.0
CVE-2012-6437HIGH

The device does not properly authenticate users and the potential exists for a remote user to upload a new firmware image to the Ethernet card, whether it is a corrupt or legitimate firmware image. Successful exploitation of this vulnerability could cause loss of availability, integrity, and confidentiality and a disruption in communications with other connected devices. Rockwell Automation EtherNet/IP products; 1756-ENBT, 1756-EWEB, 1768-ENBT, and 1768-EWEB communication modules; CompactLogix L32E and L35E controllers; 1788-ENBT FLEXLogix adapter; 1794-AENTR FLEX I/O EtherNet/IP adapter; ControlLogix 18 and earlier; CompactLogix 18 and earlier; GuardLogix 18 and earlier; SoftLogix 18 and earlier; CompactLogix controllers 19 and earlier; SoftLogix controllers 19 and earlier; ControlLogix controllers 20 and earlier; GuardLogix controllers 20 and earlier; and MicroLogix 1100 and 1400

Jan 24, 2013
10.0
CVE-2013-0657HIGH

Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA System (IGSS) 10 and earlier allows remote attackers to execute arbitrary code by sending TCP port-12397 data that does not comply with a protocol.

Jan 21, 2013
10.0
CVE-2012-5409HIGH

AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle IOCP RPC messages received over an Ethernet network, which allows remote attackers to write data to any memory location and consequently execute arbitrary code via crafted messages, as demonstrated by an arbitrary pointer dereference attack or a buffer overflow attack.

Nov 1, 2012
10.0
CVE-2012-4879HIGH

The Linux Console on the WAGO I/O System 758 model 758-870, 758-874, 758-875, and 758-876 Industrial PC (IPC) devices has a default password of wago for the (1) root and (2) admin accounts, (3) a default password of user for the user account, and (4) a default password of guest for the guest account, which makes it easier for remote attackers to obtain login access via a TELNET session, a different vulnerability than CVE-2012-3013.

Sep 7, 2012
10.0
CVE-2012-3013HIGH

WAGO I/O System 758 model 758-870, 758-874, 758-875, and 758-876 Industrial PC (IPC) devices have default passwords for unspecified Web Based Management accounts, which makes it easier for remote attackers to obtain administrative access via a TCP session.

Sep 7, 2012
10.0
CVE-2012-1799HIGH

The web server on the Siemens Scalance S Security Module firewall S602 V2, S612 V2, and S613 V2 with firmware before 2.3.0.3 does not limit the rate of authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack on the administrative password.

Apr 18, 2012
10.0
CVE-2012-0245HIGH

Multiple stack-based buffer overflows in RobNetScanHost.exe in ABB Robot Communications Runtime before 5.14.02, as used in ABB Interlink Module, IRC5 OPC Server, PC SDK, PickMaster 3 and 5, RobView 5, RobotStudio, WebWare SDK, and WebWare Server, allow remote attackers to execute arbitrary code via a crafted (1) 0xA or (2) 0xE Netscan packet.

Mar 9, 2012
10.0
CVE-2012-0243HIGH

Buffer overflow in an ActiveX control in bwocxrun.ocx in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code by leveraging the ability to write arbitrary content to any pathname.

Feb 21, 2012
10.0
CVE-2012-0242HIGH

Format string vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via format string specifiers in a message string.

Feb 21, 2012
10.0
CVE-2012-0240HIGH

GbScriptAddUp.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to execute arbitrary code via unspecified vectors.

Feb 21, 2012
10.0
CVE-2012-0238HIGH

Stack-based buffer overflow in opcImg.asp in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via unspecified vectors.

Feb 21, 2012
10.0
CVE-2011-4526HIGH

Buffer overflow in an ActiveX control in Advantech/BroadWin WebAccess before 7.0 might allow remote attackers to execute arbitrary code via a long string value in unspecified parameters.

Feb 21, 2012
10.0
CVE-2011-4525HIGH

Advantech/BroadWin WebAccess before 7.0 allows remote attackers to trigger the extraction of arbitrary web content into a batch file on a client system, and execute this batch file, via unspecified vectors.

Feb 21, 2012
10.0
CVE-2011-4524HIGH

Buffer overflow in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via a long string value in unspecified parameters.

Feb 21, 2012
10.0
CVE-2011-1914HIGH

Buffer overflow in the Advantech ADAM OLE for Process Control (OPC) Server ActiveX control in ADAM OPC Server before 3.01.012, Modbus RTU OPC Server before 3.01.010, and Modbus TCP OPC Server before 3.01.010 allows remote attackers to execute arbitrary code via unspecified vectors.

Feb 21, 2012
10.0
CVE-2011-4041HIGH

webvrpcs.exe in Advantech/BroadWin WebAccess allows remote attackers to execute arbitrary code or obtain a security-code value via a long string in an RPC request to TCP port 4592.

Feb 6, 2012
10.0
CVE-2011-4514HIGH

The TELNET daemon in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime does not perform authentication, which makes it easier for remote attackers to obtain access via a TCP session.

Feb 3, 2012
10.0
CVE-2011-4513HIGH

Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime allow user-assisted remote attackers to execute arbitrary code via a crafted project file, related to the HMI web server and runtime loader.

Feb 3, 2012
10.0
CVE-2011-4509HIGH

The HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime has an improperly selected default password for the administrator account, which makes it easier for remote attackers to obtain access via a brute-force approach involving many HTTP requests.

Feb 3, 2012
10.0
CVE-2011-5007HIGH

Stack-based buffer overflow in the CmpWebServer component in 3S CoDeSys 3.4 SP4 Patch 2 and earlier, as used on the ABB AC500 PLC and possibly other products, allows remote attackers to execute arbitrary code via a long URI to TCP port 8080.

Dec 25, 2011
10.0
CVE-2011-4861HIGH

The modbus_125_handler function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) allows remote attackers to install arbitrary firmware updates via a MODBUS 125 function code to TCP port 502.

Dec 17, 2011
10.0
CVE-2011-4860HIGH

The ComputePassword function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) generates the password for the fwupgrade account by performing a calculation on the MAC address, which makes it easier for remote attackers to obtain access via a (1) ARP request message or (2) Neighbor Solicitation message.

Dec 17, 2011
10.0
CVE-2011-4859HIGH

The Schneider Electric Quantum Ethernet Module, as used in the Quantum 140NOE771* and 140CPU65* modules, the Premium TSXETY* and TSXP57* modules, the M340 BMXNOE01* and BMXP3420* modules, and the STB DIO STBNIC2212 and STBNIP2* modules, uses hardcoded passwords for the (1) AUTCSE, (2) AUT_CSE, (3) fdrusers, (4) ftpuser, (5) loader, (6) nic2212, (7) nimrohs2212, (8) nip2212, (9) noe77111_v500, (10) ntpupdate, (11) pcfactory, (12) sysdiag, (13) target, (14) test, (15) USER, and (16) webserver accounts, which makes it easier for remote attackers to obtain access via the (a) TELNET, (b) Windriver Debug, or (c) FTP port.

Dec 17, 2011
10.0
CVE-2010-4742HIGH

Stack-based buffer overflow in a certain ActiveX control in MediaDBPlayback.DLL 2.2.0.5 in the Moxa ActiveX SDK allows remote attackers to execute arbitrary code via a long PlayFileName property value.

Feb 18, 2011
10.0
CVE-2011-0488HIGH

Stack-based buffer overflow in NTWebServer.exe in the test web service in InduSoft NTWebServer, as distributed in Advantech Studio 6.1 and InduSoft Web Studio 7.0, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long request to TCP port 80.

Jan 18, 2011
10.0
CVE-2010-2965HIGH

The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with firmware 3.2.6 and 3.6.1 and other products, allows remote attackers to read or modify arbitrary memory locations, perform function calls, or manage tasks via requests to UDP port 17185, a related issue to CVE-2005-3804.

Aug 5, 2010
10.0
CVE-2009-3739HIGH

Multiple unspecified vulnerabilities on the Rockwell Automation AB Micrologix 1100 and 1400 controllers allow remote attackers to obtain privileged access or cause a denial of service (halt) via unknown vectors.

Jan 19, 2010
10.0
CVE-2008-6993HIGH

Siemens Gigaset WLAN Camera 1.27 has an insecure default password, which allows remote attackers to conduct unauthorized activities. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Aug 19, 2009
10.0
CVE-2008-6916HIGH

Siemens SpeedStream 5200 with NetPort Software 1.1 allows remote attackers to bypass authentication via an invalid Host header, possibly involving a trailing dot in the hostname.

Aug 7, 2009
10.0
CVE-2008-5848HIGH

The Advantech ADAM-6000 module has 00000000 as its default password, which makes it easier for remote attackers to obtain access through an HTTP session, and (1) monitor or (2) control the module's Modbus/TCP I/O activity.

Jan 6, 2009
10.0
CVE-2008-2474HIGH

Buffer overflow in x87 before 3.5.5 in ABB Process Communication Unit 400 (PCU400) 4.4 through 4.6 allows remote attackers to execute arbitrary code via a crafted packet using the (1) IEC60870-5-101 or (2) IEC60870-5-104 communication protocol to the X87 web interface.

Sep 29, 2008
10.0
CVE-2000-0704HIGH

Buffer overflow in SGI Omron WorldView Wnn allows remote attackers to execute arbitrary commands via long JS_OPEN, JS_MKDIR, or JS_FILE_INFO commands.

Oct 20, 2000
10.0
CVE-2015-7908HIGH

Honeywell Midas gas detectors before 1.13b3 and Midas Black gas detectors before 2.13b3 allow remote attackers to discover cleartext passwords by sniffing the network.

Dec 21, 2015
9.3
CVE-2015-5386HIGH

Siemens SICAM MIC devices with firmware before 2404 allow remote attackers to bypass authentication and obtain administrative access via unspecified HTTP requests.

Jul 16, 2015
9.3
CVE-2014-0769HIGH

The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion do not require authentication for connections to certain TCP ports, which allows remote attackers to (1) modify the configuration via a request to the debug service on port 4000 or (2) delete log entries via a request to the log service on port 4001.

Apr 25, 2014
9.3
CVE-2014-0760HIGH

The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion provide an undocumented access method involving the FTP protocol, which could allow a remote attacker to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.

Apr 25, 2014
9.3
CVE-2014-2731HIGH

Multiple unspecified vulnerabilities in the integrated web server in Siemens SINEMA Server before 12 SP1 allow remote attackers to execute arbitrary code via HTTP traffic to port (1) 4999 or (2) 80.

Apr 19, 2014
9.3
CVE-2013-0662HIGH

Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow remote attackers to execute arbitrary code via a large buffer-size value in a Modbus Application Header.

Apr 1, 2014
9.3
CVE-2014-0781HIGH

Heap-based buffer overflow in BKCLogSvr.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via crafted UDP packets.

Mar 14, 2014
9.3
CVE-2013-2817HIGH

An ActiveX control in IcoLaunch.dll in Mitsubishi Electric Automation MC-WorX Suite 8.02 allows user-assisted remote attackers to execute arbitrary programs via a crafted HTML document in conjunction with a Login Client button click.

Feb 24, 2014
9.3
CVE-2013-2782HIGH

Schneider Electric Trio J-Series License Free Ethernet Radio with firmware 3.6.0 through 3.6.3 uses the same AES encryption key across different customers' installations, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.

Aug 28, 2013
9.3
CVE-2013-5021HIGH

Multiple absolute path traversal vulnerabilities in National Instruments cwui.ocx, as used in National Instruments LabWindows/CVI 2012 SP1 and earlier, National Instruments LabVIEW 2012 SP1 and earlier, the Data Analysis component in ABB DataManager 1 through 6.3.6, and other products allow remote attackers to create and execute arbitrary files via a full pathname in an argument to the ExportStyle method in the (1) CWNumEdit, (2) CWGraph, (3) CWBoolean, (4) CWSlide, or (5) CWKnob ActiveX control, in conjunction with file content in the (a) Caption or (b) FormatString property value.

Aug 6, 2013
9.3
CVE-2012-6440HIGH

The Web server password authentication mechanism used by the products is vulnerable to a MitM and Replay attack. Successful exploitation of this vulnerability will allow unauthorized access of the product’s Web server to view and alter product configuration and diagnostics information. Rockwell Automation EtherNet/IP products; 1756-ENBT, 1756-EWEB, 1768-ENBT, and 1768-EWEB communication modules; CompactLogix L32E and L35E controllers; 1788-ENBT FLEXLogix adapter; 1794-AENTR FLEX I/O EtherNet/IP adapter; ControlLogix 18 and earlier; CompactLogix 18 and earlier; GuardLogix 18 and earlier; SoftLogix 18 and earlier; CompactLogix controllers 19 and earlier; SoftLogix controllers 19 and earlier; ControlLogix controllers 20 and earlier; GuardLogix controllers 20 and earlier; and MicroLogix 1100 and 1400

Jan 24, 2013
9.3
CVE-2013-0655HIGH

The client in Schneider Electric Software Update (SESU) Utility 1.0.x and 1.1.x does not ensure that updates have a valid origin, which allows man-in-the-middle attackers to spoof updates, and consequently execute arbitrary code, by modifying the data stream on TCP port 80.

Jan 21, 2013
9.3
CVE-2011-4876HIGH

Directory traversal vulnerability in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime, when Transfer Mode is enabled, allows remote attackers to execute, read, create, modify, or delete arbitrary files via a .. (dot dot) in a string.

Feb 3, 2012
9.3
CVE-2011-4875HIGH

Stack-based buffer overflow in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime, when Transfer Mode is enabled, allows remote attackers to execute arbitrary code via vectors related to Unicode strings.

Feb 3, 2012
9.3
CVE-2011-4508HIGH

The HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime generates predictable authentication tokens for cookies, which makes it easier for remote attackers to bypass authentication via a crafted cookie.

Feb 3, 2012
9.3
CVE-2011-4055HIGH

Buffer overflow in the WebClient ActiveX control in Siemens Tecnomatix FactoryLink 6.6.1 (aka 6.6 SP1), 7.5.217 (aka 7.5 SP2), and 8.0.2.54 allows remote attackers to execute arbitrary code via a long string in a parameter associated with the location URL.

Jan 8, 2012
9.3
CVE-2011-4034HIGH

Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors.

Dec 2, 2011
9.3
CVE-2011-3321HIGH

Heap-based buffer overflow in the Siemens WinCC Runtime Advanced Loader, as used in SIMATIC WinCC flexible Runtime and SIMATIC WinCC (TIA Portal) Runtime Advanced, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted packet to TCP port 2308.

Sep 16, 2011
9.3
CVE-2011-2530HIGH

Buffer overflow in RSEds.dll in RSHWare.exe in the EDS Hardware Installation Tool 1.0.5.1 and earlier in Rockwell Automation RSLinx Classic before 2.58 allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed .eds file.

Jun 22, 2011
9.3
CVE-2011-0340HIGH

Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 61.6.01.05, InduSoft Web Studio before 7.0+SP1, and InduSoft Thin Client 7.0, allow remote attackers to execute arbitrary code via a long (1) InternationalOrder, (2) InternationalSeparator, or (3) LogFileName property value; or (4) a long bstrFileName argument to the OpenScreen method.

May 4, 2011
9.3
CVE-2011-0331HIGH

Use-after-free vulnerability in the addOSPLext method in the Honeywell ScanServer ActiveX control 780.0.20.5 allows remote attackers to execute arbitrary code via a crafted HTML document.

Mar 22, 2011
9.3
CVE-2010-4741HIGH

Stack-based buffer overflow in MDMUtil.dll in MDMTool.exe in MDM Tool before 2.3 in Moxa Device Manager allows remote MDM Gateways to execute arbitrary code via crafted data in a session on TCP port 54321.

Feb 18, 2011
9.3
CVE-2015-3974HIGH

EasyIO EasyIO-30P-SF controllers with firmware before 0.5.21 and 2.x before 2.0.5.21, as used in Accutrol, Bar-Tech Automation, Infocon/EasyIO, Honeywell Automation India, Johnson Controls, SyxthSENSE, Transformative Wave Technologies, Tridium Asia Pacific, and Tridium Europe products, have a hardcoded password, which makes it easier for remote attackers to obtain access via unspecified vectors.

Sep 28, 2015
9.0
CVE-2015-6456HIGH

GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 have hardcoded credentials for a support account, which allows remote attackers to obtain administrative access, and consequently execute arbitrary code, by leveraging knowledge of the password.

Sep 18, 2015
9.0
CVE-2015-4051HIGH

Beckhoff IPC Diagnostics before 1.8 does not properly restrict access to functions in /config, which allows remote attackers to cause a denial of service (reboot or shutdown), create arbitrary users, or possibly have unspecified other impact via a crafted request, as demonstrated by a beckhoff.com:service:cxconfig:1#Write SOAP action to /upnpisapi.

Jun 8, 2015
9.0
CVE-2014-8387HIGH

cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell metacharacters in the pinghost parameter to ping.cgi.

Nov 20, 2014
9.0
CVE-2014-2366HIGH

upAdminPg.asp in Advantech WebAccess before 7.2 allows remote authenticated users to discover credentials by reading HTML source code.

Jul 19, 2014
9.0
CVE-2014-0783HIGH

Stack-based buffer overflow in BKHOdeq.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet.

Mar 14, 2014
9.0
CVE-2026-32059HIGH

OpenClaw version 2026.2.22-2 prior to 2026.2.23 tools.exec.safeBins validation for sort command fails to properly validate GNU long-option abbreviations, allowing attackers to bypass denied-flag checks via abbreviated options. Remote attackers can execute sort commands with abbreviated long options to skip approval requirements in allowlist mode.

Mar 11, 2026
8.8
CVE-2024-55022HIGH

Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain an authenticated command injection vulnerability via the HMI Name parameter.

Mar 3, 2026
8.8
CVE-2025-10314HIGH

Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation FREQSHIP-mini for Windows versions 8.0.0 to 8.0.2 allows a local attacker to execute arbitrary code with system privileges by replacing service executable files (EXE) or DLLs in the installation directory with specially crafted files. As a result, the attacker may be able to disclose, tamper with, delete, or destroy information stored on the PC where the affected product is installed, or cause a Denial of Service (DoS) condition on the affected system.

Feb 5, 2026
8.8
CVE-2025-4676HIGH

Incorrect Implementation of Authentication Algorithm vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects WebPro SNMP Card PowerValue: through 1.1.8.K; WebPro SNMP Card PowerValue UL: through 1.1.8.K.

Jan 7, 2026
8.8
CVE-2025-14849HIGH

Advantech WebAccess/SCADA  is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code.

Dec 18, 2025
8.8
CVE-2025-10205HIGH

Use of a One-Way Hash with a Predictable Salt vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5. and newer versions

Sep 17, 2025
8.8
CVE-2025-9065HIGH

A server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of input sanitization. Authenticated attackers can exploit this vulnerability by specifying external SMB paths, exposing the ThinServer® service account NTLM hash.

Sep 9, 2025
8.8
CVE-2025-53515HIGH

A vulnerability exists in Advantech iView that allows for SQL injection and remote code execution through NetworkServlet.archiveTrap(). This issue requires an authenticated attacker with at least user-level privileges. Certain input parameters are not sanitized, allowing an attacker to perform SQL injection and potentially execute code in the context of the 'nt authority\local service' account.

Jul 11, 2025
8.8
CVE-2025-53475HIGH

A vulnerability exists in Advantech iView that could allow for SQL injection and remote code execution through NetworkServlet.getNextTrapPage(). This issue requires an authenticated attacker with at least user-level privileges. Certain parameters in this function are not properly sanitized, allowing an attacker to perform SQL injection and potentially execute code in the context of the 'nt authority\local service' account.

Jul 11, 2025
8.8
CVE-2025-52577HIGH

A vulnerability exists in Advantech iView that could allow SQL injection and remote code execution through NetworkServlet.archiveTrapRange(). This issue requires an authenticated attacker with at least user-level privileges. Certain input parameters are not properly sanitized, allowing an attacker to perform SQL injection and potentially execute code in the context of the 'nt authority\local service' account.

Jul 11, 2025
8.8
CVE-2024-41969HIGH

A low privileged remote attacker may modify the configuration of the CODESYS V3 service through a missing authentication vulnerability which could lead to full system access and/or DoS.

Nov 18, 2024
8.8
CVE-2024-42417HIGH

Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script Handler_CFG.ashx. An authenticated attacker may be able to exploit this issue to cause delay in the targeted product.

Oct 3, 2024
8.8
CVE-2024-38308HIGH

Advantech ADAM 5550's web application includes a "logs" page where all the HTTP requests received are displayed to the user. The device doesn't correctly neutralize malicious code when parsing HTTP requests to generate page output.

Sep 27, 2024
8.8
CVE-2024-8533HIGH

A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due to improper default file permissions allowing users to exfiltrate credentials and escalate privileges.

Sep 12, 2024
8.8
CVE-2024-45044HIGH

Bareos is open source software for backup, archiving, and recovery of data for operating systems. When a command ACL is in place and a user executes a command in bconsole using an abbreviation (i.e. "w" for "whoami") the ACL check did not apply to the full form (i.e. "whoami") but to the abbreviated form (i.e. "w"). If the command ACL is configured with negative ACL that should forbid using the "whoami" command, you could still use "w" or "who" as a command successfully. Fixes for the problem are shipped in Bareos versions 23.0.4, 22.1.6 and 21.1.11. If only positive command ACLs are used without any negation, the problem does not occur.

Sep 10, 2024
8.8
CVE-2020-11640HIGH

AdvaBuild uses a command queue to launch certain operations. An attacker who gains access to the command queue can use it to launch an attack by running any executable on the AdvaBuild node. The executables that can be run are not limited to AdvaBuild specific executables.  Improper Privilege Management vulnerability in ABB Advant MOD 300 AdvaBuild.This issue affects Advant MOD 300 AdvaBuild: from 3.0 through 3.7 SP2.

Jul 23, 2024
8.8
CVE-2024-39883HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of the current process.

Jul 9, 2024
8.8
CVE-2024-39882HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of the current process.

Jul 9, 2024
8.8
CVE-2024-39881HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a memory corruption condition. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of the current process.

Jul 9, 2024
8.8
CVE-2024-4007HIGH

Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured.

Jul 1, 2024
8.8
CVE-2023-51603HIGH

Honeywell Saia PG5 Controls Suite CAB File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Honeywell Saia PG5 Controls Suite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CAB files. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user. . Was ZDI-CAN-18592.

May 3, 2024
8.8
CVE-2023-51599HIGH

Honeywell Saia PG5 Controls Suite Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Honeywell Saia PG5 Controls Suite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ZIP files. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user. . Was ZDI-CAN-18412.

May 3, 2024
8.8
CVE-2024-34033HIGH

Delta Electronics DIAEnergie has insufficient input validation which makes it possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists on the file system, then the original file will be overwritten.

May 3, 2024
8.8
CVE-2024-34032HIGH

Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the GetDIACloudList endpoint. An authenticated attacker can exploit this issue to potentially compromise the system on which DIAEnergie is deployed.

May 3, 2024
8.8
CVE-2024-34031HIGH

Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the script Handler_CFG.ashx. An authenticated attacker can exploit this issue to potentially compromise the system on which DIAEnergie is deployed.

May 3, 2024
8.8
CVE-2023-43824HIGH

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wTitleTextLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.

Jan 18, 2024
8.8
CVE-2023-43823HIGH

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wTTitleLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.

Jan 18, 2024
8.8
CVE-2023-43822HIGH

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesTimeLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.

Jan 18, 2024
8.8
CVE-2023-43821HIGH

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesActionLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.

Jan 18, 2024
8.8
CVE-2023-43820HIGH

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesPrevValueLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.

Jan 18, 2024
8.8
CVE-2023-43819HIGH

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the InitialMacroLen field of a DPS file. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.

Jan 18, 2024
8.8
CVE-2023-43818HIGH

A buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve remote code execution.

Jan 18, 2024
8.8
CVE-2023-50466HIGH

An authenticated command injection vulnerability in Weintek cMT2078X easyweb Web Version v2.1.3, OS v20220215 allows attackers to execute arbitrary code or access sensitive information via injecting a crafted payload into the HMI Name parameter.

Dec 19, 2023
8.8
CVE-2023-46690HIGH

In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an attacker to write to any file to any location of the filesystem, which could lead to remote code execution.

Nov 30, 2023
8.8
CVE-2023-40145HIGH

In Weintek's cMT3000 HMI Web CGI device, an anonymous attacker can execute arbitrary commands after login to the device.

Oct 19, 2023
8.8
CVE-2023-29463HIGH

The JMX Console within the Rockwell Automation Pavilion8 is exposed to application users and does not require authentication. If exploited, a malicious user could potentially retrieve other application users’ session data and or log users out of their session.

Sep 12, 2023
8.8
CVE-2023-37861HIGH

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated remote attacker can execute code with root permissions with a specially crafted HTTP POST when uploading a certificate to the device.

Aug 9, 2023
8.8
CVE-2023-3573HIGH

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a command injection in a HTTP POST request releated to font configuration operations to gain full access to the device.

Aug 8, 2023
8.8
CVE-2023-3571HIGH

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a specific HTTP POST releated to certificate operations to gain full access to the device.

Aug 8, 2023
8.8
CVE-2023-3570HIGH

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a specific HTTP DELETE request to gain full access to the device.

Aug 8, 2023
8.8
CVE-2022-4046HIGH

In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user privileges to gain full access of the device.

Aug 3, 2023
8.8
CVE-2023-3663HIGH

In CODESYS Development System versions from 3.5.11.20 and before 3.5.19.20 a missing integrity check might allow an unauthenticated remote attacker to manipulate the content of notifications received via HTTP by the CODESYS notification server.

Aug 3, 2023
8.8
CVE-2023-3983HIGH

An authenticated SQL injection vulnerability exists in Advantech iView versions prior to v5.7.4 build 6752. An authenticated remote attacker can bypass checks in com.imc.iview.utils.CUtils.checkSQLInjection() to perform blind SQL injection.

Jul 31, 2023
8.8
CVE-2023-2072HIGH

The Rockwell Automation PowerMonitor 1000 contains stored cross-site scripting vulnerabilities within the web page of the product.  The vulnerable pages do not require privileges to access and can be injected with code by an attacker which could be used to leverage an attack on an authenticated user resulting in remote code execution and potentially the complete loss of confidentiality, integrity, and availability of the product.

Jul 11, 2023
8.8
CVE-2023-3256HIGH

Advantech R-SeeNet versions 2.4.22 allows low-level users to access and load the content of local files.

Jun 22, 2023
8.8
CVE-2023-0863HIGH

Improper Authentication vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC wallbox (CE) (Terra AC MID), ABB Terra AC wallbox (CE) Terra AC Juno CE, ABB Terra AC wallbox (CE) Terra AC PTB, ABB Terra AC wallbox (CE) Symbiosis, ABB Terra AC wallbox (JP).This issue affects Terra AC wallbox (UL40/80A): from 1.0;0 through 1.5.5; Terra AC wallbox (UL32A) : from 1.0;0 through 1.6.5; Terra AC wallbox (CE) (Terra AC MID): from 1.0;0 through 1.6.5; Terra AC wallbox (CE) Terra AC Juno CE: from 1.0;0 through 1.6.5; Terra AC wallbox (CE) Terra AC PTB : from 1.0;0 through 1.5.25; Terra AC wallbox (CE) Symbiosis: from 1.0;0 through 1.2.7; Terra AC wallbox (JP): from 1.0;0 through 1.6.5.

May 17, 2023
8.8
CVE-2022-47390HIGH

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

May 15, 2023
8.8
CVE-2022-47389HIGH

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

May 15, 2023
8.8
CVE-2022-47388HIGH

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

May 15, 2023
8.8
CVE-2022-47387HIGH

An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

May 15, 2023
8.8
CVE-2022-47386HIGH

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

May 15, 2023
8.8
CVE-2022-47385HIGH

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpAppForce Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

May 15, 2023
8.8
CVE-2022-47384HIGH

An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

May 15, 2023
8.8
CVE-2022-47383HIGH

An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

May 15, 2023
8.8
CVE-2022-47382HIGH

An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

May 15, 2023
8.8
CVE-2022-47381HIGH

An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

May 15, 2023
8.8
CVE-2022-47380HIGH

An authenticated remote attacker may use a stack based  out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

May 15, 2023
8.8
CVE-2022-47379HIGH

An authenticated, remote attacker may use a out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into memory which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

May 15, 2023
8.8
CVE-2023-2575HIGH

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stack-based Buffer Overflow vulnerability, which can be triggered by authenticated users via a crafted POST request.

May 8, 2023
8.8
CVE-2023-2574HIGH

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the device name input field, which can be triggered by authenticated users via a crafted POST request.

May 8, 2023
8.8
CVE-2023-2573HIGH

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the NTP server input field, which can be triggered by authenticated users via a crafted POST request.

May 8, 2023
8.8
CVE-2023-1109HIGH

In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughout the file system using specially crafted URLs via the upload and download functionality of the web service. This may lead to full control of the service.

Apr 17, 2023
8.8
CVE-2023-1144HIGH

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contains an improper access control vulnerability in which an attacker can use the Device-Gateway service and bypass authorization, which could result in privilege escalation.

Mar 27, 2023
8.8
CVE-2023-1143HIGH

In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use Lua scripts, which could allow an attacker to remotely execute arbitrary code.

Mar 27, 2023
8.8
CVE-2023-1141HIGH

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a command injection vulnerability that could allow an attacker to inject arbitrary commands, which could result in remote code execution.

Mar 27, 2023
8.8
CVE-2023-1139HIGH

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-gateway service, which could allow deserialization of requests prior to authentication, resulting in remote code execution.

Mar 27, 2023
8.8
CVE-2022-4224HIGH

In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files and OS resources or DoS the device.

Mar 23, 2023
8.8
CVE-2018-25048HIGH

The CODESYS runtime system in multiple versions allows an remote low privileged attacker to use a path traversal vulnerability to access and modify all system files as well as DoS the device.

Mar 23, 2023
8.8
CVE-2023-0228HIGH

Improper Authentication vulnerability in ABB Symphony Plus S+ Operations.This issue affects Symphony Plus S+ Operations: from 2.X through 2.1 SP2, 2.2, from 3.X through 3.3 SP1, 3.3 SP2.

Mar 2, 2023
8.8
CVE-2023-0444HIGH

A privilege escalation vulnerability exists in Delta Electronics InfraSuite Device Master 00.00.02a. A default user 'User', which is in the 'Read Only User' group, can view the password of another default user 'Administrator', which is in the 'Administrator' group. This allows any lower privileged user to log in as an administrator.

Jan 26, 2023
8.8
CVE-2022-42139HIGH

Delta Electronics DVW-W02W2-E2 1.5.0.10 is vulnerable to Command Injection via Crafted URL.

Dec 14, 2022
8.8
CVE-2022-43506HIGH

SQL Injection in HandlerTag_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network

Nov 17, 2022
8.8
CVE-2022-43457HIGH

SQL Injection in HandlerPage_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network

Nov 17, 2022
8.8
CVE-2022-43452HIGH

SQL Injection in FtyInfoSetting.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network

Nov 17, 2022
8.8
CVE-2022-43447HIGH

SQL Injection in AM_EBillAnalysis.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network

Nov 17, 2022
8.8
CVE-2022-41775HIGH

SQL Injection in Handler_CFG.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network

Nov 17, 2022
8.8
CVE-2022-41779HIGH

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize network packets without proper verification. If the device connects to an attacker-controlled server, the attacker could send maliciously crafted packets that would be deserialized and executed, leading to remote code execution.

Oct 31, 2022
8.8
CVE-2022-41644HIGH

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lacks authentication for a function that changes group privileges. An attacker could use this to create a denial-of-service state or escalate their own privileges.

Oct 31, 2022
8.8
CVE-2022-3158HIGH

Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an input validation vulnerability. The FactoryTalk VantagePoint SQL Server lacks input validation when users enter SQL statements to retrieve information from the back-end database. If successfully exploited, this could allow a user with basic user privileges to perform remote code execution on the server.

Oct 17, 2022
8.8
CVE-2022-38743HIGH

Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an improper access control vulnerability. The FactoryTalk VantagePoint SQL Server account could allow a malicious user with read-only privileges to execute SQL statements in the back-end database. If successfully exploited, this could allow the attacker to execute arbitrary code and gain access to restricted data.

Oct 17, 2022
8.8
CVE-2022-2333HIGH

If an attacker manages to trick a valid user into loading a malicious DLL, the attacker may be able to achieve code execution in Honeywell SoftMaster version 4.51 application’s context and permissions.

Sep 16, 2022
8.8
CVE-2022-30243HIGH

Honeywell Alerton Visual Logic through 2022-05-04 allows unauthenticated programming writes from remote users. This enables code to be stored on the controller and then run without verification. A user with malicious intent can send a crafted packet to change and/or stop the program without the knowledge of other users, altering the controller's function. After the programming change, the program needs to be overwritten in order for the controller to restore its original operational function.

Jul 15, 2022
8.8
CVE-2022-32143HIGH

In multiple CODESYS products, file download and upload function allows access to internal files in the working directory e.g. firmware files of the PLC. All requests are processed on the controller only if no level 1 password is configured on the controller or if remote attacker has previously successfully authenticated himself to the controller. A successful Attack may lead to a denial of service, change of local files, or drain of confidential Information. User interaction is not required

Jun 24, 2022
8.8
CVE-2022-32138HIGH

In multiple CODESYS products, a remote attacker may craft a request which may cause an unexpected sign extension, resulting in a denial-of-service condition or memory overwrite.

Jun 24, 2022
8.8
CVE-2022-32137HIGH

In multiple CODESYS products, a low privileged remote attacker may craft a request, which may cause a heap-based buffer overflow, resulting in a denial-of-service condition or memory overwrite. User interaction is not required.

Jun 24, 2022
8.8
CVE-2022-22729HIGH

CAMS for HIS Server contained in the following Yokogawa Electric products improperly authenticate the receiving packets. The authentication may be bypassed via some crafted packets: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, and Exaopc versions from R3.72.00 to R3.79.00.

Mar 11, 2022
8.8
CVE-2022-21808HIGH

Path traversal vulnerability exists in CAMS for HIS Server contained in the following Yokogawa Electric products: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00.

Mar 11, 2022
8.8
CVE-2022-22509HIGH

In Phoenix Contact FL SWITCH Series 2xxx in version 3.00 an incorrect privilege assignment allows an low privileged user to enable full access to the device configuration.

Feb 2, 2022
8.8
CVE-2021-40396HIGH

A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iService 1.1.7. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.

Jan 28, 2022
8.8
CVE-2021-40389HIGH

A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iEdge Server 1.0.2. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.

Jan 28, 2022
8.8
CVE-2021-40388HIGH

A privilege escalation vulnerability exists in Advantech SQ Manager Server 1.0.6. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.

Jan 28, 2022
8.8
CVE-2021-21917HIGH

An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at '‘ord’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.

Dec 22, 2021
8.8
CVE-2021-21916HIGH

An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at 'description_filter’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.

Dec 22, 2021
8.8
CVE-2021-21915HIGH

An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at ‘company_filter’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.

Dec 22, 2021
8.8
CVE-2021-38418HIGH

Delta Electronics DIALink versions 1.2.4.0 and prior runs by default on HTTP, which may allow an attacker to be positioned between the traffic and perform a machine-in-the-middle attack to access information without authorization.

Nov 3, 2021
8.8
CVE-2021-39279HIGH

Certain MOXA devices allow Authenticated Command Injection via /forms/web_importTFTP. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T 2.1, OnCell G3470A-LTE-EU 1.7, OnCell G3470A-LTE-EU-T 1.7, TAP-323-EU-CT-T 1.3, TAP-323-US-CT-T 1.3, TAP-323-JP-CT-T 1.3, WDR-3124A-EU 2.3, WDR-3124A-EU-T 2.3, WDR-3124A-US 2.3, and WDR-3124A-US-T 2.3.

Sep 7, 2021
8.8
CVE-2021-20994HIGH

In multiple managed switches by WAGO in different versions an attacker may trick a legitimate user to click a link to inject possible malicious code into the Web-Based Management.

May 13, 2021
8.8
CVE-2021-29238HIGH

CODESYS Automation Server before 1.16.0 allows cross-site request forgery (CSRF).

May 3, 2021
8.8
CVE-2020-13555HIGH

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In COM Server Application Privilege Escalation, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.

Feb 17, 2021
8.8
CVE-2020-13553HIGH

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webvrpcs Run Key Privilege Escalation in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.

Feb 17, 2021
8.8
CVE-2020-13552HIGH

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via multiple service executables in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.

Feb 17, 2021
8.8
CVE-2020-13551HIGH

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via PostgreSQL executable, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.

Feb 17, 2021
8.8
CVE-2020-27261HIGH

The Omron CX-One Version 4.60 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.

Feb 9, 2021
8.8
CVE-2020-27259HIGH

The Omron CX-One Version 4.60 and prior may allow an attacker to supply a pointer to arbitrary memory locations, which may allow an attacker to remotely execute arbitrary code.

Feb 9, 2021
8.8
CVE-2020-25198HIGH

The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has incorrectly implemented protections from session fixation, which may allow an attacker to gain access to a session and hijack it by stealing the user’s cookies.

Dec 23, 2020
8.8
CVE-2020-25194HIGH

The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has improper privilege management, which may allow an attacker with user privileges to perform requests with administrative privileges.

Dec 23, 2020
8.8
CVE-2020-12519HIGH

On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use this vulnerability i.e. to open a reverse shell with root privileges.

Dec 17, 2020
8.8
CVE-2020-12517HIGH

On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an authenticated low privileged user could embed malicious Javascript code to gain admin rights when the admin user visits the vulnerable website (local privilege escalation).

Dec 17, 2020
8.8
CVE-2020-12033HIGH

In Rockwell Automation FactoryTalk Services Platform, all versions, the redundancy host service (RdcyHost.exe) does not validate supplied identifiers, which could allow an unauthenticated, adjacent attacker to execute remote COM objects with elevated privileges.

Jun 23, 2020
8.8
CVE-2020-12026HIGH

Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow a low privilege user to overwrite files outside the application’s control.

May 8, 2020
8.8
CVE-2020-6081HIGH

An exploitable code execution vulnerability exists in the PLC_Task functionality of 3S-Smart Software Solutions GmbH CODESYS Runtime 3.5.14.30. A specially crafted network request can cause remote code execution. An attacker can send a malicious packet to trigger this vulnerability.

May 7, 2020
8.8
CVE-2020-8477HIGH

The installations for ABB System 800xA Information Manager versions 5.1, 6.0 to 6.0.3.2 and 6.1 wrongly contain an auxiliary component. An attacker is able to use this for an XSS-like attack to an authenticated local user, which might lead to execution of arbitrary code.

Apr 22, 2020
8.8
CVE-2020-10607HIGH

In Advantech WebAccess, Versions 8.4.2 and prior. A stack-based buffer overflow vulnerability caused by a lack of proper validation of the length of user-supplied data may allow remote code execution.

Mar 27, 2020
8.8
CVE-2020-6982HIGH

In Honeywell WIN-PAK 4.7.2, Web and prior versions, the header injection vulnerability has been identified, which may allow remote code execution.

Mar 24, 2020
8.8
CVE-2020-7005HIGH

In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable to a cross-site request forgery, which may allow an attacker to remotely execute arbitrary code.

Mar 24, 2020
8.8
CVE-2020-5546HIGH

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier allows an attacker on the same network segment to stop the network functions or execute malware via a specially crafted packet.

Mar 16, 2020
8.8
CVE-2020-9436HIGH

PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.03.17, and TC CLOUD CLIENT 1002-TXTX through 1.03.17 devices allow authenticated users to inject system commands through a modified POST request to a specific URL.

Mar 12, 2020
8.8
CVE-2019-9102HIGH

An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. A predictable mechanism of generating tokens allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism.

Mar 11, 2020
8.8
CVE-2019-5162HIGH

An exploitable improper access control vulnerability exists in the iw_webs account settings functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause the overwrite of an existing user account password, resulting in remote shell access to the device as that user. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

Feb 25, 2020
8.8
CVE-2019-5153HIGH

An exploitable remote code execution vulnerability exists in the iw_webs configuration parsing functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause an overflow of an error message buffer, resulting in remote code execution. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

Feb 25, 2020
8.8
CVE-2019-5143HIGH

An exploitable format string vulnerability exists in the iw_console conio_writestr functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted time server entry can cause an overflow of the time server buffer, resulting in remote code execution. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

Feb 25, 2020
8.8
CVE-2019-5141HIGH

An exploitable command injection vulnerability exists in the iw_webs functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted iw_serverip parameter can cause user input to be reflected in a subsequent iw_system call, resulting in remote control over the device. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

Feb 25, 2020
8.8
CVE-2019-5140HIGH

An exploitable command injection vulnerability exists in the iwwebs functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted diagnostic script file name can cause user input to be reflected in a subsequent iwsystem call, resulting in remote control over the device. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

Feb 25, 2020
8.8
CVE-2019-5136HIGH

An exploitable privilege escalation vulnerability exists in the iw_console functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted menu selection string can cause an escape from the restricted console, resulting in system access as the root user. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

Feb 25, 2020
8.8
CVE-2020-8997HIGH

Older generation Abbott FreeStyle Libre sensors allow remote attackers within close proximity to enable write access to memory via a specific NFC unlock command. NOTE: The vulnerability is not present in the FreeStyle Libre 14-day in the U.S (announced in August 2018) and FreeStyle Libre 2 outside the U.S (announced in October 2018).

Feb 16, 2020
8.8
CVE-2020-8858HIGH

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Moxa MGate 5105-MB-EIP firmware version 4.1. Authentication is required to exploit this vulnerability. The specific flaw exists within the DestIP parameter within MainPing.asp. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-9552.

Feb 14, 2020
8.8
CVE-2019-10995HIGH

ABB CP651 HMI products revision BSP UN30 v1.76 and prior implement hidden administrative accounts that are used during the provisioning phase of the HMI interface.

Jan 14, 2020
8.8
CVE-2019-18251HIGH

In Omron CX-Supervisor, Versions 3.5 (12) and prior, Omron CX-Supervisor ships with Teamviewer Version 5.0.8703 QS. This version of Teamviewer is vulnerable to an obsolete function vulnerability requiring user interaction to exploit.

Nov 26, 2019
8.8
CVE-2019-9008HIGH

An issue was discovered in 3S-Smart CODESYS V3 through 3.5.12.30. A user with low privileges can take full control over the runtime.

Sep 17, 2019
8.8
CVE-2019-9013HIGH

An issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based encryption, which results in user credentials being insufficiently protected during transport. All variants of the following CODESYS V3 products in all versions containing the CmpUserMgr component are affected regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control RTE V3, CODESYS Control RTE V3 (for Beckhoff CX), CODESYS Control Win V3 (also part of the CODESYS Development System setup), CODESYS V3 Simulation Runtime (part of the CODESYS Development System), CODESYS Control V3 Runtime System Toolkit, CODESYS HMI V3.

Aug 15, 2019
8.8
CVE-2019-10961HIGH

In Advantech WebAccess HMI Designer Version 2.1.9.23 and prior, processing specially crafted MCR files lacking proper validation of user supplied data may cause the system to write outside the intended buffer area, allowing remote code execution.

Aug 2, 2019
8.8
CVE-2018-11427HIGH

CSRF tokens are not used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior, which makes it possible to perform CSRF attacks on the device administrator.

Jul 3, 2019
8.8
CVE-2019-7225HIGH

The ABB HMI components implement hidden administrative accounts that are used during the provisioning phase of the HMI interface. These credentials allow the provisioning tool "Panel Builder 600" to flash a new interface and Tags (MODBUS coils) mapping to the HMI. These credentials are the idal123 password for the IdalMaster account, and the exor password for the exor account. These credentials are used over both HTTP(S) and FTP. There is no option to disable or change these undocumented credentials. An attacker can use these credentials to login to ABB HMI to read/write HMI configuration files and also to reset the device. This affects ABB CP635 HMI, CP600 HMIClient, Panel Builder 600, IDAL FTP server, IDAL HTTP server, and multiple other HMI components.

Jun 27, 2019
8.8
CVE-2019-7226HIGH

The ABB IDAL HTTP server CGI interface contains a URL that allows an unauthenticated attacker to bypass authentication and gain access to privileged functions. Specifically, /cgi/loginDefaultUser creates a session in an authenticated state and returns the session ID along with what may be the username and cleartext password of the user. An attacker can then supply an IDALToken value in a cookie, which will allow them to perform privileged operations such as restarting the service with /cgi/restart. A GET request to /cgi/loginDefaultUser may result in "1 #S_OK IDALToken=532c8632b86694f0232a68a0897a145c admin admin" or a similar response.

Jun 27, 2019
8.8
CVE-2019-7228HIGH

The ABB IDAL HTTP server mishandles format strings in a username or cookie during the authentication process. Attempting to authenticate with the username %25s%25p%25x%25n will crash the server. Sending %08x.AAAA.%08x.%08x will log memory content from the stack.

Jun 27, 2019
8.8
CVE-2019-7232HIGH

The ABB IDAL HTTP server is vulnerable to a buffer overflow when a long Host header is sent in a web request. The Host header value overflows a buffer and overwrites a Structured Exception Handler (SEH) address. An unauthenticated attacker can submit a Host header value of 2047 bytes or more to overflow the buffer and overwrite the SEH address, which can then be leveraged to execute attacker-controlled code on the server.

Jun 24, 2019
8.8
CVE-2019-7230HIGH

The ABB IDAL FTP server mishandles format strings in a username during the authentication process. Attempting to authenticate with the username %s%p%x%d will crash the server. Sending %08x.AAAA.%08x.%08x will log memory content from the stack.

Jun 24, 2019
8.8
CVE-2019-12870HIGH

An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to an Uninitialized Pointer and remote code execution. The attacker needs to get access to an original PC Worx or Config+ project file to be able to manipulate it. After manipulation, the attacker needs to exchange the original file with the manipulated one on the application programming workstation.

Jun 24, 2019
8.8
CVE-2019-12869HIGH

An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to an Out-Of-Bounds Read, Information Disclosure, and remote code execution. The attacker needs to get access to an original PC Worx or Config+ project file to be able to manipulate it. After manipulation, the attacker needs to exchange the original file with the manipulated one on the application programming workstation.

Jun 24, 2019
8.8
CVE-2019-12871HIGH

An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to a Use-After-Free and remote code execution. The attacker needs to get access to an original PC Worx or Config+ project file to be able to manipulate it. After manipulation, the attacker needs to exchange the original file with the manipulated one on the application programming workstation.

Jun 24, 2019
8.8
CVE-2019-6584HIGH

A vulnerability has been identified in SIEMENS LOGO!8 (6ED1052-xyyxx-0BA8 FS:01 to FS:06 / Firmware version V1.80.xx and V1.81.xx), SIEMENS LOGO!8 (6ED1052-xyy08-0BA0 FS:01 / Firmware version < V1.82.02). The integrated webserver does not invalidate the Session ID upon user logout. An attacker that successfully extracted a valid Session ID is able to use it even after the user logs out. The security vulnerability could be exploited by an attacker in a privileged network position who is able to read the communication between the affected device and the user or by an attacker who is able to obtain valid Session IDs through other means. The user must invoke a session to the affected device. At the time of advisory publication no public exploitation of this security vulnerability was known.

Jun 12, 2019
8.8
CVE-2018-10703HIGH

An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run scripts on the device to troubleshoot any issues. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "iw_serverip" is susceptible to buffer overflow. By crafting a packet that contains a string of 480 characters, it is possible for an attacker to execute the attack.

Jun 7, 2019
8.8
CVE-2018-10702HIGH

An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run scripts on the device to troubleshoot any issues. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "iw_filename" is susceptible to command injection via shell metacharacters.

Jun 7, 2019
8.8
CVE-2018-10701HIGH

An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run scripts on the device to troubleshoot any issues. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "iw_filename" is susceptible to buffer overflow. By crafting a packet that contains a string of 162 characters, it is possible for an attacker to execute the attack.

Jun 7, 2019
8.8
CVE-2018-10699HIGH

An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides certfile upload functionality so that an administrator can upload a certificate file used for connecting to the wireless network. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "iw_privatePass" is susceptible to this injection. By crafting a packet that contains shell metacharacters, it is possible for an attacker to execute the attack.

Jun 7, 2019
8.8
CVE-2018-10697HIGH

An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides ping functionality so that an administrator can execute ICMP calls to check if the network is working correctly. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "srvName" is susceptible to this injection. By crafting a packet that contains shell metacharacters, it is possible for an attacker to execute the attack.

Jun 7, 2019
8.8
CVE-2018-10696HIGH

An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a web interface to allow an administrator to manage the device. However, this interface is not protected against CSRF attacks, which allows an attacker to trick an administrator into executing actions without his/her knowledge, as demonstrated by the forms/iw_webSetParameters and forms/webSetMainRestart URIs.

Jun 7, 2019
8.8
CVE-2018-10695HIGH

An issue was discovered on Moxa AWK-3121 1.14 devices. It provides alert functionality so that an administrator can send emails to his/her account when there are changes to the device's network. However, the same functionality allows an attacker to execute commands on the device. The POST parameters "to1,to2,to3,to4" are all susceptible to buffer overflow. By crafting a packet that contains a string of 678 characters, it is possible for an attacker to execute the attack.

Jun 7, 2019
8.8
CVE-2018-10693HIGH

An issue was discovered on Moxa AWK-3121 1.14 devices. It provides ping functionality so that an administrator can execute ICMP calls to check if the network is working correctly. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "srvName" is susceptible to a buffer overflow. By crafting a packet that contains a string of 516 characters, it is possible for an attacker to execute the attack.

Jun 7, 2019
8.8
CVE-2018-13993HIGH

The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is prone to CSRF.

May 7, 2019
8.8
CVE-2019-9744HIGH

An issue was discovered on PHOENIX CONTACT FL NAT SMCS 8TX, FL NAT SMN 8TX, FL NAT SMN 8TX-M, and FL NAT SMN 8TX-M-DMG devices. There is unauthorized access to the WEB-UI by attackers arriving from the same source IP address as an authenticated user, because this IP address is used as a session identifier.

Mar 26, 2019
8.8
CVE-2019-9743HIGH

An issue was discovered on PHOENIX CONTACT RAD-80211-XD and RAD-80211-XD/HP-BUS devices. Command injection can occur in the WebHMI component.

Mar 26, 2019
8.8
CVE-2015-6458HIGH

Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution. Moxa released SoftCMS version 1.4 on June 1, 2015, to address the vulnerability.

Mar 21, 2019
8.8
CVE-2015-6457HIGH

Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution. Moxa released SoftCMS version 1.4 on June 1, 2015, to address the vulnerability.

Mar 21, 2019
8.8
CVE-2019-6561HIGH

Cross-site request forgery has been identified in Moxa IKS and EDS, which may allow for the execution of unauthorized actions on the device.

Mar 5, 2019
8.8
CVE-2018-19660HIGH

An exploitable authenticated command-injection vulnerability exists in the web server functionality of Moxa NPort W2x50A products with firmware before 2.2 Build_18082311. A specially crafted HTTP POST request to /goform/webSettingProfileSecurity can result in running OS commands as the root user.

Dec 6, 2018
8.8
CVE-2018-19659HIGH

An exploitable authenticated command-injection vulnerability exists in the web server functionality of Moxa NPort W2x50A products with firmware before 2.2 Build_18082311. A specially crafted HTTP POST request to /goform/net_WebPingGetValue can result in running OS commands as the root user. This is similar to CVE-2017-12120.

Dec 6, 2018
8.8
CVE-2018-15704HIGH

Advantech WebAccess 8.3.2 and below is vulnerable to a stack buffer overflow vulnerability. A remote authenticated attacker could potentially exploit this vulnerability by sending a crafted HTTP request to broadweb/system/opcImg.asp.

Oct 22, 2018
8.8
CVE-2018-18392HIGH

Privilege Escalation via Broken Access Control in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

Oct 19, 2018
8.8
CVE-2018-18391HIGH

User Privilege Escalation in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

Oct 19, 2018
8.8
CVE-2018-16282HIGH

A command injection vulnerability in the web server functionality of Moxa EDR-810 V4.2 build 18041013 allows remote attackers to execute arbitrary OS commands with root privilege via the caname parameter to the /xml/net_WebCADELETEGetValue URI.

Sep 20, 2018
8.8
CVE-2018-12980HIGH

An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability allows an authenticated user to upload arbitrary files to the file system with the permissions of the web server.

Jul 12, 2018
8.8
CVE-2018-13793HIGH

Multiple Cross Site Request Forgery (CSRF) vulnerabilities in the HTTP API in ABBYY FlexiCapture before 12 Release 1 Update 7 exist in Web Verification, Web Scanning, Web Capture, Monitoring and Administration, and Login.

Jul 9, 2018
8.8
CVE-2018-7782HIGH

In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, authenticated users can view passwords in clear text.

Jul 3, 2018
8.8
CVE-2018-7781HIGH

In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, by sending a specially crafted request an authenticated user can view password in clear text and results in privilege escalation.

Jul 3, 2018
8.8
CVE-2018-7777HIGH

The vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A remote, authenticated attacker can exploit this vulnerability by sending a crafted request to the target server.

Jul 3, 2018
8.8
CVE-2018-7774HIGH

The vulnerability exists within processing of localize.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the username input parameter.

Jul 3, 2018
8.8
CVE-2018-7773HIGH

The vulnerability exists within processing of nfcserver.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the sessionid input parameter.

Jul 3, 2018
8.8
CVE-2018-7772HIGH

The vulnerability exists within processing of applets which are exposed on the web service in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query to determine whether a user is logged in is subject to SQL injection on the loginSeed parameter, which can be embedded in the HTTP cookie of the request.

Jul 3, 2018
8.8
CVE-2018-7769HIGH

The vulnerability exists within processing of xmlserver.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the id input parameter.

Jul 3, 2018
8.8
CVE-2018-7768HIGH

The vulnerability exists within processing of loadtemplate.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the tpl input parameter.

Jul 3, 2018
8.8
CVE-2018-7767HIGH

The vulnerability exists within processing of editobject.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the type input parameter.

Jul 3, 2018
8.8
CVE-2018-7766HIGH

The vulnerability exists within processing of track_getdata.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the id input parameter.

Jul 3, 2018
8.8
CVE-2018-7765HIGH

The vulnerability exists within processing of track_import_export.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the object_id input parameter.

Jul 3, 2018
8.8
CVE-2018-4845HIGH

A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 500 systems (All versions_without_ use of Siemens Healthineers Informatics products), RAPIDLab 1200 Series (All versions < V3.3 _with_ Siemens Healthineers Informatics products), RAPIDPoint 500 systems (All versions >= V3.0 _with_ Siemens Healthineers Informatics products), RAPIDPoint 500 systems (V2.4.X_with_ Siemens Healthineers Informatics products), RAPIDPoint 500 systems (All versions =< V2.3 _with_ Siemens Healthineers Informatics products), RAPIDPoint 400 systems (All versions _with_ Siemens Healthineers Informatics products). Remote attackers with either local or remote credentialed access to the "Remote View" feature might be able to elevate their privileges, compromising confidentiality, integrity, and availability of the system. No special skills or user interaction are required to perform this attack. At the time of advisory publication, no public exploitation of this security vulnerability is known. Siemens Healthineers confirms the security vulnerability and provides mitigations to resolve the security issue.

Jun 26, 2018
8.8
CVE-2017-7906HIGH

In ABB IP GATEWAY 3.39 and prior, the web server does not sufficiently verify that a request was performed by the authenticated user, which may allow an attacker to launch a request impersonating that user.

Jun 6, 2018
8.8
CVE-2017-14434HIGH

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attacker can inject OS commands into the remoteNetmask0= parameter in the "/goform/net\_Web\_get_value" uri to trigger this vulnerability.

May 14, 2018
8.8
CVE-2017-14433HIGH

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attacker can inject OS commands into the remoteNetwork0= parameter in the "/goform/net\_Web\_get_value" uri to trigger this vulnerability.

May 14, 2018
8.8
CVE-2017-14432HIGH

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attacker can inject OS commands into the openvpnServer0_tmp= parameter in the "/goform/net\_Web\_get_value" uri to trigger this vulnerability.

May 14, 2018
8.8
CVE-2017-12126HIGH

An exploitable cross-site request forgery vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP packet can cause cross-site request forgery. An attacker can create malicious HTML to trigger this vulnerability.

May 14, 2018
8.8
CVE-2017-12125HIGH

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attacker can inject OS commands into the CN= parm in the "/goform/net_WebCSRGen" uri to trigger this vulnerability.

May 14, 2018
8.8
CVE-2017-12123HIGH

An exploitable clear text transmission of password vulnerability exists in the web server and telnet functionality of Moxa EDR-810 V4.1 build 17030317. An attacker can look at network traffic to get the admin password for the device. The attacker can then use the credentials to login as admin.

May 14, 2018
8.8
CVE-2017-12121HIGH

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attacker can inject OS commands into the rsakey\_name= parm in the "/goform/WebRSAKEYGen" uri to trigger this vulnerability.

May 14, 2018
8.8
CVE-2017-12120HIGH

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation, resulting in a root shell. An attacker can inject OS commands into the ip= parm in the "/goform/net_WebPingGetValue" URI to trigger this vulnerability.

May 14, 2018
8.8
CVE-2018-7509HIGH

WPLSoft in Delta Electronics versions 2.45.0 and prior writes data from a file outside the bounds of the intended buffer space, which could cause memory corruption or may allow remote code execution.

May 4, 2018
8.8
CVE-2018-7507HIGH

WPLSoft in Delta Electronics versions 2.45.0 and prior utilizes a fixed length heap buffer where a value larger than the buffer can be read from a file into the buffer, causing the buffer to be overwritten, which may allow remote code execution or cause the application to crash.

May 4, 2018
8.8
CVE-2018-7494HIGH

WPLSoft in Delta Electronics versions 2.45.0 and prior utilizes a fixed length stack buffer where a value larger than the buffer can be read from a file into the buffer, causing the buffer to be overwritten, which may allow remote code execution or cause the application to crash.

May 4, 2018
8.8
CVE-2017-12712HIGH

The authentication algorithm in Abbott Laboratories pacemakers manufactured prior to Aug 28, 2017, which involves an authentication key and time stamp, can be compromised or bypassed, which may allow a nearby attacker to issue unauthorized commands to the pacemaker via RF communications. CVSS v3 base score: 7.5, CVSS vector string: AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. Abbott has developed a firmware update to help mitigate the identified vulnerabilities.

Apr 25, 2018
8.8
CVE-2018-7240HIGH

A vulnerability exists in Schneider Electric's Modicon Quantum in all versions of the communication modules which could allow arbitrary code execution. An FTP command used to upgrade the firmware of the module can be misused to cause a denial of service, or in extreme cases, to load a malicious firmware.

Apr 18, 2018
8.8
CVE-2018-7230HIGH

A XML external entity (XXE) vulnerability exists in the import.cgi of the web interface component of the Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67.

Mar 9, 2018
8.8
CVE-2017-17888HIGH

cgi-bin/write.cgi in Anti-Web through 3.8.7, as used on NetBiter / HMS, Ouman EH-net, Alliance System WS100 --> AWU 500, Sauter ERW100F001, Carlo Gavazzi SIU-DLG, AEDILIS SMART-1, SYXTHSENSE WebBiter, ABB SREA, and ASCON DY WebServer devices, allows remote authenticated users to execute arbitrary OS commands via crafted multipart/form-data content, a different vulnerability than CVE-2017-9097.

Dec 27, 2017
8.8
CVE-2017-16731HIGH

An Unprotected Transport of Credentials issue was discovered in ABB Ellipse 8.3 through Ellipse 8.9 released prior to December 2017 (including Ellipse Select). A vulnerability exists in the authentication of Ellipse to LDAP/AD using the LDAP protocol. An attacker could exploit the vulnerability by sniffing local network traffic, allowing the discovery of authentication credentials.

Dec 20, 2017
8.8
CVE-2017-7969HIGH

A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for multiple state-changing requests. This type of attack requires some level of social engineering in order to get a legitimate user to click on or access a malicious link/site containing the CSRF attack.

Sep 26, 2017
8.8
CVE-2017-12704HIGH

A heap-based buffer overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Researchers have identified multiple vulnerabilities where there is a lack of proper validation of the length of user-supplied data prior to copying it to the heap-based buffer, which could allow an attacker to execute arbitrary code under the context of the process.

Aug 30, 2017
8.8
CVE-2017-12702HIGH

An Externally Controlled Format String issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. String format specifiers based on user provided input are not properly validated, which could allow an attacker to execute arbitrary code.

Aug 30, 2017
8.8
CVE-2017-6328HIGH

The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of cross site request forgery (also known as one-click attack and is abbreviated as CSRF or XSRF), which is a type of malicious exploit of a website where unauthorized commands are transmitted from a user that the web application trusts. A CSRF attack attempts to exploit the trust that a specific website has in a user's browser.

Aug 11, 2017
8.8
CVE-2017-7966HIGH

A DLL Hijacking vulnerability in the programming software in Schneider Electric's SoMachine HVAC v2.1.0 allows a remote attacker to execute arbitrary code on the targeted system. The vulnerability exists due to the improper loading of a DLL.

Jun 7, 2017
8.8
CVE-2017-7917HIGH

A Cross-Site Request Forgery issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 and previous versions, OnCell G3150-HSDPA Version 1.4 Build 11051315 and previous versions, OnCell 5104-HSDPA, OnCell 5104-HSPA, and OnCell 5004-HSPA. The application does not sufficiently verify if a request was intentionally provided by the user who submitted the request, which could allow an attacker to modify the configuration of the device.

May 29, 2017
8.8
CVE-2017-5156HIGH

A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The client request may be forged from a different site. This will allow an external site to access internal RDP systems on behalf of the currently logged in user.

Apr 20, 2017
8.8
CVE-2016-8718HIGH

An exploitable Cross-Site Request Forgery vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. A specially crafted form can trick a client into making an unintentional request to the web server which will be treated as an authentic request.

Apr 12, 2017
8.8
CVE-2017-5671HIGH

Honeywell Intermec PM23, PM42, PM43, PC23, PC43, PD43, and PC42 industrial printers before 10.11.013310 and 10.12.x before 10.12.013309 have /usr/bin/lua installed setuid to the itadmin account, which allows local users to conduct a BusyBox jailbreak attack and obtain root privileges by overwriting the /etc/shadow file.

Mar 29, 2017
8.8
CVE-2017-2689HIGH

Siemens RUGGEDCOM ROX I (all versions) allow an authenticated user to bypass access restrictions in the web interface at port 10000/TCP to obtain privileged file system access or change configuration settings.

Mar 29, 2017
8.8
CVE-2017-2688HIGH

The integrated web server in Siemens RUGGEDCOM ROX I (all versions) at port 10000/TCP could allow remote attackers to perform actions with the privileges of an authenticated user, provided the targeted user has an active session and is induced into clicking on a malicious link or into visiting a malicious website, aka CSRF.

Mar 29, 2017
8.8
CVE-2017-2682HIGH

The Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could allow a remote attacker to perform a Cross-Site Request Forgery (CSRF) attack, potentially allowing an attacker to execute administrative operations, provided the targeted user has an active session and is induced to trigger a malicious request.

Feb 27, 2017
8.8
CVE-2016-9365HIGH

An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPort 5100A Series & NPort P5150A versions prior to 1.3, NPort 5200A Series versions prior to 1.3, NPort 5150AI-M12 Series versions prior to 1.2, NPort 5250AI-M12 Series versions prior to 1.2, NPort 5450AI-M12 Series versions prior to 1.2, NPort 5600-8-DT Series versions prior to 2.4, NPort 5600-8-DTL Series versions prior to 2.4, NPort 6x50 Series versions prior to 1.13.11, NPort IA5450A versions prior to v1.4. Requests are not verified to be intentionally submitted by the proper user (CROSS-SITE REQUEST FORGERY).

Feb 13, 2017
8.8
CVE-2016-5809HIGH

An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series, ION8650 series, ION8800 series, and PM5XXX series. There is no CSRF Token generated to authenticate the user during a session. Successful exploitation of this vulnerability can allow unauthorized configuration changes to be made and saved.

Feb 13, 2017
8.8
CVE-2016-5793HIGH

Unquoted Windows search path vulnerability in Moxa Active OPC Server before 2.4.19 allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory.

Sep 24, 2016
8.8
CVE-2016-2285HIGH

Cross-site request forgery (CSRF) vulnerability on Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 devices with firmware 1.1 Build 10080614, MiiNePort_E2_4561 devices with firmware 1.1 Build 10080614, and MiiNePort E3 devices with firmware 1.0 Build 11071409 allows remote attackers to hijack the authentication of arbitrary users.

May 31, 2016
8.8
CVE-2015-3946HIGH

Cross-site request forgery (CSRF) vulnerability in Advantech WebAccess before 8.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

Jan 15, 2016
8.8
CVE-2025-53418HIGH

Delta Electronics COMMGR has Stack-based Buffer Overflow vulnerability.

Aug 26, 2025
8.6
CVE-2025-2521HIGH

The Honeywell Experion PKS and OneWireless WDM contains a Memory Buffer vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to an Overread Buffers, which could result in improper index validation against buffer borders leading to remote code execution. Honeywell recommends updating to the most recent version of Honeywell Experion PKS: 520.2 TCU9 HF1 and 530.1 TCU3 HF1 and OneWireless: 322.5 and 331.1. The affected Experion PKS products are C300 PCNT02, C300 PCNT05, FIM4, FIM8, UOC, CN100, HCA, C300PM, and C200E. The Experion PKS versions affected are from 520.1 through 520.2 TCU9 and from 530 through 530 TCU3.The OneWireless WDM affected versions are 322.1 through 322.4 and 330.1 through 330.3.

Jul 10, 2025
8.6
CVE-2024-3493HIGH

A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause a major nonrecoverable fault (MNRF) Rockwell Automation's ControlLogix 5580, Guard Logix 5580, CompactLogix 5380, and 1756-EN4TR. If exploited, the affected product will become unavailable and require a manual restart to recover it. Additionally, an MNRF could result in a loss of view and/or control of connected devices.

Apr 15, 2024
8.6
CVE-2024-21916HIGH

A denial-of-service vulnerability exists in specific Rockwell Automation ControlLogix ang GuardLogix controllers. If exploited, the product could potentially experience a major nonrecoverable fault (MNRF). The device will restart itself to recover from the MNRF.

Jan 31, 2024
8.6
CVE-2022-45790HIGH

The Omron FINS protocol has an authenticated feature to prevent access to memory regions. Authentication is susceptible to bruteforce attack, which may allow an adversary to gain access to protected memory. This access can allow overwrite of values including programmed logic.

Jan 22, 2024
8.6
CVE-2023-2423HIGH

A vulnerability was discovered in the Rockwell Automation Armor PowerFlex device when the product sends communications to the local event log. Threat actors could exploit this vulnerability by sending an influx of network commands, causing the product to generate an influx of event log traffic at a high rate. If exploited, the product would stop normal operations and self-reset creating a denial-of-service condition. The error code would need to be cleared prior to resuming normal operations.

Aug 8, 2023
8.6
CVE-2023-0426HIGH

ABB is aware of vulnerabilities in the product versions listed below. An update is available that resolves the reported vulnerabilities in the product versions under maintenance. An attacker who successfully exploited one or more of these vulnerabilities could cause the product to stop or make the product inaccessible. Stack-based Buffer Overflow vulnerability in ABB Freelance controllers AC 700F (conroller modules), ABB Freelance controllers AC 900F (controller modules).This issue affects:  Freelance controllers AC 700F:  from 9.0;0 through V9.2 SP2, through Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019 , through Freelance 2019 SP1, through Freelance 2019 SP1 FP1;  Freelance controllers AC 900F:  through Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019, through Freelance 2019 SP1, through Freelance 2019 SP1 FP1.

Aug 7, 2023
8.6
CVE-2023-0425HIGH

ABB is aware of vulnerabilities in the product versions listed below. An update is available that resolves the reported vulnerabilities in the product versions under maintenance. An attacker who successfully exploited one or more of these vulnerabilities could cause the product to stop or make the product inaccessible.  Numeric Range Comparison Without Minimum Check vulnerability in ABB Freelance controllers AC 700F (Controller modules), ABB Freelance controllers AC 900F (controller modules).This issue affects: Freelance controllers AC 700F:  from 9.0;0 through V9.2 SP2, through Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019, through Freelance 2019 SP1, through Freelance 2019 SP1 FP1;  Freelance controllers AC 900F:  Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019, through Freelance 2019 SP1, through Freelance 2019 SP1 FP1.

Aug 7, 2023
8.6
CVE-2022-3752HIGH

An unauthorized user could use a specially crafted sequence of Ethernet/IP messages, combined with heavy traffic loading to cause a denial-of-service condition in Rockwell Automation Logix controllers resulting in a major non-recoverable fault. If the target device becomes unavailable, a user would have to clear the fault and redownload the user project file to bring the device back online and continue normal operation.

Dec 19, 2022
8.6
CVE-2022-3157HIGH

A vulnerability exists in the Rockwell Automation controllers that allows a malformed CIP request to cause a major non-recoverable fault (MNRF) and a denial-of-service condition (DOS).

Dec 16, 2022
8.6
CVE-2022-40265HIGH

Improper Input Validation vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series RJ71EN71 Firmware version "65" and prior and Mitsubishi Electric Corporation MELSEC iQ-R Series R04/08/16/32/120ENCPU Network Part Firmware version "65" and prior allows a remote unauthenticated attacker to cause a Denial of Service condition by sending specially crafted packets. A system reset is required for recovery.

Nov 30, 2022
8.6
CVE-2022-25164HIGH

Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z and Mitsubishi Electric MX OPC UA Module Configurator-R versions 1.08J and prior allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated attackers can gain unauthorized access to the MELSEC CPU module and the MELSEC OPC UA server module.

Nov 25, 2022
8.6
CVE-2022-2465HIGH

Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Deserialization of Untrusted Data vulnerability. ISaGRAF Workbench does not limit the objects that can be deserialized. This vulnerability allows attackers to craft a malicious serialized object that, if opened by a local user in ISaGRAF Workbench, may result in remote code execution. This vulnerability requires user interaction to be successfully exploited.

Aug 25, 2022
8.6
CVE-2022-25161HIGH

Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U-xMy/z(x=32,64,80, y=T,R, z=ES,DS,ESS,DSS) with serial number 17X**** or later and versions prior to 1.270, Mitsubishi Electric Mitsubishi Electric MELSEC iQ-F series FX5U-xMy/z(x=32,64,80, y=T,R, z=ES,DS,ESS,DSS) with serial number 179**** and prior and versions prior to 1.073, MELSEC iQ-F series FX5UC-xMy/z(x=32,64,96, y=T,R, z=D,DSS) with serial number 17X**** or later and versions prior to 1.270, Mitsubishi Electric MELSEC iQ-F series FX5UC-xMy/z(x=32,64,96, y=T,R, z=D,DSS) with serial number 179**** and prior and versions prior to 1.073, Mitsubishi Electric MELSEC iQ-F series FX5UC-32MT/DS-TS versions prior to 1.270, Mitsubishi Electric MELSEC iQ-F series FX5UC-32MT/DSS-TS versions prior to 1.270, Mitsubishi Electric MELSEC iQ-F series FX5UC-32MR/DS-TS versions prior to 1.270, Mitsubishi Electric MELSEC iQ-F series FX5UJ-xMy/z(x=24,40,60, y=T,R, z=ES,ESS) versions prior to 1.030, Mitsubishi Electric MELSEC iQ-F series FX5UJ-xMy/ES-A(x=24,40,60, y=T,R) versions prior to 1.031 and Mitsubishi Electric MELSEC iQ-F series FX5S-xMy/z(x=30,40,60,80, y=T,R, z=ES,ESS) version 1.000 allows a remote unauthenticated attacker to cause a DoS condition for the product's program execution or communication by sending specially crafted packets. System reset of the product is required for recovery.

May 18, 2022
8.6
CVE-2021-22275HIGH

Buffer Overflow vulnerability in B&R Automation Runtime webserver allows an unauthenticated network-based attacker to stop the cyclic program on the device and cause a denial of service.

May 13, 2022
8.6
CVE-2021-27475HIGH

Rockwell Automation Connected Components Workbench v12.00.00 and prior does not limit the objects that can be deserialized. This vulnerability allows attackers to craft a malicious serialized object that, if opened by a local user in Connected Components Workbench, may result in remote code execution. This vulnerability requires user interaction to be successfully exploited.

Mar 23, 2022
8.6
CVE-2021-33012HIGH

Rockwell Automation MicroLogix 1100, all versions, allows a remote, unauthenticated attacker sending specially crafted commands to cause the PLC to fault when the controller is switched to RUN mode, which results in a denial-of-service condition. If successfully exploited, this vulnerability will cause the controller to fault whenever the controller is switched to RUN mode.

Jul 9, 2021
8.6
CVE-2021-22659HIGH

Rockwell Automation MicroLogix 1400 Version 21.6 and below may allow a remote unauthenticated attacker to send a specially crafted Modbus packet allowing the attacker to retrieve or modify random values in the register. If successfully exploited, this may lead to a buffer overflow resulting in a denial-of-service condition. The FAULT LED will flash RED and communications may be lost. Recovery from denial-of-service condition requires the fault to be cleared by the user.

Mar 25, 2021
8.6
CVE-2020-24685HIGH

An unauthenticated specially crafted packet sent by an attacker over the network will cause a denial-of-service (DoS) vulnerability. Vulnerability allows attacker to stop the PLC. After stopping (ERR LED flashing red), physical access to the PLC is required in order to restart the application. This issue affects: ABB AC500 V2 products with onboard Ethernet version 2.8.4 and prior versions.

Feb 9, 2021
8.6
CVE-2019-13538HIGH

3S-Smart Software Solutions GmbH CODESYS V3 Library Manager, all versions prior to 3.5.16.0, allows the system to display active library content without checking its validity, which may allow the contents of manipulated libraries to be displayed or executed. The issue also exists for source libraries, but 3S-Smart Software Solutions GmbH strongly recommends distributing compiled libraries only.

Sep 17, 2019
8.6
CVE-2018-13990HIGH

The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions prior to 1.35 is vulnerable to brute-force attacks, because of Improper Restriction of Excessive Authentication Attempts.

May 6, 2019
8.6
CVE-2018-17924HIGH

Rockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules An unauthenticated, remote threat actor could send a CIP connection request to an affected device, and upon successful connection, send a new IP configuration to the affected device even if the controller in the system is set to Hard RUN mode. When the affected device accepts this new IP configuration, a loss of communication occurs between the device and the rest of the system as the system traffic is still attempting to communicate with the device via the overwritten IP address.

Dec 7, 2018
8.6
CVE-2017-9627HIGH

An Uncontrolled Resource Consumption issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.2307.1 and prior. The uncontrolled resource consumption vulnerability could allow an attacker to exhaust the memory resources of the machine, causing a denial of service.

Jul 7, 2017
8.6
CVE-2017-7901HIGH

A Predictable Value Range from Previous Values issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Version 16.00 and prior versions; 1763-L16BBB, Series A and B, Version 16.00 and prior versions; 1763-L16BWA, Series A and B, Version 16.00 and prior versions; and 1763-L16DWD, Series A and B, Version 16.00 and prior versions and Allen-Bradley MicroLogix 1400 programmable logic controllers 1766-L32AWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWAA, Series A and B, Version 16.00 and prior versions; 1766-L32BXB, Series A and B, Version 16.00 and prior versions; 1766-L32BXBA, Series A and B, Version 16.00 and prior versions; and 1766-L32AWAA, Series A and B, Version 16.00 and prior versions. Insufficiently random TCP initial sequence numbers are generated, which may allow an attacker to predict the numbers from previous values. This may allow an attacker to spoof or disrupt TCP connections, resulting in a denial of service for the target device.

Jun 30, 2017
8.6
CVE-2017-7914HIGH

A Missing Authorization issue was discovered in Rockwell Automation PanelView Plus 6 700-1500 6.00.04, 6.00.05, 6.00.42, 6.00-20140306, 6.10.20121012, 6.10-20140122, 7.00-20121012, 7.00-20130108, 7.00-20130325, 7.00-20130619, 7.00-20140128, 7.00-20140310, 7.00-20140429, 7.00-20140621, 7.00-20140729, 7.00-20141022, 8.00-20140730, and 8.00-20141023. There is no authorization check when connecting to the device, allowing an attacker remote access.

Jun 14, 2017
8.6
CVE-2017-5143HIGH

An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. A user without authenticating can make a directory traversal attack by accessing a specific URL.

Feb 13, 2017
8.6
CVE-2016-8368HIGH

An issue was discovered in Mitsubishi Electric Automation MELSEC-Q series Ethernet interface modules QJ71E71-100, all versions, QJ71E71-B5, all versions, and QJ71E71-B2, all versions. The affected Ethernet interface module is connected to a MELSEC-Q PLC, which may allow a remote attacker to connect to the PLC via Port 5002/TCP and cause a denial of service, requiring the PLC to be reset to resume operation. This is caused by an Unrestricted Externally Accessible Lock.

Feb 13, 2017
8.6
CVE-2016-5814HIGH

Buffer overflow in Rockwell Automation RSLogix Micro Starter Lite, RSLogix Micro Developer, RSLogix 500 Starter Edition, RSLogix 500 Standard Edition, and RSLogix 500 Professional Edition allows remote attackers to execute arbitrary code via a crafted RSS project file.

Sep 19, 2016
8.6
CVE-2015-7907HIGH

Directory traversal vulnerability in the web server on Honeywell Midas gas detectors before 1.13b3 and Midas Black gas detectors before 2.13b3 allows remote attackers to bypass authentication, and write to a configuration file or trigger a calibration or test, via unspecified vectors.

Dec 21, 2015
8.6
CVE-2024-5650HIGH

DLL Hijacking vulnerability has been found in CENTUM CAMS Log server provided by Yokogawa Electric Corporation. If an attacker is somehow able to intrude into a computer that installed affected product or access to a shared folder, by replacing the DLL file with a tampered one, it is possible to execute arbitrary programs with the authority of the SYSTEM account. The affected products and versions are as follows: CENTUM CS 3000 R3.08.10 to R3.09.50 CENTUM VP R4.01.00 to R4.03.00, R5.01.00 to R5.04.20, R6.01.00 to R6.11.10.

Jun 17, 2024
8.5
CVE-2021-32960HIGH

Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed contains a vulnerability that may allow a remote, authenticated attacker to bypass FactoryTalk Security policies based on the computer name. If successfully exploited, this may allow an attacker to have the same privileges as if they were logged on to the client machine.

Apr 1, 2022
8.5
CVE-2015-6464HIGH

The administrative web interface on Moxa EDS-405A and EDS-408A switches with firmware before 3.6 allows remote authenticated users to bypass a read-only protection mechanism by using Firefox with a web-developer plugin.

Sep 11, 2015
8.5
CVE-2013-0664HIGH

The FactoryCast service on the Schneider Electric Quantum 140NOE77111 and 140NWM10000, M340 BMXNOE0110x, and Premium TSXETY5103 PLC modules allows remote authenticated users to send Modbus messages, and consequently execute arbitrary code, by embedding these messages in SOAP HTTP POST requests.

Apr 4, 2013
8.5
CVE-2012-6439HIGH

When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that changes the product’s configuration and network parameters, a DoS condition can occur. This situation could cause loss of availability and a disruption of communication with other connected devices.  Rockwell Automation EtherNet/IP products; 1756-ENBT, 1756-EWEB, 1768-ENBT, and 1768-EWEB communication modules; CompactLogix L32E and L35E controllers; 1788-ENBT FLEXLogix adapter; 1794-AENTR FLEX I/O EtherNet/IP adapter; ControlLogix 18 and earlier; CompactLogix 18 and earlier; GuardLogix 18 and earlier; SoftLogix 18 and earlier; CompactLogix controllers 19 and earlier; SoftLogix controllers 19 and earlier; ControlLogix controllers 20 and earlier; GuardLogix controllers 20 and earlier; and MicroLogix 1100 and 1400

Jan 24, 2013
8.5
CVE-2012-3009HIGH

Siemens COMOS before 9.1 Patch 413, 9.2 before Update 03 Patch 023, and 10.0 before Patch 005 allows remote authenticated users to obtain database administrative access via unspecified method calls.

Aug 16, 2012
8.5
CVE-2011-4879HIGH

miniweb.exe in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime does not properly handle URIs beginning with a 0xfa character, which allows remote attackers to read data from arbitrary memory locations or cause a denial of service (application crash) via a crafted POST request.

Feb 3, 2012
8.5
CVE-2025-13779HIGH

Missing authentication for critical function vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AWIN GW100 rev.2: 2.0-0, 2.0-1; AWIN GW120: 1.2-0, 1.2-1.

Mar 13, 2026
8.3
CVE-2025-13777HIGH

Authentication bypass by capture-replay vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AWIN GW100 rev.2: 2.0-0, 2.0-1; AWIN GW120: 1.2-0, 1.2-1.

Mar 13, 2026
8.3
CVE-2025-41659HIGH

A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and write certificates and its keys. This allows sensitive data to be extracted or to accept certificates as trusted. Although all services remain available, only unencrypted communication is possible if the certificates are deleted.

Aug 4, 2025
8.3
CVE-2024-0220HIGH

B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the vulnerability to execute arbitrary code on the products or sniff sensitive data.

Feb 22, 2024
8.3
CVE-2021-22289HIGH

Improper Input Validation vulnerability in the project upload mechanism in B&R Automation Studio version >=4.0 may allow an unauthenticated network attacker to execute code.

Aug 11, 2022
8.3
CVE-2020-14496HIGH

Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions could allow an attacker to escalate privilege and execute malicious programs, which could cause a denial-of-service condition, and allow information to be disclosed, tampered with, and/or destroyed.

May 19, 2022
8.3
CVE-2020-14523HIGH

Multiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacker to execute arbitrary code.

Feb 11, 2022
8.3
CVE-2020-14521HIGH

Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition.

Feb 11, 2022
8.3
CVE-2019-7229HIGH

The ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its software components: "Utilization of USB/SD Card to flash the device" and "Remote provisioning process via ABB Panel Builder 600 over FTP." Neither of these transmission methods implements any form of encryption or authenticity checks against the new firmware HMI software binary files.

Jun 24, 2019
8.3
CVE-2015-6481HIGH

The login function in the RequestController class in Moxa OnCell Central Manager before 2.2 has a hardcoded root password, which allows remote attackers to obtain administrative access via a login session.

Dec 21, 2015
8.3
CVE-2015-6480HIGH

The MessageBrokerServlet servlet in Moxa OnCell Central Manager before 2.2 does not require authentication, which allows remote attackers to obtain administrative access via a command, as demonstrated by the addUserAndGroup action.

Dec 21, 2015
8.3
CVE-2014-3888HIGH

Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM VP R5.03.20 and earlier, Exaopc R3.72.00 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier, when FCS/Test Function is enabled, allows remote attackers to execute arbitrary code via a crafted packet.

Jul 10, 2014
8.3
CVE-2014-0782HIGH

Stack-based buffer overflow in BKESimmgr.exe in the Expanded Test Functions package in Yokogawa CENTUM CS 1000, CENTUM CS 3000 Entry Class R3.09.50 and earlier, CENTUM VP R5.03.00 and earlier, CENTUM VP Entry Class R5.03.00 and earlier, Exaopc R3.71.02 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier allows remote attackers to execute arbitrary code via a crafted packet.

May 16, 2014
8.3
CVE-2014-2250HIGH

The random-number generator on Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 does not have sufficient entropy, which makes it easier for remote attackers to defeat cryptographic protection mechanisms and hijack sessions via unspecified vectors, a different vulnerability than CVE-2014-2251.

Mar 24, 2014
8.3
CVE-2014-2251HIGH

The random-number generator on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 does not have sufficient entropy, which makes it easier for remote attackers to defeat cryptographic protection mechanisms and hijack sessions via unspecified vectors.

Mar 16, 2014
8.3
CVE-2014-0784HIGH

Stack-based buffer overflow in BKBCopyD.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet.

Mar 14, 2014
8.3
CVE-2013-6925HIGH

The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote attackers to hijack web sessions by predicting a session id value.

Dec 17, 2013
8.3
CVE-2013-5709HIGH

The authentication implementation in the web server on Siemens SCALANCE X-200 switches with firmware before 5.0.0 does not use a sufficient source of entropy for generating values of random numbers, which makes it easier for remote attackers to hijack sessions by predicting a value.

Sep 17, 2013
8.3
CVE-2025-1924HIGH

A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receive maliciously crafted packets, a DoS attack may cause Vnet/IP communication functions to stop or arbitrary programs to be executed. The affected products and versions are as follows: Vnet/IP Interface Package (for CENTUM VP R6 VP6C3300, CENTUM VP R7 VP7C3300) R1.07.00 or earlier

Feb 13, 2026
8.2
CVE-2025-11774HIGH

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the software keyboard function (hereinafter referred to as "keypad function") of Mitsubishi Electric GENESIS64 versions 10.97.2 CFR3 and prior, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97.2 CFR3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.2 CFR3 and prior, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97.2 CFR3 and prior, Mitsubishi Electric MobileHMI versions 10.97.2 CFR3 and prior, Mitsubishi Electric Iconics Digital Solutions MobileHMI versions 10.97.2 CFR3 and prior, and Mitsubishi Electric MC Works64 all versions allows a local attacker to execute arbitrary executable files (EXE) when a legitimate user uses the keypad function by tampering with the configuration file for the function. This could allow the attacker to disclose, tamper with, delete, or destroy information stored on the PC where the affected product is installed, or cause a denial-of-service (DoS) condition on the system, through the execution of the EXE.

Dec 19, 2025
8.2
CVE-2025-3947HIGH

The Honeywell Experion PKS contains an Integer Underflow vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to Input Data Manipulation, which could result in improper integer data value checking during subtraction leading to a denial of service. Honeywell recommends updating to the most recent version of Honeywell Experion PKS:520.2 TCU9 HF1 and 530.1 TCU3 HF1. The affected Experion PKS products are C300 PCNT02, C300 PCNT05, FIM4, FIM8, UOC, CN100, HCA, C300PM, and C200E. The Experion PKS versions affected are from 520.1 through 520.2 TCU9 and from 530 through 530 TCU3.

Jul 10, 2025
8.2
CVE-2025-3946HIGH

The Honeywell Experion PKS and OneWireless WDM contains a Deployment of Wrong Handler vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to Input Data Manipulation, which could result in incorrect handling of packets leading to remote code execution. Honeywell recommends updating to the most recent version of Honeywell Experion PKS:520.2 TCU9 HF1 and 530.1 TCU3 HF1 and OneWireless: 322.5 and 331.1. The affected Experion PKS products are C300 PCNT02, C300 PCNT05, FIM4, FIM8, UOC, CN100, HCA, C300PM, and C200E. The Experion PKS versions affected are from 520.1 through 520.2 TCU9 and from 530 through 530 TCU3. The OneWireless WDM affected versions are 322.1 through 322.4 and 330.1 through 330.3.

Jul 10, 2025
8.2
CVE-2024-51544HIGH

Service Control vulnerabilities allow access to service restart requests and vm configuration settings.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

Dec 5, 2024
8.2
CVE-2024-51543HIGH

Information Disclosure vulnerabilities allow access to application configuration information.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

Dec 5, 2024
8.2
CVE-2024-51542HIGH

Configuration Download vulnerabilities allow access to dependency configuration information.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

Dec 5, 2024
8.2
CVE-2024-51541HIGH

Local File Inclusion vulnerabilities allow access to sensitive system information.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

Dec 5, 2024
8.2
CVE-2024-48847HIGH

MD5 Checksum Bypass vulnerabilities where found exploiting a weakness in the way an application dependency calculates or validates MD5 checksum hashes.  Affected products: ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01; MATRIX Series v3.08.01

Dec 5, 2024
8.2
CVE-2024-1220HIGH

A stack-based buffer overflow in the built-in web server in Moxa NPort W2150A/W2250A Series firmware version 2.3 and prior allows a remote attacker to exploit the vulnerability by sending crafted payload to the web service. Successful exploitation of the vulnerability could result in denial of service.

Mar 6, 2024
8.2
CVE-2023-5131HIGH

A heap buffer-overflow exists in Delta Electronics ISPSoft. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DVP file to achieve code execution.

Jan 18, 2024
8.2
CVE-2023-5130HIGH

A buffer overflow vulnerability exists in Delta Electronics WPLSoft. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DVP file to achieve code execution.

Jan 18, 2024
8.2
CVE-2023-29464HIGH

FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from memory via crafted malicious packets. Sending a size larger than the buffer size results in leakage of data from memory resulting in an information disclosure. If the size is large enough, it causes communications over the common industrial protocol to become unresponsive to any type of packet, resulting in a denial-of-service to FactoryTalk Linx over the common industrial protocol.

Oct 13, 2023
8.2
CVE-2023-37862HIGH

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an unauthenticated remote attacker can access upload-functions of the HTTP API. This might cause certificate errors for SSL-connections and might result in a partial denial-of-service.

Aug 9, 2023
8.2
CVE-2021-34567HIGH

In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to provoke a denial of service and an limited out-of-bounds read.

Nov 9, 2022
8.2
CVE-2022-2044HIGH

MOXA NPort 5110: Firmware Versions 2.10 is vulnerable to an out-of-bounds write that may allow an attacker to overwrite values in memory, causing a denial-of-service condition or potentially bricking the device.

Aug 31, 2022
8.2
CVE-2022-33319HIGH

Out-of-bounds Read vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric ICONICS Suite versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97 to 10.97.1, Mitsubishi Electric GENESIS32 versions 9.7 and prior, Mitsubishi Electric Iconics Digital Solutions GENESIS32 versions 9.7 and prior, and Mitsubishi Electric MC Works64 versions 4.04E and prior allows a remote unauthenticated attacker to disclose information on memory or cause a Denial of Service (DoS) condition by sending specially crafted packets to the GENESIS64, ICONICS Suite, GENESIS32, or MC Works64 server.

Jul 20, 2022
8.2
CVE-2021-20595HIGH

Improper Restriction of XML External Entity Reference vulnerability in Mitsubishi Electric Air Conditioning System/Centralized Controllers (G-50A Ver.3.35 and prior, GB-50A Ver.3.35 and prior, GB-24A Ver.9.11 and prior, AG-150A-A Ver.3.20 and prior, AG-150A-J Ver.3.20 and prior, GB-50ADA-A Ver.3.20 and prior, GB-50ADA-J Ver.3.20 and prior, EB-50GU-A Ver 7.09 and prior, EB-50GU-J Ver 7.09 and prior, AE-200A Ver 7.93 and prior, AE-200E Ver 7.93 and prior, AE-50A Ver 7.93 and prior, AE-50E Ver 7.93 and prior, EW-50A Ver 7.93 and prior, EW-50E Ver 7.93 and prior, TE-200A Ver 7.93 and prior, TE-50A Ver 7.93 and prior, TW-50A Ver 7.93 and prior, CMS-RMD-J Ver.1.30 and prior), Air Conditioning System/Expansion Controllers (PAC-YG50ECA Ver.2.20 and prior) and Air Conditioning System/BM adapter(BAC-HD150 Ver.2.21 and prior) allows a remote unauthenticated attacker to disclose some of data in the air conditioning system or cause a DoS condition by sending specially crafted packets.

Jul 13, 2021
8.2
CVE-2020-12505HIGH

Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW07 allows an attacker to change some special parameters without authentication. This issue affects: WAGO 750-852, WAGO 750-880/xxx-xxx, WAGO 750-881, WAGO 750-831/xxx-xxx, WAGO 750-882, WAGO 750-885/xxx-xxx, WAGO 750-889 in versions FW07 and below.

Sep 30, 2020
8.2
CVE-2020-12499HIGH

In PHOENIX CONTACT PLCnext Engineer version 2020.3.1 and earlier an improper path sanitation vulnerability exists on import of project files.

Jul 21, 2020
8.2
CVE-2019-18352HIGH

Improper access control exists on PHOENIX CONTACT FL NAT 2208 devices before V2.90 and FL NAT 2304-2GC-2SFP devices before V2.90 when using MAC-based port security.

Feb 18, 2020
8.2
CVE-2018-13992HIGH

The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 allows for plaintext transmission (HTTP) of user credentials by default.

May 7, 2019
8.2
CVE-2017-12069HIGH

An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and Local Discovery Server (LDS) before 1.03.367. Among the affected products are Siemens SIMATIC PCS7 (All versions V8.1 and earlier), SIMATIC WinCC (All versions < V7.4 SP1), SIMATIC WinCC Runtime Professional (All versions < V14 SP1), SIMATIC NET PC Software, and SIMATIC IT Production Suite. By sending specially crafted packets to the OPC Discovery Server at port 4840/tcp, an attacker might cause the system to access various resources chosen by the attacker.

Aug 30, 2017
8.2
CVE-2017-2683HIGH

A non-privileged user of the Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could perform a persistent Cross-Site Scripting (XSS) attack, potentially resulting in obtaining administrative permissions.

Feb 27, 2017
8.2
CVE-2025-14510HIGH

Incorrect Implementation of Authentication Algorithm vulnerability in ABB ABB Ability OPTIMAX.This issue affects ABB Ability OPTIMAX: 6.1, 6.2, from 6.3.0 before 6.3.1-251120, from 6.4.0 before 6.4.1-251120.

Jan 16, 2026
8.1
CVE-2025-14850HIGH

Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files.

Dec 18, 2025
8.1
CVE-2023-5404HIGH

Server receiving a malformed message can cause a pointer to be overwritten which can result in a remote code execution or failure. See Honeywell Security Notification for recommendations on upgrading and versioning.

Apr 17, 2024
8.1
CVE-2023-5403HIGH

Server hostname translation to IP address manipulation which could lead to an attacker performing remote code execution or causing a failure. See Honeywell Security Notification for recommendations on upgrading and versioning.

Apr 17, 2024
8.1
CVE-2023-5401HIGH

Server receiving a malformed message based on a using the specified key values can cause a stack overflow vulnerability which could lead to an attacker performing remote code execution or causing a failure. See Honeywell Security Notification for recommendations on upgrading and versioning.

Apr 17, 2024
8.1
CVE-2023-5400HIGH

Server receiving a malformed message based on a using the specified key values can cause a heap overflow vulnerability which could lead to an attacker performing remote code execution or causing a failure.  See Honeywell Security Notification for recommendations on upgrading and versioning.

Apr 17, 2024
8.1
CVE-2023-5397HIGH

Server receiving a malformed message to create a new connection could lead to an attacker performing remote code execution or causing a failure. See Honeywell Security Notification for recommendations on upgrading and versioning.

Apr 17, 2024
8.1
CVE-2023-5395HIGH

Server receiving a malformed message that uses the hostname in an internal table may cause a stack overflow resulting in possible remote code execution. See Honeywell Security Notification for recommendations on upgrading and versioning.

Apr 17, 2024
8.1
CVE-2023-1841HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Honeywell MPA2 Access Panel (Web server modules) allows XSS Using Invalid Characters.This issue affects MPA2 Access Panel all version prior to R1.00.08.05.  Honeywell released firmware update package MPA2 firmware R1.00.08.05 which addresses this vulnerability. This version and all later versions correct the reported vulnerability.

Feb 29, 2024
8.1
CVE-2022-38742HIGH

Rockwell Automation ThinManager ThinServer versions 11.0.0 - 13.0.0 is vulnerable to a heap-based buffer overflow. An attacker could send a specifically crafted TFTP or HTTPS request, causing a heap-based buffer overflow that crashes the ThinServer process. If successfully exploited, this could expose the server to arbitrary remote code execution.

Sep 23, 2022
8.1
CVE-2022-34838HIGH

Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add or alter data points and corresponding attributes. Once such engineering data is used the data visualization will be altered for the end user.

Aug 24, 2022
8.1
CVE-2022-0902HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in flow computer and remote controller products of ABB ( RMC-100 (Standard), RMC-100-LITE, XIO, XFCG5 , XRCG5 , uFLOG5 , UDC) allows an attacker who successfully exploited this vulnerability could insert and run arbitrary code in an affected system node.

Jul 21, 2022
8.1
CVE-2022-32142HIGH

Multiple CODESYS Products are prone to a out-of bounds read or write access. A low privileged remote attacker may craft a request with invalid offset, which can cause an out-of-bounds read or write access, resulting in denial-of-service condition or local memory overwrite, which can lead to a change of local files. User interaction is not required.

Jun 24, 2022
8.1
CVE-2022-1965HIGH

Multiple products of CODESYS implement a improper error handling. A low privilege remote attacker may craft a request, which is not properly processed by the error handling. In consequence, the file referenced by the request could be deleted. User interaction is not required.

Jun 24, 2022
8.1
CVE-2022-22515HIGH

A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vulnerability in order to read and modify the configuration file(s) of the affected products.

Apr 7, 2022
8.1
CVE-2022-25159HIGH

Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions, Mitsubishi Electric MELSEC iQ-F series FX5UJ CPU all versions, Mitsubishi Electric MELSEC iQ-R series R00/01/02CPU all versions, Mitsubishi Electric MELSEC iQ-R series R04/08/16/32/120(EN)CPU all versions, Mitsubishi Electric MELSEC iQ-R series R08/16/32/120SFCPU all versions, Mitsubishi Electric MELSEC iQ-R series R08/16/32/120PCPU all versions, Mitsubishi Electric MELSEC iQ-R series R08/16/32/120PSFCPU all versions, Mitsubishi Electric MELSEC iQ-R series R16/32/64MTCPU all versions, Mitsubishi Electric MELSEC iQ-R series RJ71C24(-R2/R4) all versions, Mitsubishi Electric MELSEC iQ-R series RJ71EN71 all versions, Mitsubishi Electric MELSEC iQ-R series RJ72GF15-T2 all versions, Mitsubishi Electric MELSEC Q series Q03/04/06/13/26UDVCPU all versions, Mitsubishi Electric MELSEC Q series Q04/06/13/26UDPVCPU all versions, Mitsubishi Electric MELSEC Q series QJ71C24N(-R2/R4) all versions and Mitsubishi Electric MELSEC Q series QJ71E71-100 all versions allows a remote unauthenticated attacker to login to the product by replay attack.

Apr 1, 2022
8.1
CVE-2022-25156HIGH

Use of Weak Hash vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions, Mitsubishi Electric MELSEC iQ-F series FX5UJ CPU all versions, Mitsubishi Electric MELSEC iQ-R series R00/01/02CPU all versions, Mitsubishi Electric MELSEC iQ-R series R04/08/16/32/120(EN)CPU all versions, Mitsubishi Electric MELSEC iQ-R series R08/16/32/120SFCPU all versions, Mitsubishi Electric MELSEC iQ-R series R08/16/32/120PCPU all versions, Mitsubishi Electric MELSEC iQ-R series R08/16/32/120PSFCPU all versions, Mitsubishi Electric MELSEC iQ-R series RJ71C24(-R2/R4) all versions, Mitsubishi Electric MELSEC iQ-R series RJ71EN71 all versions, Mitsubishi Electric MELSEC iQ-R series RJ72GF15-T2 all versions, Mitsubishi Electric MELSEC Q series Q03UDECPU all versions, Mitsubishi Electric MELSEC Q series Q04/06/10/13/20/26/50/100UDEHCPU all versions, Mitsubishi Electric MELSEC Q series Q03/04/06/13/26UDVCPU all versions, Mitsubishi Electric MELSEC Q series Q04/06/13/26UDPVCPU all versions, Mitsubishi Electric MELSEC Q series QJ71C24N(-R2/R4) all versions, Mitsubishi Electric MELSEC Q series QJ71E71-100 all versions, Mitsubishi Electric MELSEC Q series QJ72BR15 all versions, Mitsubishi Electric MELSEC Q series QJ72LP25(-25/G/GE) all versions, Mitsubishi Electric MELSEC L series L02/06/26CPU(-P) all versions, Mitsubishi Electric MELSEC L series L26CPU-(P)BT all versions, Mitsubishi Electric MELSEC L series LJ71C24(-R2) all versions, Mitsubishi Electric MELSEC L series LJ71E71-100 all versions and Mitsubishi Electric MELSEC L series LJ72GF15-T2 all versions allows a remote unauthenticated attacker to login to the product by using a password reversed from a previously eavesdropped password hash.

Apr 1, 2022
8.1
CVE-2022-25155HIGH

Use of Password Hash Instead of Password for Authentication vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions, Mitsubishi Electric MELSEC iQ-F series FX5UJ CPU all versions, Mitsubishi Electric MELSEC iQ-R series R00/01/02CPU all versions, Mitsubishi Electric MELSEC iQ-R series R04/08/16/32/120(EN)CPU all versions, Mitsubishi Electric MELSEC iQ-R series R08/16/32/120SFCPU all versions, Mitsubishi Electric MELSEC iQ-R series R08/16/32/120PCPU all versions, Mitsubishi Electric MELSEC iQ-R series R08/16/32/120PSFCPU all versions, Mitsubishi Electric MELSEC iQ-R series RJ71GN11-T2 all versions, Mitsubishi Electric MELSEC iQ-R series RJ71GN11-EIP all versions, Mitsubishi Electric MELSEC iQ-R series RJ71C24(-R2/R4) all versions, Mitsubishi Electric MELSEC iQ-R series RJ71EN71 all versions, Mitsubishi Electric MELSEC iQ-R series RJ72GF15-T2 all versions, Mitsubishi Electric MELSEC Q series Q03UDECPU all versions, Mitsubishi Electric MELSEC Q series Q04/06/10/13/20/26/50/100UDEHCPU all versions, Mitsubishi Electric MELSEC Q series Q03/04/06/13/26UDVCPU all versions, Mitsubishi Electric MELSEC Q series Q04/06/13/26UDPVCPU all versions, Mitsubishi Electric MELSEC Q series QJ71C24N(-R2/R4) all versions, Mitsubishi Electric MELSEC Q series QJ71E71-100 all versions, Mitsubishi Electric MELSEC Q series QJ72BR15 all versions, Mitsubishi Electric MELSEC Q series QJ72LP25(-25/G/GE) all versions, Mitsubishi Electric MELSEC L series L02/06/26CPU(-P) all versions, Mitsubishi Electric MELSEC L series L26CPU-(P)BT all versions, Mitsubishi Electric MELSEC L series LJ71C24(-R2) all versions, Mitsubishi Electric MELSEC L series LJ71E71-100 all versions and Mitsubishi Electric MELSEC L series LJ72GF15-T2 all versions allows a remote unauthenticated attacker to login to the product by replaying an eavesdropped password hash.

Apr 1, 2022
8.1
CVE-2022-22151HIGH

CAMS for HIS Log Server contained in the following Yokogawa Electric products fails to properly neutralize log outputs: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, and Exaopc versions from R3.72.00 to R3.79.00.

Mar 11, 2022
8.1
CVE-2022-22145HIGH

CAMS for HIS Log Server contained in the following Yokogawa Electric products is vulnerable to uncontrolled resource consumption. CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00.

Mar 11, 2022
8.1
CVE-2022-21177HIGH

There is a path traversal vulnerability in CAMS for HIS Log Server contained in the following Yokogawa Electric products: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, andfrom R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00.

Mar 11, 2022
8.1
CVE-2021-34595HIGH

A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or local memory overwrite.

Oct 26, 2021
8.1
CVE-2019-13533HIGH

In Omron PLC CJ series, all versions, and Omron PLC CS series, all versions, an attacker could monitor traffic between the PLC and the controller and replay requests that could result in the opening and closing of industrial valves.

Dec 16, 2019
8.1
CVE-2018-10694HIGH

An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a Wi-Fi connection that is open and does not use any encryption mechanism by default. An administrator who uses the open wireless connection to set up the device can allow an attacker to sniff the traffic passing between the user's computer and the device. This can allow an attacker to steal the credentials passing over the HTTP connection as well as TELNET traffic. Also an attacker can MITM the response and infect a user's computer very easily as well.

Jun 7, 2019
8.1
CVE-2018-10690HIGH

An issue was discovered on Moxa AWK-3121 1.14 devices. The device by default allows HTTP traffic thus providing an insecure communication mechanism for a user connecting to the web server. This allows an attacker to sniff the traffic easily and allows an attacker to compromise sensitive data such as credentials.

Jun 7, 2019
8.1
CVE-2018-19616HIGH

An issue was discovered in Rockwell Automation Allen-Bradley PowerMonitor 1000. An unauthenticated user can add/edit/remove administrators because access control is implemented on the client side via a disabled attribute for a BUTTON element.

Dec 26, 2018
8.1
CVE-2018-17896HIGH

Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The affected controllers utilize hard-coded credentials which may allow an attacker gain unauthorized access to the maintenance functions and obtain or modify information. This attack can be executed only during maintenance work.

Oct 12, 2018
8.1
CVE-2018-10728HIGH

All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to buffer overflows (a different vulnerability than CVE-2018-10731).

May 17, 2018
8.1
CVE-2018-8872HIGH

In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, system calls read directly from memory addresses within the control program area without any verification. Manipulating this data could allow attacker data to be copied anywhere within memory.

May 4, 2018
8.1
CVE-2014-8422HIGH

The web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 generates session cookies with insufficient entropy, which makes it easier for remote attackers to hijack sessions via a brute-force attack.

Apr 12, 2018
8.1
CVE-2018-7236HIGH

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could enable SSH service due to lack of authentication for /login/bin/set_param could enable SSH service.

Mar 9, 2018
8.1
CVE-2017-9963HIGH

A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for multiple state-changing requests. This type of attack requires some level of social engineering in order to get a legitimate user to click on or access a malicious link/site containing the CSRF attack.

Feb 12, 2018
8.1
CVE-2017-14263HIGH

Honeywell NVR devices allow remote attackers to create a user account in the admin group by leveraging access to a guest account to obtain a session ID, and then sending that session ID in a userManager.addUser request to the /RPC2 URI. The attacker can login to the device with that new user account to fully control the device.

Sep 11, 2017
8.1
CVE-2017-9940HIGH

A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with access to a low-privileged user account to read or write files on the file system of the SiPass integrated server over the network.

Aug 8, 2017
8.1
CVE-2017-6868HIGH

An Improper Authentication issue was discovered in Siemens SIMATIC CP 44x-1 RNA, all versions prior to 1.4.1. An unauthenticated remote attacker may be able to perform administrative actions on the Communication Process (CP) of the RNA series module, if network access to Port 102/TCP is available and the configuration file for the CP is stored on the RNA's CPU.

Jul 7, 2017
8.1
CVE-2016-8712HIGH

An exploitable nonce reuse vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless AP running firmware 1.1. The device uses one nonce for all session authentication requests and only changes the nonce if the web application has been idle for 300 seconds.

Apr 13, 2017
8.1
CVE-2016-8379HIGH

An issue was discovered in Moxa ioLogik E1210, firmware Version V2.4 and prior, ioLogik E1211, firmware Version V2.3 and prior, ioLogik E1212, firmware Version V2.4 and prior, ioLogik E1213, firmware Version V2.5 and prior, ioLogik E1214, firmware Version V2.4 and prior, ioLogik E1240, firmware Version V2.3 and prior, ioLogik E1241, firmware Version V2.4 and prior, ioLogik E1242, firmware Version V2.4 and prior, ioLogik E1260, firmware Version V2.4 and prior, ioLogik E1262, firmware Version V2.4 and prior, ioLogik E2210, firmware versions prior to V3.13, ioLogik E2212, firmware versions prior to V3.14, ioLogik E2214, firmware versions prior to V3.12, ioLogik E2240, firmware versions prior to V3.12, ioLogik E2242, firmware versions prior to V3.12, ioLogik E2260, firmware versions prior to V3.13, and ioLogik E2262, firmware versions prior to V3.12. Users are restricted to using short passwords.

Feb 13, 2017
8.1
CVE-2016-8372HIGH

An issue was discovered in Moxa ioLogik E1210, firmware Version V2.4 and prior, ioLogik E1211, firmware Version V2.3 and prior, ioLogik E1212, firmware Version V2.4 and prior, ioLogik E1213, firmware Version V2.5 and prior, ioLogik E1214, firmware Version V2.4 and prior, ioLogik E1240, firmware Version V2.3 and prior, ioLogik E1241, firmware Version V2.4 and prior, ioLogik E1242, firmware Version V2.4 and prior, ioLogik E1260, firmware Version V2.4 and prior, ioLogik E1262, firmware Version V2.4 and prior, ioLogik E2210, firmware versions prior to V3.13, ioLogik E2212, firmware versions prior to V3.14, ioLogik E2214, firmware versions prior to V3.12, ioLogik E2240, firmware versions prior to V3.12, ioLogik E2242, firmware versions prior to V3.12, ioLogik E2260, firmware versions prior to V3.13, and ioLogik E2262, firmware versions prior to V3.12. A password is transmitted in a format that is not sufficiently secure.

Feb 13, 2017
8.1
CVE-2016-8360HIGH

An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. A specially crafted URL request sent to the SoftCMS ASP Webserver can cause a double free condition on the server allowing an attacker to modify memory locations and possibly cause a denial of service or the execution of arbitrary code.

Feb 13, 2017
8.1
CVE-2016-9160HIGH

A vulnerability in SIEMENS SIMATIC WinCC (All versions < SIMATIC WinCC V7.2) and SIEMENS SIMATIC PCS 7 (All versions < SIMATIC PCS 7 V8.0 SP1) could allow a remote attacker to crash an ActiveX component or leak parts of the application memory if a user is tricked into clicking on a malicious link under certain conditions.

Dec 17, 2016
8.1
CVE-2016-0858HIGH

Race condition in Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via a crafted request.

Jan 15, 2016
8.1
CVE-2015-6467HIGH

Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code via vectors involving a browser plugin.

Jan 15, 2016
8.1
CVE-2015-3947HIGH

SQL injection vulnerability in Advantech WebAccess before 8.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

Jan 15, 2016
8.1
CVE-2021-22291HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ABB EIBPORT V3 KNX, ABB EIBPORT V3 KNX GSM.This issue affects EIBPORT V3 KNX: before 3.9.2; EIBPORT V3 KNX GSM: before 3.9.2.

Oct 7, 2025
8.0
CVE-2024-39275HIGH

Cookies of authenticated Advantech ADAM-5630 users remain as active valid cookies when a session is closed. Forging requests with a legitimate cookie, even if the session was terminated, allows an unauthorized attacker to act with the same level of privileges of the legitimate user.

Sep 27, 2024
8.0
CVE-2024-28948HIGH

Advantech ADAM-5630 contains a cross-site request forgery (CSRF) vulnerability. It allows an attacker to partly circumvent the same origin policy, which is designed to prevent different websites from interfering with each other.

Sep 27, 2024
8.0
CVE-2022-30244HIGH

Honeywell Alerton Ascent Control Module (ACM) through 2022-05-04 allows unauthenticated programming writes from remote users. This enables code to be store on the controller and then run without verification. A user with malicious intent can send a crafted packet to change and/or stop the program without the knowledge of other users, altering the controller's function. After the programming change, the program needs to be overwritten in order for the controller to restore its original operational function.

Jul 15, 2022
8.0
CVE-2018-7771HIGH

The vulnerability exists within processing of editscript.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A directory traversal vulnerability allows a caller with standard user privileges to write arbitrary php files anywhere in the web service directory tree.

Jul 3, 2018
8.0
CVE-2017-12129HIGH

An exploitable Weak Cryptography for Passwords vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. An attacker could intercept weakly encrypted passwords and could brute force them.

May 14, 2018
8.0
CVE-2013-6926HIGH

The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote authenticated users to bypass intended restrictions on administrative actions by leveraging access to a (1) guest or (2) operator account.

Dec 17, 2013
8.0
CVE-2026-3094HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

Mar 4, 2026
7.8
CVE-2026-0975HIGH

Delta Electronics DIAView has Command Injection vulnerability.

Jan 16, 2026
7.8
CVE-2025-14252HIGH

An Improper Access Control vulnerability in Advantech SUSI driver (susi.sys) allows attackers to read/write arbitrary memory, I/O ports, and MSRs, resulting in privilege escalation, arbitrary code execution, and information disclosure. This issue affects Advantech SUSI: 5.0.24335 and prior.

Dec 16, 2025
7.8
CVE-2025-41700HIGH

An unauthenticated attacker can trick a local user into executing arbitrary code by opening a deliberately manipulated CODESYS project file with a CODESYS development system. This arbitrary code is executed in the user context.

Dec 1, 2025
7.8
CVE-2025-40827HIGH

A vulnerability has been identified in Siemens Software Center (All versions < V3.5), Solid Edge SE2025 (All versions < V225.0 Update 10). The affected application is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code via placing a crafted DLL file on the system.

Nov 11, 2025
7.8
CVE-2025-9068HIGH

A security issue exists within the Rockwell Automation Driver Package x64 Microsoft Installer File (MSI) repair functionality, installed with FTLinx. Authenticated attackers with valid Windows Users credentials can initiate a repair and hijack the resulting console window for vbpinstall.exe. This allows the launching of a command prompt running with SYSTEM-level privileges, allowing full access to all files, processes, and system resources.

Oct 14, 2025
7.8
CVE-2025-59300HIGH

Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

Oct 3, 2025
7.8
CVE-2025-59299HIGH

Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

Oct 3, 2025
7.8
CVE-2025-59298HIGH

Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

Oct 3, 2025
7.8
CVE-2025-59297HIGH

Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

Oct 3, 2025
7.8
CVE-2025-58319HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

Sep 24, 2025
7.8
CVE-2025-58317HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

Sep 24, 2025
7.8
CVE-2025-53419HIGH

Delta Electronics COMMGR has Code Injection vulnerability.

Aug 26, 2025
7.8
CVE-2025-7033HIGH

A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end of memory space. Successful use requires user action, such as opening a bad file or webpage. If used, a threat actor could execute code or disclose information.

Aug 5, 2025
7.8
CVE-2025-7032HIGH

A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end of memory space. Successful use requires user action, such as opening a bad file or webpage. If used, a threat actor could execute code or disclose information.

Aug 5, 2025
7.8
CVE-2025-7025HIGH

A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end of memory space. Successful use requires user action, such as opening a bad file or webpage. If used, a threat actor could execute code or disclose information.

Aug 5, 2025
7.8
CVE-2025-6377HIGH

A remote code execution security issue exists in the Rockwell Automation Arena®.  A crafted DOE file can force Arena Simulation to write beyond the boundaries of an allocated object. Exploitation requires user interaction, such as opening a malicious file within the software. If exploited, a threat actor could execute arbitrary code on the target system. The software must run under the context of the administrator in order to cause worse case impact. This is reflected in the Rockwell CVSS score, as AT:P.

Jul 9, 2025
7.8
CVE-2025-6376HIGH

A remote code execution security issue exists in the Rockwell Automation Arena®.  A crafted DOE file can force Arena Simulation to write beyond the boundaries of an allocated object. Exploitation requires user interaction, such as opening a malicious file within the software. If exploited, a threat actor could execute arbitrary code on the target system. The software must run under the context of the administrator in order to cause worse case impact. This is reflected in the Rockwell CVSS score, as AT:P.

Jul 9, 2025
7.8
CVE-2025-53416HIGH

Delta Electronics DTN Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution

Jun 30, 2025
7.8
CVE-2025-53415HIGH

Delta Electronics DTM Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution

Jun 30, 2025
7.8
CVE-2025-3394HIGH

Incorrect Permission Assignment for Critical Resource vulnerability in ABB Automation Builder.This issue affects Automation Builder: through 2.8.0.

Apr 30, 2025
7.8
CVE-2025-4125HIGH

Delta Electronics ISPSoft version 3.20 is vulnerable to an Out-Of-Bounds Write vulnerability that could allow an attacker to execute arbitrary code when parsing ISP file.

Apr 30, 2025
7.8
CVE-2025-4124HIGH

Delta Electronics ISPSoft version 3.20 is vulnerable to an Out-Of-Bounds Write vulnerability that could allow an attacker to execute arbitrary code when parsing ISP file.

Apr 30, 2025
7.8
CVE-2025-22884HIGH

Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-Based buffer overflow vulnerability that could allow an attacker to execute arbitrary code when parsing DVP file.

Apr 30, 2025
7.8
CVE-2025-22883HIGH

Delta Electronics ISPSoft version 3.20 is vulnerable to an Out-Of-Bounds Write vulnerability that could allow an attacker to execute arbitrary code when parsing DVP file.

Apr 30, 2025
7.8
CVE-2025-22882HIGH

Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-Based buffer overflow vulnerability that could allow an attacker to leverage debugging logic to execute arbitrary code when parsing CBDGL file.

Apr 30, 2025
7.8
CVE-2025-3617HIGH

A privilege escalation vulnerability exists in the Rockwell Automation ThinManager. When the software starts up, files are deleted in the temporary folder causing the Access Control Entry of the directory to inherit permissions from the parent directory. If exploited, a threat actor could inherit elevated privileges.

Apr 15, 2025
7.8
CVE-2025-3289HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file.

Apr 8, 2025
7.8
CVE-2025-3288HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file.

Apr 8, 2025
7.8
CVE-2025-3287HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file.

Apr 8, 2025
7.8
CVE-2025-3286HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file.

Apr 8, 2025
7.8
CVE-2025-3285HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file.

Apr 8, 2025
7.8
CVE-2025-2829HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file.

Apr 8, 2025
7.8
CVE-2025-2293HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file.

Apr 8, 2025
7.8
CVE-2025-2288HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file.

Apr 8, 2025
7.8
CVE-2025-2287HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena®  due to an uninitialized pointer. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file.

Apr 8, 2025
7.8
CVE-2025-2286HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena®  due to an uninitialized pointer. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file.

Apr 8, 2025
7.8
CVE-2025-2285HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena®  due to an uninitialized pointer. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file.

Apr 8, 2025
7.8
CVE-2025-22881HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of the current process.

Feb 26, 2025
7.8
CVE-2025-22880HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of the current process.

Feb 7, 2025
7.8
CVE-2024-12836HIGH

Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics DRASimuCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of STP files. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22450.

Dec 30, 2024
7.8
CVE-2024-12835HIGH

Delta Electronics DRASimuCAD ICS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics DRASimuCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ICS files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22415.

Dec 30, 2024
7.8
CVE-2024-12834HIGH

Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics DRASimuCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of STP files. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22414.

Dec 30, 2024
7.8
CVE-2024-12677HIGH

Delta Electronics DTM Soft deserializes objects, which could allow an attacker to execute arbitrary code.

Dec 20, 2024
7.8
CVE-2024-12175HIGH

Another “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.

Dec 19, 2024
7.8
CVE-2024-12130HIGH

An “out of bounds read” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to read beyond the boundaries of an allocated memory. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.

Dec 5, 2024
7.8
CVE-2024-11156HIGH

An “out of bounds write” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.

Dec 5, 2024
7.8
CVE-2024-11155HIGH

A “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.

Dec 5, 2024
7.8
CVE-2024-9852HIGH

Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 all versions, Mitsubishi Electric Iconics Digital Solutions GENESIS64 all versions, Mitsubishi Electric ICONICS Suite all versions, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite all versions, Mitsubishi Electric MC Works64 all versions, Mitsubishi Electric GENESIS32 all versions, and Mitsubishi Electric Iconics Digital Solutions GENESIS32 all versions allows a local authenticated attacker to execute a malicious code by storing a specially crafted DLL in a specific folder. This could lead to disclose, tamper with, destroy, or delete information in the affected products, or cause a denial of service (DoS) condition on the products.

Nov 28, 2024
7.8
CVE-2024-8299HIGH

Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 all versions, Mitsubishi Electric Iconics Digital Solutions GENESIS64 all versions, Mitsubishi Electric ICONICS Suite all versions, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite all versions, Mitsubishi Electric MC Works64 all versions, Mitsubishi Electric GENESIS32 all versions, and Mitsubishi Electric Iconics Digital Solutions GENESIS32 all versions allows a local authenticated attacker to execute a malicious code by storing a specially crafted DLL in a specific folder. This could lead to disclose, tamper with, destroy, or delete information in the affected products, or cause a denial of service (DoS) condition on the products.

Nov 28, 2024
7.8
CVE-2024-47131HIGH

If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing malicious code, a stack-based buffer overflow in BACnetObjectInfo can be exploited, allowing the attacker to remotely execute arbitrary code.

Nov 11, 2024
7.8
CVE-2024-39605HIGH

If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing malicious code, a stack-based buffer overflow in BACnetParameter can be exploited, allowing the attacker to remotely execute arbitrary code.

Nov 11, 2024
7.8
CVE-2024-39354HIGH

If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing malicious code, a stack-based buffer overflow in CEtherIPTagItem can be exploited, allowing the attacker to remotely execute arbitrary code.

Nov 11, 2024
7.8
CVE-2024-7587HIGH

Incorrect Default Permissions vulnerability in GenBroker32, which is included in the installers for Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric GENESIS32 versions 9.70.300.23 and prior, Mitsubishi Electric Iconics Digital Solutions GENESIS32 versions 9.70.300.23 and prior, and Mitsubishi Electric MC Works64 all versions allows a local authenticated attacker to disclose or tamper with confidential information and data contained in the products, or cause a denial of service (DoS) condition on the products, by accessing a folder with incorrect permissions, when GenBroker32 is installed on the same PC as GENESIS64, ICONICS Suite, MC Works64, or GENESIS32.

Oct 22, 2024
7.8
CVE-2024-47966HIGH

Delta Electronics CNCSoft-G2 lacks proper initialization of memory prior to accessing it. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.

Oct 10, 2024
7.8
CVE-2024-47965HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.

Oct 10, 2024
7.8
CVE-2024-47964HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.

Oct 10, 2024
7.8
CVE-2024-47963HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.

Oct 10, 2024
7.8
CVE-2024-47962HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can manipulate an insider to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current process.

Oct 10, 2024
7.8
CVE-2024-7987HIGH

A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. To exploit this vulnerability and a threat actor must abuse the ThinServer™ service by creating a junction and use it to upload arbitrary files.

Aug 26, 2024
7.8
CVE-2024-7502HIGH

A crafted DPA file could force Delta Electronics DIAScreen to overflow a stack-based buffer, which could allow an attacker to execute arbitrary code.

Aug 6, 2024
7.8
CVE-2024-5402HIGH

Unquoted Search Path or Element vulnerability in ABB Mint Workbench. A local attacker who successfully exploited this vulnerability could gain elevated privileges by inserting an executable file in the path of the affected service. This issue affects Mint Workbench I versions: from 5866 before 5868.

Jul 15, 2024
7.8
CVE-2024-39880HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. If a target visits a malicious page or opens a malicious file an attacker can leverage this vulnerability to execute code in the context of the current process.

Jul 9, 2024
7.8
CVE-2021-47302HIGH

In the Linux kernel, the following vulnerability has been resolved: igc: Fix use-after-free error during reset Cleans the next descriptor to watch (next_to_watch) when cleaning the TX ring. Failure to do so can cause invalid memory accesses. If igc_poll() runs while the controller is being reset this can lead to the driver try to free a skb that was already freed. Log message: [ 101.525242] refcount_t: underflow; use-after-free. [ 101.525251] WARNING: CPU: 1 PID: 646 at lib/refcount.c:28 refcount_warn_saturate+0xab/0xf0 [ 101.525259] Modules linked in: sch_etf(E) sch_mqprio(E) rfkill(E) intel_rapl_msr(E) intel_rapl_common(E) x86_pkg_temp_thermal(E) intel_powerclamp(E) coretemp(E) binfmt_misc(E) kvm_intel(E) kvm(E) irqbypass(E) crc32_pclmul(E) ghash_clmulni_intel(E) aesni_intel(E) mei_wdt(E) libaes(E) crypto_simd(E) cryptd(E) glue_helper(E) snd_hda_codec_hdmi(E) rapl(E) intel_cstate(E) snd_hda_intel(E) snd_intel_dspcfg(E) sg(E) soundwire_intel(E) intel_uncore(E) at24(E) soundwire_generic_allocation(E) iTCO_wdt(E) soundwire_cadence(E) intel_pmc_bxt(E) serio_raw(E) snd_hda_codec(E) iTCO_vendor_support(E) watchdog(E) snd_hda_core(E) snd_hwdep(E) snd_soc_core(E) snd_compress(E) snd_pcsp(E) soundwire_bus(E) snd_pcm(E) evdev(E) snd_timer(E) mei_me(E) snd(E) soundcore(E) mei(E) configfs(E) ip_tables(E) x_tables(E) autofs4(E) ext4(E) crc32c_generic(E) crc16(E) mbcache(E) jbd2(E) sd_mod(E) t10_pi(E) crc_t10dif(E) crct10dif_generic(E) i915(E) ahci(E) libahci(E) ehci_pci(E) igb(E) xhci_pci(E) ehci_hcd(E) [ 101.525303] drm_kms_helper(E) dca(E) xhci_hcd(E) libata(E) crct10dif_pclmul(E) cec(E) crct10dif_common(E) tsn(E) igc(E) e1000e(E) ptp(E) i2c_i801(E) crc32c_intel(E) psmouse(E) i2c_algo_bit(E) i2c_smbus(E) scsi_mod(E) lpc_ich(E) pps_core(E) usbcore(E) drm(E) button(E) video(E) [ 101.525318] CPU: 1 PID: 646 Comm: irq/37-enp7s0-T Tainted: G E 5.10.30-rt37-tsn1-rt-ipipe #ipipe [ 101.525320] Hardware name: SIEMENS AG SIMATIC IPC427D/A5E31233588, BIOS V17.02.09 03/31/2017 [ 101.525322] RIP: 0010:refcount_warn_saturate+0xab/0xf0 [ 101.525325] Code: 05 31 48 44 01 01 e8 f0 c6 42 00 0f 0b c3 80 3d 1f 48 44 01 00 75 90 48 c7 c7 78 a8 f3 a6 c6 05 0f 48 44 01 01 e8 d1 c6 42 00 <0f> 0b c3 80 3d fe 47 44 01 00 0f 85 6d ff ff ff 48 c7 c7 d0 a8 f3 [ 101.525327] RSP: 0018:ffffbdedc0917cb8 EFLAGS: 00010286 [ 101.525329] RAX: 0000000000000000 RBX: ffff98fd6becbf40 RCX: 0000000000000001 [ 101.525330] RDX: 0000000000000001 RSI: ffffffffa6f2700c RDI: 00000000ffffffff [ 101.525332] RBP: ffff98fd6becc14c R08: ffffffffa7463d00 R09: ffffbdedc0917c50 [ 101.525333] R10: ffffffffa74c3578 R11: 0000000000000034 R12: 00000000ffffff00 [ 101.525335] R13: ffff98fd6b0b1000 R14: 0000000000000039 R15: ffff98fd6be35c40 [ 101.525337] FS: 0000000000000000(0000) GS:ffff98fd6e240000(0000) knlGS:0000000000000000 [ 101.525339] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 101.525341] CR2: 00007f34135a3a70 CR3: 0000000150210003 CR4: 00000000001706e0 [ 101.525343] Call Trace: [ 101.525346] sock_wfree+0x9c/0xa0 [ 101.525353] unix_destruct_scm+0x7b/0xa0 [ 101.525358] skb_release_head_state+0x40/0x90 [ 101.525362] skb_release_all+0xe/0x30 [ 101.525364] napi_consume_skb+0x57/0x160 [ 101.525367] igc_poll+0xb7/0xc80 [igc] [ 101.525376] ? sched_clock+0x5/0x10 [ 101.525381] ? sched_clock_cpu+0xe/0x100 [ 101.525385] net_rx_action+0x14c/0x410 [ 101.525388] __do_softirq+0xe9/0x2f4 [ 101.525391] __local_bh_enable_ip+0xe3/0x110 [ 101.525395] ? irq_finalize_oneshot.part.47+0xe0/0xe0 [ 101.525398] irq_forced_thread_fn+0x6a/0x80 [ 101.525401] irq_thread+0xe8/0x180 [ 101.525403] ? wake_threads_waitq+0x30/0x30 [ 101.525406] ? irq_thread_check_affinity+0xd0/0xd0 [ 101.525408] kthread+0x183/0x1a0 [ 101.525412] ? kthread_park+0x80/0x80 [ 101.525415] ret_from_fork+0x22/0x30

May 21, 2024
7.8
CVE-2024-4192HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.

Apr 30, 2024
7.8
CVE-2024-2929HIGH

A memory corruption vulnerability in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert unauthorized code to the software by corrupting the memory triggering an access violation. Once inside, the threat actor can run harmful code on the system. This affects the confidentiality, integrity, and availability of the product. To trigger this, the user would unwittingly need to open a malicious file shared by the threat actor.

Mar 26, 2024
7.8
CVE-2024-21919HIGH

An uninitialized pointer in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert unauthorized code to the software by leveraging the pointer after it is properly. Once inside, the threat actor can run harmful code on the system. This affects the confidentiality, integrity, and availability of the product. To trigger this, the user would unwittingly need to open a malicious file shared by the threat actor.

Mar 26, 2024
7.8
CVE-2024-21918HIGH

A memory buffer vulnerability in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert unauthorized code to the software by corrupting the memory and triggering an access violation. Once inside, the threat actor can run harmful code on the system. This affects the confidentiality, integrity, and availability of the product. To trigger this, the user would unwittingly need to open a malicious file shared by the threat actor.

Mar 26, 2024
7.8
CVE-2024-21913HIGH

A heap-based memory buffer overflow vulnerability in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert unauthorized code into the software by overstepping the memory boundaries, which triggers an access violation. Once inside, the threat actor can run harmful code on the system. This affects the confidentiality, integrity, and availability of the product. To trigger this, the user would unwittingly need to open a malicious file shared by the threat actor.

Mar 26, 2024
7.8
CVE-2024-21912HIGH

An arbitrary code execution vulnerability in Rockwell Automation Arena Simulation could let a malicious user insert unauthorized code into the software. This is done by writing beyond the designated memory area, which causes an access violation. Once inside, the threat actor can run harmful code on the system. This affects the confidentiality, integrity, and availability of the product. To trigger this, the user would unwittingly need to open a malicious file shared by the threat actor.

Mar 26, 2024
7.8
CVE-2024-1941HIGH

Delta Electronics CNCSoft-B versions 1.0.0.4 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.

Mar 1, 2024
7.8
CVE-2024-1595HIGH

Delta Electronics CNCSoft-B DOPSoft prior to v4.0.0.82 insecurely loads libraries, which may allow an attacker to use DLL hijacking and take over the system where the software is installed.

Feb 29, 2024
7.8
CVE-2022-48626HIGH

In the Linux kernel, the following vulnerability has been resolved: moxart: fix potential use-after-free on remove path It was reported that the mmc host structure could be accessed after it was freed in moxart_remove(), so fix this by saving the base register of the device and using it instead of the pointer dereference.

Feb 26, 2024
7.8
CVE-2023-5944HIGH

Delta Electronics DOPSoft is vulnerable to a stack-based buffer overflow, which may allow for arbitrary code execution if an attacker can lead a legitimate user to execute a specially crafted file.

Dec 4, 2023
7.8
CVE-2023-5247HIGH

Malicious Code Execution Vulnerability due to External Control of File Name or Path in multiple Mitsubishi Electric FA Engineering Software Products allows a malicious attacker to execute a malicious code by having legitimate users open a specially crafted project file, which could result in information disclosure, tampering and deletion, or a denial-of-service (DoS) condition.

Nov 30, 2023
7.8
CVE-2023-6179HIGH

Honeywell ProWatch, 4.5, including all Service Pack versions, contain a Vulnerability in Application Server's executable folder(s). A(n) attacker could potentially exploit this vulnerability, leading to a standard user to have arbitrary system code execution. Honeywell recommends updating to the most recent version of this product, service or offering (Pro-watch 6.0.2, 6.0, 5.5.2,5.0.5).

Nov 17, 2023
7.8
CVE-2023-27858HIGH

Rockwell Automation Arena Simulation contains an arbitrary code execution vulnerability that could potentially allow a malicious user to commit unauthorized code to the software by using an uninitialized pointer in the application.  The threat-actor could then execute malicious code on the system affecting the confidentiality, integrity, and availability of the product.  The user would need to open a malicious file provided to them by the attacker for the code to execute.

Oct 27, 2023
7.8
CVE-2023-27854HIGH

An arbitrary code execution vulnerability was reported to Rockwell Automation in Arena Simulation that could potentially allow a malicious user to commit unauthorized arbitrary code to the software by using a memory buffer overflow.  The threat-actor could then execute malicious code on the system affecting the confidentiality, integrity, and availability of the product.  The user would need to open a malicious file provided to them by the attacker for the code to execute.

Oct 27, 2023
7.8
CVE-2023-5068HIGH

Delta Electronics DIAScreen may write past the end of an allocated buffer while parsing a specially crafted input file. This could allow an attacker to execute code in the context of the current process.

Sep 21, 2023
7.8
CVE-2023-4685HIGH

Delta Electronics' CNCSoft-B version 1.0.0.4 and DOPSoft versions 4.0.0.82 and prior are vulnerable to stack-based buffer overflow, which could allow an attacker to execute arbitrary code.

Sep 7, 2023
7.8
CVE-2021-41544HIGH

A vulnerability has been identified in Siemens Software Center (All versions < V3.0). A DLL Hijacking vulnerability could allow a local attacker to execute code with elevated privileges by placing a malicious DLL in one of the directories on the DLL search path.

Aug 8, 2023
7.8
CVE-2023-25177HIGH

Delta Electronics' CNCSoft-B DOPSoft versions 1.0.0.4 and prior are vulnerable to stack-based buffer overflow, which could allow an attacker to execute arbitrary code.

Jun 7, 2023
7.8
CVE-2023-24014HIGH

Delta Electronics' CNCSoft-B DOPSoft versions 1.0.0.4 and prior are vulnerable to heap-based buffer overflow, which could allow an attacker to execute arbitrary code.

Jun 7, 2023
7.8
CVE-2023-0635HIGH

Improper Privilege Management vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS Series, Linux (2CQG100102R2021, 2CQG100104R2021, 2CQG100105R2021, 2CQG100106R2021, 2CQG100110R2021, 2CQG100112R2021, 2CQG100103R2021, 2CQG100107R2021, 2CQG100108R2021, 2CQG100109R2021, 2CQG100111R2021, 2CQG100113R2021 modules), ABB Ltd. MATRIX Series on MATRIX Series, Linux (2CQG100102R1021, 2CQG100103R1021, 2CQG100104R1021, 2CQG100105R1021, 2CQG100106R1021 modules) allows Privilege Escalation.This issue affects ASPECT®-Enterprise: from 3.0;0 before 3.07.01; NEXUS Series: from 3.0;0 before 3.07.01; MATRIX Series: from 3.0;0 before 3.07.01.

Jun 5, 2023
7.8
CVE-2022-0010HIGH

Insertion of Sensitive Information into Log File vulnerability in ABB QCS 800xA, ABB QCS AC450, ABB Platform Engineering Tools. An attacker, who already has local access to the QCS nodes, could successfully obtain the password for a system user account. Using this information, the attacker could have the potential to exploit this vulnerability to gain control of system nodes. This issue affects QCS 800xA: from 1.0;0 through 6.1SP2; QCS AC450: from 1.0;0 through 5.1SP2; Platform Engineering Tools: from 1.0:0 through 2.3.0.

May 22, 2023
7.8
CVE-2023-29462HIGH

An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a malicious user to commit unauthorized arbitrary code to the software by using a memory buffer overflow in the heap. potentially resulting in a complete loss of confidentiality, integrity, and availability.

May 9, 2023
7.8
CVE-2023-29461HIGH

An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a malicious user to commit unauthorized arbitrary code to the software by using a memory buffer overflow in the heap. potentially resulting in a complete loss of confidentiality, integrity, and availability.

May 9, 2023
7.8
CVE-2023-29460HIGH

An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a malicious user to commit unauthorized arbitrary code to the software by using a memory buffer overflow potentially resulting in a complete loss of confidentiality, integrity, and availability.

May 9, 2023
7.8
CVE-2023-26593HIGH

CENTUM series provided by Yokogawa Electric Corporation are vulnerable to cleartext storage of sensitive information. If an attacker who can login or access the computer where the affected product is installed tampers the password file stored in the computer, the user privilege which CENTUM managed may be escalated. As a result, the control system may be operated with the escalated user privilege. To exploit this vulnerability, the following prerequisites must be met: (1)An attacker has obtained user credentials where the affected product is installed, (2)CENTUM Authentication Mode is used for user authentication when CENTUM VP is used. The affected products and versions are as follows: CENTUM CS 1000, CENTUM CS 3000 (Including CENTUM CS 3000 Entry Class) R2.01.00 to R3.09.50, CENTUM VP (Including CENTUM VP Entry Class) R4.01.00 to R4.03.00, R5.01.00 to R5.04.20, and R6.01.00 and later, B/M9000 CS R5.04.01 to R5.05.01, and B/M9000 VP R6.01.01 to R7.04.51 and R8.01.01 and later

Apr 11, 2023
7.8
CVE-2023-1145HIGH

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the Device-DataCollect service, which could allow deserialization of requests prior to authentication, resulting in remote code execution.

Mar 27, 2023
7.8
CVE-2023-1135HIGH

In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could set incorrect directory permissions, which could result in local privilege escalation.

Mar 27, 2023
7.8
CVE-2023-0598HIGH

GE Digital Proficy iFIX 2022, GE Digital Proficy iFIX v6.1, and GE Digital Proficy iFIX v6.5 are vulnerable to code injection, which may allow an attacker to insert malicious configuration files in the expected web server execution path and gain full control of the HMI software.

Mar 16, 2023
7.8
CVE-2023-0251HIGH

Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to a buffer overflow through improper restrictions of operations within memory, which could allow an attacker to remotely execute arbitrary code.

Feb 8, 2023
7.8
CVE-2023-0250HIGH

Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to a stack-based buffer overflow, which could allow an attacker to remotely execute arbitrary code.

Feb 8, 2023
7.8
CVE-2023-0249HIGH

Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to out-of-bounds write, which may allow an attacker to remotely execute arbitrary code.

Feb 8, 2023
7.8
CVE-2023-0124HIGH

Delta Electronics DOPSoft versions 4.00.16.22 and prior are vulnerable to an out-of-bounds write, which could allow an attacker to remotely execute arbitrary code when a malformed file is introduced to the software.

Feb 3, 2023
7.8
CVE-2023-0123HIGH

Delta Electronics DOPSoft versions 4.00.16.22 and prior are vulnerable to a stack-based buffer overflow, which could allow an attacker to remotely execute arbitrary code when a malformed file is introduced to the software.

Feb 3, 2023
7.8
CVE-2022-42973HIGH

A CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause local privilege escalation when local attacker connects to the database. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)

Feb 1, 2023
7.8
CVE-2022-42972HIGH

A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cause local privilege escalation when a local attacker modifies the webroot directory. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261)

Feb 1, 2023
7.8
CVE-2022-3156HIGH

A remote code execution vulnerability exists in Rockwell Automation Studio 5000 Logix Emulate software.  Users are granted elevated permissions on certain product services when the software is installed. Due to this misconfiguration, a malicious user could potentially achieve remote code execution on the targeted software.

Dec 27, 2022
7.8
CVE-2020-12069HIGH

In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.

Dec 26, 2022
7.8
CVE-2022-3088HIGH

UC-8100A-ME-T System Image: Versions v1.0 to v1.6, UC-2100 System Image: Versions v1.0 to v1.12, UC-2100-W System Image: Versions v1.0 to v 1.12,&nbsp;UC-3100 System Image: Versions v1.0 to v1.6,&nbsp;UC-5100 System Image: Versions v1.0 to v1.4, UC-8100 System Image: Versions v3.0 to v3.5, UC-8100-ME-T System Image: Versions v3.0 and v3.1, UC-8200 System Image: v1.0 to v1.5, AIG-300 System Image: v1.0 to v1.4, UC-8410A with Debian 9 System Image: Versions v4.0.2 and v4.1.2, UC-8580 with Debian 9 System Image: Versions v2.0 and v2.1, UC-8540 with Debian 9 System Image: Versions v2.0 and v2.1, and DA-662C-16-LX (GLB) System Image: Versions v1.0.2 to v1.1.2 of Moxa's ARM-based computers have an execution with unnecessary privileges vulnerability, which could allow an attacker with user-level privileges to gain root privileges.

Nov 28, 2022
7.8
CVE-2022-3737HIGH

In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 memory can be read beyond the intended scope due to insufficient validation of input data. Availability, integrity, or confidentiality of an application programming workstation might be compromised by attacks using these vulnerabilities.

Nov 15, 2022
7.8
CVE-2022-3461HIGH

In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 manipulated PC Worx or Config+ files could lead to a heap buffer overflow and a read access violation. Availability, integrity, or confidentiality of an application programming workstation might be compromised by attacks using these vulnerabilities.

Nov 15, 2022
7.8
CVE-2022-2069HIGH

The APDFL.dll in Siemens JT2Go prior to V13.3.0.5 and Siemens Teamcenter Visualization prior to V14.0.0.2 contains an out of bounds write past the fixed-length heap-based buffer while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.

Oct 20, 2022
7.8
CVE-2022-3398HIGH

OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code.

Oct 6, 2022
7.8
CVE-2022-3397HIGH

OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code.

Oct 6, 2022
7.8
CVE-2022-3396HIGH

OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code.

Oct 6, 2022
7.8
CVE-2022-33320HIGH

Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric ICONICS Suite versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97 to 10.97.1, and Mitsubishi Electric MC Works64 versions 4.04E and prior allows an unauthenticated attacker to execute an arbitrary malicious code by leading a user to load a project configuration file including malicious XML codes.

Jul 20, 2022
7.8
CVE-2022-33317HIGH

Inclusion of Functionality from Untrusted Control Sphere vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric ICONICS Suite versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97 to 10.97.1, and Mitsubishi Electric MC Works64 versions 4.04E and prior allows an unauthenticated attacker to execute an arbitrary malicious code by leading a user to load a monitoring screen file including malicious script codes.

Jul 20, 2022
7.8
CVE-2022-33316HIGH

Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric ICONICS Suite versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97 to 10.97.1, and Mitsubishi Electric MC Works64 versions 4.04E and prior allows an unauthenticated attacker to execute an arbitrary malicious code by leading a user to load a monitoring screen file including malicious XAML codes.

Jul 20, 2022
7.8
CVE-2022-33315HIGH

Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric ICONICS Suite versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97 to 10.97.1, and Mitsubishi Electric MC Works64 versions 4.04E and prior allows an unauthenticated attacker to execute an arbitrary malicious code by leading a user to load a monitoring screen file including malicious XAML codes.

Jul 20, 2022
7.8
CVE-2022-29483HIGH

Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with SYSTEM permissions violating confidentiality, integrity, and availability of the target machine.

Jun 2, 2022
7.8
CVE-2021-32969HIGH

Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to an out-of-bounds write condition, which may result in a system crash or allow an attacker to remotely execute arbitrary code.

May 24, 2022
7.8
CVE-2021-32965HIGH

Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to type confusion, which may allow an attacker to remotely execute arbitrary code.

May 24, 2022
7.8
CVE-2022-22516HIGH

The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory space.

Apr 7, 2022
7.8
CVE-2022-26419HIGH

Omron CX-Position (versions 2.5.3 and prior) is vulnerable to multiple stack-based buffer overflow conditions while parsing a specific project file, which may allow an attacker to locally execute arbitrary code.

Apr 1, 2022
7.8
CVE-2022-26417HIGH

Omron CX-Position (versions 2.5.3 and prior) is vulnerable to a use after free memory condition while processing a specific project file, which may allow an attacker to execute arbitrary code.

Apr 1, 2022
7.8
CVE-2022-26022HIGH

Omron CX-Position (versions 2.5.3 and prior) is vulnerable to an out-of-bounds write while processing a specific project file, which may allow an attacker to execute arbitrary code.

Apr 1, 2022
7.8
CVE-2022-25959HIGH

Omron CX-Position (versions 2.5.3 and prior) is vulnerable to memory corruption while processing a specific project file, which may allow an attacker to execute arbitrary code.

Apr 1, 2022
7.8
CVE-2022-1098HIGH

Delta Electronics DIAEnergie (all versions prior to 1.8.02.004) are vulnerable to a DLL hijacking condition. When combined with the Incorrect Default Permissions vulnerability of 4.2.2 above, this makes it possible for an attacker to escalate privileges

Apr 1, 2022
7.8
CVE-2022-26839HIGH

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to an incorrect default permission in the DIAEnergie application, which may allow an attacker to plant new files (such as DLLs) or replace existing executable files.

Mar 29, 2022
7.8
CVE-2020-25184HIGH

Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable file. ISaGRAF Runtime reads the file and saves the data in a variable without any additional modification. A local, unauthenticated attacker could compromise the user passwords, resulting in information disclosure.

Mar 18, 2022
7.8
CVE-2022-23401HIGH

The following Yokogawa Electric products contain insecure DLL loading issues. CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00.

Mar 11, 2022
7.8
CVE-2022-22148HIGH

'Root Service' service implemented in the following Yokogawa Electric products creates some named pipe with improper ACL configuration. CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00.

Mar 11, 2022
7.8
CVE-2022-22141HIGH

'Long-term Data Archive Package' service implemented in the following Yokogawa Electric products creates some named pipe with imporper ACL configuration. CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00.

Mar 11, 2022
7.8
CVE-2021-40397HIGH

A privilege escalation vulnerability exists in the installation of Advantech WISE-PaaS/OTA Server 3.0.9. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.

Jan 28, 2022
7.8
CVE-2021-22808HIGH

A CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution when a malicious *.gd1 configuration file is loaded into the GUIcon tool. Affected Product: Eurotherm by Schneider Electric GUIcon Version 2.0 (Build 683.003) and prior

Jan 28, 2022
7.8
CVE-2021-22807HIGH

A CWE-787: Out-of-bounds Write vulnerability exists that could cause arbitrary code execution when a malicious *.gd1 configuration file is loaded into the GUIcon tool. Affected Product: Eurotherm by Schneider Electric GUIcon Version 2.0 (Build 683.003) and prior

Jan 28, 2022
7.8
CVE-2022-21137HIGH

Omron CX-One Versions 4.60 and prior are vulnerable to a stack-based buffer overflow while processing specific project files, which may allow an attacker to execute arbitrary code.

Jan 14, 2022
7.8
CVE-2021-21912HIGH

A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.

Dec 22, 2021
7.8
CVE-2021-21911HIGH

A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.

Dec 22, 2021
7.8
CVE-2021-21910HIGH

A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.

Dec 22, 2021
7.8
CVE-2021-43982HIGH

Delta Electronics CNCSoft Versions 1.01.30 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.

Dec 9, 2021
7.8
CVE-2021-34597HIGH

Improper Input Validation vulnerability in PC Worx Automation Suite of Phoenix Contact up to version 1.88 could allow an attacker with a manipulated project file to unpack arbitrary files outside of the selected project directory.

Nov 4, 2021
7.8
CVE-2021-38422HIGH

Delta Electronics DIALink versions 1.2.4.0 and prior stores sensitive information in cleartext, which may allow an attacker to have extensive access to the application directory and escalate privileges.

Nov 3, 2021
7.8
CVE-2021-38420HIGH

Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged user accounts, which may allow an attacker to modify the installation directory and upload malicious files.

Nov 3, 2021
7.8
CVE-2021-38416HIGH

Delta Electronics DIALink versions 1.2.4.0 and prior insecurely loads libraries, which may allow an attacker to use DLL hijacking and takeover the system where the software is installed.

Nov 3, 2021
7.8
CVE-2021-33019HIGH

A stack-based buffer overflow vulnerability in Delta Electronics DOPSoft Version 4.00.11 and prior may be exploited by processing a specially crafted project file, which may allow an attacker to execute arbitrary code.

Aug 30, 2021
7.8
CVE-2021-33007HIGH

A heap-based buffer overflow in Delta Electronics TPEditor: v1.98.06 and prior may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to execute arbitrary code.

Aug 30, 2021
7.8
CVE-2021-21869HIGH

An unsafe deserialization vulnerability exists in the Engine.plugin ProfileInformation ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.

Aug 25, 2021
7.8
CVE-2021-21868HIGH

An unsafe deserialization vulnerability exists in the ObjectManager.plugin Project.get_MissingTypes() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.

Aug 18, 2021
7.8
CVE-2021-21867HIGH

An unsafe deserialization vulnerability exists in the ObjectManager.plugin ObjectStream.ProfileByteArray functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.

Aug 18, 2021
7.8
CVE-2021-21863HIGH

A unsafe deserialization vulnerability exists in the ComponentModel Profile.FromFile() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.

Aug 5, 2021
7.8
CVE-2021-21866HIGH

A unsafe deserialization vulnerability exists in the ObjectManager.plugin ProfileInformation.ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.

Aug 2, 2021
7.8
CVE-2021-21865HIGH

A unsafe deserialization vulnerability exists in the PackageManagement.plugin ExtensionMethods.Clone() functionality of CODESYS GmbH CODESYS Development System 3.5.16. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.

Aug 2, 2021
7.8
CVE-2021-21864HIGH

A unsafe deserialization vulnerability exists in the ComponentModel ComponentManager.StartupCultureSettings functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.

Aug 2, 2021
7.8
CVE-2021-27412HIGH

Delta Electronics DOPSoft Versions 4.0.10.17 and prior are vulnerable to an out-of-bounds read, which may allow an attacker to execute arbitrary code.

Jul 2, 2021
7.8
CVE-2021-33542HIGH

Phoenix Contact Classic Automation Worx Software Suite in Version 1.87 and below is affected by a remote code execution vulnerability. Manipulated PC Worx or Config+ projects could lead to a remote code execution when unallocated memory is freed because of incompletely initialized data. The attacker needs to get access to an original bus configuration file (*.bcp) to be able to manipulate data inside. After manipulation the attacker needs to exchange the original file by the manipulated one on the application programming workstation. Availability, integrity, or confidentiality of an application programming workstation might be compromised by attacks using these vulnerabilities. Automated systems in operation which were programmed with one of the above-mentioned products are not affected.

Jun 25, 2021
7.8
CVE-2021-27413HIGH

Omron CX-One Versions 4.60 and prior, including CX-Server Versions 5.0.29.0 and prior, are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.

May 13, 2021
7.8
CVE-2021-22672HIGH

Delta Electronics' CNCSoft ScreenEditor in versions prior to v1.01.30 could allow the corruption of data, a denial-of-service condition, or code execution. The vulnerability may allow an attacker to remotely execute arbitrary code.

May 10, 2021
7.8
CVE-2021-29240HIGH

The Package Manager of CODESYS Development System 3 before 3.5.17.0 does not check the validity of packages before installation and may be used to install CODESYS packages with malicious content.

May 4, 2021
7.8
CVE-2021-29239HIGH

CODESYS Development System 3 before 3.5.17.0 displays or executes malicious documents or files embedded in libraries without first checking their validity.

May 3, 2021
7.8
CVE-2021-22665HIGH

Rockwell Automation DriveTools SP v5.13 and below and Drives AOP v4.12 and below both contain a vulnerability that a local attacker with limited privileges may be able to exploit resulting in privilege escalation and complete control of the system.

Mar 18, 2021
7.8
CVE-2020-13554HIGH

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webvrpcs Run Key Privilege Escalation in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.

Mar 3, 2021
7.8
CVE-2020-27257HIGH

This vulnerability allows local attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, which can result in a type-confusion condition in the Omron CX-One Version 4.60 and prior devices.

Feb 9, 2021
7.8
CVE-2020-27293HIGH

Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior has a type confusion issue while processing project files, which may allow an attacker to execute arbitrary code.

Jan 11, 2021
7.8
CVE-2020-27291HIGH

Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior is vulnerable to an out-of-bounds read while processing project files, which may allow an attacker to execute arbitrary code.

Jan 11, 2021
7.8
CVE-2020-27289HIGH

Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior has a null pointer dereference issue while processing project files, which may allow an attacker to execute arbitrary code.

Jan 11, 2021
7.8
CVE-2020-27287HIGH

Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior is vulnerable to an out-of-bounds write while processing project files, which may allow an attacker to execute arbitrary code.

Jan 11, 2021
7.8
CVE-2020-27281HIGH

A stack-based buffer overflow may exist in Delta Electronics CNCSoft ScreenEditor versions 1.01.26 and prior when processing specially crafted project files, which may allow an attacker to execute arbitrary code.

Jan 11, 2021
7.8
CVE-2020-27277HIGH

Delta Electronics DOPSoft Version 4.0.8.21 and prior has a null pointer dereference issue while processing project files, which may allow an attacker to execute arbitrary code.

Jan 11, 2021
7.8
CVE-2020-27275HIGH

Delta Electronics DOPSoft Version 4.0.8.21 and prior is vulnerable to an out-of-bounds write while processing project files, which may allow an attacker to execute arbitrary code.

Jan 11, 2021
7.8
CVE-2020-13537HIGH

An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8 installation. Depending on the vector chosen, an attacker can either add code to a script or replace a binary.By default MXViewService, which starts as a NT SYSTEM authority user executes a series of Node.Js scripts to start additional application functionality and among them the mosquitto executable is also run.

Nov 5, 2020
7.8
CVE-2020-13536HIGH

An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8 installation. Depending on the vector chosen, an attacker can either add code to a script or replace a binary. By default MXViewService, which starts as a NT SYSTEM authority user executes a series of Node.Js scripts to start additional application functionality.

Nov 5, 2020
7.8
CVE-2020-7523HIGH

Improper Privilege Management vulnerability exists in Schneider Electric Modbus Serial Driver (see security notification for versions) which could cause local privilege escalation when the Modbus Serial Driver service is invoked. The driver does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Aug 31, 2020
7.8
CVE-2019-20383HIGH

ABBYY network license server in ABBYY FineReader 15 before Release 4 (aka 15.0.112.2130) allows escalation of privileges by local users via manipulations involving files and using symbolic links.

Aug 13, 2020
7.8
CVE-2020-16227HIGH

Delta Electronics TPEditor Versions 1.97 and prior. An improper input validation may be exploited by processing a specially crafted project file not validated when the data is entered by a user. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.

Aug 7, 2020
7.8
CVE-2020-16225HIGH

Delta Electronics TPEditor Versions 1.97 and prior. A write-what-where condition may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.

Aug 7, 2020
7.8
CVE-2020-16223HIGH

Delta Electronics TPEditor Versions 1.97 and prior. A heap-based buffer overflow may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.

Aug 7, 2020
7.8
CVE-2020-16221HIGH

Delta Electronics TPEditor Versions 1.97 and prior. A stack-based buffer overflow may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.

Aug 7, 2020
7.8
CVE-2020-16219HIGH

Delta Electronics TPEditor Versions 1.97 and prior. An out-of-bounds read may be exploited by processing specially crafted project files. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.

Aug 7, 2020
7.8
CVE-2020-16229HIGH

Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper validation of user supplied data may cause a type confusion condition, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.

Aug 6, 2020
7.8
CVE-2020-16217HIGH

Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. A double free vulnerability caused by processing specially crafted project files may allow remote code execution, disclosure/modification of information, or cause the application to crash.

Aug 6, 2020
7.8
CVE-2020-16215HIGH

Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper validation of user supplied data may cause a stack-based buffer overflow, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.

Aug 6, 2020
7.8
CVE-2020-16213HIGH

Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper validation of user supplied data may cause the system to write outside the intended buffer area, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.

Aug 6, 2020
7.8
CVE-2020-16207HIGH

Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by opening specially crafted project files that may overflow the heap, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.

Aug 6, 2020
7.8
CVE-2020-12498HIGH

mwe file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier is vulnerable to out-of-bounds read remote code execution. Manipulated PC Worx projects could lead to a remote code execution due to insufficient input data validation.

Jul 1, 2020
7.8
CVE-2020-12497HIGH

PLCopen XML file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier can lead to a stack-based overflow. Manipulated PC Worx projects could lead to a remote code execution due to insufficient input data validation.

Jul 1, 2020
7.8
CVE-2020-8482HIGH

Insecure storage of sensitive information in ABB Device Library Wizard versions 6.0.X, 6.0.3.1 and 6.0.3.2 allows unauthenticated low privilege user to read file that contains confidential data

May 29, 2020
7.8
CVE-2019-5621HIGH

ABBS Software Audio Media Player version 3.1 suffers from an instance of CWE-121: Stack-based Buffer Overflow.

Apr 29, 2020
7.8
CVE-2020-8489HIGH

Insufficient protection of the inter-process communication functions in ABB System 800xA Information Management (all published versions) enables an attacker authenticated on the local system to inject data, affecting the runtime values to be stored in the archive, or making Information Management history services unavailable.

Apr 29, 2020
7.8
CVE-2020-8488HIGH

Insufficient protection of the inter-process communication functions in ABB System 800xA Batch Management (all published versions) enables an attacker authenticated on the local system to inject data, affecting User Interface update during batch execution and/or compare/printing functionalities.

Apr 29, 2020
7.8
CVE-2020-8485HIGH

Insufficient protection of the inter-process communication functions in ABB System 800xA for MOD 300 (all published versions) enables an attacker authenticated on the local system to inject data, allowing reads and writes to the controllers or cause windows processes to crash.

Apr 29, 2020
7.8
CVE-2020-8484HIGH

Insufficient protection of the inter-process communication functions in ABB System 800xA for DCI (all published versions) enables an attacker authenticated on the local system to inject data, allowing reads and writes to the controllers or cause windows processes to crash.

Apr 29, 2020
7.8
CVE-2020-8471HIGH

For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+ Engineering 1.1 to 2.2, Composer Harmony 5.1, 6.0 and 6.1, Melody Composer 5.3, 6.1/6.2 and SPE for Melody 1.0SPx (Composer 6.3), Harmony OPC Server (HAOPC) Standalone 6.0, 6.1 and 7.0, ABB Ability™ System 800xA/ Advant® OCS Control Builder A 1.3 and 1.4, Advant® OCS AC100 OPC Server 5.1, 6.0 and 6.1, Composer CTK 6.1 and 6.2, AdvaBuild 3.7 SP1 and SP2, OPCServer for MOD 300 (non-800xA) 1.4, OPC Data Link 2.1 and 2.2, Knowledge Manager 8.0, 9.0 and 9.1, Manufacturing Operations Management 1812 and 1909, weak file permissions allow an authenticated attacker to block the license handling, escalate his/her privileges and execute arbitrary code.

Apr 29, 2020
7.8
CVE-2020-8474HIGH

Weak Registry permissions in ABB System 800xA Base allow low privileged users to read and modify registry settings related to control system functionality, allowing an authenticated attacker to cause system functions to stop or malfunction.

Apr 22, 2020
7.8
CVE-2020-10642HIGH

In Rockwell Automation RSLinx Classic versions 4.11.00 and prior, an authenticated local attacker could modify a registry key, which could lead to the execution of malicious code using system privileges when opening RSLinx Classic.

Apr 13, 2020
7.8
CVE-2020-10940HIGH

Local Privilege Escalation can occur in PHOENIX CONTACT PORTICO SERVER through 3.0.7 when installed to run as a service.

Mar 27, 2020
7.8
CVE-2020-10939HIGH

Insecure, default path permissions in PHOENIX CONTACT PC WORX SRT through 1.14 allow for local privilege escalation.

Mar 27, 2020
7.8
CVE-2019-5184HIGH

An exploitable double free vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200. A specially crafted XML cache file written to a specific location on the device can cause a heap pointer to be freed twice, resulting in a denial of service and potentially code execution. An attacker can send a specially crafted packet to trigger the parsing of this cache file.

Mar 23, 2020
7.8
CVE-2019-5181HIGH

An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can cause a stack buffer overflow, resulting in code execution. An attacker can send a specially crafted packet to trigger the parsing of this cache file. The destination buffer sp+0x440 is overflowed with the call to sprintf() for any subnetmask values that are greater than 1024-len(‘/etc/config-tools/config_interfaces interface=X1 state=enabled subnet-mask=‘) in length. A subnetmask value of length 0x3d9 will cause the service to crash.

Mar 12, 2020
7.8
CVE-2019-5180HIGH

An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 Firmware version 03.02.02(14). An attacker can send a specially crafted packet to trigger the parsing of this cache file. The destination buffer sp+0x440 is overflowed with the call to sprintf() for any ip values that are greater than 1024-len(‘/etc/config-tools/config_interfaces interface=X1 state=enabled ip-address=‘) in length. A ip value of length 0x3da will cause the service to crash.

Mar 12, 2020
7.8
CVE-2019-5179HIGH

An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 Firmware version 03.02.02(14). An attacker can send a specially crafted packet to trigger the parsing of this cache file.

Mar 12, 2020
7.8
CVE-2019-5178HIGH

An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 Firmware version 03.02.02(14). An attacker can send a specially crafted packet to trigger the parsing of this cache file. The destination buffer sp+0x440 is overflowed with the call to sprintf() for any hostname values that are greater than 1024-len(‘/etc/config-tools/change_hostname hostname=‘) in length. A hostname value of length 0x3fd will cause the service to crash.

Mar 12, 2020
7.8
CVE-2019-5171HIGH

An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). An attacker can send specially crafted packet at 0x1ea48 to the extracted hostname value from the xml file that is used as an argument to /etc/config-tools/config_interfaces interface=X1 state=enabled ip-address=<contents of ip node> using sprintf().

Mar 12, 2020
7.8
CVE-2019-5170HIGH

An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can be used to inject OS commands. An attacker can send a specially crafted packet to trigger the parsing of this cache file.At 0x1e87c the extracted hostname value from the xml file is used as an argument to /etc/config-tools/change_hostname hostname=<contents of hostname node> using sprintf(). This command is later executed via a call to system().

Mar 12, 2020
7.8
CVE-2019-5169HIGH

An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can be used to inject OS commands. An attacker can send a specially crafted packet to trigger the parsing of this cache file. At 0x1e900 the extracted gateway value from the xml file is used as an argument to /etc/config-tools/config_default_gateway number=0 state=enabled value=<contents of gateway node> using sprintf(). This command is later executed via a call to system().

Mar 12, 2020
7.8
CVE-2019-5175HIGH

An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can be used to inject OS commands. An attacker can send a specially crafted packet to trigger the parsing of this cache file.At 0x1ea28 the extracted type value from the xml file is used as an argument to /etc/config-tools/config_interfaces interface=X1 state=enabled config-type=<contents of type node> using sprintf(). This command is later executed via a call to system().

Mar 11, 2020
7.8
CVE-2019-5174HIGH

An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can be used to inject OS commands. An attacker can send a specially crafted packet to trigger the parsing of this cache file.At 0x1e9fc the extracted subnetmask value from the xml file is used as an argument to /etc/config-tools/config_interfaces interface=X1 state=enabled subnet-mask=<contents of subnetmask node> using sprintf(). This command is later executed via a call to system().

Mar 11, 2020
7.8
CVE-2019-5173HIGH

An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can be used to inject OS commands. An attacker can send a specially crafted packet to trigger the parsing of this cache file. At 0x1e9fc the extracted state value from the xml file is used as an argument to /etc/config-tools/config_interfaces interface=X1 state=<contents of state node> using sprintf(). This command is later executed via a call to system().

Mar 11, 2020
7.8
CVE-2019-5172HIGH

An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). An attacker can send a specially crafted packet to trigger the parsing of this cache file. At 0x1e840 the extracted ntp value from the xml file is used as an argument to /etc/config-tools/config_sntp time-server-%d=<contents of ntp node> using sprintf(). This command is later executed via a call to system(). This is done in a loop and there is no limit to how many ntp entries will be parsed from the xml file.

Mar 11, 2020
7.8
CVE-2019-5168HIGH

An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 version 03.02.02(14). An attacker can send a specially crafted XML cache file At 0x1e8a8 the extracted domainname value from the xml file is used as an argument to /etc/config-tools/edit_dns_server domain-name=<contents of domainname node> using sprintf().This command is later executed via a call to system().

Mar 11, 2020
7.8
CVE-2019-5167HIGH

An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 version 03.02.02(14). At 0x1e3f0 the extracted dns value from the xml file is used as an argument to /etc/config-tools/edit_dns_server %s dns-server-nr=%d dns-server-name=<contents of dns node> using sprintf(). This command is later executed via a call to system(). This is done in a loop and there is no limit to how many dns entries will be parsed from the xml file.

Mar 11, 2020
7.8
CVE-2019-5166HIGH

An exploitable stack buffer overflow vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can cause a stack buffer overflow, resulting in code execution. An attacker can send a specially crafted packet to trigger the parsing of this cache file.

Mar 11, 2020
7.8
CVE-2019-5159HIGH

An exploitable improper input validation vulnerability exists in the firmware update functionality of WAGO e!COCKPIT automation software v1.6.0.7. A specially crafted firmware update file can allow an attacker to write arbitrary files to arbitrary locations on WAGO controllers as a part of executing a firmware update, potentially resulting in code execution. An attacker can create a malicious firmware update package file using any zip utility. The user must initiate a firmware update through e!COCKPIT and choose the malicious wup file using the file browser to trigger the vulnerability.

Mar 11, 2020
7.8
CVE-2019-5158HIGH

An exploitable firmware downgrade vulnerability exists in the firmware update package functionality of the WAGO e!COCKPIT automation software v1.6.1.5. A specially crafted firmware update file can allow an attacker to install an older firmware version while the user thinks a newer firmware version is being installed. An attacker can create a custom firmware update package with invalid metadata in order to trigger this vulnerability.

Mar 11, 2020
7.8
CVE-2020-6968HIGH

Honeywell INNCOM INNControl 3 allows workstation users to escalate application user privileges through the modification of local configuration files.

Feb 20, 2020
7.8
CVE-2019-13521HIGH

A maliciously crafted program file opened by an unsuspecting user of Rockwell Automation Arena Simulation Software version 16.00.00 and earlier may result in the limited exposure of information related to the targeted workstation. Rockwell Automation has released version 16.00.01 of Arena Simulation Software to address the reported vulnerabilities.

Jan 27, 2020
7.8
CVE-2019-13519HIGH

A maliciously crafted program file opened by an unsuspecting user of Rockwell Automation Arena Simulation Software version 16.00.00 and earlier may result in the limited exposure of information related to the targeted workstation. Rockwell Automation has released version 16.00.01 of Arena Simulation Software to address the reported vulnerabilities.

Jan 27, 2020
7.8
CVE-2019-6008HIGH

An unquoted search path vulnerability in Multiple Yokogawa products for Windows (Exaopc (R1.01.00 ? R3.77.00), Exaplog (R1.10.00 ? R3.40.00), Exaquantum (R1.10.00 ? R3.02.00 and R3.15.00), Exaquantum/Batch (R1.01.00 ? R2.50.40), Exasmoc (all revisions), Exarqe (all revisions), GA10 (R1.01.01 ? R3.05.01), and InsightSuiteAE (R1.01.00 ? R1.06.00)) allow local users to gain privileges via a Trojan horse executable file and execute arbitrary code with eleveted privileges.

Dec 26, 2019
7.8
CVE-2019-16675HIGH

An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to an Out-of-bounds Read and remote code execution. The attacker needs to get access to an original PC Worx or Config+ project to be able to manipulate data inside. After manipulation, the attacker needs to exchange the original files with the manipulated ones on the application programming workstation.

Oct 31, 2019
7.8
CVE-2019-13527HIGH

In Rockwell Automation Arena Simulation Software Cat. 9502-Ax, Versions 16.00.00 and earlier, a maliciously crafted Arena file opened by an unsuspecting user may result in the use of a pointer that has not been initialized.

Sep 24, 2019
7.8
CVE-2019-13544HIGH

Delta Electronics TPEditor, Versions 1.94 and prior. Multiple out-of-bounds write vulnerabilities may be exploited by processing specially crafted project files, which may allow remote code execution.

Sep 11, 2019
7.8
CVE-2019-13540HIGH

Delta Electronics TPEditor, Versions 1.94 and prior. Multiple stack-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to remotely execute arbitrary code.

Sep 11, 2019
7.8
CVE-2019-13536HIGH

Delta Electronics TPEditor, Versions 1.94 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, which may allow an attacker to remotely execute arbitrary code.

Sep 11, 2019
7.8
CVE-2019-13510HIGH

Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain a USE AFTER FREE CWE-416. A maliciously crafted Arena file opened by an unsuspecting user may result in the application crashing or the execution of arbitrary code.

Aug 15, 2019
7.8
CVE-2019-10982HIGH

Delta Electronics CNCSoft ScreenEditor, Versions 1.00.89 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, allowing an attacker to remotely execute arbitrary code. There is a lack of user input validation before copying data from project files onto the heap.

Jul 24, 2019
7.8
CVE-2018-19008HIGH

The TextEditor 2.0 in ABB CP400 Panel Builder versions 2.0.7.05 and earlier contain a vulnerability in the file parser of the Text Editor wherein the application doesn't properly prevent the insertion of specially crafted files which could allow arbitrary code execution.

Feb 13, 2019
7.8
CVE-2018-7815HIGH

A Type Confusion (CWE-843) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0) on c3core.dll which could cause remote code to be executed when parsing a GD1 file

Feb 6, 2019
7.8
CVE-2018-7814HIGH

A Stack-based Buffer Overflow (CWE-121) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0) which could cause remote code to be executed when parsing a GD1 file

Feb 6, 2019
7.8
CVE-2018-7813HIGH

A Type Confusion (CWE-843) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0) on pcwin.dll which could cause remote code to be executed when parsing a GD1 file

Feb 6, 2019
7.8
CVE-2018-17913HIGH

A type confusion vulnerability exists when processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior, which may allow an attacker to execute code in the context of the application.

Nov 5, 2018
7.8
CVE-2018-17909HIGH

When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior, the application fails to check if it is referencing freed memory, which may allow an attacker to execute code under the context of the application.

Nov 5, 2018
7.8
CVE-2018-17905HIGH

When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with a specific byte, memory corruption may occur within a specific object.

Nov 5, 2018
7.8
CVE-2018-7799HIGH

A DLL hijacking vulnerability exists in Schneider Electric Software Update (SESU), all versions prior to V2.2.0, which could allow an attacker to execute arbitrary code on the targeted system when placing a specific DLL file.

Nov 2, 2018
7.8
CVE-2018-14828HIGH

Advantech WebAccess 8.3.1 and earlier has an improper privilege management vulnerability, which may allow an attacker to access those files and perform actions at a system administrator level.

Oct 23, 2018
7.8
CVE-2018-14800HIGH

Delta Electronics ISPSoft version 3.0.5 and prior allow an attacker, by opening a crafted file, to cause the application to read past the boundary allocated to a stack object, which could allow execution of code under the context of the application.

Oct 3, 2018
7.8
CVE-2018-13806HIGH

A vulnerability has been identified in SIEMENS TD Keypad Designer (All versions). A DLL hijacking vulnerability exists in all versions of SIEMENS TD Keypad Designer which could allow an attacker to execute code with the permission of the user running TD Designer. The attacker must have write access to the directory containing the TD project file in order to exploit the vulnerability. A legitimate user with higher privileges than the attacker must open the TD project in order for this vulnerability to be exploited. At the time of advisory publication no public exploitation of this security vulnerability was known.

Sep 12, 2018
7.8
CVE-2018-10616HIGH

ABB Panel Builder 800 all versions has an improper input validation vulnerability which may allow an attacker to insert and run arbitrary code on a computer where the affected product is used.

Jul 18, 2018
7.8
CVE-2018-4858HIGH

A vulnerability has been identified in IEC 61850 system configurator (All versions < V5.80), DIGSI 5 (affected as IEC 61850 system configurator is incorporated) (All versions < V7.80), DIGSI 4 (All versions < V4.93), SICAM PAS/PQS (All versions < V8.11), SICAM PQ Analyzer (All versions < V3.11), SICAM SCC (All versions < V9.02 HF3). A service of the affected products listening on all of the host's network interfaces on either port 4884/TCP, 5885/TCP, or port 5886/TCP could allow an attacker to either exfiltrate limited data from the system or to execute code with Microsoft Windows user permissions. Successful exploitation requires an attacker to be able to send a specially crafted network request to the vulnerable service and a user interacting with the service's client application on the host. In order to execute arbitrary code with Microsoft Windows user permissions, an attacker must be able to plant the code in advance on the host by other means. The vulnerability has limited impact to confidentiality and integrity of the affected system. At the time of advisory publication no public exploitation of this security vulnerability was known. Siemens confirms the security vulnerability and provides mitigations to resolve the security issue.

Jul 9, 2018
7.8
CVE-2018-8841HIGH

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an improper privilege management vulnerability may allow an authenticated user to modify files when read access should only be given to the user.

May 15, 2018
7.8
CVE-2017-6015HIGH

Without quotation marks, any whitespace in the file path for Rockwell Automation FactoryTalk Activation version 4.00.02 remains ambiguous, which may allow an attacker to link to or run a malicious executable. This may allow an authorized, but not privileged local user to execute arbitrary code with elevated privileges on the system. CVSS v3 base score: 8.8, CVSS vector string: (AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). Rockwell Automation has released a new version of FactoryTalk Activation, Version 4.01, which addresses the identified vulnerability. Rockwell Automation recommends upgrading to the latest version of FactoryTalk Activation, Version 4.01 or later.

May 11, 2018
7.8
CVE-2017-5175HIGH

Advantech WebAccess 8.1 and earlier contains a DLL hijacking vulnerability which may allow an attacker to run a malicious DLL file within the search path resulting in execution of arbitrary code.

May 9, 2018
7.8
CVE-2018-8839HIGH

Delta PMSoft versions 2.10 and prior have multiple stack-based buffer overflow vulnerabilities where a .ppm file can introduce a value larger than is readable by PMSoft's fixed-length stack buffer. This can cause the buffer to be overwritten, which may allow arbitrary code execution or cause the application to crash. CVSS v3 base score: 7.1; CVSS vector string: AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H. Delta Electronics recommends affected users update to at least PMSoft v2.11, which was made available as of March 22, 2018, or the latest available version.

Apr 30, 2018
7.8
CVE-2018-8837HIGH

Processing specially crafted .pm3 files in Advantech WebAccess HMI Designer 2.1.7.32 and prior may cause the system to write outside the intended buffer area and may allow remote code execution.

Apr 25, 2018
7.8
CVE-2018-8835HIGH

Double free vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by processing specially crafted .pm3 files may allow remote code execution.

Apr 25, 2018
7.8
CVE-2018-8833HIGH

Heap-based buffer overflow vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by processing specially crafted .pm3 files may allow remote code execution.

Apr 25, 2018
7.8
CVE-2018-8834HIGH

Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet versions 1.00 and prior, CX-Protocol versions 1.992 and prior, CX-Programmer versions 9.65 and prior, CX-Server versions 5.0.22 and prior, Network Configurator versions 3.63 and prior, and Switch Box Utility versions 1.68 and prior, may cause a heap-based buffer overflow.

Apr 17, 2018
7.8
CVE-2018-7530HIGH

Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet versions 1.00 and prior, CX-Protocol versions 1.992 and prior, CX-Programmer versions 9.65 and prior, CX-Server versions 5.0.22 and prior, Network Configurator versions 3.63 and prior, and Switch Box Utility versions 1.68 and prior, may allow the pointer to call an incorrect object resulting in an access of resource using incompatible type condition.

Apr 17, 2018
7.8
CVE-2018-7514HIGH

Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet versions 1.00 and prior, CX-Protocol versions 1.992 and prior, CX-Programmer versions 9.65 and prior, CX-Server versions 5.0.22 and prior, Network Configurator versions 3.63 and prior, and Switch Box Utility versions 1.68 and prior, may cause a stack-based buffer overflow.

Apr 17, 2018
7.8
CVE-2018-7502HIGH

Kernel drivers in Beckhoff TwinCAT 3.1 Build 4022.4, TwinCAT 2.11 R3 2259, and TwinCAT 3.1 lack proper validation of user-supplied pointer values. An attacker who is able to execute code on the target may be able to exploit this vulnerability to obtain SYSTEM privileges.

Mar 23, 2018
7.8
CVE-2018-5476HIGH

A Stack-based Buffer Overflow issue was discovered in Delta Electronics Delta Industrial Automation DOPSoft, Version 4.00.01 or prior. Stack-based buffer overflow vulnerabilities caused by processing specially crafted .dop or .dpb files may allow an attacker to remotely execute arbitrary code.

Mar 15, 2018
7.8
CVE-2017-16751HIGH

A Stack-based Buffer Overflow issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior. Stack-based buffer overflow vulnerabilities caused by processing specially crafted .dpb files may allow an attacker to remotely execute arbitrary code.

Mar 15, 2018
7.8
CVE-2017-16749HIGH

A Use-after-Free issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior. Specially crafted .dpb files could exploit a use-after-free vulnerability.

Mar 15, 2018
7.8
CVE-2017-16747HIGH

An Out-of-bounds Write issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior. Specially crafted .dpb files may cause the system to write outside the intended buffer area.

Mar 15, 2018
7.8
CVE-2017-16745HIGH

A Type Confusion issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior. An access of resource using incompatible type ('type confusion') vulnerability may allow an attacker to execute remote code when processing specially crafted .dpb files.

Mar 15, 2018
7.8
CVE-2018-7239HIGH

A DLL hijacking vulnerability exists in Schneider Electric's SoMove Software and associated DTM software components in all versions prior to 2.6.2 which could allow an attacker to execute arbitrary code.

Mar 9, 2018
7.8
CVE-2018-1168HIGH

This vulnerability allows local attackers to escalate privileges on vulnerable installations of ABB MicroSCADA 9.3 with FP 1-2-3. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the configuration of the access controls for the installed product files. The installation procedure leaves critical files open to manipulation by any authenticated user. An attacker can leverage this vulnerability to escalate privileges to SYSTEM. Was ZDI-CAN-5097.

Feb 21, 2018
7.8
CVE-2017-9967HIGH

A security misconfiguration vulnerability exists in Schneider Electric's IGSS SCADA Software versions 12 and prior. Security configuration settings such as Address Space Layout Randomization (ASLR) and Data Execution prevention (DEP) were not properly configured resulting in weak security.

Feb 12, 2018
7.8
CVE-2018-5441HIGH

An Improper Validation of Integrity Check Value issue was discovered in PHOENIX CONTACT mGuard firmware versions 7.2 to 8.6.0. mGuard devices rely on internal checksums for verification of the internal integrity of the update packages. Verification may not always be performed correctly, allowing an attacker to modify firmware update packages.

Jan 30, 2018
7.8
CVE-2017-14030HIGH

An issue was discovered in Moxa MXview v2.8 and prior. The unquoted service path escalation vulnerability could allow an authorized user with file access to escalate privileges by inserting arbitrary code into the unquoted service path.

Jan 12, 2018
7.8
CVE-2017-12705HIGH

A Heap-Based Buffer Overflow issue was discovered in Advantech WebOP. A maliciously crafted project file may be able to trigger a heap-based buffer overflow, which may crash the process and allow an attacker to execute arbitrary code.

Oct 25, 2017
7.8
CVE-2017-9961HIGH

A vulnerability exists in Schneider Electric's Pro-Face GP Pro EX version 4.07.000 that allows an attacker to execute arbitrary code. Malicious code installation requires an access to the computer. By placing a specific DLL/OCX file, an attacker is able to force the process to load arbitrary DLL and execute arbitrary code in the context of the process.

Sep 26, 2017
7.8
CVE-2017-9958HIGH

An improper access control vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an improper handling of the system configuration can allow an attacker to execute arbitrary code under the context of root.

Sep 26, 2017
7.8
CVE-2017-12717HIGH

An Uncontrolled Search Path Element issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. A maliciously crafted dll file placed earlier in the search path may allow an attacker to execute code within the context of the application.

Aug 30, 2017
7.8
CVE-2017-12713HIGH

An Incorrect Permission Assignment for Critical Resource issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Multiple files and folders with ACLs that affect other users are allowed to be modified by non-administrator accounts.

Aug 30, 2017
7.8
CVE-2017-12711HIGH

An Incorrect Privilege Assignment issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. A built-in user account has been granted a sensitive privilege that may allow a user to elevate to administrative privileges.

Aug 30, 2017
7.8
CVE-2017-9942HIGH

A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with local access to the SiPass integrated server or SiPass integrated client to potentially obtain credentials from the systems.

Aug 8, 2017
7.8
CVE-2017-7968HIGH

An Incorrect Default Permissions issue was discovered in Schneider Electric Wonderware InduSoft Web Studio v8.0 Patch 3 and prior versions. Upon installation, Wonderware InduSoft Web Studio creates a new directory and two files, which are placed in the system's path and can be manipulated by non-administrators. This could allow an authenticated user to escalate his or her privileges.

May 19, 2017
7.8
CVE-2017-6033HIGH

A DLL Hijacking issue was discovered in Schneider Electric Interactive Graphical SCADA System (IGSS) Software, Version 12 and previous versions. The software will execute a malicious file if it is named the same as a legitimate file and placed in a location that is earlier in the search path.

Apr 7, 2017
7.8
CVE-2016-9356HIGH

An issue was discovered in Moxa DACenter Versions 1.4 and older. The application may suffer from an unquoted search path issue.

Feb 13, 2017
7.8
CVE-2016-9353HIGH

An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The admin password is stored in the system and is encrypted with a static key hard-coded in the program. Attackers could reverse the admin account password for use.

Feb 13, 2017
7.8
CVE-2016-8566HIGH

An issue was discovered in Siemens SICAM PAS before 8.00. Because of Storing Passwords in a Recoverable Format, an authenticated local attacker with certain privileges could possibly reconstruct the passwords of users for accessing the database.

Feb 13, 2017
7.8
CVE-2016-5805HIGH

An issue was discovered in Delta Electronics WPLSoft, Versions prior to V2.42.11, ISPSoft, Versions prior to 3.02.11, and PMSoft, Versions prior to2.10.10. There are multiple instances of heap-based buffer overflows that may allow malicious files to cause the execution of arbitrary code or a denial of service.

Feb 13, 2017
7.8
CVE-2016-5802HIGH

An issue was discovered in Delta Electronics WPLSoft, Versions prior to V2.42.11, ISPSoft, Versions prior to 3.02.11, and PMSoft, Versions prior to 2.10.10. Multiple instances of out-of-bounds write conditions may allow malicious files to be read and executed by the affected software.

Feb 13, 2017
7.8
CVE-2016-6486HIGH

Siemens SINEMA Server uses weak permissions for the application folder, which allows local users to gain privileges via unspecified vectors.

Aug 8, 2016
7.8
CVE-2015-3938HIGH

The HTTP application on Mitsubishi Electric MELSEC FX3G PLC devices before April 2015 allows remote attackers to cause a denial of service (device outage) via a long parameter.

Oct 6, 2015
7.8
CVE-2015-2177HIGH

Siemens SIMATIC S7-300 CPU devices allow remote attackers to cause a denial of service (defect-mode transition) via crafted packets on (1) TCP port 102 or (2) Profibus.

Mar 7, 2015
7.8
CVE-2014-9369HIGH

Siemens SPC controllers SPC4000, SPC5000, and SPC6000 before 3.6.0 allow remote attackers to cause a denial of service (device restart) via crafted packets.

Mar 7, 2015
7.8
CVE-2014-8478HIGH

The web server on Siemens SCALANCE X-300 switches with firmware before 4.0 and SCALANCE X 408 switches with firmware before 4.0 allows remote attackers to cause a denial of service (reboot) via malformed HTTP requests.

Jan 21, 2015
7.8
CVE-2014-2380HIGH

Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows remote attackers to obtain sensitive information by reading a credential file.

Aug 28, 2014
7.8
CVE-2014-2258HIGH

Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted HTTPS packets, a different vulnerability than CVE-2014-2259.

Mar 24, 2014
7.8
CVE-2014-2254HIGH

Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted HTTP packets, a different vulnerability than CVE-2014-2255.

Mar 24, 2014
7.8
CVE-2014-2256HIGH

Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted ISO-TSAP packets, a different vulnerability than CVE-2014-2257.

Mar 24, 2014
7.8
CVE-2014-2259HIGH

Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted HTTPS packets.

Mar 16, 2014
7.8
CVE-2014-2257HIGH

Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted ISO-TSAP packets.

Mar 16, 2014
7.8
CVE-2014-2255HIGH

Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted HTTP packets.

Mar 16, 2014
7.8
CVE-2013-2824HIGH

Schneider Electric StruxureWare SCADA Expert Vijeo Citect 7.40, Vijeo Citect 7.20 through 7.30SP1, CitectSCADA 7.20 through 7.30SP1, StruxureWare PowerSCADA Expert 7.30 through 7.30SR1, and PowerLogic SCADA 7.20 through 7.20SR1 do not properly handle exceptions, which allows remote attackers to cause a denial of service via a crafted packet.

Feb 26, 2014
7.8
CVE-2014-1966HIGH

The SNMP implementation in Siemens RuggedCom ROS before 3.11, ROS 3.11 for RS950G, ROS 3.12 before 3.12.4, and ROS 4.0 for RSG2488 allows remote attackers to cause a denial of service (device outage) via crafted packets.

Feb 24, 2014
7.8
CVE-2013-4780HIGH

core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Controller (SBC) before 2 R0.32.0, and 7 before 7 R1.7.0, allows remote attackers to read arbitrary files via unspecified vectors.

Jul 18, 2013
7.8
CVE-2013-4778HIGH

core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Controller (SBC) before 2 R0.32.0, and 7 before 7 R1.7.0, allows remote attackers to obtain sensitive server and statistics information via unspecified vectors.

Jul 18, 2013
7.8
CVE-2013-2780HIGH

Siemens SIMATIC S7-1200 PLCs 2.x and 3.x allow remote attackers to cause a denial of service (defect-mode transition and control outage) via crafted packets to UDP port 161 (aka the SNMP port).

Apr 22, 2013
7.8
CVE-2013-0700HIGH

Siemens SIMATIC S7-1200 PLCs 2.x and 3.x allow remote attackers to cause a denial of service (defect-mode transition and control outage) via crafted packets to TCP port 102 (aka the ISO-TSAP port).

Apr 22, 2013
7.8
CVE-2012-4714HIGH

Integer overflow in RNADiagnostics.dll in Rockwell Automation FactoryTalk Services Platform (FTSP) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 allows remote attackers to cause a denial of service (service outage or RNADiagReceiver.exe daemon crash) via UDP data that specifies a large integer value.

Apr 18, 2013
7.8
CVE-2012-4713HIGH

Integer signedness error in RNADiagnostics.dll in Rockwell Automation FactoryTalk Services Platform (FTSP) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 allows remote attackers to cause a denial of service (service outage or RNADiagReceiver.exe daemon crash) via UDP data that specifies a negative integer value.

Apr 18, 2013
7.8
CVE-2013-1627HIGH

Absolute path traversal vulnerability in NTWebServer.exe in Indusoft Studio 7.0 and earlier and Advantech Studio 7.0 and earlier allows remote attackers to read arbitrary files via a full pathname in an argument to the sub_401A90 CreateFileW function.

Mar 11, 2013
7.8
CVE-2012-4706HIGH

Integer signedness error in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to cause a denial of service via a crafted packet that triggers a heap-based buffer overflow.

Feb 24, 2013
7.8
CVE-2012-6442HIGH

When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that instructs the product to reset, a DoS can occur. This situation could cause loss of availability and a disruption of communication with other connected devices. Rockwell Automation EtherNet/IP products; 1756-ENBT, 1756-EWEB, 1768-ENBT, and 1768-EWEB communication modules; CompactLogix L32E and L35E controllers; 1788-ENBT FLEXLogix adapter; 1794-AENTR FLEX I/O EtherNet/IP adapter; ControlLogix 18 and earlier; CompactLogix 18 and earlier; GuardLogix 18 and earlier; SoftLogix 18 and earlier; CompactLogix controllers 19 and earlier; SoftLogix controllers 19 and earlier; ControlLogix controllers 20 and earlier; GuardLogix controllers 20 and earlier; and MicroLogix 1100 and 1400

Jan 24, 2013
7.8
CVE-2012-6438HIGH

The device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP, which creates a buffer overflow and causes the NIC to crash. Successful exploitation of this vulnerability could cause loss of availability and a disruption in communications with other connected devices. Rockwell Automation EtherNet/IP products; 1756-ENBT, 1756-EWEB, 1768-ENBT, and 1768-EWEB communication modules; CompactLogix L32E and L35E controllers; 1788-ENBT FLEXLogix adapter; 1794-AENTR FLEX I/O EtherNet/IP adapter; ControlLogix 18 and earlier; CompactLogix 18 and earlier; GuardLogix 18 and earlier; SoftLogix 18 and earlier; CompactLogix controllers 19 and earlier; SoftLogix controllers 19 and earlier; ControlLogix controllers 20 and earlier; GuardLogix controllers 20 and earlier; and MicroLogix 1100 and 1400

Jan 24, 2013
7.8
CVE-2012-6436HIGH

The device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP, which creates a buffer overflow and causes the CPU to crash. Successful exploitation of this vulnerability could cause loss of availability and a disruption in communications with other connected devices. Rockwell Automation EtherNet/IP products; 1756-ENBT, 1756-EWEB, 1768-ENBT, and 1768-EWEB communication modules; CompactLogix L32E and L35E controllers; 1788-ENBT FLEXLogix adapter; 1794-AENTR FLEX I/O EtherNet/IP adapter; ControlLogix 18 and earlier; CompactLogix 18 and earlier; GuardLogix 18 and earlier; SoftLogix 18 and earlier; CompactLogix controllers 19 and earlier; SoftLogix controllers 19 and earlier; ControlLogix controllers 20 and earlier; GuardLogix controllers 20 and earlier; and MicroLogix 1100 and 1400

Jan 24, 2013
7.8
CVE-2012-6435HIGH

When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that instructs the CPU to stop logic execution and enter a fault state, a DoS can occur. This situation could cause loss of availability and a disruption of communication with other connected devices. Rockwell Automation EtherNet/IP products; 1756-ENBT, 1756-EWEB, 1768-ENBT, and 1768-EWEB communication modules; CompactLogix L32E and L35E controllers; 1788-ENBT FLEXLogix adapter; 1794-AENTR FLEX I/O EtherNet/IP adapter; ControlLogix 18 and earlier; CompactLogix 18 and earlier; GuardLogix 18 and earlier; SoftLogix 18 and earlier; CompactLogix controllers 19 and earlier; SoftLogix controllers 19 and earlier; ControlLogix controllers 20 and earlier; GuardLogix controllers 20 and earlier; and MicroLogix 1100 and 1400

Jan 24, 2013
7.8
CVE-2012-3017HIGH

Siemens SIMATIC S7-400 PN CPU devices with firmware 5.x allow remote attackers to cause a denial of service (defect-mode transition and service outage) via (1) malformed HTTP traffic or (2) malformed IP packets.

Jul 31, 2012
7.8
CVE-2012-3016HIGH

Siemens SIMATIC S7-400 PN CPU devices with firmware 6 before 6.0.3 allow remote attackers to cause a denial of service (defect-mode transition and service outage) via crafted ICMP packets.

Jul 31, 2012
7.8
CVE-2012-1802HIGH

Buffer overflow in the embedded web server on the Siemens Scalance X Industrial Ethernet switch X414-3E before 3.7.1, X308-2M before 3.7.2, X-300EEC before 3.7.2, XR-300 before 3.7.2, and X-300 before 3.7.2 allows remote attackers to cause a denial of service (device reboot) or possibly execute arbitrary code via a malformed URL.

Apr 18, 2012
7.8
CVE-2011-4878HIGH

Directory traversal vulnerability in miniweb.exe in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime allows remote attackers to read arbitrary files via a ..%5c (dot dot backslash) in a URI.

Feb 3, 2012
7.8
CVE-2010-2772HIGH

Siemens Simatic WinCC and PCS 7 SCADA system uses a hard-coded password, which allows local users to access a back-end database and gain privileges, as demonstrated in the wild in July 2010 by the Stuxnet worm, a different vulnerability than CVE-2010-2568.

Jul 22, 2010
7.8
CVE-2010-2568HIGH

Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not properly handled during icon display in Windows Explorer, as demonstrated in the wild in July 2010, and originally reported for malware that leverages CVE-2010-2772 in Siemens WinCC SCADA systems.

Jul 22, 2010
7.8
CVE-2009-3322HIGH

The Siemens Gigaset SE361 WLAN router allows remote attackers to cause a denial of service (device reboot) via a flood of crafted TCP packets to port 1723.

Sep 23, 2009
7.8
CVE-2008-7065HIGH

Siemens C450 IP and C475 IP VoIP devices allow remote attackers to cause a denial of service (disconnected calls and device reboot) via a crafted SIP packet to UDP port 5060.

Aug 25, 2009
7.8
CVE-2008-1546HIGH

servlet/MIMEReceiveServlet in the web controller for Mitsubishi Electric GB-50 and GB-50A air-conditioning control systems allows remote attackers to cause a denial of service (air-conditioning outage) via an XML document containing a setRequest command.

Mar 28, 2008
7.8
CVE-2008-1267HIGH

The Siemens SpeedStream 6520 router allows remote attackers to cause a denial of service (web interface crash) via an HTTP request to basehelp_English.htm with a large integer in the Content-Length field.

Mar 10, 2008
7.8
CVE-2003-1464HIGH

Buffer overflow in Siemens 45 series mobile phones allows remote attackers to cause a denial of service (disconnect and unavailable inbox) via a Short Message Service (SMS) message with a long image name.

Dec 31, 2003
7.8
CVE-2025-10089HIGH

Uncontrolled Search Path Element Vulnerability in Setting and Operation Application for Lighting Control System MILCO.S Setting Application all versions, MILCO.S Setting Application (IR) all versions, MILCO.S Easy Setting Application (IR) all versions, and MILCO.S Easy Switch Application (IR) all versions allows a local attacker to execute malicious code by having installer to load a malicious DLL. However, if the signer name "Mitsubishi Electric Lighting" appears on the "Digital Signatures" tab of the properties for "MILCO.S Lighting Control.exe", the application is a fixed one. This vulnerability only affects when the installer is run, not after installation. If a user downloads directly from Mitsubishi Electric website and installs the affected product, there is no risk of malicious code being introduced.

Nov 18, 2025
7.7
CVE-2024-48844HIGH

Denial of Service vulnerabilities where found providing a potiential for device service disruptions.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

Dec 5, 2024
7.7
CVE-2024-48843HIGH

Denial of Service vulnerabilities where found providing a potiential for device service disruptions.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

Dec 5, 2024
7.7
CVE-2024-7847HIGH

VULNERABILITY DETAILS Rockwell Automation used the latest versions of the CVSS scoring system to assess the following vulnerabilities. The following vulnerabilities were reported to us by Sharon Brizinov of Claroty Research - Team82. A feature in the affected products enables users to prepare a project file with an embedded VBA script and can be configured to run once the project file has been opened without user intervention. This feature can be abused to trick a legitimate user into executing malicious code upon opening an infected RSP/RSS project file. If exploited, a threat actor may be able to perform a remote code execution. Connected devices may also be impacted by exploitation of this vulnerability.

Oct 14, 2024
7.7
CVE-2022-4048HIGH

Inadequate Encryption Strength in CODESYS Development System V3 versions prior to V3.5.18.40 allows an unauthenticated local attacker to access and manipulate code of the encrypted boot application.

May 15, 2023
7.7
CVE-2022-2464HIGH

Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability. Crafted malicious files can allow an attacker to traverse the file system when opened by ISaGRAF Workbench. If successfully exploited, an attacker could overwrite existing files and create additional files with the same permissions of the ISaGRAF Workbench software. User interaction is required for this exploit to be successful.

Aug 25, 2022
7.7
CVE-2022-1159HIGH

Rockwell Automation Studio 5000 Logix Designer (all versions) are vulnerable when an attacker who achieves administrator access on a workstation running Studio 5000 Logix Designer could inject controller code undetectable to a user.

Apr 1, 2022
7.7
CVE-2021-27471HIGH

The parsing mechanism that processes certain file types does not provide input sanitization for file paths. This may allow an attacker to craft malicious files that, when opened by Rockwell Automation Connected Components Workbench v12.00.00 and prior, can traverse the file system. If successfully exploited, an attacker could overwrite existing files and create additional files with the same permissions of the Connected Components Workbench software. User interaction is required for this exploit to be successful.

Mar 23, 2022
7.7
CVE-2021-35529HIGH

Insufficiently Protected Credentials vulnerability in client environment of Hitachi ABB Power Grids Retail Operations and Counterparty Settlement Billing (CSB) allows an attacker or unauthorized user to access database credentials, shut down the product and access or alter. This issue affects: Hitachi ABB Power Grids Retail Operations version 5.7.2 and prior versions. Hitachi ABB Power Grids Counterparty Settlement Billing (CSB) version 5.7.2 and prior versions.

Aug 20, 2021
7.7
CVE-2020-13550HIGH

A local file inclusion vulnerability exists in the installation functionality of Advantech WebAccess/SCADA 9.0.1. A specially crafted application can lead to information disclosure. An attacker can send an authenticated HTTP request to trigger this vulnerability.

Feb 17, 2021
7.7
CVE-2016-4514HIGH

Moxa PT-7728 devices with software 3.4 build 15081113 allow remote authenticated users to change the configuration via vectors involving a local proxy.

Jun 19, 2016
7.7
CVE-2015-3977HIGH

Buffer overflow in Schneider Electric IMT25 Magnetic Flow DTM before 1.500.004 for the HART Protocol allows remote authenticated users to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HART reply.

Nov 15, 2015
7.7
CVE-2012-1801HIGH

Multiple stack-based buffer overflows in (1) COM and (2) ActiveX controls in ABB WebWare Server, WebWare SDK, Interlink Module, S4 OPC Server, QuickTeach, RobotStudio S4, and RobotStudio Lite allow remote attackers to execute arbitrary code via crafted input data.

Apr 18, 2012
7.7
CVE-2025-48891HIGH

A vulnerability exists in Advantech iView that could allow for SQL injection through the CUtils.checkSQLInjection() function. This vulnerability can be exploited by an authenticated attacker with at least user-level privileges, potentially leading to information disclosure or a denial-of-service condition.

Jul 11, 2025
7.6
CVE-2023-1257HIGH

An attacker with physical access to the affected Moxa UC Series devices can initiate a restart of the device and gain access to its BIOS. Command line options can then be altered, allowing the attacker to access the terminal. From the terminal, the attacker can modify the device’s authentication files to create a new user and gain full access to the system.

Mar 7, 2023
7.6
CVE-2019-19094HIGH

Lack of input checks for SQL queries in ABB eSOMS versions 3.9 to 6.0.3 might allow an attacker SQL injection attacks against the backend database.

Apr 2, 2020
7.6
CVE-2014-2717HIGH

Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to bypass authentication and obtain administrative access by visiting the change-password page.

Jul 24, 2014
7.6
CVE-2012-4694HIGH

Moxa EDR-G903 series routers with firmware before 2.11 do not use a sufficient source of entropy for (1) SSH and (2) SSL keys, which makes it easier for man-in-the-middle attackers to spoof a device or modify a client-server data stream by leveraging knowledge of a key from a product installation elsewhere.

Feb 15, 2013
7.6
CVE-2026-3631HIGH

Delta Electronics COMMGR2 has Buffer Over-read DoS vulnerability.

Mar 9, 2026
7.5
CVE-2024-55027HIGH

Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_temp.db.

Mar 3, 2026
7.5
CVE-2024-55021HIGH

Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol.

Mar 3, 2026
7.5
CVE-2024-55019HIGH

Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows unauthenticated attack to download arbitrary files.

Mar 3, 2026
7.5
CVE-2025-66598HIGH

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product supports old SSL/TLS versions, potentially allowing an attacker to decrypt communications with the web server. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04

Feb 9, 2026
7.5
CVE-2025-66597HIGH

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product supports weak cryptographic algorithms, potentially allowing an attacker to decrypt communications with the web server. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04

Feb 9, 2026
7.5
CVE-2025-66608HIGH

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly validate URLs. An attacker could send specially crafted requests to steal files from the web server. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04

Feb 9, 2026
7.5
CVE-2025-13373HIGH

Advantech iView versions 5.7.05.7057 and prior do not properly sanitize SNMP v1 trap (Port 162) requests, which could allow an attacker to inject SQL commands.

Dec 4, 2025
7.5
CVE-2025-41738HIGH

An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition.

Dec 1, 2025
7.5
CVE-2022-50594HIGH

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘data’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for the exfiltration of user data, included clear text passwords.

Nov 6, 2025
7.5
CVE-2025-7731HIGH

Cleartext Transmission of Sensitive Information vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote unauthenticated attacker to obtain credential information by intercepting SLMP communication messages, and read or write the device values of the product and stop the operations of programs by using the obtained credential information.

Sep 1, 2025
7.5
CVE-2025-8754HIGH

Missing Authentication for Critical Function vulnerability in ABB ABB AbilityTM zenon.This issue affects ABB AbilityTM zenon: from 7.50 through 14.

Aug 13, 2025
7.5
CVE-2025-41691HIGH

An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Control runtime systems by sending specially crafted communication requests, potentially leading to a denial-of-service (DoS) condition.

Aug 4, 2025
7.5
CVE-2025-2520HIGH

The Honeywell Experion PKS contains an Uninitialized Variable in the common Epic Platform Analyzer (EPA) communications. An attacker could potentially exploit this vulnerability, leading to a Communication Channel Manipulation, which results in a dereferencing of an uninitialized pointer leading to a denial of service. Honeywell recommends updating to the most recent version of Honeywell Experion PKS: 520.2 TCU9 HF1and 530.1 TCU3 HF1. The affected Experion PKS products are C300 PCNT02, EHB, EHPM, ELMM, Classic ENIM, ETN, FIM4, FIM8, PGM, and RFIM. The Experion PKS versions affected are from 520.1 through 520.2 TCU9 and from 530 through 530 TCU3.

Jul 10, 2025
7.5
CVE-2025-6073HIGH

Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enabled by the user, and an attacker gains access to the control network, and user/password broker authentication is enabled, and CVE-2025-6074 is exploited, the attacker can overflow the buffer for username or password. This issue affects RMC-100: from 2105457-043 through 2105457-045; RMC-100 LITE: from 2106229-015 through 2106229-016.

Jul 3, 2025
7.5
CVE-2025-6072HIGH

Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enabled by the user, and an attacker gains access to the control network, and CVE-2025-6074 is exploited, the attacker can use the JSON configuration to overflow the date of expiration field.This issue affects RMC-100: from 2105457-043 through 2105457-045; RMC-100 LITE: from 2106229-015 through 2106229-016.

Jul 3, 2025
7.5
CVE-2025-3511HIGH

Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module, CC-Link IE TSN Analog-Digital Converter module, CC-Link IE TSN Digital-Analog Converter module, CC-Link IE TSN FPGA module, CC-Link IE TSN Remote Station Communication LSI CP620 with GbE-PHY, MELSEC iQ-R Series CC-Link IE TSN Master/Local Module, MELSEC iQ-R Series Ethernet Interface Module, CC-Link IE TSN Master/Local Station Communication LSI CP610, MELSEC iQ-F Series FX5 CC-Link IE TSN Master/Local Module, MELSEC iQ-F Series FX5 Ethernet Module, and MELSEC iQ-F Series FX5-ENET/IP Ethernet Module allows a remote unauthenticated attacker to cause a Denial of Service condition in the products by sending specially crafted UDP packets.

Apr 25, 2025
7.5
CVE-2025-1468HIGH

An unauthenticated remote attacker can gain access to sensitive information including authentication information when using CODESYS OPC UA Server with the non-default Basic128Rsa15 security policy.

Mar 18, 2025
7.5
CVE-2024-8603HIGH

A “Use of a Broken or Risky Cryptographic Algorithm” vulnerability in the SSL/TLS component used in B&R Automation Runtime versions before 6.1 and B&R mapp View versions before 6.1 may be abused by unauthenticated network-based attackers to masquerade as services on impacted devices.

Jan 15, 2025
7.5
CVE-2024-51546HIGH

Credentials Disclosure vulnerabilities allow access to on board project back-up bundles.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

Dec 5, 2024
7.5
CVE-2024-11316HIGH

Fileszie Check vulnerabilities allow a malicious user to bypass size limits or overload to the product.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

Dec 5, 2024
7.5
CVE-2024-9404HIGH

This vulnerability could lead to denial-of-service or service crashes. Exploitation of the moxa_cmd service, because of insufficient input validation, allows attackers to disrupt operations. If exposed to public networks, the vulnerability poses a significant remote threat, potentially allowing attackers to shut down affected systems.

Dec 4, 2024
7.5
CVE-2023-52335HIGH

Advantech iView ConfigurationServlet SQL Injection Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Advantech iView. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ConfigurationServlet servlet, which listens on TCP port 8080 by default. When parsing the column_value element, the process does not properly validate a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-17863.

Nov 22, 2024
7.5
CVE-2024-8403HIGH

Improper Validation of Specified Type of Input vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET versions 1.100 and later and FX5-ENET/IP versions 1.100 to 1.104 allows a remote attacker to cause a Denial of Service condition in Ethernet communication of the products by sending specially crafted SLMP packets.

Nov 19, 2024
7.5
CVE-2024-48989HIGH

A vulnerability in the PROFINET stack implementation of the IndraDrive (all versions) of Bosch Rexroth allows an attacker to cause a denial of service, rendering the device unresponsive by sending arbitrary UDP messages.

Nov 13, 2024
7.5
CVE-2024-9124HIGH

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 600T. If the device is overloaded with requests, it will become unavailable. The device may require a power cycle to recover it if it does not re-establish a connection after it stops receiving requests.

Oct 8, 2024
7.5
CVE-2024-8626HIGH

Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vulnerability by performing multiple actions on certain web pages of the product causing the affected products to become fully unavailable and require a power cycle to recover.

Oct 8, 2024
7.5
CVE-2024-8175HIGH

An unauthenticated remote attacker can causes the CODESYS web server to access invalid memory which results in a DoS.

Sep 25, 2024
7.5
CVE-2024-6077HIGH

A denial-of-service vulnerability exists in the Rockwell Automation affected products when specially crafted packets are sent to the CIP Security Object. If exploited the device will become unavailable and require a factory reset to recover.

Sep 12, 2024
7.5
CVE-2024-7986HIGH

A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensitive information. A threat actor can exploit this vulnerability by abusing the ThinServer™ service to read arbitrary files by creating a junction that points to the target directory.

Aug 23, 2024
7.5
CVE-2024-5800HIGH

Diffie-Hellman groups with insufficient strength are used in the SSL/TLS stack of B&R Automation Runtime versions before 6.0.2, allowing a network attacker to decrypt the SSL/TLS communication.

Aug 12, 2024
7.5
CVE-2024-6089HIGH

An input validation vulnerability exists in the Rockwell Automation 5015 - AENFTXT when a manipulated PTP packet is sent, causing the secondary adapter to result in a major nonrecoverable fault. If exploited, a power cycle is required to recover the product.

Jul 16, 2024
7.5
CVE-2024-5990HIGH

Due to an improper input validation, an unauthenticated threat actor can send a malicious message to a monitor thread within Rockwell Automation ThinServer™ and cause a denial-of-service condition on the affected device.

Jun 25, 2024
7.5
CVE-2024-37368HIGH

A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI project. Due to the lack of proper authentication, this action is allowed without proper authentication verification.

Jun 14, 2024
7.5
CVE-2024-37367HIGH

A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI project. This action is allowed without proper authentication verification.

Jun 14, 2024
7.5
CVE-2024-5000HIGH

An unauthenticated remote attacker can use a malicious OPC UA client to send a crafted request to affected CODESYS products which can cause a DoS due to incorrect calculation of buffer size.

Jun 4, 2024
7.5
CVE-2024-4549HIGH

A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. When processing an 'ICS Restart!' message, CEBC.exe restarts the system.

May 6, 2024
7.5
CVE-2023-27336HIGH

Softing edgeConnector Siemens OPC UA Server Null Pointer Dereference Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Softing edgeConnector Siemens. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of OPC client certificates. The issue results from dereferencing a NULL pointer. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-20508.

May 3, 2024
7.5
CVE-2023-27334HIGH

Softing edgeConnector Siemens ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Softing edgeConnector Siemens. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of OPC UA ConditionRefresh requests. By sending a large number of requests, an attacker can consume all available resources on the server. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-20498.

May 3, 2024
7.5
CVE-2024-2424HIGH

An input validation vulnerability exists in the Rockwell Automation 5015-AENFTXT that causes the secondary adapter to result in a major nonrecoverable fault (MNRF) when malicious input is entered. If exploited, the availability of the device will be impacted, and a manual restart is required. Additionally, a malformed PTP packet is needed to exploit this vulnerability.

Apr 15, 2024
7.5
CVE-2023-5392HIGH

C300 information leak due to an analysis feature which allows extracting more memory over the network than required by the function. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning.

Apr 11, 2024
7.5
CVE-2024-0335HIGH

ABB has internally identified a vulnerability in the ABB VPNI feature of the S+ Control API component which may be used by several Symphony Plus products (e.g., S+ Operations, S+ Engineering and S+ Analyst) This issue affects Symphony Plus S+ Operations: from 3..0;0 through 3.3 SP1 RU4, from 2.1;0 through 2.1 SP2 RU3, from 2.0;0 through 2.0 SP6 TC6; Symphony Plus S+ Engineering: from 2.1 through 2.3 RU3; Symphony Plus S+ Analyst: from 7.0.0.0 through 7.2.0.2.

Apr 3, 2024
7.5
CVE-2024-2427HIGH

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper traffic throttling in the device. If multiple data packets are sent to the device repeatedly the device will crash and require a manual restart to recover.

Mar 25, 2024
7.5
CVE-2024-2426HIGH

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, a disruption in the CIP communication will occur and a manual restart will be required by the user to recover it.

Mar 25, 2024
7.5
CVE-2024-2425HIGH

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, the web server will crash and need a manual restart to recover it.

Mar 25, 2024
7.5
CVE-2023-6942HIGH

Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5.92, GT Designer3 Version1(GOT1000) versions 1.325P and prior, GT Designer3 Version1(GOT2000) versions 1.320J and prior, GX Works2 versions 1.11M to 1.626C, GX Works3 versions 1.106L and prior, MELSOFT Navigator versions 1.04E to 2.102G, MT Works2 versions 1.190Y and prior, MX Component versions 4.00A to 5.007H and MX OPC Server DA/UA all versions allows a remote unauthenticated attacker to bypass authentication by sending specially crafted packets and connect to the products illegally.

Jan 30, 2024
7.5
CVE-2023-43817HIGH

A buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when parsing the wMailContentLen field of a DPS file. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve code execution.

Jan 18, 2024
7.5
CVE-2023-5592HIGH

Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to download and execute applications without integrity checks on the device which may result in a complete loss of integrity.

Dec 14, 2023
7.5
CVE-2023-46143HIGH

Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC.

Dec 14, 2023
7.5
CVE-2023-5188HIGH

The MMS Interpreter of WagoAppRTU in versions below 1.4.6.0 which is used by the WAGO Telecontrol Configurator is vulnerable to malformed packets. An remote unauthenticated attacker could send specifically crafted packets that lead to a denial-of-service condition until restart of the affected device.

Dec 5, 2023
7.5
CVE-2023-47279HIGH

In Delta Electronics InfraSuite Device Master v.1.0.7, A vulnerability exists that allows an unauthenticated attacker to disclose user information through a single UDP packet, obtain plaintext credentials, or perform NTLM relaying.

Nov 30, 2023
7.5
CVE-2023-46590HIGH

A vulnerability has been identified in Siemens OPC UA Modelling Editor (SiOME) (All versions < V2.8). Affected products suffer from a XML external entity (XXE) injection vulnerability. This vulnerability could allow an attacker to interfere with an application's processing of XML data and read arbitrary files in the system.

Nov 14, 2023
7.5
CVE-2023-46289HIGH

Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow threat actors to send malicious data bringing the product offline. If exploited, the product would become unavailable and require a restart to recover resulting in a denial-of-service condition.

Oct 27, 2023
7.5
CVE-2023-2915HIGH

The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, Due to improper input validation, a path traversal vulnerability exists when the ThinManager software processes a certain function. If exploited, an unauthenticated remote threat actor can delete arbitrary files with system privileges. A malicious user could exploit this vulnerability by sending a specifically crafted synchronization protocol message resulting in a denial-of-service condition.

Aug 17, 2023
7.5
CVE-2023-2914HIGH

The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, an integer overflow condition exists in the affected products. When the ThinManager processes incoming messages, a read access violation occurs and terminates the process. A malicious user could exploit this vulnerability by sending a crafted synchronization protocol message and causing a denial of service condition in the software.

Aug 17, 2023
7.5
CVE-2023-37860HIGH

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote unauthenticated attacker can obtain the r/w community string of the SNMPv2 daemon.

Aug 9, 2023
7.5
CVE-2023-0525HIGH

Weak Encoding for Password vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01.49.000 and prior, GT25 model versions 01.49.000 and prior, GT23 model versions 01.49.000 and prior, GT21 model versions 01.49.000 and prior, GOT SIMPLE Series GS25 model versions 01.49.000 and prior, GS21 model versions 01.49.000 and prior, GT Designer3 Version1 (GOT2000) versions 1.295H and prior and GT SoftGOT2000 versions 1.295H and prior allows a remote unauthenticated attacker to obtain plaintext passwords by sniffing packets containing encrypted passwords and decrypting the encrypted passwords, in the case of transferring data with GT Designer3 Version1(GOT2000) and GOT2000 Series or GOT SIMPLE Series with the Data Transfer Security function enabled, or in the case of transferring data by the SoftGOT-GOT link function with GT SoftGOT2000 and GOT2000 series with the Data Transfer Security function enabled.

Aug 4, 2023
7.5
CVE-2023-34429HIGH

Weintek Weincloud v0.13.6 could allow an attacker to cause a denial-of-service condition for Weincloud by sending a forged JWT token.

Jul 19, 2023
7.5
CVE-2023-2913HIGH

An executable used in Rockwell Automation ThinManager ThinServer can be configured to enable an API feature in the HTTPS Server Settings. This feature is disabled by default. When the API is enabled and handling requests, a path traversal vulnerability exists that allows a remote actor to leverage the privileges of the server’s file system and read arbitrary files stored in it. A malicious user could exploit this vulnerability by executing a path that contains manipulating variables.

Jul 18, 2023
7.5
CVE-2023-2263HIGH

The Rockwell Automation Kinetix 5700 DC Bus Power Supply Series A is vulnerable to CIP fuzzing.  The new ENIP connections cannot be established if impacted by this vulnerability,  which prohibits operational capabilities of the device resulting in a denial-of-service attack.

Jul 18, 2023
7.5
CVE-2023-26597HIGH

Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller. See Honeywell Security Notification for recommendations on upgrading and versioning. See Honeywell Security Notification for recommendations on upgrading and versioning.

Jul 13, 2023
7.5
CVE-2023-25948HIGH

Server information leak of configuration data when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning.

Jul 13, 2023
7.5
CVE-2023-3596HIGH

Where this vulnerability exists in the Rockwell Automation 1756-EN4* Ethernet/IP communication products, it could allow a malicious user to cause a denial of service by asserting the target system through maliciously crafted CIP messages.

Jul 12, 2023
7.5
CVE-2023-2846HIGH

Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series main modules allows a remote unauthenticated attacker to cancel the password/keyword setting and login to the affected products by sending specially crafted packets.

Jun 30, 2023
7.5
CVE-2023-1150HIGH

Uncontrolled resource consumption in Series WAGO 750-3x/-8x products may allow an unauthenticated remote attacker to DoS the MODBUS server with specially crafted packets.

Jun 26, 2023
7.5
CVE-2023-2778HIGH

A denial-of-service vulnerability exists in Rockwell Automation FactoryTalk Transaction Manager. This vulnerability can be exploited by sending a modified packet to port 400. If exploited, the application could potentially crash or experience a high CPU or memory usage condition, causing intermittent application functionality issues. The application would need to be restarted to recover from the DoS.

Jun 13, 2023
7.5
CVE-2023-2060HIGH

Weak Password Requirements vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP allows a remote unauthenticated attacker to access to the module via FTP by dictionary attack or password sniffing.

Jun 2, 2023
7.5
CVE-2023-1618HIGH

Active Debug Code vulnerability in Mitsubishi Electric Corporation MELSEC WS Series WS0-GETH00200 Serial number 2310 **** and prior allows a remote unauthenticated attacker to bypass authentication and illegally log into the affected module by connecting to it via telnet which is hidden function and is enabled by default when shipped from the factory. As a result, a remote attacker with unauthorized login can reset the module, and if certain conditions are met, he/she can disclose or tamper with the module's configuration or rewrite the firmware.

May 19, 2023
7.5
CVE-2022-47391HIGH

In multiple CODESYS products in multiple versions an unauthorized, remote attacker may use a improper input validation vulnerability to read from invalid addresses leading to a denial of service.

May 15, 2023
7.5
CVE-2023-2443HIGH

Rockwell Automation ThinManager product allows the use of medium strength ciphers.  If the client requests an insecure cipher, a malicious actor could potentially decrypt traffic sent between the client and server API.

May 11, 2023
7.5
CVE-2023-1285HIGH

Signal Handler Race Condition vulnerability in Mitsubishi Electric India GC-ENET-COM whose first 2 digits of 11-digit serial number of unit are "16" allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition in Ethernet communication by sending a large number of specially crafted packets to any UDP port when GC-ENET-COM is configured as a Modbus TCP Server. The communication resumes only when the power of the main unit is turned off and on or when the GC-ENET-COM is hot-swapped from the main unit.

Apr 14, 2023
7.5
CVE-2023-1142HIGH

In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use URL decoding to retrieve system files, credentials, and bypass authentication resulting in privilege escalation.

Mar 27, 2023
7.5
CVE-2023-1138HIGH

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain an improper access control vulnerability, which could allow an attacker to retrieve Gateway configuration files to obtain plaintext credentials.

Mar 27, 2023
7.5
CVE-2023-27857HIGH

In affected versions, a heap-based buffer over-read condition occurs when the message field indicates more data than is present in the message field in Rockwell Automation's ThinManager ThinServer.  An unauthenticated remote attacker can exploit this vulnerability to crash ThinServer.exe due to a read access violation.

Mar 22, 2023
7.5
CVE-2023-27856HIGH

In affected versions, path traversal exists when processing a message of type 8 in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker can exploit this vulnerability to download arbitrary files on the disk drive where ThinServer.exe is installed.

Mar 22, 2023
7.5
CVE-2023-0457HIGH

Plaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series, MELSEC iQ-R Series, MELSEC-Q Series and MELSEC-L Series allows a remote unauthenticated attacker to disclose plaintext credentials stored in project files and login into FTP server or Web server.

Mar 3, 2023
7.5
CVE-2022-40693HIGH

A cleartext transmission vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted network sniffing can lead to a disclosure of sensitive information. An attacker can sniff network traffic to trigger this vulnerability.

Feb 7, 2023
7.5
CVE-2022-40224HIGH

A denial of service vulnerability exists in the web server functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP message header can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.

Feb 7, 2023
7.5
CVE-2022-33323HIGH

Active Debug Code vulnerability in robot controller of Mitsubishi Electric Corporation industrial robot MELFA SD/SQ Series and MELFA F-Series allows a remote unauthenticated attacker to gain unauthorized access by authentication bypass through an unauthorized telnet login. As for the affected model names, controller types and firmware versions, see the Mitsubishi Electric's advisory which is listed in [References] section.

Feb 2, 2023
7.5
CVE-2020-12067HIGH

In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's password may be changed by an attacker without knowledge of the current password.

Dec 26, 2022
7.5
CVE-2022-33324HIGH

Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series R00/01/02CPU Firmware versions "32" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R04/08/16/32/120(EN)CPU Firmware versions "65" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R08/16/32/120SFCPU Firmware versions "29" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R08/16/32/120PSFCPU Firmware versions "08" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R12CCPU-V Firmware versions "17" and prior, Mitsubishi Electric Corporation MELSEC iQ-L Series L04/08/16/32HCPU Firmware versions "05" and prior and Mitsubishi Electric Corporation MELIPC Series MI5122-VW Firmware versions "07" and prior allows a remote unauthenticated attacker to cause a Denial of Service condition in Ethernet communication on the module by sending specially crafted packets. A system reset of the module is required for recovery.

Dec 23, 2022
7.5
CVE-2022-3166HIGH

Rockwell Automation was made aware that the webservers of the Micrologix 1100 and 1400 controllers contain a vulnerability that may lead to a denial-of-service condition. The security vulnerability could be exploited by an attacker with network access to the affected systems by sending TCP packets to webserver and closing it abruptly which would cause a denial-of-service condition for the web server application on the device

Dec 16, 2022
7.5
CVE-2022-29831HIGH

Use of Hard-coded Password vulnerability in Mitsubishi Electric Corporation GX Works3 versions from 1.015R to 1.095Z allows a remote unauthenticated attacker to obtain information about the project file for MELSEC safety CPU modules.

Nov 25, 2022
7.5
CVE-2022-3480HIGH

A remote, unauthenticated attacker could cause a denial-of-service of PHOENIX CONTACT FL MGUARD and TC MGUARD devices below version 8.9.0 by sending a larger number of unauthenticated HTTPS connections originating from different source IP’s. Configuring firewall limits for incoming connections cannot prevent the issue.

Nov 15, 2022
7.5
CVE-2021-34579HIGH

In Phoenix Contact: FL MGUARD DM version 1.12.0 and 1.13.0 access to the Apache web server being installed as part of the FL MGUARD DM on Microsoft Windows does not require login credentials even if configured during installation.Attackers with network access to the Apache web server can download and therefore read mGuard configuration profiles (“ATV profiles”). Such configuration profiles may contain sensitive information, e.g. private keys associated with IPsec VPN connections.

Nov 9, 2022
7.5
CVE-2021-34568HIGH

In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to provoke a denial of service.

Nov 9, 2022
7.5
CVE-2022-41776HIGH

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to trigger the WriteConfiguration method, which could allow an attacker to provide new values for user configuration files such as UserListInfo.xml. This could lead to the changing of administrative passwords.

Oct 31, 2022
7.5
CVE-2022-41629HIGH

Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to access the aprunning endpoint, which could allow an attacker to retrieve any file from the “RunningConfigs” directory. The attacker could then view and modify configuration files such as UserListInfo.xml, which would allow them to see existing administrative passwords.

Oct 31, 2022
7.5
CVE-2021-38399HIGH

Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to relative path traversal, which may allow an attacker access to unauthorized files and directories.

Oct 28, 2022
7.5
CVE-2022-38744HIGH

An unauthenticated attacker with network access to a victim's Rockwell Automation FactoryTalk Alarm and Events service could open a connection, causing the service to fault and become unavailable. The affected port could be used as a server ping port and uses messages structured with XML.

Oct 27, 2022
7.5
CVE-2022-3281HIGH

WAGO Series PFC100/PFC200, Series Touch Panel 600, Compact Controller CC100 and Edge Controller in multiple versions are prone to a loss of MAC-Address-Filtering after reboot. This may allow an remote attacker to circumvent the reach the network that should be protected by the MAC address filter.

Oct 17, 2022
7.5
CVE-2022-3323HIGH

An SQL injection vulnerability in Advantech iView 5.7.04.6469. The specific flaw exists within the ConfigurationServlet endpoint, which listens on TCP port 8080 by default. An unauthenticated remote attacker can craft a special column_value parameter in the setConfiguration action to bypass checks in com.imc.iview.utils.CUtils.checkSQLInjection() to perform SQL injection. For example, the attacker can exploit the vulnerability to retrieve the iView admin password.

Sep 27, 2022
7.5
CVE-2022-2043HIGH

MOXA NPort 5110: Firmware Versions 2.10 is vulnerable to an out-of-bounds write that can cause the device to become unresponsive.

Aug 31, 2022
7.5
CVE-2022-30313HIGH

Honeywell Experion PKS Safety Manager through 2022-05-06 has Missing Authentication for a Critical Function. According to FSCT-2022-0051, there is a Honeywell Experion PKS Safety Manager multiple proprietary protocols with unauthenticated functionality issue. The affected components are characterized as: Honeywell Experion TCP (51000/TCP), Safety Builder (51010/TCP). The potential impact is: Manipulate controller state, Manipulate controller configuration, Manipulate controller logic, Manipulate controller files, Manipulate IO. The Honeywell Experion PKS Distributed Control System (DCS) Safety Manager utilizes several proprietary protocols for a wide variety of functionality, including process data acquisition, controller steering and configuration management. These protocols include: Experion TCP (51000/TCP) and Safety Builder (51010/TCP). None of these protocols have any authentication features, allowing any attacker capable of communicating with the ports in question to invoke (a subset of) desired functionality. There is no authentication functionality on the protocols in question. An attacker capable of invoking the protocols' functionalities could achieve a wide range of adverse impacts, including (but not limited to), the following: for Experion TCP (51000/TCP): Issue IO manipulation commands, Issue file read/write commands; and for Safety Builder (51010/TCP): Issue controller start/stop commands, Issue logic download/upload commands, Issue file read commands, Issue system time change commands. A mitigating factor with regards to some, but not all, of the above functionality is that these require the Safety Manager physical keyswitch to be in the right position.

Jul 28, 2022
7.5
CVE-2022-31205HIGH

In Omron CS series, CJ series, and CP series PLCs through 2022-05-18, the password for access to the Web UI is stored in memory area D1449...D1452 and can be read out using the Omron FINS protocol without any further authentication.

Jul 26, 2022
7.5
CVE-2022-31204HIGH

Omron CS series, CJ series, and CP series PLCs through 2022-05-18 use cleartext passwords. They feature a UM Protection setting that allows users or system integrators to configure a password in order to restrict sensitive engineering operations (such as project/logic uploads and downloads). This password is set using the OMRON FINS command Program Area Protect and unset using the command Program Area Protect Clear, both of which are transmitted in cleartext.

Jul 26, 2022
7.5
CVE-2022-29834HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric ICONICS Suite versions 10.97 to 10.97.1, and Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97 to 10.97.1 allows a remote unauthenticated attacker to access to arbitrary files in the GENESIS64 server or ICONICS suite server and disclose information stored in the files by embedding a malicious URL parameter in the URL of the monitoring screen delivered to the GENESIS64 or ICONICS Suite mobile monitoring application and accessing the monitoring screen.

Jul 20, 2022
7.5
CVE-2022-30792HIGH

In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communication channel connections. Existing connections are not affected.

Jul 11, 2022
7.5
CVE-2022-30791HIGH

In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections. Existing connections are not affected.

Jul 11, 2022
7.5
CVE-2022-33971HIGH

Authentication bypass by capture-replay vulnerability exists in Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, and Machine automation controller NJ series all models V 1.48 and earlier, which may allow an adjacent attacker who can analyze the communication between the controller and the specific software used by OMRON internally to cause a denial-of-service (DoS) condition or execute a malicious program.

Jul 4, 2022
7.5
CVE-2022-32284HIGH

Use of insufficiently random values vulnerability exists in Vnet/IP communication module VI461 of YOKOGAWA Wide Area Communication Router (WAC Router) AW810D, which may allow a remote attacker to cause denial-of-service (DoS) condition by sending a specially crafted packet.

Jul 4, 2022
7.5
CVE-2022-31805HIGH

In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.

Jun 24, 2022
7.5
CVE-2022-31804HIGH

The CODESYS Gateway Server V2 does not verifiy that the size of a request is within expected limits. An unauthenticated attacker may allocate an arbitrary amount of memory, which may lead to a crash of the Gateway due to an out-of-memory condition.

Jun 24, 2022
7.5
CVE-2022-24946HIGH

Improper Resource Locking vulnerability in Mitsubishi Electric MELSEC iQ-R Series R12CCPU-V firmware versions "16" and prior, Mitsubishi Electric MELSEC-Q Series Q03UDECPU the first 5 digits of serial No. "24061" and prior, Mitsubishi Electric MELSEC-Q Series Q04/06/10/13/20/26/50/100UDEHCPU the first 5 digits of serial No. "24061" and prior, Mitsubishi Electric MELSEC-Q Series Q03/04/06/13/26UDVCPU the first 5 digits of serial number "24051" and prior, Mitsubishi Electric MELSEC-Q Series Q04/06/13/26UDPVCPU the first 5 digits of serial number "24051" and prior, Mitsubishi Electric MELSEC-Q Series Q12DCCPU-V all versions, Mitsubishi Electric MELSEC-Q Series Q24DHCCPU-V(G) all versions, Mitsubishi Electric MELSEC-Q Series Q24/26DHCCPU-LS all versions, Mitsubishi Electric MELSEC-L series L02/06/26CPU(-P) the first 5 digits of serial number "24051" and prior, Mitsubishi Electric MELSEC-L series L26CPU-(P)BT the first 5 digits of serial number "24051" and prior and Mitsubishi Electric MELIPC Series MI5122-VW firmware versions "05" and prior allows a remote unauthenticated attacker to cause a denial of service (DoS) condition in Ethernet communications by sending specially crafted packets. A system reset of the products is required for recovery.

Jun 15, 2022
7.5
CVE-2021-40392HIGH

An information disclosure vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. Network sniffing can lead to a disclosure of sensitive information. An attacker can sniff network traffic to exploit this vulnerability.

Apr 14, 2022
7.5
CVE-2022-22519HIGH

A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserver of the CODESYS Control runtime system.

Apr 7, 2022
7.5
CVE-2022-22517HIGH

An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a valid channel ID and injecting packets. This results in the communication channel to be closed.

Apr 7, 2022
7.5
CVE-2021-30065HIGH

On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, crafted ModBus packets can bypass the ModBus enforcer. NOTE: this issue exists because of an incomplete fix of CVE-2017-11401.

Apr 3, 2022
7.5
CVE-2021-30063HIGH

On Schneider Electric ConneXium Tofino OPCLSM TCSEFM0000 before 03.23 and Belden Tofino Xenon Security Appliance, crafted OPC packets can cause an OPC enforcer denial of service.

Apr 3, 2022
7.5
CVE-2021-30062HIGH

On Schneider Electric ConneXium Tofino OPCLSM TCSEFM0000 before 03.23 and Belden Tofino Xenon Security Appliance, crafted OPC packets can bypass the OPC enforcer.

Apr 3, 2022
7.5
CVE-2021-32970HIGH

Data can be copied without validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier, which may allow a remote attacker to cause denial-of-service conditions.

Apr 1, 2022
7.5
CVE-2021-32968HIGH

Two buffer overflows in the built-in web server in Moxa NPort IAW5000A-I/O Series firmware version 2.2 or earlier may allow a remote attacker to cause a denial-of-service condition.

Apr 1, 2022
7.5
CVE-2021-22277HIGH

Improper Input Validation vulnerability in ABB 800xA, Control Software for AC 800M, Control Builder Safe, Compact Product Suite - Control and I/O, ABB Base Software for SoftControl allows an attacker to cause the denial of service.

Apr 1, 2022
7.5
CVE-2020-25178HIGH

ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communication protocol provides various file system operations, as well as the uploading of applications. Data is transferred over this protocol unencrypted, which could allow a remote unauthenticated attacker to upload, read, and delete files.

Mar 18, 2022
7.5
CVE-2021-39364HIGH

Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow command spoofing (for camera control) after ARP cache poisoning has been achieved.

Feb 24, 2022
7.5
CVE-2021-46082HIGH

Moxa TN-5900 v3.1 series routers, MGate 5109 v2.2 series protocol gateways, and MGate 5101-PBM-MN v2.1 series protocol gateways were discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via crafted packets.

Feb 18, 2022
7.5
CVE-2021-22288HIGH

Improper Input Validation vulnerability in the ABB SPIET800 and PNI800 module allows an attacker to cause the denial of service or make the module unresponsive.

Feb 4, 2022
7.5
CVE-2021-22286HIGH

Improper Input Validation vulnerability in the ABB SPIET800 and PNI800 module allows an attacker to cause the denial of service or make the module unresponsive.

Feb 4, 2022
7.5
CVE-2021-22285HIGH

Improper Handling of Exceptional Conditions, Improper Check for Unusual or Exceptional Conditions vulnerability in the ABB SPIET800 and PNI800 module that allows an attacker to cause the denial of service or make the module unresponsive.

Feb 4, 2022
7.5
CVE-2022-22510HIGH

Codesys Profinet in version V4.2.0.0 is prone to null pointer dereference that allows a denial of service (DoS) attack of an unauthenticated user via SNMP.

Feb 2, 2022
7.5
CVE-2021-46559HIGH

The firmware on Moxa TN-5900 devices through 3.1 has a weak algorithm that allows an attacker to defeat an inspection mechanism for integrity protection.

Jan 26, 2022
7.5
CVE-2021-20608HIGH

Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric GX Works2 versions 1.606G and prior allows a remote unauthenticated attacker to cause a DoS condition in GX Works2 by getting GX Works2 to read a tampered program file from a Mitsubishi Electric PLC by sending malicious crafted packets to tamper with the program file.

Dec 17, 2021
7.5
CVE-2021-20611HIGH

Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/08/16/32/120(EN)CPU, MELSEC iQ-R Series R08/16/32/120SFCPU, MELSEC iQ-R Series R08/16/32/120PCPU, MELSEC iQ-R Series R08/16/32/120PSFCPU, MELSEC iQ-R Series R16/32/64MTCPU, MELSEC iQ-R Series R12CCPU-V, MELSEC Q Series Q03UDECPU, MELSEC Q Series Q04/06/10/13/20/26/50/100UDEHCPU, MELSEC Q Series Q03/04/06/13/26UDVCPU, MELSEC Q Series Q04/06/13/26UDPVCPU, MELSEC Q Series Q12DCCPU-V, MELSEC Q Series Q24DHCCPU-V(G), MELSEC Q Series Q24/26DHCCPU-LS, MELSEC Q Series MR-MQ100, MELSEC Q Series Q172/173DCPU-S1, MELSEC Q Series Q172/173DSCPU, MELSEC Q Series Q170MCPU, MELSEC Q Series Q170MSCPU(-S1), MELSEC L Series L02/06/26CPU(-P), MELSEC L Series L26CPU-(P)BT and MELIPC Series MI5122-VW allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition by sending specially crafted packets. System reset is required for recovery.

Dec 1, 2021
7.5
CVE-2021-20610HIGH

Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/08/16/32/120(EN)CPU, MELSEC iQ-R Series R08/16/32/120SFCPU, MELSEC iQ-R Series R08/16/32/120PCPU, MELSEC iQ-R Series R08/16/32/120PSFCPU, MELSEC iQ-R Series R16/32/64MTCPU, MELSEC iQ-R Series R12CCPU-V, MELSEC Q Series Q03UDECPU, MELSEC Q Series Q04/06/10/13/20/26/50/100UDEHCPU, MELSEC Q Series Q03/04/06/13/26UDVCPU, MELSEC Q Series Q04/06/13/26UDPVCPU, MELSEC Q Series Q12DCCPU-V, MELSEC Q Series Q24DHCCPU-V(G), MELSEC Q Series Q24/26DHCCPU-LS, MELSEC Q Series MR-MQ100, MELSEC Q Series Q172/173DCPU-S1, MELSEC Q Series Q172/173DSCPU, MELSEC Q Series Q170MCPU, MELSEC Q Series Q170MSCPU(-S1), MELSEC L Series L02/06/26CPU(-P), MELSEC L Series L26CPU-(P)BT and MELIPC Series MI5122-VW allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition by sending specially crafted packets. System reset is required for recovery.

Dec 1, 2021
7.5
CVE-2021-20609HIGH

Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/08/16/32/120(EN)CPU, MELSEC iQ-R Series R08/16/32/120SFCPU, MELSEC iQ-R Series R08/16/32/120PCPU, MELSEC iQ-R Series R08/16/32/120PSFCPU, MELSEC iQ-R Series R16/32/64MTCPU, MELSEC iQ-R Series R12CCPU-V, MELSEC Q Series Q03UDECPU, MELSEC Q Series Q04/06/10/13/20/26/50/100UDEHCPU, MELSEC Q Series Q03/04/06/13/26UDVCPU, MELSEC Q Series Q04/06/13/26UDPVCPU, MELSEC Q Series Q12DCCPU-V, MELSEC Q Series Q24DHCCPU-V(G), MELSEC Q Series Q24/26DHCCPU-LS, MELSEC Q Series MR-MQ100, MELSEC Q Series Q172/173DCPU-S1, MELSEC Q Series Q172/173DSCPU, MELSEC Q Series Q170MCPU, MELSEC Q Series Q170MSCPU(-S1), MELSEC L Series L02/06/26CPU(-P), MELSEC L Series L26CPU-(P)BT and MELIPC Series MI5122-VW allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition by sending specially crafted packets. System reset is required for recovery.

Dec 1, 2021
7.5
CVE-2021-34598HIGH

In Phoenix Contact FL MGUARD 1102 and 1105 in Versions 1.4.0, 1.4.1 and 1.5.0 the remote logging functionality is impaired by the lack of memory release for data structures from syslog-ng when remote logging is active

Nov 10, 2021
7.5
CVE-2021-34593HIGH

In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several denial-of-service conditions. Running PLC programs may be stopped, memory may be leaked, or further communication clients may be blocked from accessing the PLC.

Oct 26, 2021
7.5
CVE-2021-34586HIGH

In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests may cause a Null pointer dereference in the CODESYS web server and may result in a denial-of-service condition.

Oct 26, 2021
7.5
CVE-2021-34585HIGH

In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser result is not checked under all conditions, a pointer dereference with an invalid address can occur. This leads to a denial of service situation.

Oct 26, 2021
7.5
CVE-2021-34583HIGH

Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22.

Oct 26, 2021
7.5
CVE-2018-16060HIGH

Mitsubishi Electric Europe B.V. SmartRTU devices allow remote attackers to obtain sensitive information (directory listing and source code) via a direct request to the /web URI.

Oct 15, 2021
7.5
CVE-2021-38460HIGH

A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.

Oct 12, 2021
7.5
CVE-2021-38452HIGH

A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.

Oct 12, 2021
7.5
CVE-2021-34570HIGH

Multiple Phoenix Contact PLCnext control devices in versions prior to 2021.0.5 LTS are prone to a DoS attack through special crafted JSON requests.

Sep 27, 2021
7.5
CVE-2021-34581HIGH

Missing Release of Resource after Effective Lifetime vulnerability in OpenSSL implementation of WAGO 750-831/xxx-xxx, 750-880/xxx-xxx, 750-881, 750-889 in versions FW4 up to FW15 allows an unauthenticated attacker to cause DoS on the device.

Aug 31, 2021
7.5
CVE-2021-20594HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions "26" and prior and Mitsubishi Electric MELSEC iQ-R series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions "11" and prior allows a remote unauthenticated attacker to acquire legitimate user names registered in the module via brute-force attack on user names.

Aug 6, 2021
7.5
CVE-2021-36765HIGH

In CODESYS EtherNetIP before 4.1.0.0, specific EtherNet/IP requests may cause a null pointer dereference in the downloaded vulnerable EtherNet/IP stack that is executed by the CODESYS Control runtime system.

Aug 4, 2021
7.5
CVE-2021-36764HIGH

In CODESYS Gateway V3 before 3.5.17.10, there is a NULL Pointer Dereference. Crafted communication requests may cause a Null pointer dereference in the affected CODESYS products and may result in a denial-of-service condition.

Aug 4, 2021
7.5
CVE-2021-36763HIGH

In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties.

Aug 3, 2021
7.5
CVE-2021-33486HIGH

All versions of the CODESYS V3 Runtime Toolkit for VxWorks from version V3.5.8.0 and before version V3.5.17.10 have Improper Handling of Exceptional Conditions.

Aug 3, 2021
7.5
CVE-2021-35527HIGH

Password autocomplete vulnerability in the web application password field of Hitachi ABB Power Grids eSOMS allows attacker to gain access to user credentials that are stored by the browser. This issue affects: Hitachi ABB Power Grids eSOMS version 6.3 and prior versions.

Jul 14, 2021
7.5
CVE-2021-33541HIGH

Phoenix Contact Classic Line Controllers ILC1x0 and ILC1x1 in all versions/variants are affected by a Denial-of-Service vulnerability. The communication protocols and device access do not feature authentication measures. Remote attackers can use specially crafted IP packets to cause a denial of service on the PLC's network communication module. A successful attack stops all network communication. To restore the network connectivity the device needs to be restarted. The automation task is not affected.

Jun 25, 2021
7.5
CVE-2021-21005HIGH

In Phoenix Contact FL SWITCH SMCS series products in multiple versions if an attacker sends a hand-crafted TCP-Packet with the Urgent-Flag set and the Urgent-Pointer set to 0, the network stack will crash. The device needs to be rebooted afterwards.

Jun 25, 2021
7.5
CVE-2021-21002HIGH

In Phoenix Contact FL COMSERVER UNI in versions < 2.40 a invalid Modbus exception response can lead to a temporary denial of service.

Jun 25, 2021
7.5
CVE-2021-33824HIGH

An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, until its resource exhausted. Then the web server is denial-of-service.

Jun 18, 2021
7.5
CVE-2021-33823HIGH

An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attacker could send a huge amount of TCP SYN packet to make web service's resource exhausted. Then the web server is denial-of-service.

Jun 18, 2021
7.5
CVE-2021-27196HIGH

Improper Input Validation vulnerability in Hitachi ABB Power Grids Relion 670 Series, Relion 670/650 Series, Relion 670/650/SAM600-IO, Relion 650, REB500, RTU500 Series, FOX615 (TEGO1), MSM, GMS600, PWC600 allows an attacker with access to the IEC 61850 network with knowledge of how to reproduce the attack, as well as the IP addresses of the different IEC 61850 access points (of IEDs/products), to force the device to reboot, which renders the device inoperable for approximately 60 seconds. This vulnerability affects only products with IEC 61850 interfaces. This issue affects: Hitachi ABB Power Grids Relion 670 Series 1.1; 1.2.3 versions prior to 1.2.3.20; 2.0 versions prior to 2.0.0.13; 2.1; 2.2.2 versions prior to 2.2.2.3; 2.2.3 versions prior to 2.2.3.2. Hitachi ABB Power Grids Relion 670/650 Series 2.2.0 versions prior to 2.2.0.13. Hitachi ABB Power Grids Relion 670/650/SAM600-IO 2.2.1 versions prior to 2.2.1.6. Hitachi ABB Power Grids Relion 650 1.1; 1.2; 1.3 versions prior to 1.3.0.7. Hitachi ABB Power Grids REB500 7.3; 7.4; 7.5; 7.6; 8.2; 8.3. Hitachi ABB Power Grids RTU500 Series 7.x version 7.x and prior versions; 8.x version 8.x and prior versions; 9.x version 9.x and prior versions; 10.x version 10.x and prior versions; 11.x version 11.x and prior versions; 12.x version 12.x and prior versions. Hitachi ABB Power Grids FOX615 (TEGO1) R1D02 version R1D02 and prior versions. Hitachi ABB Power Grids MSM 2.1.0 versions prior to 2.1.0. Hitachi ABB Power Grids GMS600 1.3.0 version 1.3.0 and prior versions. Hitachi ABB Power Grids PWC600 1.0 versions prior to 1.0.1.4; 1.1 versions prior to 1.1.0.1.

Jun 14, 2021
7.5
CVE-2021-26845HIGH

Information Exposure vulnerability in Hitachi ABB Power Grids eSOMS allows unauthorized user to gain access to report data if the URL used to access the report is discovered. This issue affects: Hitachi ABB Power Grids eSOMS 6.0 versions prior to 6.0.4.2.2; 6.1 versions prior to 6.1.4; 6.3 versions prior to 6.3.

Jun 14, 2021
7.5
CVE-2021-20591HIGH

Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric MELSEC iQ-R series CPU modules (R00/01/02CPU all versions, R04/08/16/32/120(EN)CPU all versions, R08/16/32/120SFCPU all versions, R08/16/32/120PCPU all versions, R08/16/32/120PSFCPU all versions) allows a remote unauthenticated attacker to prevent legitimate clients from connecting to the MELSOFT transmission port (TCP/IP) by not closing a connection properly, which may lead to a denial of service (DoS) condition.

Jun 11, 2021
7.5
CVE-2021-30195HIGH

CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation.

May 25, 2021
7.5
CVE-2021-30191HIGH

CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input.

May 25, 2021
7.5
CVE-2021-30186HIGH

CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow.

May 25, 2021
7.5
CVE-2020-27185HIGH

Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully exploiting the vulnerability could enable attackers to read authentication data, device configuration, and other sensitive data transmitted over Moxa Service.

May 14, 2021
7.5
CVE-2021-20997HIGH

In multiple managed switches by WAGO in different versions it is possible to read out the password hashes of all Web-based Management users.

May 13, 2021
7.5
CVE-2021-25849HIGH

An integer underflow was discovered in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, improper validation of the PortID TLV leads to Denial of Service via a crafted lldp packet.

May 10, 2021
7.5
CVE-2021-25846HIGH

Improper validation of the ChassisID TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allows attackers to cause a denial of service due to a negative number passed to the memcpy function via a crafted lldp packet.

May 10, 2021
7.5
CVE-2021-25845HIGH

Improper validation of the ChassisID TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allows attackers to cause a denial of service due to a NULL pointer dereference via a crafted lldp packet.

May 10, 2021
7.5
CVE-2021-29241HIGH

CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS).

May 3, 2021
7.5
CVE-2019-18231HIGH

Advantech Spectre RT ERT351 Versions 5.1.3 and prior logins and passwords are transmitted in clear text form, which may allow an attacker to intercept the request.

Mar 17, 2021
7.5
CVE-2020-24686HIGH

The vulnerabilities can be exploited to cause the web visualization component of the PLC to stop and not respond, leading to genuine users losing remote visibility of the PLC state. If a user attempts to login to the PLC while this vulnerability is exploited, the PLC will show an error state and refuse connections to Automation Builder. The execution of the PLC application is not affected by this vulnerability. This issue affects ABB AC500 V2 products with onboard Ethernet.

Feb 26, 2021
7.5
CVE-2021-20588HIGH

Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all versions, FR Configurator SW3 all versions, FR Configurator2 versions 1.24A and prior, GT Designer3 Version1(GOT1000) versions 1.250L and prior, GT Designer3 Version1(GOT2000) versions 1.250L and prior, GT SoftGOT1000 Version3 versions 3.245F and prior, GT SoftGOT2000 Version1 versions 1.250L and prior, GX Configurator-DP versions 7.14Q and prior, GX Configurator-QP all versions, GX Developer versions 8.506C and prior, GX Explorer all versions, GX IEC Developer all versions, GX LogViewer versions 1.115U and prior, GX RemoteService-I all versions, GX Works2 versions 1.597X and prior, GX Works3 versions 1.070Y and prior, iQ Monozukuri ANDON (Data Transfer) versions 1.003D and prior, iQ Monozukuri Process Remote Monitoring (Data Transfer) versions 1.002C and prior, M_CommDTM-HART all versions, M_CommDTM-IO-Link versions 1.03D and prior, MELFA-Works versions 4.4 and prior, MELSEC WinCPU Setting Utility all versions, MELSOFT EM Software Development Kit (EM Configurator) versions 1.015R and prior, MELSOFT Navigator versions 2.74C and prior, MH11 SettingTool Version2 versions 2.004E and prior, MI Configurator versions 1.004E and prior, MT Works2 versions 1.167Z and prior, MX Component versions 5.001B and prior, Network Interface Board CC IE Control utility versions 1.29F and prior, Network Interface Board CC IE Field Utility versions 1.16S and prior, Network Interface Board CC-Link Ver.2 Utility versions 1.23Z and prior, Network Interface Board MNETH utility versions 34L and prior, PX Developer versions 1.53F and prior, RT ToolBox2 versions 3.73B and prior, RT ToolBox3 versions 1.82L and prior, Setting/monitoring tools for the C Controller module (SW4PVC-CCPU) versions 4.12N and prior, and SLMP Data Collector versions 1.04E and prior) allows a remote unauthenticated attacker to cause a DoS condition on the software products, and possibly to execute a malicious code on the personal computer running the software products although it has not been reproduced, by spoofing MELSEC, GOT or FREQROL and returning crafted reply packets.

Feb 19, 2021
7.5
CVE-2021-20587HIGH

Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all versions, FR Configurator SW3 all versions, FR Configurator2 versions 1.24A and prior, GT Designer3 Version1(GOT1000) versions 1.250L and prior, GT Designer3 Version1(GOT2000) versions 1.250L and prior, GT SoftGOT1000 Version3 versions 3.245F and prior, GT SoftGOT2000 Version1 versions 1.250L and prior, GX Configurator-DP versions 7.14Q and prior, GX Configurator-QP all versions, GX Developer versions 8.506C and prior, GX Explorer all versions, GX IEC Developer all versions, GX LogViewer versions 1.115U and prior, GX RemoteService-I all versions, GX Works2 versions 1.597X and prior, GX Works3 versions 1.070Y and prior, iQ Monozukuri ANDON (Data Transfer) versions 1.003D and prior, iQ Monozukuri Process Remote Monitoring (Data Transfer) versions 1.002C and prior, M_CommDTM-HART all versions, M_CommDTM-IO-Link versions 1.03D and prior, MELFA-Works versions 4.4 and prior, MELSEC WinCPU Setting Utility all versions, MELSOFT EM Software Development Kit (EM Configurator) versions 1.015R and prior, MELSOFT Navigator versions 2.74C and prior, MH11 SettingTool Version2 versions 2.004E and prior, MI Configurator versions 1.004E and prior, MT Works2 versions 1.167Z and prior, MX Component versions 5.001B and prior, Network Interface Board CC IE Control utility versions 1.29F and prior, Network Interface Board CC IE Field Utility versions 1.16S and prior, Network Interface Board CC-Link Ver.2 Utility versions 1.23Z and prior, Network Interface Board MNETH utility versions 34L and prior, PX Developer versions 1.53F and prior, RT ToolBox2 versions 3.73B and prior, RT ToolBox3 versions 1.82L and prior, Setting/monitoring tools for the C Controller module (SW4PVC-CCPU) versions 4.12N and prior, and SLMP Data Collector versions 1.04E and prior) allows a remote unauthenticated attacker to cause a DoS condition on the software products, and possibly to execute a malicious code on the personal computer running the software products although it has not been reproduced, by spoofing MELSEC, GOT or FREQROL and returning crafted reply packets.

Feb 19, 2021
7.5
CVE-2021-22656HIGH

Advantech iView versions prior to v5.7.03.6112 are vulnerable to directory traversal, which may allow an attacker to read sensitive files.

Feb 11, 2021
7.5
CVE-2021-22654HIGH

Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an unauthorized attacker to disclose information.

Feb 11, 2021
7.5
CVE-2020-13573HIGH

A denial-of-service vulnerability exists in the Ethernet/IP server functionality of Rockwell Automation RSLinx Classic 2.57.00.14 CPR 9 SR 3. A specially crafted network request can lead to a denial of service. An attacker can send a sequence of malicious packets to trigger this vulnerability.

Jan 7, 2021
7.5
CVE-2020-25190HIGH

The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower stores and transmits the credentials of third-party services in cleartext.

Dec 23, 2020
7.5
CVE-2020-12516HIGH

Older firmware versions (FW1 up to FW10) of the WAGO PLC family 750-88x and 750-352 are vulnerable for a special denial of service attack.

Dec 10, 2020
7.5
CVE-2020-12524HIGH

Uncontrolled Resource Consumption can be exploited to cause the Phoenix Contact HMIs BTP 2043W, BTP 2070W and BTP 2102W in all versions to become unresponsive and not accurately update the display content (Denial of Service).

Dec 2, 2020
7.5
CVE-2020-7524HIGH

Out-of-bounds Write vulnerability exists in Modicon M218 Logic Controller (V5.0.0.7 and prior) which could cause Denial of Service when sending specific crafted IPV4 packet to the controller: Sending a specific IPv4 protocol package to Schneider Electric Modicon M218 Logic Controller can cause IPv4 devices to go down. The device does not work properly and must be powered back on to return to normal.

Aug 31, 2020
7.5
CVE-2020-15806HIGH

CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation.

Jul 22, 2020
7.5
CVE-2020-12031HIGH

In all versions of FactoryTalk View SE, after bypassing memory corruption mechanisms found in the operating system, a local, authenticated attacker may corrupt the associated memory space allowing for arbitrary code execution. Rockwell Automation recommends applying patch 1126290. Before installing this patch, the patch rollup dated 06 Apr 2020 or later MUST be applied. 1066644 – Patch Roll-up for CPR9 SRx.

Jul 20, 2020
7.5
CVE-2020-12015HIGH

A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition due to improper deserialization. This issue affects: Mitsubishi Electric MC Works64 version 4.02C (10.95.208.31) and earlier, all versions; Mitsubishi Electric MC Works32 version 3.00A (9.50.255.02); ICONICS GenBroker64, Platform Services, Workbench, FrameWorX Server version 10.96 and prior; ICONICS GenBroker32 version 9.5 and prior.

Jul 16, 2020
7.5
CVE-2020-12009HIGH

A specially crafted communication packet sent to the affected device could cause a denial-of-service condition due to a deserialization vulnerability. This affects: Mitsubishi Electric MC Works64 Version 4.02C (10.95.208.31) and earlier, all versions; Mitsubishi Electric MC Works32 Version 3.00A (9.50.255.02); ICONICS GenBroker64, Platform Services, Workbench, FrameWorX Server v10.96 and prior; ICONICS GenBroker32 v9.5 and prior.

Jul 16, 2020
7.5
CVE-2020-14499HIGH

Advantech iView, versions 5.6 and prior, has an improper access control vulnerability. Successful exploitation of this vulnerability may allow an attacker to obtain all user accounts credentials.

Jul 15, 2020
7.5
CVE-2020-5600HIGH

TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains a resource management error vulnerability, which may allow a remote attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.

Jul 7, 2020
7.5
CVE-2020-5598HIGH

TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains an improper access control vulnerability, which may which may allow a remote attacker tobypass access restriction and stop the network functions of the products or execute a malicious program via a specially crafted packet.

Jul 7, 2020
7.5
CVE-2020-5597HIGH

TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains a null pointer dereference vulnerability, which may allow a remote attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.

Jul 7, 2020
7.5
CVE-2020-5596HIGH

TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) does not properly manage sessions, which may allow a remote attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.

Jul 7, 2020
7.5
CVE-2020-12018HIGH

Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. An out-of-bounds vulnerability exists that may allow access to unauthorized data.

May 8, 2020
7.5
CVE-2020-12014HIGH

Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Input is not properly sanitized and may allow an attacker to inject SQL commands.

May 8, 2020
7.5
CVE-2019-19100HIGH

A privilege escalation vulnerability in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x, 4.2.x, < 4.3.11SP, < 4.4.9SP, < 4.5.4SP, <. 4.6.3SP, < 4.7.2 and < 4.8.1 allow authenticated users to delete arbitrary files via an exposed interface.

Apr 29, 2020
7.5
CVE-2019-3942HIGH

Advantech WebAccess 8.3.4 does not properly restrict an RPC call that allows unauthenticated, remote users to read files. An attacker can use this vulnerability to recover the administrator password.

Apr 1, 2020
7.5
CVE-2020-5527HIGH

When MELSOFT transmission port (UDP/IP) of Mitsubishi Electric MELSEC iQ-R series (all versions), MELSEC iQ-F series (all versions), MELSEC Q series (all versions), MELSEC L series (all versions), and MELSEC F series (all versions) receives massive amount of data via unspecified vectors, resource consumption occurs and the port does not process the data properly. As a result, it may fall into a denial-of-service (DoS) condition. The vendor states this vulnerability only affects Ethernet communication functions.

Mar 30, 2020
7.5
CVE-2019-5105HIGH

An exploitable memory corruption vulnerability exists in the Name Service Client functionality of 3S-Smart Software Solutions CODESYS GatewayService. A specially crafted packet can cause a large memcpy, resulting in an access violation and termination of the process. An attacker can send a packet to a device running the GatewayService.exe to trigger this vulnerability. All variants of the CODESYS V3 products in all versions prior V3.5.16.10 containing the CmpRouter or CmpRouterEmbedded component are affected, regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PLCnext, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control RTE V3, CODESYS Control RTE V3 (for Beckhoff CX), CODESYS Control Win V3 (also part of the CODESYS Development System setup), CODESYS Control V3 Runtime System Toolkit, CODESYS V3 Embedded Target Visu Toolkit, CODESYS V3 Remote Target Visu Toolkit, CODESYS V3 Safety SIL2, CODESYS Edge Gateway V3, CODESYS Gateway V3, CODESYS HMI V3, CODESYS OPC Server V3, CODESYS PLCHandler SDK, CODESYS V3 Simulation Runtime (part of the CODESYS Development System).

Mar 26, 2020
7.5
CVE-2020-7001HIGH

In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the affected products use a weak cryptographic algorithm, which may allow confidential information to be disclosed.

Mar 24, 2020
7.5
CVE-2020-6997HIGH

In Moxa EDS-G516E Series firmware, Version 5.2 or lower, sensitive information is transmitted over some web applications in cleartext.

Mar 24, 2020
7.5
CVE-2020-6979HIGH

In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the affected products use a hard-coded cryptographic key, increasing the possibility that confidential data can be recovered.

Mar 24, 2020
7.5
CVE-2020-6993HIGH

In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, an attacker can gain access to sensitive information from the web service without authorization.

Mar 24, 2020
7.5
CVE-2020-6987HIGH

In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, the affected products use a weak cryptographic algorithm, which may allow confidential information to be disclosed.

Mar 24, 2020
7.5
CVE-2020-6983HIGH

In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, the affected products use a hard-coded cryptographic key, which increases the possibility that confidential data can be recovered.

Mar 24, 2020
7.5
CVE-2020-7003HIGH

In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive information is transmitted over some web applications in clear text.

Mar 24, 2020
7.5
CVE-2019-18242HIGH

In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, frequent and multiple requests for short-term use may cause the web server to fail.

Mar 24, 2020
7.5
CVE-2020-6988HIGH

Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, A remote, unauthenticated attacker can send a request from the RSLogix 500 software to the victim’s MicroLogix controller. The controller will then respond to the client with used password values to authenticate the user on the client-side. This method of authentication may allow an attacker to bypass authentication altogether, disclose sensitive information, or leak credentials.

Mar 16, 2020
7.5
CVE-2020-6984HIGH

Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, The cryptographic function utilized to protect the password in MicroLogix is discoverable.

Mar 16, 2020
7.5
CVE-2020-9464HIGH

A Denial-of-Service vulnerability exists in BECKHOFF Ethernet TCP/IP Bus Coupler BK9000. After an attack has occurred, the device's functionality can be restored by rebooting.

Mar 12, 2020
7.5
CVE-2020-9435HIGH

PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.03.17, and TC CLOUD CLIENT 1002-TXTX through 1.03.17 devices contain a hardcoded certificate (and key) that is used by default for web-based services on the device. Impersonation, man-in-the-middle, or passive decryption attacks are possible if the generic certificate is not replaced by a device-specific certificate during installation.

Mar 12, 2020
7.5
CVE-2019-5149HIGH

The WBM web application on firmwares prior to 03.02.02 and 03.01.07 on the WAGO PFC100 and PFC2000, respectively, runs on a lighttpd web server and makes use of the FastCGI module, which is intended to provide high performance for all Internet applications without the penalties of Web server APIs. However, the default configuration of this module appears to limit the number of concurrent php-cgi processes to two, which can be abused to cause a denial of service of the entire web server. This affects WAGO PFC200 Firmware version 03.00.39(12) and version 03.01.07(13), and WAGO PFC100 Firmware version 03.00.39(12) and version 03.02.02(14).

Mar 11, 2020
7.5
CVE-2019-5134HIGH

An exploitable regular expression without anchors vulnerability exists in the Web-Based Management (WBM) authentication functionality of WAGO PFC200 versions 03.00.39(12) and 03.01.07(13), and WAGO PFC100 version 03.00.39(12). A specially crafted authentication request can bypass regular expression filters, resulting in sensitive information disclosure.

Mar 11, 2020
7.5
CVE-2019-5107HIGH

A cleartext transmission vulnerability exists in the network communication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to network traffic can easily intercept, interpret, and manipulate data coming from, or destined for e!Cockpit. This includes passwords, configurations, and binaries being transferred to endpoints.

Mar 11, 2020
7.5
CVE-2019-9104HIGH

An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. The application's configuration file contains parameters that represent passwords in cleartext.

Mar 11, 2020
7.5
CVE-2019-9101HIGH

An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. Sensitive information is sent to the web server in cleartext, which may allow an attacker to discover the credentials if they are able to observe traffic between the web browser and the server.

Mar 11, 2020
7.5
CVE-2019-9098HIGH

An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. An Integer overflow in the built-in web server allows remote attackers to initiate DoS.

Mar 11, 2020
7.5
CVE-2019-19279HIGH

A vulnerability has been identified in SIPROTEC 4 and SIPROTEC Compact relays equipped with EN100 Ethernet communication modules (All versions). Specially crafted packets sent to port 50000/UDP of the EN100 Ethernet communication modules could cause a Denial-of-Service of the affected device. A manual reboot is required to recover the service of the device. At the time of advisory publication no public exploitation of this security vulnerability was known to Siemens.

Mar 10, 2020
7.5
CVE-2020-6986HIGH

In all versions of Omron PLC CJ Series, an attacker can send a series of specific data packets within a short period, causing a service error on the PLC Ethernet module, which in turn causes a PLC service denied result.

Mar 5, 2020
7.5
CVE-2019-18238HIGH

In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive information is stored in configuration files without encryption, which may allow an attacker to access an administrative account.

Feb 26, 2020
7.5
CVE-2019-5148HIGH

An exploitable denial-of-service vulnerability exists in ServiceAgent functionality of the Moxa AWK-3131A, firmware version 1.13. A specially crafted packet can cause an integer underflow, triggering a large memcpy that will access unmapped or out-of-bounds memory. An attacker can send this packet while unauthenticated to trigger this vulnerability.

Feb 25, 2020
7.5
CVE-2019-5137HIGH

The usage of hard-coded cryptographic keys within the ServiceAgent binary allows for the decryption of captured traffic across the network from or to the Moxa AWK-3131A firmware version 1.13.

Feb 25, 2020
7.5
CVE-2018-16994HIGH

An issue was discovered on PHOENIX CONTACT AXL F BK PN <=1.0.4, AXL F BK ETH <= 1.12, and AXL F BK ETH XC <= 1.11 devices and Bosch Rexroth S20-ETH-BK and Rexroth S20-PN-BK+ (the S20-PN-BK+/S20-ETH-BK fieldbus couplers sold by Bosch Rexroth contain technology from Phoenix Contact). Incorrect handling of a request with non-standard symbols allows remote attackers to initiate a complete lock up of the bus coupler. Authentication of the request is not required.

Feb 18, 2020
7.5
CVE-2019-13537HIGH

The IEC870IP driver for AVEVA’s Vijeo Citect and Citect SCADA and Schneider Electric’s Power SCADA Operation has a buffer overflow vulnerability that could result in a server-side crash.

Jan 14, 2020
7.5
CVE-2019-19707HIGH

On Moxa EDS-G508E, EDS-G512E, and EDS-G516E devices (with firmware through 6.0), denial of service can occur via PROFINET DCE-RPC endpoint discovery packets.

Dec 11, 2019
7.5
CVE-2019-5637HIGH

When Beckhoff TwinCAT is configured to use the Profinet driver, a denial of service of the controller could be reached by sending a malformed UDP packet to the device. This issue affects TwinCAT 2 version 2304 (and prior) and TwinCAT 3.1 version 4204.0 (and prior).

Nov 21, 2019
7.5
CVE-2019-18230HIGH

Honeywell equIP and Performance series IP cameras, multiple versions, A vulnerability exists where the affected product allows unauthenticated access to audio streaming over HTTP.

Oct 31, 2019
7.5
CVE-2019-18228HIGH

Honeywell equIP series IP cameras Multiple equIP Series Cameras, A vulnerability exists in the affected products where a specially crafted HTTP packet request could result in a denial of service.

Oct 31, 2019
7.5
CVE-2019-18227HIGH

Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. XXE vulnerabilities exist that may allow disclosure of sensitive data.

Oct 31, 2019
7.5
CVE-2019-14927HIGH

An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote configuration download vulnerability allows an attacker to download the smartRTU's configuration file (which contains data such as usernames, passwords, and other sensitive RTU data).

Oct 28, 2019
7.5
CVE-2019-16901HIGH

Advantech WebAccess/HMI Designer 2.1.9.31 has Exception Handler Chain corruption starting at Unknown Symbol @ 0x0000000000000000 called from ntdll!RtlRaiseStatus+0x00000000000000b4.

Sep 26, 2019
7.5
CVE-2019-16900HIGH

Advantech WebAccess/HMI Designer 2.1.9.31 has a User Mode Write AV starting at MSVCR90!memcpy+0x000000000000015c.

Sep 26, 2019
7.5
CVE-2019-16899HIGH

In Advantech WebAccess/HMI Designer 2.1.9.31, Data from a Faulting Address controls Code Flow starting at PM_V3!CTagInfoThreadBase::GetNICInfo+0x0000000000512918.

Sep 26, 2019
7.5
CVE-2019-9009HIGH

An issue was discovered in 3S-Smart CODESYS before 3.5.15.0 . Crafted network packets cause the Control Runtime to crash.

Sep 17, 2019
7.5
CVE-2019-13532HIGH

CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which may allow access to files outside the restricted working directory of the controller.

Sep 13, 2019
7.5
CVE-2019-9012HIGH

An issue was discovered in 3S-Smart CODESYS V3 products. A crafted communication request may cause uncontrolled memory allocations in the affected CODESYS products and may result in a denial-of-service condition. All variants of the following CODESYS V3 products in all versions prior to v3.5.14.20 that contain the CmpGateway component are affected, regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, CODESYS Control for IOT2000, CODESYS Control for Linux, CODESYS Control for PFC100, CODESYS Control for PFC200, CODESYS Control for Raspberry Pi, CODESYS Control V3 Runtime System Toolkit, CODESYS Gateway V3, CODESYS V3 Development System.

Aug 15, 2019
7.5
CVE-2018-11424HIGH

There is Memory corruption in the web interface of Moxa OnCell G3470A-LTE Series version 1.6 Build 18021314 and prior, a different vulnerability than CVE-2018-11425.

Jul 3, 2019
7.5
CVE-2018-11423HIGH

There is Memory corruption in the web interface Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior, different vulnerability than CVE-2018-11420.

Jul 3, 2019
7.5
CVE-2019-6571HIGH

A vulnerability has been identified in SIEMENS LOGO!8 (6ED1052-xyyxx-0BA8 FS:01 to FS:06 / Firmware version V1.80.xx and V1.81.xx), SIEMENS LOGO!8 (6ED1052-xyy08-0BA0 FS:01 / Firmware version < V1.82.02). An attacker with network access to port 10005/tcp of the LOGO! device could cause a Denial-of-Service condition by sending specially crafted packets. The security vulnerability could be exploited by an unauthenticated attacker with network access to the affected service. No user interaction is required to exploit this security vulnerability. Successful exploitation of the security vulnerability compromises availability of the targeted system. At the time of advisory publication no public exploitation of this security vulnerability was known.

Jun 12, 2019
7.5
CVE-2018-10691HIGH

An issue was discovered on Moxa AWK-3121 1.14 devices. It is intended that an administrator can download /systemlog.log (the system log). However, the same functionality allows an attacker to download the file without any authentication or authorization.

Jun 7, 2019
7.5
CVE-2019-10977HIGH

In Mitsubishi Electric MELSEC-Q series Ethernet module QJ71E71-100 serial number 20121 and prior, an attacker could send crafted TCP packets against the FTP service, forcing the target devices to enter an error mode and cause a denial-of-service condition.

May 23, 2019
7.5
CVE-2018-13994HIGH

The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is vulnerable to a denial-of-service attack by making more than 120 connections.

May 7, 2019
7.5
CVE-2019-10953HIGH

ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network packets.

Apr 17, 2019
7.5
CVE-2018-16561HIGH

A vulnerability has been identified in SIMATIC S7-300 CPUs (All versions < V3.X.16). The affected CPUs improperly validate S7 communication packets which could cause a Denial-of-Service condition of the CPU. The CPU will remain in DEFECT mode until manual restart. Successful exploitation requires an attacker to be able to send a specially crafted S7 communication packet to a communication interface of the CPU. This includes Ethernet, PROFIBUS, and Multi Point Interfaces (MPI). No user interaction or privileges are required to exploit the security vulnerability. The vulnerability could allow causing a Denial-of-Service condition of the core functionality of the CPU, compromising the availability of the system. At the time of advisory publication no public exploitation of this security vulnerability was known. Siemens confirms the security vulnerability and provides mitigations to resolve the security issue.

Apr 17, 2019
7.5
CVE-2019-3941HIGH

Advantech WebAccess 8.3.4 allows unauthenticated, remote attackers to delete arbitrary files via IOCTL 10005 RPC.

Apr 9, 2019
7.5
CVE-2014-5436HIGH

A directory traversal vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, which could lead to possible information disclosure. Honeywell strongly encourages and recommends all customers running unsupported versions of EKPS prior to R400 to upgrade to a supported version.

Apr 8, 2019
7.5
CVE-2019-6554HIGH

Advantech WebAccess/SCADA, Versions 8.3.5 and prior. An improper access control vulnerability may allow an attacker to cause a denial-of-service condition.

Apr 5, 2019
7.5
CVE-2018-19016HIGH

Rockwell Automation EtherNet/IP Web Server Modules 1756-EWEB (includes 1756-EWEBK) Version 5.001 and earlier, and CompactLogix 1768-EWEB Version 2.005 and earlier. A remote attacker could send a crafted UDP packet to the SNMP service causing a denial-of-service condition to occur until the affected product is restarted.

Mar 27, 2019
7.5
CVE-2013-2805HIGH

Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 does not handle input correctly and results in a logic error if it receives a datagram with an incorrect value in the “Record Data Size” field. By sending a datagram to the service over Port 4444/UDP with the “Record Data Size” field modified to an oversized value, an attacker could cause an out-of-bounds read access violation that leads to a service crash. The service can be recovered with a manual reboot. The patches and details pertaining to this vulnerability can be found at the following Rockwell Automation Security Advisory link (login is required): https://rockwellautomation.custhelp.com/app/answers/detail/a_id/537599

Mar 26, 2019
7.5
CVE-2013-2807HIGH

Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 does not handle input correctly and results in a logic error if it calculates an incorrect value for the “Total Record Size” field. By sending a datagram to the service over Port 4444/UDP with the “Record Data Size” field modified to a specifically oversized value, the service will calculate an undersized value for the “Total Record Size” that will cause an out-of-bounds read access violation that leads to a service crash. The service can be recovered with a manual reboot. The patches and details pertaining to these vulnerabilities can be found at the following Rockwell Automation Security Advisory link (login is required): https://rockwellautomation.custhelp.com/app/answers/detail/a_id/537599

Mar 26, 2019
7.5
CVE-2013-2806HIGH

Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 does not handle input correctly and results in a logic error if it calculates an incorrect value for the “End of Current Record” field. By sending a datagram to the service over Port 4444/UDP with the “Record Data Size” field modified to a specifically oversized value, the service will calculate an undersized value for the “Total Record Size.” Then the service will calculate an incorrect value for the “End of Current Record” field causing access violations that lead to a service crash. The service can be recovered with a manual reboot. The patches and details pertaining to these vulnerabilities can be found at the following Rockwell Automation security advisory link (login is required): https://rockwellautomation.custhelp.com/app/answers/detail/a_id/537599

Mar 26, 2019
7.5
CVE-2019-6520HIGH

Moxa IKS and EDS does not properly check authority on server side, which results in a read-only user being able to perform arbitrary configuration changes.

Mar 5, 2019
7.5
CVE-2019-6518HIGH

Moxa IKS and EDS store plaintext passwords, which may allow sensitive information to be read by someone with access to the device.

Mar 5, 2019
7.5
CVE-2018-20026HIGH

Improper Communication Address Filtering exists in CODESYS V3 products versions prior V3.5.14.0.

Feb 19, 2019
7.5
CVE-2018-20025HIGH

Use of Insufficiently Random Values exists in CODESYS V3 products versions prior V3.5.14.0.

Feb 19, 2019
7.5
CVE-2019-6535HIGH

Mitsubishi Electric Q03/04/06/13/26UDVCPU: serial number 20081 and prior, Q04/06/13/26UDPVCPU: serial number 20081 and prior, and Q03UDECPU, Q04/06/10/13/20/26/50/100UDEHCPU: serial number 20101 and prior. A remote attacker can send specific bytes over Port 5007 that will result in an Ethernet stack crash and disruption to USB communication.

Feb 5, 2019
7.5
CVE-2018-18981HIGH

In Rockwell Automation FactoryTalk Services Platform 2.90 and earlier, a remote unauthenticated attacker could send numerous crafted packets to service ports resulting in memory consumption that could lead to a partial or complete denial-of-service condition to the affected services.

Jan 24, 2019
7.5
CVE-2018-20720HIGH

ABB Relion 630 devices 1.1 before 1.1.0.C0, 1.2 before 1.2.0.B3, and 1.3 before 1.3.0.A6 allow remote attackers to cause a denial of service (reboot) via a reboot command in an SPA message.

Jan 16, 2019
7.5
CVE-2018-16196HIGH

Multiple Yokogawa products that contain Vnet/IP Open Communication Driver (CENTUM CS 3000(R3.05.00 - R3.09.50), CENTUM CS 3000 Entry Class(R3.05.00 - R3.09.50), CENTUM VP(R4.01.00 - R6.03.10), CENTUM VP Entry Class(R4.01.00 - R6.03.10), Exaopc(R3.10.00 - R3.75.00), PRM(R2.06.00 - R3.31.00), ProSafe-RS(R1.02.00 - R4.02.00), FAST/TOOLS(R9.02.00 - R10.02.00), B/M9000 VP(R6.03.01 - R8.01.90)) allows remote attackers to cause a denial of service attack that may result in stopping Vnet/IP Open Communication Driver's communication via unspecified vectors.

Jan 9, 2019
7.5
CVE-2018-14820HIGH

Advantech WebAccess 8.3.1 and earlier has a .dll component that is susceptible to external control of file name or path vulnerability, which may allow an arbitrary file deletion when processing.

Oct 23, 2018
7.5
CVE-2018-18390HIGH

User Enumeration in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

Oct 19, 2018
7.5
CVE-2018-17898HIGH

Yokogawa STARDOM Controllers FCJ,FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The controller application fails to prevent memory exhaustion by unauthorized requests. This could allow an attacker to cause the controller to become unstable.

Oct 12, 2018
7.5
CVE-2018-14827HIGH

Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. A remote, unauthenticated threat actor may intentionally send specially crafted Ethernet/IP packets to Port 44818, causing the software application to stop responding and crash. The user must restart the software to regain functionality.

Sep 20, 2018
7.5
CVE-2018-14821HIGH

Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. This vulnerability may allow a remote, unauthenticated threat actor to intentionally send a malformed CIP packet to Port 44818, causing the RSLinx Classic application to terminate. The user will need to manually restart the software to regain functionality.

Sep 20, 2018
7.5
CVE-2018-7792HIGH

A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to decode the password using rainbow table.

Aug 29, 2018
7.5
CVE-2018-7789HIGH

An Improper Check for Unusual or Exceptional Conditions vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to remotely reboot Modicon M221 using crafted programing protocol frames.

Aug 29, 2018
7.5
CVE-2018-10632HIGH

In Moxa NPort 5210, 5230, and 5232 versions 2.9 build 17030709 and prior, the amount of resources requested by a malicious actor are not restricted, allowing for a denial-of-service condition.

Jul 24, 2018
7.5
CVE-2018-7783HIGH

Schneider Electric SoMachine Basic prior to v1.6 SP1 suffers from an XML External Entity (XXE) vulnerability using the DTD parameter entities technique resulting in disclosure and retrieval of arbitrary data on the affected node via out-of-band (OOB) attack. The vulnerability is triggered when input passed to the xml parser is not sanitized while parsing the xml project/template file.

Jul 3, 2018
7.5
CVE-2018-7779HIGH

In Schneider Electric Wiser for KNX V2.1.0 and prior, homeLYnk V2.0.1 and prior; and spaceLYnk V2.1.0 and prior, weak and unprotected FTP access could allow an attacker unauthorized access.

Jul 3, 2018
7.5
CVE-2018-1000531HIGH

inversoft prime-jwt version prior to commit abb0d479389a2509f939452a6767dc424bb5e6ba contains a CWE-20 vulnerability in JWTDecoder.decode that can result in an incorrect signature validation of a JWT token. This attack can be exploitable when an attacker crafts a JWT token with a valid header using 'none' as algorithm and a body to requests it be validated. This vulnerability was fixed after commit abb0d479389a2509f939452a6767dc424bb5e6ba.

Jun 26, 2018
7.5
CVE-2018-7503HIGH

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, a path transversal vulnerability has been identified, which may allow an attacker to disclose sensitive information on the target.

May 15, 2018
7.5
CVE-2018-7501HIGH

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, several SQL injection vulnerabilities have been identified, which may allow an attacker to disclose sensitive information from the host.

May 15, 2018
7.5
CVE-2018-7495HIGH

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an external control of file name or path vulnerability has been identified, which may allow an attacker to delete files.

May 15, 2018
7.5
CVE-2018-10590HIGH

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an information exposure vulnerability through directory listing has been identified, which may allow an attacker to find important files that are not normally visible.

May 15, 2018
7.5
CVE-2017-14439HIGH

Exploitable denial of service vulnerabilities exists in the Service Agent functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted packet can cause a denial of service. An attacker can send a large packet to 4001/tcp to trigger this vulnerability.

May 14, 2018
7.5
CVE-2017-14438HIGH

Exploitable denial of service vulnerabilities exists in the Service Agent functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted packet can cause a denial of service. An attacker can send a large packet to 4000/tcp to trigger this vulnerability.

May 14, 2018
7.5
CVE-2017-14437HIGH

An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP URI can cause a null pointer dereference resulting in denial of service. An attacker can send a GET request to "/MOXA\_LOG.ini" without a cookie header to trigger this vulnerability.

May 14, 2018
7.5
CVE-2017-14436HIGH

An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP URI can cause a null pointer dereference resulting in denial of service. An attacker can send a GET request to "/MOXA\_CFG2.ini" without a cookie header to trigger this vulnerability.

May 14, 2018
7.5
CVE-2017-14435HIGH

An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP URI can cause a null pointer dereference resulting in denial of service. An attacker can send a GET request to "/MOXA\_CFG.ini" without a cookie header to trigger this vulnerability.

May 14, 2018
7.5
CVE-2017-12128HIGH

An exploitable information disclosure vulnerability exists in the Server Agent functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted TCP packet can cause information disclosure. An attacker can send a crafted TCP packet to trigger this vulnerability.

May 14, 2018
7.5
CVE-2017-6021HIGH

In Schneider Electric ClearSCADA 2014 R1 (build 75.5210) and prior, 2014 R1.1 (build 75.5387) and prior, 2015 R1 (build 76.5648) and prior, and 2015 R2 (build 77.5882) and prior, an attacker with network access to the ClearSCADA server can send specially crafted sequences of commands and data packets to the ClearSCADA server that can cause the ClearSCADA server process and ClearSCADA communications driver processes to terminate. A CVSS v3 base score of 7.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

May 14, 2018
7.5
CVE-2018-7762HIGH

A vulnerability exists in the web services to process SOAP requests in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200 which could allow result in a buffer overflow.

Apr 18, 2018
7.5
CVE-2018-7759HIGH

A buffer overflow vulnerability exists in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200. The buffer overflow vulnerability is caused by the length of the source string specified (instead of the buffer size) as the number of bytes to be copied.

Apr 18, 2018
7.5
CVE-2014-8421HIGH

Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 allow remote attackers to gain super-user privileges by leveraging SSH access and incorrect ownership of (1) ConfigureCoreFile.sh, (2) Traceroute.sh, (3) apps.sh, (4) conversion_java2native.sh, (5) coreCompression.sh, (6) deletePasswd.sh, (7) findHealthSvcFDs.sh, (8) fw_printenv.sh, (9) fw_setenv.sh, (10) hw_wd_kicker.sh, (11) new_rootfs.sh, (12) opera_killSnmpd.sh, (13) opera_startSnmpd.sh, (14) rebootOperaSoftware.sh, (15) removeLogFiles.sh, (16) runOperaServices.sh, (17) setPasswd.sh, (18) startAccTestSvcs.sh, (19) usbNotification.sh, or (20) appWeb in /Opera_Deploy.

Apr 12, 2018
7.5
CVE-2018-7506HIGH

The private key of the web server in Moxa MXview versions 2.8 and prior is able to be read and accessed via an HTTP GET request, which may allow a remote attacker to decrypt encrypted information.

Apr 6, 2018
7.5
CVE-2018-7235HIGH

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow arbitrary system file download due to lack of validation of the shell meta characters with the value of 'system.download.sd_file'

Mar 9, 2018
7.5
CVE-2018-7234HIGH

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow arbitrary system file download due to lack of validation of SSL certificate.

Mar 9, 2018
7.5
CVE-2018-5453HIGH

An Improper Handling of Length Parameter Inconsistency issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. An attacker may be able to edit the element of an HTTP request, causing the device to become unavailable.

Mar 5, 2018
7.5
CVE-2017-16736HIGH

An Unrestricted Upload Of File With Dangerous Type issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows a remote attacker to upload arbitrary files.

Jan 12, 2018
7.5
CVE-2017-16753HIGH

An Improper Input Validation issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows some inputs that may cause the program to crash.

Jan 5, 2018
7.5
CVE-2017-16728HIGH

An Untrusted Pointer Dereference issue was discovered in Advantech WebAccess versions prior to 8.3. There are multiple vulnerabilities that may allow an attacker to cause the program to use an invalid memory address, resulting in a program crash.

Jan 5, 2018
7.5
CVE-2017-14022HIGH

An Improper Input Validation issue was discovered in Rockwell Automation FactoryTalk Alarms and Events, Version 2.90 and earlier. An unauthenticated attacker with remote access to a network with FactoryTalk Alarms and Events can send a specially crafted set of packets packet to Port 403/TCP (the history archiver service), causing the service to either stall or terminate.

Dec 23, 2017
7.5
CVE-2017-13699HIGH

An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The password encryption method can be retrieved from the firmware. This encryption method is based on a chall value that is sent in cleartext as a POST parameter. An attacker could reverse the password encryption algorithm to retrieve it.

Nov 23, 2017
7.5
CVE-2017-13698HIGH

An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. An attacker could extract public and private keys from the firmware image available on the MOXA website and could use them against a production switch that has the default keys embedded.

Nov 23, 2017
7.5
CVE-2017-13703HIGH

An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. A denial of service may occur.

Nov 17, 2017
7.5
CVE-2017-16719HIGH

An Injection issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, NPort 5110 Version 2.6, NPort 5110 Version 2.7, NPort 5130 Version 3.7 and prior, and NPort 5150 Version 3.7 and prior. An attacker may be able to inject packets that could potentially disrupt the availability of the device.

Nov 16, 2017
7.5
CVE-2017-16715HIGH

An Information Exposure issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, NPort 5110 Version 2.6, NPort 5110 Version 2.7, NPort 5130 Version 3.7 and prior, and NPort 5150 Version 3.7 and prior. An attacker may be able to exploit a flaw in the handling of Ethernet frame padding that may allow for information exposure.

Nov 16, 2017
7.5
CVE-2017-14028HIGH

A Resource Exhaustion issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, NPort 5110 Version 2.6, NPort 5110 Version 2.7, NPort 5130 Version 3.7 and prior, and NPort 5150 Version 3.7 and prior. An attacker may be able to exhaust memory resources by sending a large amount of TCP SYN packets.

Nov 16, 2017
7.5
CVE-2017-12719HIGH

An Untrusted Pointer Dereference issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. A remote attacker is able to execute code to dereference a pointer within the program causing the application to become unavailable.

Nov 6, 2017
7.5
CVE-2017-9946HIGH

A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. An attacker with network access to the integrated web server (80/tcp and 443/tcp) could bypass the authentication and download sensitive information from the device.

Oct 23, 2017
7.5
CVE-2017-9962HIGH

Schneider Electric's ClearSCADA versions released prior to August 2017 are susceptible to a memory allocation vulnerability, whereby malformed requests can be sent to ClearSCADA client applications to cause unexpected behavior. Client applications affected include ViewX and the Server Icon.

Sep 26, 2017
7.5
CVE-2017-7924HIGH

An Improper Input Validation issue was discovered in Rockwell Automation MicroLogix 1100 controllers 1763-L16BWA, 1763-L16AWA, 1763-L16BBB, and 1763-L16DWD. A remote, unauthenticated attacker could send a single, specially crafted Programmable Controller Communication Commands (PCCC) packet to the controller that could potentially cause the controller to enter a DoS condition.

Sep 20, 2017
7.5
CVE-2017-12734HIGH

A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V1.81.2). An attacker with network access to the integrated web server on port 80/tcp could obtain the session ID of an active user session. A user must be logged in to the web interface. Siemens recommends to use the integrated webserver on port 80/tcp only in trusted networks.

Aug 30, 2017
7.5
CVE-2017-12710HIGH

A SQL Injection issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. By submitting a specially crafted parameter, it is possible to inject arbitrary SQL statements that could allow an attacker to obtain sensitive information.

Aug 30, 2017
7.5
CVE-2017-9938HIGH

A vulnerability was discovered in Siemens SIMATIC Logon (All versions before V1.6) that could allow specially crafted packets sent to the SIMATIC Logon Remote Access service on port 16389/tcp to cause a Denial-of-Service condition. The service restarts automatically.

Aug 8, 2017
7.5
CVE-2017-7920HIGH

An Improper Authentication issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versions 2.1.3 and prior. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access internal information about status and connected devices without authenticating.

Aug 7, 2017
7.5
CVE-2017-9631HIGH

A Null Pointer Dereference issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.2307.1 and prior. The null pointer dereference vulnerability could allow an attacker to crash the logger process, causing a denial of service for logging and log-viewing (applications that use the Wonderware ArchestrA Logger continue to run when the Wonderware ArchestrA Logger service is unavailable).

Jul 7, 2017
7.5
CVE-2017-6017HIGH

A Resource Exhaustion issue was discovered in Schneider Electric Modicon M340 PLC BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP341000, BMXP342000, BMXP3420102, BMXP3420102CL, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, and BMXP342030H. A remote attacker could send a specially crafted set of packets to the PLC causing it to freeze, requiring the operator to physically press the reset button on the PLC in order to recover.

Jun 30, 2017
7.5
CVE-2017-7935HIGH

A Resource Exhaustion issue was discovered in Phoenix Contact GmbH mGuard firmware versions 8.3.0 to 8.4.2. An attacker may compromise the device's availability by performing multiple initial VPN requests.

May 19, 2017
7.5
CVE-2017-7456HIGH

Moxa MXView 2.8 allows remote attackers to cause a Denial of Service by sending overly long junk payload for the MXView client login credentials.

Apr 14, 2017
7.5
CVE-2017-7455HIGH

Moxa MXView 2.8 allows remote attackers to read web server's private key file, no access control.

Apr 14, 2017
7.5
CVE-2016-8727HIGH

An exploitable information disclosure vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point. Retrieving a series of URLs without authentication can reveal sensitive configuration and system information to an attacker.

Apr 13, 2017
7.5
CVE-2016-8726HIGH

An exploitable null pointer dereference vulnerability exists in the Web Application /forms/web_runScript iw_filename functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. An HTTP POST request with a blank line in the header will cause a segmentation fault in the web server.

Apr 13, 2017
7.5
CVE-2016-8723HIGH

An exploitable null pointer dereference exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. Any HTTP GET request not preceded by an '/' will cause a segmentation fault in the web server. An attacker can send any of a multitude of potentially unexpected HTTP get requests to trigger this vulnerability.

Apr 13, 2017
7.5
CVE-2016-8716HIGH

An exploitable Cleartext Transmission of Password vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. The Change Password functionality of the Web Application transmits the password in cleartext. An attacker capable of intercepting this traffic is able to obtain valid credentials.

Apr 12, 2017
7.5
CVE-2017-6019HIGH

An issue was discovered in Schneider Electric Conext ComBox, model 865-1058, all firmware versions prior to V3.03 BN 830. A series of rapid requests to the device may cause it to reboot.

Apr 7, 2017
7.5
CVE-2016-9367HIGH

An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPort 5100A Series & NPort P5150A versions prior to 1.3, NPort 5200A Series versions prior to 1.3, NPort 5150AI-M12 Series versions prior to 1.2, NPort 5250AI-M12 Series versions prior to 1.2, NPort 5450AI-M12 Series versions prior to 1.2, NPort 5600-8-DT Series versions prior to 2.4, NPort 5600-8-DTL Series versions prior to 2.4, NPort 6x50 Series versions prior to 1.13.11, NPort IA5450A versions prior to v1.4. The amount of resources requested by a malicious actor is not restricted, leading to a denial-of-service caused by resource exhaustion.

Feb 13, 2017
7.5
CVE-2016-9349HIGH

An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. An attacker could traverse the file system and extract files that can result in information disclosure.

Feb 13, 2017
7.5
CVE-2016-9344HIGH

An issue was discovered in Moxa MiiNePort E1 versions prior to 1.8, E2 versions prior to 1.4, and E3 versions prior to 1.1. An attacker may be able to brute force an active session cookie to be able to download configuration files.

Feb 13, 2017
7.5
CVE-2016-9332HIGH

An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. Moxa SoftCMS Webserver does not properly validate input. An attacker could provide unexpected values and cause the program to crash or excessive consumption of resources could result in a denial-of-service condition.

Feb 13, 2017
7.5
CVE-2016-8374HIGH

An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all versions, Magelis GTU Universal Panel, all versions, Magelis STO5xx and STU Small panels, all versions, Magelis XBT GH Advanced Hand-held Panels, all versions, Magelis XBT GK Advanced Touchscreen Panels with Keyboard, all versions, Magelis XBT GT Advanced Touchscreen Panels, all versions, and Magelis XBT GTW Advanced Open Touchscreen Panels (Windows XPe). An attacker may be able to disrupt a targeted web server, resulting in a denial of service because of UNCONTROLLED RESOURCE CONSUMPTION.

Feb 13, 2017
7.5
CVE-2016-8370HIGH

An issue was discovered in Mitsubishi Electric Automation MELSEC-Q series Ethernet interface modules QJ71E71-100, all versions, QJ71E71-B5, all versions, and QJ71E71-B2, all versions. Weakly encrypted passwords are transmitted to a MELSEC-Q PLC.

Feb 13, 2017
7.5
CVE-2016-8346HIGH

An issue was discovered in Moxa EDR-810 Industrial Secure Router. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access configuration and log files (PRIVILEGE ESCALATION).

Feb 13, 2017
7.5
CVE-2016-7987HIGH

An issue was discovered in Siemens ETA4 firmware (all versions prior to Revision 08) of the SM-2558 extension module for: SICAM AK, SICAM TM 1703, SICAM BC 1703, and SICAM AK 3. Specially crafted packets sent to Port 2404/TCP could cause the affected device to go into defect mode. A cold start might be required to recover the system, a Denial-of-Service Vulnerability.

Feb 13, 2017
7.5
CVE-2016-9154HIGH

Siemens Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 for Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D (All firmware versions < V6.00.046) and Desigo PX Web modules PXA30-W0, PXA30-W1, PXA30-W2 for Desigo PX automation controllers PXC00-U, PXC64-U, PXC128-U (All firmware versions < V6.00.046) use a pseudo random number generator with insufficient entropy to generate certificates for HTTPS, potentially allowing remote attackers to reconstruct the corresponding private key.

Dec 23, 2016
7.5
CVE-2016-8563HIGH

Siemens Automation License Manager (ALM) before 5.3 SP3 Update 1 allows remote attackers to cause a denial of service (ALM service outage) via crafted packets to TCP port 4410.

Oct 13, 2016
7.5
CVE-2016-4526HIGH

ABB DataManagerPro 1.x before 1.7.1 allows local users to gain privileges by replacing a DLL file in the package directory.

Sep 19, 2016
7.5
CVE-2016-5874HIGH

Siemens SIMATIC NET PC-Software before 13 SP2 allows remote attackers to cause a denial of service (OPC UA service outage) via crafted TCP packets.

Jul 22, 2016
7.5
CVE-2016-5744HIGH

Siemens SIMATIC WinCC 7.0 through SP3 and 7.2 allows remote attackers to read arbitrary WinCC station files via crafted packets.

Jul 22, 2016
7.5
CVE-2016-3949HIGH

Siemens SIMATIC S7-300 Profinet-enabled CPU devices with firmware before 3.2.12 and SIMATIC S7-300 Profinet-disabled CPU devices with firmware before 3.3.12 allow remote attackers to cause a denial of service (defect-mode transition) via crafted (1) ISO-TSAP or (2) Profibus packets.

Jun 27, 2016
7.5
CVE-2016-2295HIGH

Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 devices with firmware 1.1 Build 10080614, MiiNePort_E2_4561 devices with firmware 1.1 Build 10080614, and MiiNePort E3 devices with firmware 1.0 Build 11071409 allow remote attackers to obtain sensitive cleartext information by reading a configuration file.

May 31, 2016
7.5
CVE-2016-2286HIGH

Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 devices with firmware 1.1 Build 10080614, MiiNePort_E2_4561 devices with firmware 1.1 Build 10080614, and MiiNePort E3 devices with firmware 1.0 Build 11071409 have a blank default password, which allows remote attackers to obtain access via unspecified vectors.

May 31, 2016
7.5
CVE-2016-0879HIGH

Moxa Secure Router EDR-G903 devices before 3.4.12 do not delete copies of configuration and log files after completing the import function, which allows remote attackers to obtain sensitive information by requesting these files at an unspecified URL.

May 31, 2016
7.5
CVE-2016-0878HIGH

Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to cause a denial of service (cold start) by sending two crafted ping requests.

May 31, 2016
7.5
CVE-2016-0877HIGH

Memory leak on Moxa Secure Router EDR-G903 devices before 3.4.12 allows remote attackers to cause a denial of service (memory consumption) by executing the ping function.

May 31, 2016
7.5
CVE-2016-0876HIGH

Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to discover cleartext passwords by reading a configuration file.

May 31, 2016
7.5
CVE-2016-0875HIGH

Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to read configuration and log files via a crafted URL.

May 31, 2016
7.5
CVE-2016-2280HIGH

Buffer overflow in RDISERVER in Honeywell Uniformance Process History Database (PHD) R310, R320, and R321 allows remote attackers to cause a denial of service (service outage) via unspecified vectors.

Apr 21, 2016
7.5
CVE-2016-2200HIGH

Siemens SIMATIC S7-1500 CPU devices before 1.8.3 allow remote attackers to cause a denial of service (STOP mode transition) via crafted packets on TCP port 102.

Feb 8, 2016
7.5
CVE-2016-0860HIGH

Buffer overflow in the BwpAlarm subsystem in Advantech WebAccess before 8.1 allows remote attackers to cause a denial of service via a crafted RPC request.

Jan 15, 2016
7.5
CVE-2016-0855HIGH

Directory traversal vulnerability in Advantech WebAccess before 8.1 allows remote attackers to list arbitrary virtual-directory files via unspecified vectors.

Jan 15, 2016
7.5
CVE-2016-0853HIGH

Advantech WebAccess before 8.1 allows remote attackers to obtain sensitive information via crafted input.

Jan 15, 2016
7.5
CVE-2016-0852HIGH

Advantech WebAccess before 8.1 allows remote attackers to bypass an intended administrative requirement and obtain file or folder access via unspecified vectors.

Jan 15, 2016
7.5
CVE-2016-0851HIGH

Advantech WebAccess before 8.1 allows remote attackers to cause a denial of service (out-of-bounds memory access) via unspecified vectors.

Jan 15, 2016
7.5
CVE-2015-7375HIGH

Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code or cause a denial of service (unhandled runtime exception and application crash) via a crafted Indusoft Project file.

Sep 25, 2015
7.5
CVE-2015-7374HIGH

The Remote Agent component in Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code via unspecified vectors, aka ZDI-CAN-2649.

Sep 25, 2015
7.5
CVE-2015-6460HIGH

Multiple heap-based buffer overflows in 3S-Smart CODESYS Gateway Server before 2.3.9.34 allow remote attackers to execute arbitrary code via opcode (1) 0x3ef or (2) 0x3f0.

Sep 18, 2015
7.5
CVE-2015-5698HIGH

Cross-site request forgery (CSRF) vulnerability in the web server on Siemens SIMATIC S7-1200 CPU devices with firmware before 4.1.3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

Aug 30, 2015
7.5
CVE-2015-0986HIGH

Multiple stack-based buffer overflows in Moxa VPort ActiveX SDK Plus before 2.8 allow remote attackers to insert assembly-code lines via vectors involving a regkey (1) set or (2) get command.

May 26, 2015
7.5
CVE-2015-0982HIGH

Buffer overflow in an unspecified DLL in Schneider Electric Pelco DS-NVs before 7.8.90 allows remote attackers to execute arbitrary code via unspecified vectors.

Mar 14, 2015
7.5
CVE-2014-9200HIGH

Stack-based buffer overflow in an unspecified DLL file in a DTM development kit in Schneider Electric Unity Pro, SoMachine, SoMove, SoMove Lite, Modbus Communication Library 2.2.6 and earlier, CANopen Communication Library 1.0.2 and earlier, EtherNet/IP Communication Library 1.0.0 and earlier, EM X80 Gateway DTM (MB TCP/SL), Advantys DTM for OTB, Advantys DTM for STB, KINOS DTM, SOLO DTM, and Xantrex DTMs allows remote attackers to execute arbitrary code via unspecified vectors.

Feb 1, 2015
7.5
CVE-2014-8386HIGH

Multiple stack-based buffer overflows in Advantech AdamView 4.3 and earlier allow remote attackers to execute arbitrary code via a crafted (1) display properties or (2) conditional bitmap parameter in a GNI file.

Jan 20, 2015
7.5
CVE-2014-8514HIGH

Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8513 and CVE-2014-9188. NOTE: this may be clarified later based on details provided by researchers.

Dec 27, 2014
7.5
CVE-2014-8513HIGH

Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8514 and CVE-2014-9188. NOTE: this may be clarified later based on details provided by researchers.

Dec 27, 2014
7.5
CVE-2014-8512HIGH

Buffer overflow in an ActiveX control in Atx45.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8511. NOTE: this may be clarified later based on details provided by researchers.

Dec 27, 2014
7.5
CVE-2014-5208HIGH

BKBCopyD.exe in the Batch Management Packages in Yokogawa CENTUM CS 3000 through R3.09.50 and CENTUM VP through R4.03.00 and R5.x through R5.04.00, and Exaopc through R3.72.10, does not require authentication, which allows remote attackers to read arbitrary files via a RETR operation, write to arbitrary files via a STOR operation, or obtain sensitive database-location information via a PMODE operation, a different vulnerability than CVE-2014-0784.

Dec 22, 2014
7.5
CVE-2014-8269HIGH

Multiple stack-based buffer overflows in (1) HWOPOSScale.ocx and (2) HWOPOSSCANNER.ocx in Honeywell OPOS Suite before 1.13.4.15 allow remote attackers to execute arbitrary code via a crafted file that is improperly handled by the Open method.

Dec 13, 2014
7.5
CVE-2014-5424HIGH

Rockwell Automation Connected Components Workbench (CCW) before 7.00.00 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an invalid property value to an ActiveX control that was built with an outdated compiler.

Nov 14, 2014
7.5
CVE-2014-5399HIGH

SQL injection vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Aug 28, 2014
7.5
CVE-2014-5397HIGH

Cross-site scripting (XSS) vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Aug 28, 2014
7.5
CVE-2014-2368HIGH

The BrowseFolder method in the bwocxrun ActiveX control in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a crafted call.

Jul 19, 2014
7.5
CVE-2014-2367HIGH

The ChkCookie subroutine in an ActiveX control in broadweb/include/gChkCook.asp in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a crafted call.

Jul 19, 2014
7.5
CVE-2014-2364HIGH

Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to execute arbitrary code via a long string in the (1) ProjectName, (2) SetParameter, (3) NodeName, (4) CCDParameter, (5) SetColor, (6) AlarmImage, (7) GetParameter, (8) GetColor, (9) ServerResponse, (10) SetBaud, or (11) IPAddress parameter to an ActiveX control in (a) webvact.ocx, (b) dvs.ocx, or (c) webdact.ocx.

Jul 19, 2014
7.5
CVE-2014-1697HIGH

The integrated web server in Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to execute arbitrary code via crafted packets to TCP port 4999.

Feb 7, 2014
7.5
CVE-2013-3958HIGH

The login implementation in the Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, has a hardcoded account, which makes it easier for remote attackers to obtain access via an unspecified request.

Jun 14, 2013
7.5
CVE-2013-3957HIGH

SQL injection vulnerability in the login screen in the Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Jun 14, 2013
7.5
CVE-2012-3032HIGH

SQL injection vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to execute arbitrary SQL commands via a crafted SOAP message.

Sep 18, 2012
7.5
CVE-2012-0254HIGH

Stack-based buffer overflow in the HMIWeb Browser HSCDSPRenderDLL ActiveX control in Honeywell Process Solutions (HPS) Experion R2xx, R30x, R31x, and R400.x; Honeywell Building Solutions (HBS) Enterprise Building Manager R400 and R410.1; and Honeywell Environmental Combustion and Controls (ECC) SymmetrE R410.1 allows remote attackers to execute arbitrary code via unspecified vectors.

Sep 8, 2012
7.5
CVE-2012-3020HIGH

The Siemens Synco OZW Web Server devices OZW672.*, OZW772.*, and OZW775 with firmware before 4 have an unspecified default password, which makes it easier for remote attackers to obtain administrative access via a network session.

Aug 6, 2012
7.5
CVE-2012-0244HIGH

Multiple SQL injection vulnerabilities in Advantech/BroadWin WebAccess before 7.0 allow remote attackers to execute arbitrary SQL commands via crafted string input.

Feb 21, 2012
7.5
CVE-2012-0234HIGH

SQL injection vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary SQL commands via a malformed URL.

Feb 21, 2012
7.5
CVE-2011-4521HIGH

SQL injection vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary SQL commands via crafted string input.

Feb 21, 2012
7.5
CVE-2012-0929HIGH

Multiple buffer overflows in Schneider Electric Modicon Quantum PLC allow remote attackers to cause a denial of service via malformed requests to the (1) FTP server or (2) HTTP server.

Jan 28, 2012
7.5
CVE-2011-4529HIGH

Multiple buffer overflows in Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 allow remote attackers to execute arbitrary code via a long serialid field in an _licensekey command, as demonstrated by the (1) check_licensekey or (2) read_licensekey command.

Jan 8, 2012
7.5
CVE-2011-5008HIGH

Integer overflow in the GatewayService component in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to execute arbitrary code via a large size value in the packet header, which triggers a heap-based buffer overflow.

Dec 25, 2011
7.5
CVE-2010-0985HIGH

Directory traversal vulnerability in the Abbreviations Manager (com_abbrev) component 1.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

Mar 16, 2010
7.5
CVE-2006-3344HIGH

Siemens Speedstream Wireless Router 2624 allows local users to bypass authentication and access protected files by using the Universal Plug and Play UPnP/1.0 component.

Jul 3, 2006
7.5
CVE-2005-2424HIGH

The management interface for Siemens SANTIS 50 running firmware 4.2.8.0, and possibly other products including Ericsson HN294dp and Dynalink RTA300W, allows remote attackers to access the Telnet port without authentication via certain packets to the web interface that cause the interface to freeze.

Aug 3, 2005
7.5
CVE-2025-9970HIGH

Cleartext Storage of Sensitive Information in Memory vulnerability in ABB MConfig.This issue affects MConfig: through 1.4.9.21.

Oct 8, 2025
7.4
CVE-2023-5396HIGH

Server receiving a malformed message creates connection for a hostname that may cause a stack overflow resulting in possible remote code execution. See Honeywell Security Notification for recommendations on upgrading and versioning.

Apr 17, 2024
7.4
CVE-2023-5394HIGH

Server receiving a malformed message that where the GCL message hostname may be too large which may cause a stack overflow; resulting in possible remote code execution. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning.

Apr 11, 2024
7.4
CVE-2023-5393HIGH

Server receiving a malformed message that causes a disconnect to a hostname may causing a stack overflow resulting in possible remote code execution. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning.

Apr 11, 2024
7.4
CVE-2023-35134HIGH

Weintek Weincloud v0.13.6 could allow an attacker to reset a password with the corresponding account’s JWT token only.

Jul 19, 2023
7.4
CVE-2022-27048HIGH

A vulnerability has been discovered in Moxa MGate which allows an attacker to perform a man-in-the-middle (MITM) attack on the device. This affects MGate MB3170 Series Firmware Version 4.2 or lower. and MGate MB3270 Series Firmware Version 4.2 or lower. and MGate MB3280 Series Firmware Version 4.1 or lower. and MGate MB3480 Series Firmware Version 3.2 or lower.

Apr 15, 2022
7.4
CVE-2021-34599HIGH

Affected versions of CODESYS Git in Versions prior to V1.1.0.0 lack certificate validation in HTTPS handshakes. CODESYS Git does not implement certificate validation by default, so it does not verify that the server provides a valid and trusted HTTPS certificate. Since the certificate of the server to which the connection is made is not properly verified, the server connection is vulnerable to a man-in-the-middle attack.

Dec 1, 2021
7.4
CVE-2021-21004HIGH

In Phoenix Contact FL SWITCH SMCS series products in multiple versions an attacker may insert malicious code via LLDP frames into the web-based management which could then be executed by the client.

Jun 25, 2021
7.4
CVE-2018-4849HIGH

A vulnerability has been identified in Siveillance VMS Video for Android (All versions < V12.1a (2018 R1)), Siveillance VMS Video for iOS (All versions < V12.1a (2018 R1)). Improper certificate validation could allow an attacker in a privileged network position to read data from and write data to the encrypted communication channel between the app and a server. The security vulnerability could be exploited by an attacker in a privileged network position which allows intercepting the communication channel between the affected app and a server (such as Man-in-the-Middle). Furthermore, an attacker must be able to generate a certificate that results for the validation algorithm in a checksum identical to a trusted certificate. Successful exploitation requires no user interaction. The vulnerability could allow reading data from and writing data to the encrypted communication channel between the app and a server, impacting the communication's confidentiality and integrity. At the time of advisory publication no public exploitation of this security vulnerability was known. Siemens confirms the security vulnerability and provides mitigations to resolve the security issue.

May 3, 2018
7.4
CVE-2017-9941HIGH

A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker in a Man-in-the-Middle position between the SiPass integrated server and SiPass integrated clients to read or modify the network communication.

Aug 8, 2017
7.4
CVE-2017-6873HIGH

A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could allow an attacker to read and manipulate data in TLS sessions while performing a man-in-the-middle (MITM) attack on the integrated web server on port 443/tcp.

Aug 8, 2017
7.4
CVE-2017-6870HIGH

A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2). The existing TLS protocol implementation could allow an attacker to read and modify data within a TLS session while performing a Man-in-the-Middle (MitM) attack.

Aug 8, 2017
7.4
CVE-2017-2685HIGH

Siemens SINUMERIK Integrate Operate Clients between 2.0.3.00.016 (including) and 2.0.6 (excluding) and between 3.0.4.00.032 (including) and 3.0.6 (excluding) contain a vulnerability that could allow an attacker to read and manipulate data in TLS sessions while performing a man-in-the-middle (MITM) attack.

Mar 1, 2017
7.4
CVE-2026-2364HIGH

If a legitimate user confirms a self-update prompt or initiate an installation of a CODESYS Development System, a low privileged local attacker can gain elevated rights due to a TOCTOU vulnerability in the CODESYS installer.

Mar 10, 2026
7.3
CVE-2025-11918HIGH

Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the parsing of DOE files. Local attackers are able to exploit this issue to potentially execute arbitrary code on affected installations of Arena®. Exploiting the vulnerability requires opening a malicious DOE file.

Nov 14, 2025
7.3
CVE-2025-58320HIGH

Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.

Sep 11, 2025
7.3
CVE-2025-7405HIGH

Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote unauthenticated attacker to read or write the device values of the product and stop the operation of the programs, since MODBUS/TCP in the products does not have authentication features.

Sep 1, 2025
7.3
CVE-2025-47728HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

Jun 4, 2025
7.3
CVE-2025-47727HIGH

Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

Jun 4, 2025
7.3
CVE-2025-47726HIGH

Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

Jun 4, 2025
7.3
CVE-2025-47725HIGH

Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

Jun 4, 2025
7.3
CVE-2025-47724HIGH

Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

Jun 4, 2025
7.3
CVE-2024-9876HIGH

: Modification of Assumed-Immutable Data (MAID) vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC: through 1.1.4; ANC-L: through 1.1.4; ANC-mini: through 1.1.4.

Apr 30, 2025
7.3
CVE-2024-12672HIGH

A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.

Dec 19, 2024
7.3
CVE-2024-11364HIGH

Another “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to access a variable prior to it being initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.

Dec 19, 2024
7.3
CVE-2024-11157HIGH

A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.

Dec 19, 2024
7.3
CVE-2024-50376HIGH

A CWE-79 "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited remotely leveraging a rogue Wi-Fi access point with a malicious SSID.

Nov 26, 2024
7.3
CVE-2023-3662HIGH

In CODESYS Development System versions from 3.5.17.0 and prior to 3.5.19.20 a vulnerability allows for execution of binaries from the current working directory in the users context .

Aug 3, 2023
7.3
CVE-2023-3670HIGH

In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe directory permissions would allow an attacker with local access to the workstation to place potentially harmful and disguised scripts that could be executed by legitimate users.

Jul 28, 2023
7.3
CVE-2023-2637HIGH

Rockwell Automation's FactoryTalk System Services uses a hard-coded cryptographic key to generate administrator cookies.  Hard-coded cryptographic key may lead to privilege escalation.  This vulnerability may allow a local, authenticated non-admin user to generate an invalid administrator cookie giving them administrative privileges to the FactoryTalk Policy Manger database. This may allow the threat actor to make malicious changes to the database that will be deployed when a legitimate FactoryTalk Policy Manager user deploys a security policy model. User interaction is required for this vulnerability to be successfully exploited.

Jun 13, 2023
7.3
CVE-2023-2866HIGH

If an attacker can trick an authenticated user into loading a maliciously crafted .zip file onto Advantech WebAccess version 8.4.5, a web shell could be used to give the attacker full control of the SCADA server.

Jun 7, 2023
7.3
CVE-2019-6834HIGH

A CWE-502: Deserialization of Untrusted Data vulnerability exists which could allow an attacker to execute arbitrary code on the targeted system with SYSTEM privileges when placing a malicious user to be authenticated for this vulnerability to be successfully exploited. Affected Product: Schneider Electric Software Update (SESU) SUT Service component (V2.1.1 to V2.3.0)

Apr 13, 2022
7.3
CVE-2021-33540HIGH

In certain devices of the Phoenix Contact AXL F BK and IL BK product families an undocumented password protected FTP access to the root directory exists.

Jun 25, 2021
7.3
CVE-2021-29242HIGH

CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.

May 3, 2021
7.3
CVE-2020-12510HIGH

The default installation path of the TwinCAT XAR 3.1 software in all versions is underneath C:\TwinCAT. If the directory does not exist it and further subdirectories are created with permissions which allow every local user to modify the content. The default installation registers TcSysUI.exe for automatic execution upon log in of a user. If a less privileged user has a local account he or she can replace TcSysUI.exe. It will be executed automatically by another user during login. This is also true for users with administrative access. Consequently, a less privileged user can trick a higher privileged user into executing code he or she modified this way. By default Beckhoff’s IPCs are shipped with TwinCAT software installed this way and with just a single local user configured. Thus the vulnerability exists if further less privileged users have been added.

Nov 19, 2020
7.3
CVE-2020-12028HIGH

In all versions of FactoryTalk View SEA remote, an authenticated attacker may be able to utilize certain handlers to interact with the data on the remote endpoint since those handlers do not enforce appropriate permissions. Rockwell Automation recommends enabling built in security features found within FactoryTalk View SE. Users should follow guidance found in knowledge base articles 109056 and 1126943 to set up IPSec and/or HTTPs.

Jul 20, 2020
7.3
CVE-2020-8473HIGH

Insufficient folder permissions used by system functions in ABB System 800xA Base (version 6.1 and earlier) allow low privileged users to read, modify, add and delete system and application files. An authenticated attacker who successfully exploit the vulnerabilities could escalate his/her privileges, cause system functions to stop and to corrupt user applications.

Apr 29, 2020
7.3
CVE-2019-7227HIGH

In the ABB IDAL FTP server, an authenticated attacker can traverse to arbitrary directories on the hard disk with "CWD ../" and then use the FTP server functionality to download and upload files. An unauthenticated attacker can take advantage of the hardcoded or default credential pair exor/exor to become an authenticated attacker.

Jun 27, 2019
7.3
CVE-2015-1014HIGH

A successful exploit of these vulnerabilities requires the local user to load a crafted DLL file in the system directory on servers running Schneider Electric OFS v3.5 with version v7.40 of SCADA Expert Vijeo Citect/CitectSCADA, OFS v3.5 with version v7.30 of Vijeo Citect/CitectSCADA, and OFS v3.5 with version v7.20 of Vijeo Citect/CitectSCADA.. If the application attempts to open that file, the application could crash or allow the attacker to execute arbitrary code. Schneider Electric recommends vulnerable users upgrade the OFS to V3.5 and install the latest service pack (SP 6 or newer) for their associated version.

Mar 25, 2019
7.3
CVE-2016-8380HIGH

The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.

Apr 5, 2018
7.3
CVE-2016-8371HIGH

The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism is enabled.

Apr 5, 2018
7.3
CVE-2016-8366HIGH

Webvisit in Phoenix Contact ILC PLCs offers a password macro to protect HMI pages on the PLC against casual or coincidental opening of HMI pages by the user. The password macro can be configured in a way that the password is stored and transferred in clear text.

Apr 5, 2018
7.3
CVE-2017-9956HIGH

An authentication bypass vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system contains a hard-coded valid session. An attacker can use that session ID as part of the HTTP cookie of a web request, resulting in authentication bypass

Sep 26, 2017
7.3
CVE-2017-7965HIGH

A buffer overflow vulnerability exists in Programming Software executable AlTracePrint.exe, in Schneider Electric's SoMachine HVAC v2.1.0 for Modicon M171/M172 Controller.

Jun 7, 2017
7.3
CVE-2017-5155HIGH

An issue was discovered in Schneider Electric Wonderware Historian 2014 R2 SP1 P01 and earlier. Wonderware Historian creates logins with default passwords, which can allow a malicious entity to compromise Historian databases. In some installation scenarios, resources beyond those created by Wonderware Historian may be compromised as well.

Feb 13, 2017
7.3
CVE-2016-9363HIGH

An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPort 5100A Series & NPort P5150A versions prior to 1.3, NPort 5200A Series versions prior to 1.3, NPort 5150AI-M12 Series versions prior to 1.2, NPort 5250AI-M12 Series versions prior to 1.2, NPort 5450AI-M12 Series versions prior to 1.2, NPort 5600-8-DT Series versions prior to 2.4, NPort 5600-8-DTL Series versions prior to 2.4, NPort 6x50 Series versions prior to 1.13.11, NPort IA5450A versions prior to v1.4. Buffer overflow vulnerability may allow an unauthenticated attacker to remotely execute arbitrary code.

Feb 13, 2017
7.3
CVE-2016-9334HIGH

An issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 controller 1763-L16AWA, Series A and B, Version 14.000 and prior versions; 1763-L16BBB, Series A and B, Version 14.000 and prior versions; 1763-L16BWA, Series A and B, Version 14.000 and prior versions; and 1763-L16DWD, Series A and B, Version 14.000 and prior versions. User credentials are sent to the web server in clear text, which may allow an attacker to discover the credentials if they are able to observe traffic between the web browser and the server.

Feb 13, 2017
7.3
CVE-2016-9156HIGH

A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to upload, download, or delete files in certain parts of the file system by sending specially crafted packets to port 19235/TCP.

Dec 5, 2016
7.3
CVE-2016-4860HIGH

Yokogawa STARDOM FCN/FCJ controller R1.01 through R4.01 does not require authentication for Logic Designer connections, which allows remote attackers to reconfigure the device or cause a denial of service via a (1) stop application program, (2) change value, or (3) modify application command.

Sep 19, 2016
7.3
CVE-2016-5645HIGH

Rockwell Automation MicroLogix 1400 PLC 1766-L32BWA, 1766-L32AWA, 1766-L32BXB, 1766-L32BWAA, 1766-L32AWAA, and 1766-L32BXBA devices have a hardcoded SNMP community, which makes it easier for remote attackers to load arbitrary firmware updates by leveraging knowledge of this community.

Aug 24, 2016
7.3
CVE-2016-4531HIGH

Rockwell Automation FactoryTalk EnergyMetrix before 2.20.00 does not invalidate credentials upon a logout action, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

Jul 28, 2016
7.3
CVE-2016-4529HIGH

An unspecified ActiveX control in Schneider Electric SoMachine HVAC Programming Software for M171/M172 Controllers before 2.1.0 allows remote attackers to execute arbitrary code via unknown vectors, related to the INTERFACESAFE_FOR_UNTRUSTED_CALLER (aka safe for scripting) flag.

Jul 15, 2016
7.3
CVE-2009-1152HIGH

Siemens Gigaset SE461 WiMAX router 1.5-BL024.9.6401, and possibly other versions, allows remote attackers to cause a denial of service (device restart and loss of configuration) by connecting to TCP port 53, then closing the connection.

Mar 26, 2009
7.3
CVE-2026-2670HIGH

A vulnerability was identified in Advantech WISE-6610 1.2.1_20251110. Affected is an unknown function of the file /cgi-bin/luci/admin/openvpn_apply of the component Background Management. Such manipulation of the argument delete_file leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Feb 18, 2026
7.2
CVE-2025-34239HIGH

Advantech WebAccess/VPN versions prior to 1.1.5 contain a command injection vulnerability in AppManagementController.appUpgradeAction() that allows an authenticated system administrator to execute arbitrary commands as the web server user (www-data) by supplying a crafted uploaded filename.

Nov 6, 2025
7.2
CVE-2022-50595HIGH

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘ztp_search_value’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for remote code execution with administrator privileges.

Nov 6, 2025
7.2
CVE-2022-50592HIGH

Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘getInventoryReportData’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for remote code execution with administrator privileges.

Nov 6, 2025
7.2
CVE-2025-10207HIGH

Improper Validation of Specified Type of Input vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5.

Sep 18, 2025
7.2
CVE-2024-48851HIGH

Improper Validation of Specified Type of Input vulnerability in ABB FLXEON.A remote code execution is possible due to an improper input validation. This issue affects FLXEON: through 9.3.5.

Sep 18, 2025
7.2
CVE-2024-9138HIGH

Moxa’s cellular routers, secure routers, and network security appliances are affected by a high-severity vulnerability, CVE-2024-9138. This vulnerability involves hard-coded credentials, enabling an authenticated user to escalate privileges and gain root-level access to the system, posing a significant security risk.

Jan 3, 2025
7.2
CVE-2024-50369HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "multiple_ssid_htm" API which are not properly sanitized before being concatenated to OS level commands.

Nov 26, 2024
7.2
CVE-2024-50368HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "basic_htm" API which are not properly sanitized before being concatenated to OS level commands.

Nov 26, 2024
7.2
CVE-2024-50367HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "sta_log_htm" API which are not properly sanitized before being concatenated to OS level commands.

Nov 26, 2024
7.2
CVE-2024-50366HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "applications_apply" API which are not properly sanitized before being concatenated to OS level commands.

Nov 26, 2024
7.2
CVE-2024-50365HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "lan_apply" API which are not properly sanitized before being concatenated to OS level commands.

Nov 26, 2024
7.2
CVE-2024-50364HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "export_log" API which are not properly sanitized before being concatenated to OS level commands.

Nov 26, 2024
7.2
CVE-2024-50363HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "mp_apply" API which are not properly sanitized before being concatenated to OS level commands.

Nov 26, 2024
7.2
CVE-2024-50362HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "connection_profile_apply" API which are not properly sanitized before being concatenated to OS level commands.

Nov 26, 2024
7.2
CVE-2024-50361HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "certificate_file_remove" API which are not properly sanitized before being concatenated to OS level commands.

Nov 26, 2024
7.2
CVE-2024-50360HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "snmp_apply" API which are not properly sanitized before being concatenated to OS level commands.

Nov 26, 2024
7.2
CVE-2024-50359HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "scan_ap" API which are not properly sanitized before being concatenated to OS level commands.

Nov 26, 2024
7.2
CVE-2024-50358HIGH

A CWE-15 "External Control of System or Configuration Setting" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can be exploited by authenticated users by restoring a tampered configuration backup.

Nov 26, 2024
7.2
CVE-2021-22280HIGH

Improper DLL loading algorithms in B&R Automation Studio versions >=4.0 and <4.12 may allow an authenticated local attacker to execute code in the context of the product.

May 14, 2024
7.2
CVE-2023-37864HIGH

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may use an a special SNMP request to gain full access to the device.

Aug 9, 2023
7.2
CVE-2023-37863HIGH

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may use an a special SNMP request to gain full access to the device.

Aug 9, 2023
7.2
CVE-2023-37859HIGH

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 the SNMP daemon is running with root privileges allowing a remote attacker with knowledge of the SNMPv2 r/w community string to execute system commands as root.

Aug 9, 2023
7.2
CVE-2023-37362HIGH

Weintek Weincloud v0.13.6 could allow an attacker to abuse the registration functionality to login with testing credentials to the official website.

Jul 19, 2023
7.2
CVE-2023-32628HIGH

In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to modify the file extension of a certificate file to ASP when uploading it, which can lead to remote code execution.

Jun 6, 2023
7.2
CVE-2023-32540HIGH

In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file in the operating system (including system files), inject code into an XLS file, and modify the file extension, which could lead to arbitrary code execution.

Jun 6, 2023
7.2
CVE-2023-22450HIGH

In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to upload an ASP script file to a webserver when logged in as manager user, which can lead to arbitrary code execution.

Jun 6, 2023
7.2
CVE-2023-0636HIGH

Improper Input Validation vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS Series, Linux (2CQG100102R2021, 2CQG100104R2021, 2CQG100105R2021, 2CQG100106R2021, 2CQG100110R2021, 2CQG100112R2021, 2CQG100103R2021, 2CQG100107R2021, 2CQG100108R2021, 2CQG100109R2021, 2CQG100111R2021, 2CQG100113R2021 modules), ABB Ltd. MATRIX Series on MATRIX Series, Linux (2CQG100102R1021, 2CQG100103R1021, 2CQG100104R1021, 2CQG100105R1021, 2CQG100106R1021 modules) allows Command Injection.This issue affects ASPECT®-Enterprise: from 3.0;0 before 3.07.0; NEXUS Series: from 3.0;0 before 3.07.0; MATRIX Series: from 3.0;0 before 3.07.1.

Jun 5, 2023
7.2
CVE-2022-42140HIGH

Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Command Injection via lform/net_diagnose.

Dec 14, 2022
7.2
CVE-2020-16244HIGH

GE Digital APM Classic, Versions 4.4 and prior. Salt is not used for hash calculation of passwords, making it possible to decrypt passwords. This design flaw, along with the IDOR vulnerability, puts the entire platform at high risk because an authenticated user can retrieve all user account data and then retrieve the actual passwords.

Sep 23, 2020
7.2
CVE-2020-6090HIGH

An exploitable code execution vulnerability exists in the Web-Based Management (WBM) functionality of WAGO PFC 200 03.03.10(15). A specially crafted series of HTTP requests can cause code execution resulting in remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

Jun 11, 2020
7.2
CVE-2020-6978HIGH

In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable due to the usage of old jQuery libraries.

Mar 24, 2020
7.2
CVE-2019-5157HIGH

An exploitable command injection vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 Firmware versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). An attacker can inject OS commands into the TimeoutUnconfirmed parameter value contained in the Firmware Update command.

Mar 11, 2020
7.2
CVE-2019-5156HIGH

An exploitable command injection vulnerability exists in the cloud connectivity functionality of WAGO PFC200 versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). An attacker can inject operating system commands into the TimeoutPrepared parameter value contained in the firmware update command.

Mar 11, 2020
7.2
CVE-2019-5155HIGH

An exploitable command injection vulnerability exists in the cloud connectivity feature of WAGO PFC200. An attacker can inject operating system commands into any of the parameter values contained in the firmware update command. This affects WAGO PFC200 Firmware version 03.02.02(14), version 03.01.07(13), and version 03.00.39(12)

Mar 11, 2020
7.2
CVE-2019-5165HIGH

An exploitable authentication bypass vulnerability exists in the hostname processing of the Moxa AWK-3131A firmware version 1.13. A specially configured device hostname can cause the device to interpret select remote traffic as local traffic, resulting in a bypass of web authentication. An attacker can send authenticated SNMP requests to trigger this vulnerability.

Feb 25, 2020
7.2
CVE-2019-5142HIGH

An exploitable command injection vulnerability exists in the hostname functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted entry to network configuration information can cause execution of arbitrary system commands, resulting in full control of the device. An attacker can send various authenticated requests to trigger this vulnerability.

Feb 25, 2020
7.2
CVE-2019-10969HIGH

Moxa EDR 810, all versions 5.1 and prior, allows an authenticated attacker to abuse the ping feature to execute unauthorized commands on the router, which may allow an attacker to perform remote code execution.

Oct 8, 2019
7.2
CVE-2017-9970HIGH

A remote code execution vulnerability exists in Schneider Electric's StruxureOn Gateway versions 1.1.3 and prior. Uploading a zip which contains carefully crafted metadata allows for the file to be uploaded to any directory on the host machine information which could lead to remote code execution.

Feb 12, 2018
7.2
CVE-2017-5170HIGH

An Uncontrolled Search Path Element issue was discovered in Moxa SoftNVR-IA Live Viewer, Version 3.30.3122 and prior versions. An uncontrolled search path element (DLL Hijacking) vulnerability has been identified. To exploit this vulnerability, an attacker could rename a malicious DLL to meet the criteria of the application, and the application would not verify that the DLL is correct. The attacker needs to have administrative access to the default install location in order to plant the insecure DLL. Once loaded by the application, the DLL could run malicious code at the privilege level of the application.

Jan 18, 2018
7.2
CVE-2016-2281HIGH

Untrusted search path vulnerability in ABB Panel Builder 800 5.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory.

Mar 18, 2016
7.2
CVE-2016-2278HIGH

Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows remote authenticated administrators to execute arbitrary OS commands by defeating an msh (aka Minimal Shell) protection mechanism.

Mar 2, 2016
7.2
CVE-2014-8388HIGH

Stack-based buffer overflow in Advantech WebAccess, formerly BroadWin WebAccess, before 8.0 allows remote attackers to execute arbitrary code via a crafted ip_address parameter in an HTML document.

Nov 21, 2014
7.2
CVE-2013-4943HIGH

The client application in Siemens COMOS before 9.1 Update 458, 9.2 before 9.2.0.6.37, and 10.0 before 10.0.3.0.19 allows local users to gain privileges and bypass intended database-operation restrictions by leveraging COMOS project access.

Aug 9, 2013
7.2
CVE-2011-3330HIGH

Buffer overflow in the UnitelWay Windows Device Driver, as used in Schneider Electric Unity Pro 6 and earlier, OPC Factory Server 3.34, Vijeo Citect 7.20 and earlier, Telemecanique Driver Pack 2.6 and earlier, Monitor Pro 7.6 and earlier, and PL7 Pro 4.5 and earlier, allows local users, and possibly remote attackers, to execute arbitrary code via an unspecified system parameter.

Nov 4, 2011
7.2
CVE-2003-1528HIGH

nsr_shutdown in Fujitsu Siemens NetWorker 6.0 allows local users to overwrite arbitrary files via a symlink attack on the nsrsh[PID] temporary file.

Dec 31, 2003
7.2
CVE-2025-3465HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB CoreSense™ HM, ABB CoreSense™ M10.This issue affects CoreSense™ HM: through 2.3.1; CoreSense™ M10: through 1.4.1.12.

Oct 20, 2025
7.1
CVE-2025-5023HIGH

Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Corporation photovoltaic system monitor “EcoGuideTAB” PV-DR004J all versions and PV-DR004JA all versions allows an attacker within the Wi-Fi communication range between the units of the product (measurement unit and display unit) to disclose information such as generated power and electricity sold back to the grid stored in the product, tamper with or destroy stored or configured information in the product, or cause a Denial-of-Service (DoS) condition on the product, by using hardcoded user ID and password common to the product series obtained by exploiting CVE-2025-5022. The affected products discontinued in 2015, support ended in 2020.

Jul 10, 2025
7.1
CVE-2025-3395HIGH

Incorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vulnerability in ABB Automation Builder.This issue affects Automation Builder: through 2.8.0.

Apr 30, 2025
7.1
CVE-2024-48846HIGH

Cross Site Request Forgery vulnerabilities where found providing a potiential for exposing sensitive information or changing system settings.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

Dec 5, 2024
7.1
CVE-2023-43815HIGH

A buffer overflow vulnerability exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when parsing the wScreenDESCTextLen field of a DPS file. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DPS file to achieve code execution.

Jan 18, 2024
7.1
CVE-2023-0864HIGH

Cleartext Transmission of Sensitive Information vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC wallbox (CE) (Terra AC MID), ABB Terra AC wallbox (CE) Terra AC Juno CE, ABB Terra AC wallbox (CE) Terra AC PTB, ABB Terra AC wallbox (CE) Symbiosis, ABB Terra AC wallbox (JP).This issue affects Terra AC wallbox (UL40/80A): from 1.0;0 through 1.5.5; Terra AC wallbox (UL32A) : from 1.0;0 through 1.6.5; Terra AC wallbox (CE) (Terra AC MID): from 1.0;0 through 1.6.5; Terra AC wallbox (CE) Terra AC Juno CE: from 1.0;0 through 1.6.5; Terra AC wallbox (CE) Terra AC PTB : from 1.0;0 through 1.5.25; Terra AC wallbox (CE) Symbiosis: from 1.0;0 through 1.2.7; Terra AC wallbox (JP): from 1.0;0 through 1.6.5.

May 17, 2023
7.1
CVE-2023-2444HIGH

A cross site request forgery vulnerability exists in Rockwell Automation's FactoryTalk Vantagepoint. This vulnerability can be exploited in two ways. If an attacker sends a malicious link to a computer that is on the same domain as the FactoryTalk Vantagepoint server and a user clicks the link, the attacker could impersonate the legitimate user and send requests to the affected product.  Additionally, if an attacker sends an untrusted link to a computer that is not on the same domain as the server and a user opens the FactoryTalk Vantagepoint website, enters credentials for the FactoryTalk Vantagepoint server, and clicks on the malicious link a cross site request forgery attack would be successful as well.

May 11, 2023
7.1
CVE-2023-1134HIGH

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a path traversal vulnerability, which could allow an attacker to read local files, disclose plaintext credentials, and escalate privileges.

Mar 27, 2023
7.1
CVE-2022-46670HIGH

Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institute of Technology that the MicroLogix 1100 and 1400 controllers contain a vulnerability that may give an attacker the ability to accomplish remote code execution.  The vulnerability is an unauthenticated stored cross-site scripting vulnerability in the embedded webserver. The payload is transferred to the controller over SNMP and is rendered on the homepage of the embedded website.

Dec 16, 2022
7.1
CVE-2022-0988HIGH

Delta Electronics DIAEnergie (Version 1.7.5 and prior) is vulnerable to cleartext transmission as the web application runs by default on HTTP. This could allow an attacker to remotely read transmitted information between the client and product.

Mar 25, 2022
7.1
CVE-2021-20593HIGH

Incorrect Implementation of Authentication Algorithm in Mitsubishi Electric Air Conditioning System/Centralized Controllers (G-50A Ver.2.50 to Ver. 3.35, GB-50A Ver.2.50 to Ver. 3.35, AG-150A-A Ver.3.20 and prior, AG-150A-J Ver.3.20 and prior, GB-50ADA-A Ver.3.20 and prior, GB-50ADA-J Ver.3.20 and prior, EB-50GU-A Ver 7.09 and prior, EB-50GU-J Ver 7.09 and prior, AE-200A Ver 7.93 and prior, AE-200E Ver 7.93 and prior, AE-50A Ver 7.93 and prior, AE-50E Ver 7.93 and prior, EW-50A Ver 7.93 and prior, EW-50E Ver 7.93 and prior, TE-200A Ver 7.93 and prior, TE-50A Ver 7.93 and prior, TW-50A Ver 7.93 and prior, CMS-RMD-J Ver.1.30 and prior) and Air Conditioning System/Expansion Controllers (PAC-YG50ECA Ver.2.20 and prior) allows a remote authenticated attacker to impersonate administrators to disclose configuration information of the air conditioning system and tamper information (e.g. operation information and configuration of air conditioning system) by exploiting this vulnerability.

Jul 13, 2021
7.1
CVE-2020-12010HIGH

Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow an authenticated user to use a specially crafted file to delete files outside the application’s control.

May 8, 2020
7.1
CVE-2019-5139HIGH

An exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities of the Moxa AWK-3131A firmware version 1.13. The device operating system contains an undocumented encryption password, allowing for the creation of custom diagnostic scripts.

Feb 25, 2020
7.1
CVE-2019-18998HIGH

Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0 enables full access to directly referenced objects. An attacker with knowledge of a resource's URL can access the resource directly.

Feb 17, 2020
7.1
CVE-2019-18996HIGH

Path settings in HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier accept DLLs outside of the program directory, potentially allowing an attacker with access to the local file system the execution of code in the application’s context.

Dec 18, 2019
7.1
CVE-2017-9966HIGH

A privilege escalation vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2.0 and prior. By replacing certain files, an unauthorized user can obtain system privileges and the inserted code would execute at an elevated privilege level.

Jan 2, 2018
7.1
CVE-2017-7929HIGH

An Absolute Path Traversal issue was discovered in Advantech WebAccess Version 8.1 and prior. The absolute path traversal vulnerability has been identified, which may allow an attacker to traverse the file system to access restricted files or directories.

May 6, 2017
7.1
CVE-2014-5410HIGH

The DNP3 feature on Rockwell Automation Allen-Bradley MicroLogix 1400 1766-Lxxxxx A FRN controllers 7 and earlier and 1400 1766-Lxxxxx B FRN controllers before 15.001 allows remote attackers to cause a denial of service (process disruption) via malformed packets over (1) an Ethernet network or (2) a serial line.

Oct 3, 2014
7.1
CVE-2014-5074HIGH

Siemens SIMATIC S7-1500 CPU devices with firmware before 1.6 allow remote attackers to cause a denial of service (device restart and STOP transition) via crafted TCP packets.

Aug 17, 2014
7.1
CVE-2014-0757HIGH

Smart Software Solutions (3S) CoDeSys Runtime Toolkit before 2.4.7.44 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors.

Jan 31, 2014
7.1
CVE-2012-3039HIGH

Moxa OnCell Gateway G3111, G3151, G3211, and G3251 devices with firmware before 1.4 do not use a sufficient source of entropy for SSH and SSL keys, which makes it easier for remote attackers to obtain access by leveraging knowledge of a key from a product installation elsewhere.

Aug 9, 2013
7.1
CVE-2012-4695HIGH

LogReceiver.exe in Rockwell Automation RSLinx Enterprise CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 allows remote attackers to cause a denial of service (service outage) via a zero-byte UDP packet that is not properly handled by Logger.dll.

Apr 18, 2013
7.1
CVE-2012-4690HIGH

Rockwell Automation Allen-Bradley MicroLogix controller 1100, 1200, 1400, and 1500; SLC 500 controller platform; and PLC-5 controller platform, when Static status is not enabled, allow remote attackers to cause a denial of service via messages that trigger modification of status bits.

Dec 8, 2012
7.1
CVE-2011-4877HIGH

HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime, when Transfer Mode is enabled, allows remote attackers to cause a denial of service (application crash) by sending crafted data over TCP.

Feb 3, 2012
7.1
CVE-2024-48842HIGH

Use of Hard-coded Credentials vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5 and newer versions

Sep 17, 2025
7.0
CVE-2024-8300HIGH

Dead Code vulnerability in Mitsubishi Electric GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, Mitsubishi Electric Iconics Digital Solutions GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, Mitsubishi Electric ICONICS Suite Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, and Mitsubishi Electric Iconics Digital Solutions ICONICS Suite Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3 allows a local authenticated attacker to execute a malicious code by tampering with a specially crafted DLL. This could lead to disclose, tamper with, destroy, or delete information in the affected products, or cause a denial of service (DoS) condition on the products.

Nov 28, 2024
7.0
CVE-2024-1182HIGH

Uncontrolled Search Path Element vulnerability in Mitsubishi Electric Iconics Digital Solutions GENESIS64 all versions, Mitsubishi Electric GENESIS64 all versions, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite all versions, Mitsubishi Electric ICONICS Suite all versions, Mitsubishi Electric Iconics Digital Solutions GENESIS32 all versions, Mitsubishi Electric GENESIS32 all versions, and Mitsubishi Electric MC Works64 all versions allows a local attacker to execute a malicious code by storing a specially crafted DLL in a specific folder when GENESIS64, ICONICS Suite, GENESIS32, and MC Works64 are installed with the Pager agent in the alarm multi-agent notification feature.

Jul 4, 2024
7.0
CVE-2023-3322HIGH

A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted programs to exploit the vulnerabilities by allowing them to run on the zenon installed hosts. This issue affects ABB Ability™ zenon: from 11 build through 11 build 106404.

Jul 24, 2023
7.0
CVE-2023-3321HIGH

A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted programs to exploit the vulnerabilities by allowing them to run on the zenon installed hosts. This issue affects ABB Ability™ zenon: from 11 build through 11 build 106404.

Jul 24, 2023
7.0
CVE-2023-29031HIGH

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User interaction, such as a phishing attack, is required for successful exploitation of this vulnerability.

May 11, 2023
7.0
CVE-2023-29030HIGH

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User interaction, such as a phishing attack, is required for successful exploitation of this vulnerability.

May 11, 2023
7.0
CVE-2023-29023HIGH

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User interaction, such as a phishing attack, is required for successful exploitation of this vulnerability.

May 11, 2023
7.0
CVE-2019-5186HIGH

An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200. An attacker can send a specially crafted packet to trigger the parsing of this cache file.At 0x1eb9c the extracted interface element name from the xml file is used as an argument to /etc/config-tools/config_interfaces interface=<contents of interface element> using sprintf(). The destination buffer sp+0x40 is overflowed with the call to sprintf() for any interface values that are greater than 512-len("/etc/config-tools/config_interfaces interface=") in length. Later, at 0x1ea08 strcpy() is used to copy the contents of the stack buffer that was overflowed sp+0x40 into sp+0x440. The buffer sp+0x440 is immediately adjacent to sp+0x40 on the stack. Therefore, there is no NULL termination on the buffer sp+0x40 since it overflowed into sp+0x440. The strcpy() will result in invalid memory access. An interface value of length 0x3c4 will cause the service to crash.

Mar 23, 2020
7.0
CVE-2019-5185HIGH

An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200. An attacker can send a specially crafted packet to trigger the parsing of this cache file. At 0x1ea28 the extracted state value from the xml file is used as an argument to /etc/config-tools/config_interfaces interface=X1 state=<contents of state node> using sprintf(). The destination buffer sp+0x40 is overflowed with the call to sprintf() for any state values that are greater than 512-len("/etc/config-tools/config_interfaces interface=X1 state=") in length. Later, at 0x1ea08 strcpy() is used to copy the contents of the stack buffer that was overflowed sp+0x40 into sp+0x440. The buffer sp+0x440 is immediately adjacent to sp+0x40 on the stack. Therefore, there is no NULL termination on the buffer sp+0x40 since it overflowed into sp+0x440. The strcpy() will result in invalid memory access. An state value of length 0x3c9 will cause the service to crash.

Mar 23, 2020
7.0
CVE-2019-11486HIGH

The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c in the Linux kernel before 5.0.8 has multiple race conditions.

Apr 23, 2019
7.0
CVE-2017-5176HIGH

A DLL Hijack issue was discovered in Rockwell Automation Connected Components Workbench (CCW). The following versions are affected: Connected Components Workbench - Developer Edition, v9.01.00 and earlier: 9328-CCWDEVENE, 9328-CCWDEVZHE, 9328-CCWDEVFRE, 9328-CCWDEVITE, 9328-CCWDEVDEE, 9328-CCWDEVESE, and 9328-CCWDEVPTE; and Connected Components Workbench - Free Standard Edition (All Supported Languages), v9.01.00 and earlier. Certain DLLs included with versions of CCW software can be potentially hijacked to allow an attacker to gain rights to a victim's affected personal computer. Such access rights can be at the same or potentially higher level of privileges as the compromised user account, including and up to computer administrator privileges.

May 19, 2017
7.0
CVE-2016-9351HIGH

An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The directory traversal/file upload error allows an attacker to upload and unpack a zip file.

Feb 13, 2017
7.0
CVE-2016-8354HIGH

An issue was discovered in Schneider Electric Unity PRO prior to V11.1. Unity projects can be compiled as x86 instructions and loaded onto the PLC Simulator delivered with Unity PRO. These x86 instructions are subsequently executed directly by the simulator. A specially crafted patched Unity project file can make the simulator execute malicious code by redirecting the control flow of these instructions.

Feb 13, 2017
7.0
CVE ID ⇅Severity ↓CVSS ⇅DescriptionPublished ⇅
CVE-2015-7937HIGH
10.0
Stack-based buffer overflow in the GoAhead Web Server on Schneider Electric Modicon M340 PLC BMXNOx …Dec 21, 2015›
CVE-2015-6476HIGH
10.0
Advantech EKI-122x-BE devices with firmware before 1.65, EKI-132x devices with firmware before 1.98,…Nov 7, 2015›
CVE-2015-6459HIGH
10.0
Absolute path traversal vulnerability in the download feature in FileDownloadServlet in GE Digital E…Sep 18, 2015›
CVE-2014-9208HIGH
10.0
Multiple stack-based buffer overflows in unspecified DLL files in Advantech WebAccess before 8.0.1 a…Sep 11, 2015›
CVE-2015-0984HIGH
10.0
Directory traversal vulnerability in the FTP server on Honeywell Excel Web XL1000C50 52 I/O, XL1000C…Mar 31, 2015›
CVE-2014-8385HIGH
10.0
Buffer overflow on Advantech EKI-1200 gateways with firmware before 1.63 allows remote attackers to …Feb 13, 2015›
CVE-2015-1449HIGH
10.0
Buffer overflow in the integrated web server on Siemens Ruggedcom WIN51xx devices with firmware befo…Feb 2, 2015›
CVE-2015-1448HIGH
10.0
The integrated management service on Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.46…Feb 2, 2015›
CVE-2014-9198HIGH
10.0
The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 …Jan 27, 2015›
CVE-2014-9197HIGH
10.0
The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.ja…Jan 27, 2015›
CVE-2014-9195HIGH
10.0
Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote attackers …Jan 17, 2015›
CVE-2014-9190HIGH
10.0
Stack-based buffer overflow in Schneider Electric Wonderware InTouch Access Anywhere Server 10.6 and…Jan 10, 2015›
CVE-2014-9188HIGH
10.0
Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 all…Dec 27, 2014›
CVE-2014-8511HIGH
10.0
Buffer overflow in an ActiveX control in Atx45.ocx in Schneider Electric ProClima before 6.1.7 allow…Dec 27, 2014›
CVE-2014-8551HIGH
10.0
The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Updat…Nov 26, 2014›
CVE-2014-0754HIGH
10.0
Directory traversal vulnerability in SchneiderWEB on Schneider Electric Modicon PLC Ethernet modules…Oct 3, 2014›
CVE-2013-6920HIGH
10.0
Siemens SINAMICS S/G controllers with firmware before 4.6.11 do not require authentication for FTP a…Dec 7, 2013›
CVE-2013-5944HIGH
10.0
The integrated web server on Siemens SCALANCE X-200 switches with firmware before 4.5.0 and X-200IRT…Oct 3, 2013›
CVE-2013-4652HIGH
10.0
Unspecified vulnerability in the command-line management interface on Siemens Scalance W7xx devices …Aug 1, 2013›
CVE-2013-4781HIGH
10.0
core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Co…Jul 18, 2013›
CVE-2013-2781HIGH
10.0
Use-after-free vulnerability in the server application in 3S CODESYS Gateway 2.3.9.27 allows remote …May 23, 2013›
CVE-2012-4715HIGH
10.0
Buffer overflow in LogReceiver.exe in Rockwell Automation RSLinx Enterprise CPR9, CPR9-SR1, CPR9-SR2…Apr 18, 2013›
CVE-2013-2762HIGH
10.0
The Schneider Electric Magelis XBT HMI controller has a default password for authentication of confi…Apr 4, 2013›
CVE-2013-0659HIGH
10.0
The debugging feature on the Siemens CP 1604 and CP 1616 interface cards with firmware before 2.5.2 …Apr 1, 2013›
CVE-2012-4708HIGH
10.0
Stack-based buffer overflow in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to …Feb 24, 2013›
CVE-2012-4707HIGH
10.0
3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vect…Feb 24, 2013›
CVE-2012-4705HIGH
10.0
Directory traversal vulnerability in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attacke…Feb 24, 2013›
CVE-2012-4704HIGH
10.0
Array index error in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute ar…Feb 24, 2013›
CVE-2013-0658HIGH
10.0
Heap-based buffer overflow in RFManagerService.exe in Schneider Electric Accutech Manager 2.00.1 and…Feb 15, 2013›
CVE-2012-6437HIGH
10.0
The device does not properly authenticate users and the potential exists for a remote user to upload…Jan 24, 2013›
CVE-2013-0657HIGH
10.0
Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA System (IGSS) 10 and e…Jan 21, 2013›
CVE-2012-5409HIGH
10.0
AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle…Nov 1, 2012›
CVE-2012-4879HIGH
10.0
The Linux Console on the WAGO I/O System 758 model 758-870, 758-874, 758-875, and 758-876 Industrial…Sep 7, 2012›
CVE-2012-3013HIGH
10.0
WAGO I/O System 758 model 758-870, 758-874, 758-875, and 758-876 Industrial PC (IPC) devices have de…Sep 7, 2012›
CVE-2012-1799HIGH
10.0
The web server on the Siemens Scalance S Security Module firewall S602 V2, S612 V2, and S613 V2 with…Apr 18, 2012›
CVE-2012-0245HIGH
10.0
Multiple stack-based buffer overflows in RobNetScanHost.exe in ABB Robot Communications Runtime befo…Mar 9, 2012›
CVE-2012-0243HIGH
10.0
Buffer overflow in an ActiveX control in bwocxrun.ocx in Advantech/BroadWin WebAccess before 7.0 all…Feb 21, 2012›
CVE-2012-0242HIGH
10.0
Format string vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to ex…Feb 21, 2012›
CVE-2012-0240HIGH
10.0
GbScriptAddUp.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authenticatio…Feb 21, 2012›
CVE-2012-0238HIGH
10.0
Stack-based buffer overflow in opcImg.asp in Advantech/BroadWin WebAccess before 7.0 allows remote a…Feb 21, 2012›
CVE-2011-4526HIGH
10.0
Buffer overflow in an ActiveX control in Advantech/BroadWin WebAccess before 7.0 might allow remote …Feb 21, 2012›
CVE-2011-4525HIGH
10.0
Advantech/BroadWin WebAccess before 7.0 allows remote attackers to trigger the extraction of arbitra…Feb 21, 2012›
CVE-2011-4524HIGH
10.0
Buffer overflow in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitr…Feb 21, 2012›
CVE-2011-1914HIGH
10.0
Buffer overflow in the Advantech ADAM OLE for Process Control (OPC) Server ActiveX control in ADAM O…Feb 21, 2012›
CVE-2011-4041HIGH
10.0
webvrpcs.exe in Advantech/BroadWin WebAccess allows remote attackers to execute arbitrary code or ob…Feb 6, 2012›
CVE-2011-4514HIGH
10.0
The TELNET daemon in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); …Feb 3, 2012›
CVE-2011-4513HIGH
10.0
Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfo…Feb 3, 2012›
CVE-2011-4509HIGH
10.0
The HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal);…Feb 3, 2012›
CVE-2011-5007HIGH
10.0
Stack-based buffer overflow in the CmpWebServer component in 3S CoDeSys 3.4 SP4 Patch 2 and earlier,…Dec 25, 2011›
CVE-2011-4861HIGH
10.0
The modbus_125_handler function in the Schneider Electric Quantum Ethernet Module on the NOE 771 dev…Dec 17, 2011›
CVE-2011-4860HIGH
10.0
The ComputePassword function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device…Dec 17, 2011›
CVE-2011-4859HIGH
10.0
The Schneider Electric Quantum Ethernet Module, as used in the Quantum 140NOE771* and 140CPU65* modu…Dec 17, 2011›
CVE-2010-4742HIGH
10.0
Stack-based buffer overflow in a certain ActiveX control in MediaDBPlayback.DLL 2.2.0.5 in the Moxa …Feb 18, 2011›
CVE-2011-0488HIGH
10.0
Stack-based buffer overflow in NTWebServer.exe in the test web service in InduSoft NTWebServer, as d…Jan 18, 2011›
CVE-2010-2965HIGH
10.0
The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockw…Aug 5, 2010›
CVE-2009-3739HIGH
10.0
Multiple unspecified vulnerabilities on the Rockwell Automation AB Micrologix 1100 and 1400 controll…Jan 19, 2010›
CVE-2008-6993HIGH
10.0
Siemens Gigaset WLAN Camera 1.27 has an insecure default password, which allows remote attackers to …Aug 19, 2009›
CVE-2008-6916HIGH
10.0
Siemens SpeedStream 5200 with NetPort Software 1.1 allows remote attackers to bypass authentication …Aug 7, 2009›
CVE-2008-5848HIGH
10.0
The Advantech ADAM-6000 module has 00000000 as its default password, which makes it easier for remot…Jan 6, 2009›
CVE-2008-2474HIGH
10.0
Buffer overflow in x87 before 3.5.5 in ABB Process Communication Unit 400 (PCU400) 4.4 through 4.6 a…Sep 29, 2008›
CVE-2000-0704HIGH
10.0
Buffer overflow in SGI Omron WorldView Wnn allows remote attackers to execute arbitrary commands via…Oct 20, 2000›
CVE-2015-7908HIGH
9.3
Honeywell Midas gas detectors before 1.13b3 and Midas Black gas detectors before 2.13b3 allow remote…Dec 21, 2015›
CVE-2015-5386HIGH
9.3
Siemens SICAM MIC devices with firmware before 2404 allow remote attackers to bypass authentication …Jul 16, 2015›
CVE-2014-0769HIGH
9.3
The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoD…Apr 25, 2014›
CVE-2014-0760HIGH
9.3
The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with Co…Apr 25, 2014›
CVE-2014-2731HIGH
9.3
Multiple unspecified vulnerabilities in the integrated web server in Siemens SINEMA Server before 12…Apr 19, 2014›
CVE-2013-0662HIGH
9.3
Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.…Apr 1, 2014›
CVE-2014-0781HIGH
9.3
Heap-based buffer overflow in BKCLogSvr.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows r…Mar 14, 2014›
CVE-2013-2817HIGH
9.3
An ActiveX control in IcoLaunch.dll in Mitsubishi Electric Automation MC-WorX Suite 8.02 allows user…Feb 24, 2014›
CVE-2013-2782HIGH
9.3
Schneider Electric Trio J-Series License Free Ethernet Radio with firmware 3.6.0 through 3.6.3 uses …Aug 28, 2013›
CVE-2013-5021HIGH
9.3
Multiple absolute path traversal vulnerabilities in National Instruments cwui.ocx, as used in Nation…Aug 6, 2013›
CVE-2012-6440HIGH
9.3
The Web server password authentication mechanism used by the products is vulnerable to a MitM and Re…Jan 24, 2013›
CVE-2013-0655HIGH
9.3
The client in Schneider Electric Software Update (SESU) Utility 1.0.x and 1.1.x does not ensure that…Jan 21, 2013›
CVE-2011-4876HIGH
9.3
Directory traversal vulnerability in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2…Feb 3, 2012›
CVE-2011-4875HIGH
9.3
Stack-based buffer overflow in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2…Feb 3, 2012›
CVE-2011-4508HIGH
9.3
The HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka T…Feb 3, 2012›
CVE-2011-4055HIGH
9.3
Buffer overflow in the WebClient ActiveX control in Siemens Tecnomatix FactoryLink 6.6.1 (aka 6.6 SP…Jan 8, 2012›
CVE-2011-4034HIGH
9.3
Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historia…Dec 2, 2011›
CVE-2011-3321HIGH
9.3
Heap-based buffer overflow in the Siemens WinCC Runtime Advanced Loader, as used in SIMATIC WinCC fl…Sep 16, 2011›
CVE-2011-2530HIGH
9.3
Buffer overflow in RSEds.dll in RSHWare.exe in the EDS Hardware Installation Tool 1.0.5.1 and earlie…Jun 22, 2011›
CVE-2011-0340HIGH
9.3
Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904…May 4, 2011›
CVE-2011-0331HIGH
9.3
Use-after-free vulnerability in the addOSPLext method in the Honeywell ScanServer ActiveX control 78…Mar 22, 2011›
CVE-2010-4741HIGH
9.3
Stack-based buffer overflow in MDMUtil.dll in MDMTool.exe in MDM Tool before 2.3 in Moxa Device Mana…Feb 18, 2011›
CVE-2015-3974HIGH
9.0
EasyIO EasyIO-30P-SF controllers with firmware before 0.5.21 and 2.x before 2.0.5.21, as used in Acc…Sep 28, 2015›
CVE-2015-6456HIGH
9.0
GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 have hardcoded credentials f…Sep 18, 2015›
CVE-2015-4051HIGH
9.0
Beckhoff IPC Diagnostics before 1.8 does not properly restrict access to functions in /config, which…Jun 8, 2015›
CVE-2014-8387HIGH
9.0
cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users…Nov 20, 2014›
CVE-2014-2366HIGH
9.0
upAdminPg.asp in Advantech WebAccess before 7.2 allows remote authenticated users to discover creden…Jul 19, 2014›
CVE-2014-0783HIGH
9.0
Stack-based buffer overflow in BKHOdeq.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows re…Mar 14, 2014›
CVE-2026-32059HIGH
8.8
OpenClaw version 2026.2.22-2 prior to 2026.2.23 tools.exec.safeBins validation for sort command fail…Mar 11, 2026›
CVE-2024-55022HIGH
8.8
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain an authenticated command…Mar 3, 2026›
CVE-2025-10314HIGH
8.8
Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation FREQSHIP-mini for Win…Feb 5, 2026›
CVE-2025-4676HIGH
8.8
Incorrect Implementation of Authentication Algorithm vulnerability in ABB WebPro SNMP Card PowerValu…Jan 7, 2026›
CVE-2025-14849HIGH
8.8
Advantech WebAccess/SCADA  is vulnerable to unrestricted file upload, which may allow an attacker to…Dec 18, 2025›
CVE-2025-10205HIGH
8.8
Use of a One-Way Hash with a Predictable Salt vulnerability in ABB FLXEON.This issue affects FLXEON:…Sep 17, 2025›
CVE-2025-9065HIGH
8.8
A server-side request forgery security issue exists within Rockwell Automation ThinManager® software…Sep 9, 2025›
CVE-2025-53515HIGH
8.8
A vulnerability exists in Advantech iView that allows for SQL injection and remote code execution t…Jul 11, 2025›
CVE-2025-53475HIGH
8.8
A vulnerability exists in Advantech iView that could allow for SQL injection and remote code execut…Jul 11, 2025›
CVE-2025-52577HIGH
8.8
A vulnerability exists in Advantech iView that could allow SQL injection and remote code execution …Jul 11, 2025›
CVE-2024-41969HIGH
8.8
A low privileged remote attacker may modify the configuration of the CODESYS V3 service through a mi…Nov 18, 2024›
CVE-2024-42417HIGH
8.8
Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script Handler_CFG.ashx. An au…Oct 3, 2024›
CVE-2024-38308HIGH
8.8
Advantech ADAM 5550's web application includes a "logs" page where all the HTTP requests received a…Sep 27, 2024›
CVE-2024-8533HIGH
8.8
A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulner…Sep 12, 2024›
CVE-2024-45044HIGH
8.8
Bareos is open source software for backup, archiving, and recovery of data for operating systems. Wh…Sep 10, 2024›
CVE-2020-11640HIGH
8.8
AdvaBuild uses a command queue to launch certain operations. An attacker who gains access to the com…Jul 23, 2024›
CVE-2024-39883HIGH
8.8
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to co…Jul 9, 2024›
CVE-2024-39882HIGH
8.8
Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a re…Jul 9, 2024›
CVE-2024-39881HIGH
8.8
Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a me…Jul 9, 2024›
CVE-2024-4007HIGH
8.8
Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows…Jul 1, 2024›
CVE-2023-51603HIGH
8.8
Honeywell Saia PG5 Controls Suite CAB File Parsing Directory Traversal Remote Code Execution Vulnera…May 3, 2024›
CVE-2023-51599HIGH
8.8
Honeywell Saia PG5 Controls Suite Directory Traversal Remote Code Execution Vulnerability. This vuln…May 3, 2024›
CVE-2024-34033HIGH
8.8
Delta Electronics DIAEnergie has insufficient input validation which makes it possible to perform a…May 3, 2024›
CVE-2024-34032HIGH
8.8
Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the Get…May 3, 2024›
CVE-2024-34031HIGH
8.8
Delta Electronics DIAEnergie is vulnerable to an SQL injection vulnerability that exists in the scr…May 3, 2024›
CVE-2023-43824HIGH
8.8
A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when p…Jan 18, 2024›
CVE-2023-43823HIGH
8.8
A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when p…Jan 18, 2024›
CVE-2023-43822HIGH
8.8
A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when p…Jan 18, 2024›
CVE-2023-43821HIGH
8.8
A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when p…Jan 18, 2024›
CVE-2023-43820HIGH
8.8
A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when p…Jan 18, 2024›
CVE-2023-43819HIGH
8.8
A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when p…Jan 18, 2024›
CVE-2023-43818HIGH
8.8
A buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft. A remote, unauthe…Jan 18, 2024›
CVE-2023-50466HIGH
8.8
An authenticated command injection vulnerability in Weintek cMT2078X easyweb Web Version v2.1.3, OS …Dec 19, 2023›
CVE-2023-46690HIGH
8.8
In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an attacke…Nov 30, 2023›
CVE-2023-40145HIGH
8.8
In Weintek's cMT3000 HMI Web CGI device, an anonymous attacker can execute arbitrary comman…Oct 19, 2023›
CVE-2023-29463HIGH
8.8
The JMX Console within the Rockwell Automation Pavilion8 is exposed to application users and does n…Sep 12, 2023›
CVE-2023-37861HIGH
8.8
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated remote at…Aug 9, 2023›
CVE-2023-3573HIGH
8.8
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low…Aug 8, 2023›
CVE-2023-3571HIGH
8.8
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low…Aug 8, 2023›
CVE-2023-3570HIGH
8.8
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low…Aug 8, 2023›
CVE-2022-4046HIGH
8.8
In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a …Aug 3, 2023›
CVE-2023-3663HIGH
8.8
In CODESYS Development System versions from 3.5.11.20 and before 3.5.19.20 a missing integrity check…Aug 3, 2023›
CVE-2023-3983HIGH
8.8
An authenticated SQL injection vulnerability exists in Advantech iView versions prior to v5.7.4 buil…Jul 31, 2023›
CVE-2023-2072HIGH
8.8
The Rockwell Automation PowerMonitor 1000 contains stored cross-site scripting vulnerabilities withi…Jul 11, 2023›
CVE-2023-3256HIGH
8.8
Advantech R-SeeNet versions 2.4.22 allows low-level users to access and load the content of local …Jun 22, 2023›
CVE-2023-0863HIGH
8.8
Improper Authentication vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32…May 17, 2023›
CVE-2022-47390HIGH
8.8
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the Cmp…May 15, 2023›
CVE-2022-47389HIGH
8.8
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the Cmp…May 15, 2023›
CVE-2022-47388HIGH
8.8
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the Cmp…May 15, 2023›
CVE-2022-47387HIGH
8.8
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpT…May 15, 2023›
CVE-2022-47386HIGH
8.8
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the Cmp…May 15, 2023›
CVE-2022-47385HIGH
8.8
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the Cmp…May 15, 2023›
CVE-2022-47384HIGH
8.8
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpT…May 15, 2023›
CVE-2022-47383HIGH
8.8
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the Cmp…May 15, 2023›
CVE-2022-47382HIGH
8.8
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpT…May 15, 2023›
CVE-2022-47381HIGH
8.8
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple…May 15, 2023›
CVE-2022-47380HIGH
8.8
An authenticated remote attacker may use a stack based  out-of-bounds write vulnerability in multipl…May 15, 2023›
CVE-2022-47379HIGH
8.8
An authenticated, remote attacker may use a out-of-bounds write vulnerability in multiple CODESYS pr…May 15, 2023›
CVE-2023-2575HIGH
8.8
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stack-based Buffer Ove…May 8, 2023›
CVE-2023-2574HIGH
8.8
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vul…May 8, 2023›
CVE-2023-2573HIGH
8.8
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vul…May 8, 2023›
CVE-2023-1109HIGH
8.8
In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend c…Apr 17, 2023›
CVE-2023-1144HIGH
8.8
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contains an improper access contr…Mar 27, 2023›
CVE-2023-1143HIGH
8.8
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use Lua scr…Mar 27, 2023›
CVE-2023-1141HIGH
8.8
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a command injection vulne…Mar 27, 2023›
CVE-2023-1139HIGH
8.8
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization…Mar 27, 2023›
CVE-2022-4224HIGH
8.8
In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize t…Mar 23, 2023›
CVE-2018-25048HIGH
8.8
The CODESYS runtime system in multiple versions allows an remote low privileged attacker to use a pa…Mar 23, 2023›
CVE-2023-0228HIGH
8.8
Improper Authentication vulnerability in ABB Symphony Plus S+ Operations.This issue affects Symphony…Mar 2, 2023›
CVE-2023-0444HIGH
8.8
A privilege escalation vulnerability exists in Delta Electronics InfraSuite Device Master 00.00.02a.…Jan 26, 2023›
CVE-2022-42139HIGH
8.8
Delta Electronics DVW-W02W2-E2 1.5.0.10 is vulnerable to Command Injection via Crafted URL.Dec 14, 2022›
CVE-2022-43506HIGH
8.8
SQL Injection in HandlerTag_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.0…Nov 17, 2022›
CVE-2022-43457HIGH
8.8
SQL Injection in HandlerPage_KID.ashx in Delta Electronics DIAEnergie versions prior to …Nov 17, 2022›
CVE-2022-43452HIGH
8.8
SQL Injection in FtyInfoSetting.aspx in Delta Electronics DIAEnergie versions prior to…Nov 17, 2022›
CVE-2022-43447HIGH
8.8
SQL Injection in AM_EBillAnalysis.aspx in Delta Electronics DIAEnergie versions prior to v…Nov 17, 2022›
CVE-2022-41775HIGH
8.8
SQL Injection in Handler_CFG.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.…Nov 17, 2022›
CVE-2022-41779HIGH
8.8
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize network packets…Oct 31, 2022›
CVE-2022-41644HIGH
8.8
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lacks authentication for …Oct 31, 2022›
CVE-2022-3158HIGH
8.8
Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to …Oct 17, 2022›
CVE-2022-38743HIGH
8.8
Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to …Oct 17, 2022›
CVE-2022-2333HIGH
8.8
If an attacker manages to trick a valid user into loading a malicious DLL, the attacker may be able …Sep 16, 2022›
CVE-2022-30243HIGH
8.8
Honeywell Alerton Visual Logic through 2022-05-04 allows unauthenticated programming writes from rem…Jul 15, 2022›
CVE-2022-32143HIGH
8.8
In multiple CODESYS products, file download and upload function allows access to internal files in t…Jun 24, 2022›
CVE-2022-32138HIGH
8.8
In multiple CODESYS products, a remote attacker may craft a request which may cause an unexpected si…Jun 24, 2022›
CVE-2022-32137HIGH
8.8
In multiple CODESYS products, a low privileged remote attacker may craft a request, which may cause …Jun 24, 2022›
CVE-2022-22729HIGH
8.8
CAMS for HIS Server contained in the following Yokogawa Electric products improperly authenticate th…Mar 11, 2022›
CVE-2022-21808HIGH
8.8
Path traversal vulnerability exists in CAMS for HIS Server contained in the following Yokogawa Elect…Mar 11, 2022›
CVE-2022-22509HIGH
8.8
In Phoenix Contact FL SWITCH Series 2xxx in version 3.00 an incorrect privilege assignment allows an…Feb 2, 2022›
CVE-2021-40396HIGH
8.8
A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iService 1.1.7…Jan 28, 2022›
CVE-2021-40389HIGH
8.8
A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iEdge Server 1…Jan 28, 2022›
CVE-2021-40388HIGH
8.8
A privilege escalation vulnerability exists in Advantech SQ Manager Server 1.0.6. A specially-crafte…Jan 28, 2022›
CVE-2021-21917HIGH
8.8
An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet …Dec 22, 2021›
CVE-2021-21916HIGH
8.8
An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet …Dec 22, 2021›
CVE-2021-21915HIGH
8.8
An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet …Dec 22, 2021›
CVE-2021-38418HIGH
8.8
Delta Electronics DIALink versions 1.2.4.0 and prior runs by default on HTTP, which may allow an att…Nov 3, 2021›
CVE-2021-39279HIGH
8.8
Certain MOXA devices allow Authenticated Command Injection via /forms/web_importTFTP. This affects W…Sep 7, 2021›
CVE-2021-20994HIGH
8.8
In multiple managed switches by WAGO in different versions an attacker may trick a legitimate user t…May 13, 2021›
CVE-2021-29238HIGH
8.8
CODESYS Automation Server before 1.16.0 allows cross-site request forgery (CSRF).May 3, 2021›
CVE-2020-13555HIGH
8.8
An exploitable local privilege elevation vulnerability exists in the file system permissions of Adva…Feb 17, 2021›
CVE-2020-13553HIGH
8.8
An exploitable local privilege elevation vulnerability exists in the file system permissions of Adva…Feb 17, 2021›
CVE-2020-13552HIGH
8.8
An exploitable local privilege elevation vulnerability exists in the file system permissions of Adva…Feb 17, 2021›
CVE-2020-13551HIGH
8.8
An exploitable local privilege elevation vulnerability exists in the file system permissions of Adva…Feb 17, 2021›
CVE-2020-27261HIGH
8.8
The Omron CX-One Version 4.60 and prior is vulnerable to a stack-based buffer overflow, which may al…Feb 9, 2021›
CVE-2020-27259HIGH
8.8
The Omron CX-One Version 4.60 and prior may allow an attacker to supply a pointer to arbitrary memor…Feb 9, 2021›
CVE-2020-25198HIGH
8.8
The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has incorrectly im…Dec 23, 2020›
CVE-2020-25194HIGH
8.8
The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has improper privi…Dec 23, 2020›
CVE-2020-12519HIGH
8.8
On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use this vulne…Dec 17, 2020›
CVE-2020-12517HIGH
8.8
On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an authenticated low privilege…Dec 17, 2020›
CVE-2020-12033HIGH
8.8
In Rockwell Automation FactoryTalk Services Platform, all versions, the redundancy host service (Rdc…Jun 23, 2020›
CVE-2020-12026HIGH
8.8
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal v…May 8, 2020›
CVE-2020-6081HIGH
8.8
An exploitable code execution vulnerability exists in the PLC_Task functionality of 3S-Smart Softwar…May 7, 2020›
CVE-2020-8477HIGH
8.8
The installations for ABB System 800xA Information Manager versions 5.1, 6.0 to 6.0.3.2 and 6.1 wron…Apr 22, 2020›
CVE-2020-10607HIGH
8.8
In Advantech WebAccess, Versions 8.4.2 and prior. A stack-based buffer overflow vulnerability caused…Mar 27, 2020›
CVE-2020-6982HIGH
8.8
In Honeywell WIN-PAK 4.7.2, Web and prior versions, the header injection vulnerability has been iden…Mar 24, 2020›
CVE-2020-7005HIGH
8.8
In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable to a cross-si…Mar 24, 2020›
CVE-2020-5546HIGH
8.8
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in …Mar 16, 2020›
CVE-2020-9436HIGH
8.8
PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002…Mar 12, 2020›
CVE-2019-9102HIGH
8.8
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 device…Mar 11, 2020›
CVE-2019-5162HIGH
8.8
An exploitable improper access control vulnerability exists in the iw_webs account settings function…Feb 25, 2020›
CVE-2019-5153HIGH
8.8
An exploitable remote code execution vulnerability exists in the iw_webs configuration parsing funct…Feb 25, 2020›
CVE-2019-5143HIGH
8.8
An exploitable format string vulnerability exists in the iw_console conio_writestr functionality of …Feb 25, 2020›
CVE-2019-5141HIGH
8.8
An exploitable command injection vulnerability exists in the iw_webs functionality of the Moxa AWK-3…Feb 25, 2020›
CVE-2019-5140HIGH
8.8
An exploitable command injection vulnerability exists in the iwwebs functionality of the Moxa AWK-31…Feb 25, 2020›
CVE-2019-5136HIGH
8.8
An exploitable privilege escalation vulnerability exists in the iw_console functionality of the Moxa…Feb 25, 2020›
CVE-2020-8997HIGH
8.8
Older generation Abbott FreeStyle Libre sensors allow remote attackers within close proximity to ena…Feb 16, 2020›
CVE-2020-8858HIGH
8.8
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Mo…Feb 14, 2020›
CVE-2019-10995HIGH
8.8
ABB CP651 HMI products revision BSP UN30 v1.76 and prior implement hidden administrative accounts th…Jan 14, 2020›
CVE-2019-18251HIGH
8.8
In Omron CX-Supervisor, Versions 3.5 (12) and prior, Omron CX-Supervisor ships with Teamviewer Versi…Nov 26, 2019›
CVE-2019-9008HIGH
8.8
An issue was discovered in 3S-Smart CODESYS V3 through 3.5.12.30. A user with low privileges can tak…Sep 17, 2019›
CVE-2019-9013HIGH
8.8
An issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based e…Aug 15, 2019›
CVE-2019-10961HIGH
8.8
In Advantech WebAccess HMI Designer Version 2.1.9.23 and prior, processing specially crafted MCR fil…Aug 2, 2019›
CVE-2018-11427HIGH
8.8
CSRF tokens are not used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 1…Jul 3, 2019›
CVE-2019-7225HIGH
8.8
The ABB HMI components implement hidden administrative accounts that are used during the provisionin…Jun 27, 2019›
CVE-2019-7226HIGH
8.8
The ABB IDAL HTTP server CGI interface contains a URL that allows an unauthenticated attacker to byp…Jun 27, 2019›
CVE-2019-7228HIGH
8.8
The ABB IDAL HTTP server mishandles format strings in a username or cookie during the authentication…Jun 27, 2019›
CVE-2019-7232HIGH
8.8
The ABB IDAL HTTP server is vulnerable to a buffer overflow when a long Host header is sent in a web…Jun 24, 2019›
CVE-2019-7230HIGH
8.8
The ABB IDAL FTP server mishandles format strings in a username during the authentication process. A…Jun 24, 2019›
CVE-2019-12870HIGH
8.8
An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and C…Jun 24, 2019›
CVE-2019-12869HIGH
8.8
An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and C…Jun 24, 2019›
CVE-2019-12871HIGH
8.8
An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and C…Jun 24, 2019›
CVE-2019-6584HIGH
8.8
A vulnerability has been identified in SIEMENS LOGO!8 (6ED1052-xyyxx-0BA8 FS:01 to FS:06 / Firmware …Jun 12, 2019›
CVE-2018-10703HIGH
8.8
An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administ…Jun 7, 2019›
CVE-2018-10702HIGH
8.8
An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administ…Jun 7, 2019›
CVE-2018-10701HIGH
8.8
An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administ…Jun 7, 2019›
CVE-2018-10699HIGH
8.8
An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides certfile upload fu…Jun 7, 2019›
CVE-2018-10697HIGH
8.8
An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides ping functionality…Jun 7, 2019›
CVE-2018-10696HIGH
8.8
An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a web interface to allow …Jun 7, 2019›
CVE-2018-10695HIGH
8.8
An issue was discovered on Moxa AWK-3121 1.14 devices. It provides alert functionality so that an ad…Jun 7, 2019›
CVE-2018-10693HIGH
8.8
An issue was discovered on Moxa AWK-3121 1.14 devices. It provides ping functionality so that an adm…Jun 7, 2019›
CVE-2018-13993HIGH
8.8
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is prone to CSRF.May 7, 2019›
CVE-2019-9744HIGH
8.8
An issue was discovered on PHOENIX CONTACT FL NAT SMCS 8TX, FL NAT SMN 8TX, FL NAT SMN 8TX-M, and FL…Mar 26, 2019›
CVE-2019-9743HIGH
8.8
An issue was discovered on PHOENIX CONTACT RAD-80211-XD and RAD-80211-XD/HP-BUS devices. Command inj…Mar 26, 2019›
CVE-2015-6458HIGH
8.8
Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow rem…Mar 21, 2019›
CVE-2015-6457HIGH
8.8
Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow rem…Mar 21, 2019›
CVE-2019-6561HIGH
8.8
Cross-site request forgery has been identified in Moxa IKS and EDS, which may allow for the executio…Mar 5, 2019›
CVE-2018-19660HIGH
8.8
An exploitable authenticated command-injection vulnerability exists in the web server functionality …Dec 6, 2018›
CVE-2018-19659HIGH
8.8
An exploitable authenticated command-injection vulnerability exists in the web server functionality …Dec 6, 2018›
CVE-2018-15704HIGH
8.8
Advantech WebAccess 8.3.2 and below is vulnerable to a stack buffer overflow vulnerability. A remote…Oct 22, 2018›
CVE-2018-18392HIGH
8.8
Privilege Escalation via Broken Access Control in Moxa ThingsPro IIoT Gateway and Device Management …Oct 19, 2018›
CVE-2018-18391HIGH
8.8
User Privilege Escalation in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions ve…Oct 19, 2018›
CVE-2018-16282HIGH
8.8
A command injection vulnerability in the web server functionality of Moxa EDR-810 V4.2 build 1804101…Sep 20, 2018›
CVE-2018-12980HIGH
8.8
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW …Jul 12, 2018›
CVE-2018-13793HIGH
8.8
Multiple Cross Site Request Forgery (CSRF) vulnerabilities in the HTTP API in ABBYY FlexiCapture bef…Jul 9, 2018›
CVE-2018-7782HIGH
8.8
In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior t…Jul 3, 2018›
CVE-2018-7781HIGH
8.8
In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior t…Jul 3, 2018›
CVE-2018-7777HIGH
8.8
The vulnerability is due to insufficient handling of update_file request parameter on update_module.…Jul 3, 2018›
CVE-2018-7774HIGH
8.8
The vulnerability exists within processing of localize.php in Schneider Electric U.motion Builder so…Jul 3, 2018›
CVE-2018-7773HIGH
8.8
The vulnerability exists within processing of nfcserver.php in Schneider Electric U.motion Builder s…Jul 3, 2018›
CVE-2018-7772HIGH
8.8
The vulnerability exists within processing of applets which are exposed on the web service in Schnei…Jul 3, 2018›
CVE-2018-7769HIGH
8.8
The vulnerability exists within processing of xmlserver.php in Schneider Electric U.motion Builder s…Jul 3, 2018›
CVE-2018-7768HIGH
8.8
The vulnerability exists within processing of loadtemplate.php in Schneider Electric U.motion Builde…Jul 3, 2018›
CVE-2018-7767HIGH
8.8
The vulnerability exists within processing of editobject.php in Schneider Electric U.motion Builder …Jul 3, 2018›
CVE-2018-7766HIGH
8.8
The vulnerability exists within processing of track_getdata.php in Schneider Electric U.motion Build…Jul 3, 2018›
CVE-2018-7765HIGH
8.8
The vulnerability exists within processing of track_import_export.php in Schneider Electric U.motion…Jul 3, 2018›
CVE-2018-4845HIGH
8.8
A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 5…Jun 26, 2018›
CVE-2017-7906HIGH
8.8
In ABB IP GATEWAY 3.39 and prior, the web server does not sufficiently verify that a request was per…Jun 6, 2018›
CVE-2017-14434HIGH
8.8
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-81…May 14, 2018›
CVE-2017-14433HIGH
8.8
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-81…May 14, 2018›
CVE-2017-14432HIGH
8.8
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-81…May 14, 2018›
CVE-2017-12126HIGH
8.8
An exploitable cross-site request forgery vulnerability exists in the web server functionality of Mo…May 14, 2018›
CVE-2017-12125HIGH
8.8
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-81…May 14, 2018›
CVE-2017-12123HIGH
8.8
An exploitable clear text transmission of password vulnerability exists in the web server and telnet…May 14, 2018›
CVE-2017-12121HIGH
8.8
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-81…May 14, 2018›
CVE-2017-12120HIGH
8.8
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-81…May 14, 2018›
CVE-2018-7509HIGH
8.8
WPLSoft in Delta Electronics versions 2.45.0 and prior writes data from a file outside the bounds of…May 4, 2018›
CVE-2018-7507HIGH
8.8
WPLSoft in Delta Electronics versions 2.45.0 and prior utilizes a fixed length heap buffer where a v…May 4, 2018›
CVE-2018-7494HIGH
8.8
WPLSoft in Delta Electronics versions 2.45.0 and prior utilizes a fixed length stack buffer where a …May 4, 2018›
CVE-2017-12712HIGH
8.8
The authentication algorithm in Abbott Laboratories pacemakers manufactured prior to Aug 28, 2017, w…Apr 25, 2018›
CVE-2018-7240HIGH
8.8
A vulnerability exists in Schneider Electric's Modicon Quantum in all versions of the communication …Apr 18, 2018›
CVE-2018-7230HIGH
8.8
A XML external entity (XXE) vulnerability exists in the import.cgi of the web interface component of…Mar 9, 2018›
CVE-2017-17888HIGH
8.8
cgi-bin/write.cgi in Anti-Web through 3.8.7, as used on NetBiter / HMS, Ouman EH-net, Alliance Syste…Dec 27, 2017›
CVE-2017-16731HIGH
8.8
An Unprotected Transport of Credentials issue was discovered in ABB Ellipse 8.3 through Ellipse 8.9 …Dec 20, 2017›
CVE-2017-7969HIGH
8.8
A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Elect…Sep 26, 2017›
CVE-2017-12704HIGH
8.8
A heap-based buffer overflow issue was discovered in Advantech WebAccess versions prior to V8.2_2017…Aug 30, 2017›
CVE-2017-12702HIGH
8.8
An Externally Controlled Format String issue was discovered in Advantech WebAccess versions prior to…Aug 30, 2017›
CVE-2017-6328HIGH
8.8
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of cross site request forger…Aug 11, 2017›
CVE-2017-7966HIGH
8.8
A DLL Hijacking vulnerability in the programming software in Schneider Electric's SoMachine HVAC v2.…Jun 7, 2017›
CVE-2017-7917HIGH
8.8
A Cross-Site Request Forgery issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 150821…May 29, 2017›
CVE-2017-5156HIGH
8.8
A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access An…Apr 20, 2017›
CVE-2016-8718HIGH
8.8
An exploitable Cross-Site Request Forgery vulnerability exists in the Web Application functionality …Apr 12, 2017›
CVE-2017-5671HIGH
8.8
Honeywell Intermec PM23, PM42, PM43, PC23, PC43, PD43, and PC42 industrial printers before 10.11.013…Mar 29, 2017›
CVE-2017-2689HIGH
8.8
Siemens RUGGEDCOM ROX I (all versions) allow an authenticated user to bypass access restrictions in …Mar 29, 2017›
CVE-2017-2688HIGH
8.8
The integrated web server in Siemens RUGGEDCOM ROX I (all versions) at port 10000/TCP could allow re…Mar 29, 2017›
CVE-2017-2682HIGH
8.8
The Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could allow a remote …Feb 27, 2017›
CVE-2016-9365HIGH
8.8
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions pr…Feb 13, 2017›
CVE-2016-5809HIGH
8.8
An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX se…Feb 13, 2017›
CVE-2016-5793HIGH
8.8
Unquoted Windows search path vulnerability in Moxa Active OPC Server before 2.4.19 allows local user…Sep 24, 2016›
CVE-2016-2285HIGH
8.8
Cross-site request forgery (CSRF) vulnerability on Moxa MiiNePort_E1_4641 devices with firmware 1.1.…May 31, 2016›
CVE-2015-3946HIGH
8.8
Cross-site request forgery (CSRF) vulnerability in Advantech WebAccess before 8.1 allows remote atta…Jan 15, 2016›
CVE-2025-53418HIGH
8.6
Delta Electronics COMMGR has Stack-based Buffer Overflow vulnerability.Aug 26, 2025›
CVE-2025-2521HIGH
8.6
The Honeywell Experion PKS and OneWireless WDM contains a Memory Buffer vulnerability in the compone…Jul 10, 2025›
CVE-2024-3493HIGH
8.6
A specific malformed fragmented packet type (fragmented packets may be generated automatically by d…Apr 15, 2024›
CVE-2024-21916HIGH
8.6
A denial-of-service vulnerability exists in specific Rockwell Automation ControlLogix ang GuardLogi…Jan 31, 2024›
CVE-2022-45790HIGH
8.6
The Omron FINS protocol has an authenticated feature to prevent access to memory regions. Authentica…Jan 22, 2024›
CVE-2023-2423HIGH
8.6
A vulnerability was discovered in the Rockwell Automation Armor PowerFlex device when the product s…Aug 8, 2023›
CVE-2023-0426HIGH
8.6
ABB is aware of vulnerabilities in the product versions listed below. An update is available that r…Aug 7, 2023›
CVE-2023-0425HIGH
8.6
ABB is aware of vulnerabilities in the product versions listed below. An update is available that r…Aug 7, 2023›
CVE-2022-3752HIGH
8.6
An unauthorized user could use a specially crafted sequence of Ethernet/IP messages, combined with h…Dec 19, 2022›
CVE-2022-3157HIGH
8.6
A vulnerability exists in the Rockwell Automation controllers that allows a malformed CIP request t…Dec 16, 2022›
CVE-2022-40265HIGH
8.6
Improper Input Validation vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series RJ71EN…Nov 30, 2022›
CVE-2022-25164HIGH
8.6
Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GX Works3 versions f…Nov 25, 2022›
CVE-2022-2465HIGH
8.6
Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Deserial…Aug 25, 2022›
CVE-2022-25161HIGH
8.6
Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U-xMy/z(x=32,64…May 18, 2022›
CVE-2021-22275HIGH
8.6
Buffer Overflow vulnerability in B&R Automation Runtime webserver allows an unauthenticated network-…May 13, 2022›
CVE-2021-27475HIGH
8.6
Rockwell Automation Connected Components Workbench v12.00.00 and prior does not limit the objects th…Mar 23, 2022›
CVE-2021-33012HIGH
8.6
Rockwell Automation MicroLogix 1100, all versions, allows a remote, unauthenticated attacker sending…Jul 9, 2021›
CVE-2021-22659HIGH
8.6
Rockwell Automation MicroLogix 1400 Version 21.6 and below may allow a remote unauthenticated attack…Mar 25, 2021›
CVE-2020-24685HIGH
8.6
An unauthenticated specially crafted packet sent by an attacker over the network will cause a denial…Feb 9, 2021›
CVE-2019-13538HIGH
8.6
3S-Smart Software Solutions GmbH CODESYS V3 Library Manager, all versions prior to 3.5.16.0, allows …Sep 17, 2019›
CVE-2018-13990HIGH
8.6
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions prior to 1.35 is vulnerable to brut…May 6, 2019›
CVE-2018-17924HIGH
8.6
Rockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules An unau…Dec 7, 2018›
CVE-2017-9627HIGH
8.6
An Uncontrolled Resource Consumption issue was discovered in Schneider Electric Wonderware ArchestrA…Jul 7, 2017›
CVE-2017-7901HIGH
8.6
A Predictable Value Range from Previous Values issue was discovered in Rockwell Automation Allen-Bra…Jun 30, 2017›
CVE-2017-7914HIGH
8.6
A Missing Authorization issue was discovered in Rockwell Automation PanelView Plus 6 700-1500 6.00.0…Jun 14, 2017›
CVE-2017-5143HIGH
8.6
An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and…Feb 13, 2017›
CVE-2016-8368HIGH
8.6
An issue was discovered in Mitsubishi Electric Automation MELSEC-Q series Ethernet interface modules…Feb 13, 2017›
CVE-2016-5814HIGH
8.6
Buffer overflow in Rockwell Automation RSLogix Micro Starter Lite, RSLogix Micro Developer, RSLogix …Sep 19, 2016›
CVE-2015-7907HIGH
8.6
Directory traversal vulnerability in the web server on Honeywell Midas gas detectors before 1.13b3 a…Dec 21, 2015›
CVE-2024-5650HIGH
8.5
DLL Hijacking vulnerability has been found in CENTUM CAMS Log server provided by Yokogawa Electric C…Jun 17, 2024›
CVE-2021-32960HIGH
8.5
Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enab…Apr 1, 2022›
CVE-2015-6464HIGH
8.5
The administrative web interface on Moxa EDS-405A and EDS-408A switches with firmware before 3.6 all…Sep 11, 2015›
CVE-2013-0664HIGH
8.5
The FactoryCast service on the Schneider Electric Quantum 140NOE77111 and 140NWM10000, M340 BMXNOE01…Apr 4, 2013›
CVE-2012-6439HIGH
8.5
When an affected product receives a valid CIP message from an unauthorized or unintended source to…Jan 24, 2013›
CVE-2012-3009HIGH
8.5
Siemens COMOS before 9.1 Patch 413, 9.2 before Update 03 Patch 023, and 10.0 before Patch 005 allows…Aug 16, 2012›
CVE-2011-4879HIGH
8.5
miniweb.exe in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; W…Feb 3, 2012›
CVE-2025-13779HIGH
8.3
Missing authentication for critical function vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.T…Mar 13, 2026›
CVE-2025-13777HIGH
8.3
Authentication bypass by capture-replay vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This i…Mar 13, 2026›
CVE-2025-41659HIGH
8.3
A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system a…Aug 4, 2025›
CVE-2024-0220HIGH
8.3
B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for …Feb 22, 2024›
CVE-2021-22289HIGH
8.3
Improper Input Validation vulnerability in the project upload mechanism in B&R Automation Studio ver…Aug 11, 2022›
CVE-2020-14496HIGH
8.3
Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation En…May 19, 2022›
CVE-2020-14523HIGH
8.3
Multiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacke…Feb 11, 2022›
CVE-2020-14521HIGH
8.3
Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code …Feb 11, 2022›
CVE-2019-7229HIGH
8.3
The ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its software c…Jun 24, 2019›
CVE-2015-6481HIGH
8.3
The login function in the RequestController class in Moxa OnCell Central Manager before 2.2 has a ha…Dec 21, 2015›
CVE-2015-6480HIGH
8.3
The MessageBrokerServlet servlet in Moxa OnCell Central Manager before 2.2 does not require authenti…Dec 21, 2015›
CVE-2014-3888HIGH
8.3
Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 a…Jul 10, 2014›
CVE-2014-0782HIGH
8.3
Stack-based buffer overflow in BKESimmgr.exe in the Expanded Test Functions package in Yokogawa CENT…May 16, 2014›
CVE-2014-2250HIGH
8.3
The random-number generator on Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 does…Mar 24, 2014›
CVE-2014-2251HIGH
8.3
The random-number generator on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 do…Mar 16, 2014›
CVE-2014-0784HIGH
8.3
Stack-based buffer overflow in BKBCopyD.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows r…Mar 14, 2014›
CVE-2013-6925HIGH
8.3
The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote attackers to hijack…Dec 17, 2013›
CVE-2013-5709HIGH
8.3
The authentication implementation in the web server on Siemens SCALANCE X-200 switches with firmware…Sep 17, 2013›
CVE-2025-1924HIGH
8.2
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporatio…Feb 13, 2026›
CVE-2025-11774HIGH
8.2
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabi…Dec 19, 2025›
CVE-2025-3947HIGH
8.2
The Honeywell Experion PKS contains an Integer Underflow vulnerability in the component Control …Jul 10, 2025›
CVE-2025-3946HIGH
8.2
The Honeywell Experion PKS and OneWireless WDM contains a Deployment of Wrong Handler vulnera…Jul 10, 2025›
CVE-2024-51544HIGH
8.2
Service Control vulnerabilities allow access to service restart requests and vm configuration settin…Dec 5, 2024›
CVE-2024-51543HIGH
8.2
Information Disclosure vulnerabilities allow access to application configuration information.  Affec…Dec 5, 2024›
CVE-2024-51542HIGH
8.2
Configuration Download vulnerabilities allow access to dependency configuration information.  Affect…Dec 5, 2024›
CVE-2024-51541HIGH
8.2
Local File Inclusion vulnerabilities allow access to sensitive system information.  Affected product…Dec 5, 2024›
CVE-2024-48847HIGH
8.2
MD5 Checksum Bypass vulnerabilities where found exploiting a weakness in the way an application depe…Dec 5, 2024›
CVE-2024-1220HIGH
8.2
A stack-based buffer overflow in the built-in web server in Moxa NPort W2150A/W2250A Series firmware…Mar 6, 2024›
CVE-2023-5131HIGH
8.2
A heap buffer-overflow exists in Delta Electronics ISPSoft. An anonymous attacker can exploit this v…Jan 18, 2024›
CVE-2023-5130HIGH
8.2
A buffer overflow vulnerability exists in Delta Electronics WPLSoft. An anonymous attacker can explo…Jan 18, 2024›
CVE-2023-29464HIGH
8.2
FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor…Oct 13, 2023›
CVE-2023-37862HIGH
8.2
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an unauthenticated remote …Aug 9, 2023›
CVE-2021-34567HIGH
8.2
In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a special…Nov 9, 2022›
CVE-2022-2044HIGH
8.2
MOXA NPort 5110: Firmware Versions 2.10 is vulnerable to an out-of-bounds write that may allow an at…Aug 31, 2022›
CVE-2022-33319HIGH
8.2
Out-of-bounds Read vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubi…Jul 20, 2022›
CVE-2021-20595HIGH
8.2
Improper Restriction of XML External Entity Reference vulnerability in Mitsubishi Electric Air Condi…Jul 13, 2021›
CVE-2020-12505HIGH
8.2
Improper Authentication vulnerability in WAGO 750-8XX series with FW version <= FW07 allows an attac…Sep 30, 2020›
CVE-2020-12499HIGH
8.2
In PHOENIX CONTACT PLCnext Engineer version 2020.3.1 and earlier an improper path sanitation vulnera…Jul 21, 2020›
CVE-2019-18352HIGH
8.2
Improper access control exists on PHOENIX CONTACT FL NAT 2208 devices before V2.90 and FL NAT 2304-2…Feb 18, 2020›
CVE-2018-13992HIGH
8.2
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 allows for plaintext tr…May 7, 2019›
CVE-2017-12069HIGH
8.2
An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and…Aug 30, 2017›
CVE-2017-2683HIGH
8.2
A non-privileged user of the Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/…Feb 27, 2017›
CVE-2025-14510HIGH
8.1
Incorrect Implementation of Authentication Algorithm vulnerability in ABB ABB Ability OPTIMAX.This i…Jan 16, 2026›
CVE-2025-14850HIGH
8.1
Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delet…Dec 18, 2025›
CVE-2023-5404HIGH
8.1
Server receiving a malformed message can cause a pointer to be overwritten which can result in a rem…Apr 17, 2024›
CVE-2023-5403HIGH
8.1
Server hostname translation to IP address manipulation which could lead to an attacker performing re…Apr 17, 2024›
CVE-2023-5401HIGH
8.1
Server receiving a malformed message based on a using the specified key values can cause a stack ove…Apr 17, 2024›
CVE-2023-5400HIGH
8.1
Server receiving a malformed message based on a using the specified key values can cause a heap over…Apr 17, 2024›
CVE-2023-5397HIGH
8.1
Server receiving a malformed message to create a new connection could lead to an attacker performing…Apr 17, 2024›
CVE-2023-5395HIGH
8.1
Server receiving a malformed message that uses the hostname in an internal table may cause a stack o…Apr 17, 2024›
CVE-2023-1841HIGH
8.1
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…Feb 29, 2024›
CVE-2022-38742HIGH
8.1
Rockwell Automation ThinManager ThinServer versions 11.0.0 - 13.0.0 is vulnerable to a heap-based bu…Sep 23, 2022›
CVE-2022-34838HIGH
8.1
Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who suc…Aug 24, 2022›
CVE-2022-0902HIGH
8.1
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralizat…Jul 21, 2022›
CVE-2022-32142HIGH
8.1
Multiple CODESYS Products are prone to a out-of bounds read or write access. A low privileged remote…Jun 24, 2022›
CVE-2022-1965HIGH
8.1
Multiple products of CODESYS implement a improper error handling. A low privilege remote attacker ma…Jun 24, 2022›
CVE-2022-22515HIGH
8.1
A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime sy…Apr 7, 2022›
CVE-2022-25159HIGH
8.1
Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U…Apr 1, 2022›
CVE-2022-25156HIGH
8.1
Use of Weak Hash vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions, M…Apr 1, 2022›
CVE-2022-25155HIGH
8.1
Use of Password Hash Instead of Password for Authentication vulnerability in Mitsubishi Electric MEL…Apr 1, 2022›
CVE-2022-22151HIGH
8.1
CAMS for HIS Log Server contained in the following Yokogawa Electric products fails to properly neut…Mar 11, 2022›
CVE-2022-22145HIGH
8.1
CAMS for HIS Log Server contained in the following Yokogawa Electric products is vulnerable to uncon…Mar 11, 2022›
CVE-2022-21177HIGH
8.1
There is a path traversal vulnerability in CAMS for HIS Log Server contained in the following Yokoga…Mar 11, 2022›
CVE-2021-34595HIGH
8.1
A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2…Oct 26, 2021›
CVE-2019-13533HIGH
8.1
In Omron PLC CJ series, all versions, and Omron PLC CS series, all versions, an attacker could monit…Dec 16, 2019›
CVE-2018-10694HIGH
8.1
An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a Wi-Fi connection that i…Jun 7, 2019›
CVE-2018-10690HIGH
8.1
An issue was discovered on Moxa AWK-3121 1.14 devices. The device by default allows HTTP traffic thu…Jun 7, 2019›
CVE-2018-19616HIGH
8.1
An issue was discovered in Rockwell Automation Allen-Bradley PowerMonitor 1000. An unauthenticated u…Dec 26, 2018›
CVE-2018-17896HIGH
8.1
Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The affec…Oct 12, 2018›
CVE-2018-10728HIGH
8.1
All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33…May 17, 2018›
CVE-2018-8872HIGH
8.1
In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, system calls read d…May 4, 2018›
CVE-2014-8422HIGH
8.1
The web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk …Apr 12, 2018›
CVE-2018-7236HIGH
8.1
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions pri…Mar 9, 2018›
CVE-2017-9963HIGH
8.1
A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Elect…Feb 12, 2018›
CVE-2017-14263HIGH
8.1
Honeywell NVR devices allow remote attackers to create a user account in the admin group by leveragi…Sep 11, 2017›
CVE-2017-9940HIGH
8.1
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could a…Aug 8, 2017›
CVE-2017-6868HIGH
8.1
An Improper Authentication issue was discovered in Siemens SIMATIC CP 44x-1 RNA, all versions prior …Jul 7, 2017›
CVE-2016-8712HIGH
8.1
An exploitable nonce reuse vulnerability exists in the Web Application functionality of Moxa AWK-313…Apr 13, 2017›
CVE-2016-8379HIGH
8.1
An issue was discovered in Moxa ioLogik E1210, firmware Version V2.4 and prior, ioLogik E1211, firmw…Feb 13, 2017›
CVE-2016-8372HIGH
8.1
An issue was discovered in Moxa ioLogik E1210, firmware Version V2.4 and prior, ioLogik E1211, firmw…Feb 13, 2017›
CVE-2016-8360HIGH
8.1
An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. A specially crafted URL reque…Feb 13, 2017›
CVE-2016-9160HIGH
8.1
A vulnerability in SIEMENS SIMATIC WinCC (All versions < SIMATIC WinCC V7.2) and SIEMENS SIMATIC PCS…Dec 17, 2016›
CVE-2016-0858HIGH
8.1
Race condition in Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code o…Jan 15, 2016›
CVE-2015-6467HIGH
8.1
Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code via vectors involvi…Jan 15, 2016›
CVE-2015-3947HIGH
8.1
SQL injection vulnerability in Advantech WebAccess before 8.1 allows remote authenticated users to e…Jan 15, 2016›
CVE-2021-22291HIGH
8.0
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab…Oct 7, 2025›
CVE-2024-39275HIGH
8.0
Cookies of authenticated Advantech ADAM-5630 users remain as active valid cookies when a session is…Sep 27, 2024›
CVE-2024-28948HIGH
8.0
Advantech ADAM-5630 contains a cross-site request forgery (CSRF) vulnerability. It allows an attacke…Sep 27, 2024›
CVE-2022-30244HIGH
8.0
Honeywell Alerton Ascent Control Module (ACM) through 2022-05-04 allows unauthenticated programming …Jul 15, 2022›
CVE-2018-7771HIGH
8.0
The vulnerability exists within processing of editscript.php in Schneider Electric U.motion Builder …Jul 3, 2018›
CVE-2017-12129HIGH
8.0
An exploitable Weak Cryptography for Passwords vulnerability exists in the web server functionality …May 14, 2018›
CVE-2013-6926HIGH
8.0
The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote authenticated users…Dec 17, 2013›
CVE-2026-3094HIGH
7.8
Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a ma…Mar 4, 2026›
CVE-2026-0975HIGH
7.8
Delta Electronics DIAView has Command Injection vulnerability.Jan 16, 2026›
CVE-2025-14252HIGH
7.8
An Improper Access Control vulnerability in Advantech SUSI driver (susi.sys) allows attackers to rea…Dec 16, 2025›
CVE-2025-41700HIGH
7.8
An unauthenticated attacker can trick a local user into executing arbitrary code by opening a delibe…Dec 1, 2025›
CVE-2025-40827HIGH
7.8
A vulnerability has been identified in Siemens Software Center (All versions < V3.5), Solid Edge SE2…Nov 11, 2025›
CVE-2025-9068HIGH
7.8
A security issue exists within the Rockwell Automation Driver Package x64 Microsoft Installer File (…Oct 14, 2025›
CVE-2025-59300HIGH
7.8
Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a mal…Oct 3, 2025›
CVE-2025-59299HIGH
7.8
Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a mal…Oct 3, 2025›
CVE-2025-59298HIGH
7.8
Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a mal…Oct 3, 2025›
CVE-2025-59297HIGH
7.8
Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a mal…Oct 3, 2025›
CVE-2025-58319HIGH
7.8
Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a ma…Sep 24, 2025›
CVE-2025-58317HIGH
7.8
Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a ma…Sep 24, 2025›
CVE-2025-53419HIGH
7.8
Delta Electronics COMMGR has Code Injection vulnerability.Aug 26, 2025›
CVE-2025-7033HIGH
7.8
A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Ar…Aug 5, 2025›
CVE-2025-7032HIGH
7.8
A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Ar…Aug 5, 2025›
CVE-2025-7025HIGH
7.8
A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Ar…Aug 5, 2025›
CVE-2025-6377HIGH
7.8
A remote code execution security issue exists in the Rockwell Automation Arena®.  A crafted DOE file…Jul 9, 2025›
CVE-2025-6376HIGH
7.8
A remote code execution security issue exists in the Rockwell Automation Arena®.  A crafted DOE file…Jul 9, 2025›
CVE-2025-53416HIGH
7.8
Delta Electronics DTN Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execut…Jun 30, 2025›
CVE-2025-53415HIGH
7.8
Delta Electronics DTM Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execut…Jun 30, 2025›
CVE-2025-3394HIGH
7.8
Incorrect Permission Assignment for Critical Resource vulnerability in ABB Automation Builder.This i…Apr 30, 2025›
CVE-2025-4125HIGH
7.8
Delta Electronics ISPSoft version 3.20 is vulnerable to an Out-Of-Bounds Write vulnerability that co…Apr 30, 2025›
CVE-2025-4124HIGH
7.8
Delta Electronics ISPSoft version 3.20 is vulnerable to an Out-Of-Bounds Write vulnerability that co…Apr 30, 2025›
CVE-2025-22884HIGH
7.8
Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-Based buffer overflow vulnerability …Apr 30, 2025›
CVE-2025-22883HIGH
7.8
Delta Electronics ISPSoft version 3.20 is vulnerable to an Out-Of-Bounds Write vulnerability that co…Apr 30, 2025›
CVE-2025-22882HIGH
7.8
Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-Based buffer overflow vulnerability …Apr 30, 2025›
CVE-2025-3617HIGH
7.8
A privilege escalation vulnerability exists in the Rockwell Automation ThinManager. When the softwar…Apr 15, 2025›
CVE-2025-3289HIGH
7.8
A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based m…Apr 8, 2025›
CVE-2025-3288HIGH
7.8
A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor …Apr 8, 2025›
CVE-2025-3287HIGH
7.8
A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based m…Apr 8, 2025›
CVE-2025-3286HIGH
7.8
A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor …Apr 8, 2025›
CVE-2025-3285HIGH
7.8
A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor …Apr 8, 2025›
CVE-2025-2829HIGH
7.8
A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor …Apr 8, 2025›
CVE-2025-2293HIGH
7.8
A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor …Apr 8, 2025›
CVE-2025-2288HIGH
7.8
A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor …Apr 8, 2025›
CVE-2025-2287HIGH
7.8
A local code execution vulnerability exists in the Rockwell Automation Arena®  due to an uninitializ…Apr 8, 2025›
CVE-2025-2286HIGH
7.8
A local code execution vulnerability exists in the Rockwell Automation Arena®  due to an uninitializ…Apr 8, 2025›
CVE-2025-2285HIGH
7.8
A local code execution vulnerability exists in the Rockwell Automation Arena®  due to an uninitializ…Apr 8, 2025›
CVE-2025-22881HIGH
7.8
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to co…Feb 26, 2025›
CVE-2025-22880HIGH
7.8
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to co…Feb 7, 2025›
CVE-2024-12836HIGH
7.8
Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. Th…Dec 30, 2024›
CVE-2024-12835HIGH
7.8
Delta Electronics DRASimuCAD ICS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerabilit…Dec 30, 2024›
CVE-2024-12834HIGH
7.8
Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. Th…Dec 30, 2024›
CVE-2024-12677HIGH
7.8
Delta Electronics DTM Soft deserializes objects, which could allow an attacker to execute arbitrary …Dec 20, 2024›
CVE-2024-12175HIGH
7.8
Another “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that …Dec 19, 2024›
CVE-2024-12130HIGH
7.8
An “out of bounds read” code execution vulnerability exists in the Rockwell Automation Arena® that…Dec 5, 2024›
CVE-2024-11156HIGH
7.8
An “out of bounds write” code execution vulnerability exists in the Rockwell Automation Arena® t…Dec 5, 2024›
CVE-2024-11155HIGH
7.8
A “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could…Dec 5, 2024›
CVE-2024-9852HIGH
7.8
Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 all versions, Mitsub…Nov 28, 2024›
CVE-2024-8299HIGH
7.8
Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 all versions, Mitsub…Nov 28, 2024›
CVE-2024-47131HIGH
7.8
If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing m…Nov 11, 2024›
CVE-2024-39605HIGH
7.8
If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing m…Nov 11, 2024›
CVE-2024-39354HIGH
7.8
If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing m…Nov 11, 2024›
CVE-2024-7587HIGH
7.8
Incorrect Default Permissions vulnerability in GenBroker32, which is included in the installers for …Oct 22, 2024›
CVE-2024-47966HIGH
7.8
Delta Electronics CNCSoft-G2 lacks proper initialization of memory prior to accessing it. An attacke…Oct 10, 2024›
CVE-2024-47965HIGH
7.8
Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a re…Oct 10, 2024›
CVE-2024-47964HIGH
7.8
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to co…Oct 10, 2024›
CVE-2024-47963HIGH
7.8
Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a wr…Oct 10, 2024›
CVE-2024-47962HIGH
7.8
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to co…Oct 10, 2024›
CVE-2024-7987HIGH
7.8
A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ tha…Aug 26, 2024›
CVE-2024-7502HIGH
7.8
A crafted DPA file could force Delta Electronics DIAScreen to overflow a stack-based buffer, which c…Aug 6, 2024›
CVE-2024-5402HIGH
7.8
Unquoted Search Path or Element vulnerability in ABB Mint Workbench. A local attacker who success…Jul 15, 2024›
CVE-2024-39880HIGH
7.8
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to co…Jul 9, 2024›
CVE-2021-47302HIGH
7.8
In the Linux kernel, the following vulnerability has been resolved: igc: Fix use-after-free error d…May 21, 2024›
CVE-2024-4192HIGH
7.8
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to c…Apr 30, 2024›
CVE-2024-2929HIGH
7.8
A memory corruption vulnerability in Rockwell Automation Arena Simulation software could potentiall…Mar 26, 2024›
CVE-2024-21919HIGH
7.8
An uninitialized pointer in Rockwell Automation Arena Simulation software could potentially allow a…Mar 26, 2024›
CVE-2024-21918HIGH
7.8
A memory buffer vulnerability in Rockwell Automation Arena Simulation software could potentially al…Mar 26, 2024›
CVE-2024-21913HIGH
7.8
A heap-based memory buffer overflow vulnerability in Rockwell Automation Arena Simulation software …Mar 26, 2024›
CVE-2024-21912HIGH
7.8
An arbitrary code execution vulnerability in Rockwell Automation Arena Simulation could let a malic…Mar 26, 2024›
CVE-2024-1941HIGH
7.8
Delta Electronics CNCSoft-B versions 1.0.0.4 and prior are vulnerable to a stack-based buffer overf…Mar 1, 2024›
CVE-2024-1595HIGH
7.8
Delta Electronics CNCSoft-B DOPSoft prior to v4.0.0.82 insecurely loads libraries, which may allow…Feb 29, 2024›
CVE-2022-48626HIGH
7.8
In the Linux kernel, the following vulnerability has been resolved: moxart: fix potential use-after…Feb 26, 2024›
CVE-2023-5944HIGH
7.8
Delta Electronics DOPSoft is vulnerable to a stack-based buffer overflow, which may allow for arbit…Dec 4, 2023›
CVE-2023-5247HIGH
7.8
Malicious Code Execution Vulnerability due to External Control of File Name or Path in multiple Mits…Nov 30, 2023›
CVE-2023-6179HIGH
7.8
Honeywell ProWatch, 4.5, including all Service Pack versions, contain a Vulnerability in Application…Nov 17, 2023›
CVE-2023-27858HIGH
7.8
Rockwell Automation Arena Simulation contains an arbitrary code execution vulnerability that could …Oct 27, 2023›
CVE-2023-27854HIGH
7.8
An arbitrary code execution vulnerability was reported to Rockwell Automation in Arena Simulation t…Oct 27, 2023›
CVE-2023-5068HIGH
7.8
Delta Electronics DIAScreen may write past the end of an allocated buffer while parsing a specially…Sep 21, 2023›
CVE-2023-4685HIGH
7.8
Delta Electronics' CNCSoft-B version 1.0.0.4 and DOPSoft versions 4.0.0.82 and prior are vulnerable …Sep 7, 2023›
CVE-2021-41544HIGH
7.8
A vulnerability has been identified in Siemens Software Center (All versions < V3.0). A DLL Hijackin…Aug 8, 2023›
CVE-2023-25177HIGH
7.8
Delta Electronics' CNCSoft-B DOPSoft versions 1.0.0.4 and prior are vulnerable to stack-based buff…Jun 7, 2023›
CVE-2023-24014HIGH
7.8
Delta Electronics' CNCSoft-B DOPSoft versions 1.0.0.4 and prior are vulnerable to heap-based buffer…Jun 7, 2023›
CVE-2023-0635HIGH
7.8
Improper Privilege Management vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Li…Jun 5, 2023›
CVE-2022-0010HIGH
7.8
Insertion of Sensitive Information into Log File vulnerability in ABB QCS 800xA, ABB QCS AC450, ABB …May 22, 2023›
CVE-2023-29462HIGH
7.8
An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation softwa…May 9, 2023›
CVE-2023-29461HIGH
7.8
An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation softwa…May 9, 2023›
CVE-2023-29460HIGH
7.8
An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation softwa…May 9, 2023›
CVE-2023-26593HIGH
7.8
CENTUM series provided by Yokogawa Electric Corporation are vulnerable to cleartext storage of sensi…Apr 11, 2023›
CVE-2023-1145HIGH
7.8
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserial…Mar 27, 2023›
CVE-2023-1135HIGH
7.8
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an a…Mar 27, 2023›
CVE-2023-0598HIGH
7.8
GE Digital Proficy iFIX 2022, GE Digital Proficy iFIX v6.1, and GE Digital Proficy iFIX v6.5 are vu…Mar 16, 2023›
CVE-2023-0251HIGH
7.8
Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to a buffer overflow through …Feb 8, 2023›
CVE-2023-0250HIGH
7.8
Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to a stack-based buffer overf…Feb 8, 2023›
CVE-2023-0249HIGH
7.8
Delta Electronics DIAScreen versions 1.2.1.23 and prior are vulnerable to out-of-bounds write, which…Feb 8, 2023›
CVE-2023-0124HIGH
7.8
Delta Electronics DOPSoft versions 4.00.16.22 and prior are vulnerable to an out-of-bounds write, wh…Feb 3, 2023›
CVE-2023-0123HIGH
7.8
Delta Electronics DOPSoft versions 4.00.16.22 and prior are vulnerable to a stack-based buffer overf…Feb 3, 2023›
CVE-2022-42973HIGH
7.8
A CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause local privilege escal…Feb 1, 2023›
CVE-2022-42972HIGH
7.8
A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cau…Feb 1, 2023›
CVE-2022-3156HIGH
7.8
A remote code execution vulnerability exists in Rockwell Automation Studio 5000 Logix Emulate softwa…Dec 27, 2022›
CVE-2020-12069HIGH
7.8
In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Contro…Dec 26, 2022›
CVE-2022-3088HIGH
7.8
UC-8100A-ME-T System Image: Versions v1.0 to v1.6, UC-2100 System Image: Versions v1.0 to v1.12, UC-…Nov 28, 2022›
CVE-2022-3737HIGH
7.8
In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 memory can be read beyond the in…Nov 15, 2022›
CVE-2022-3461HIGH
7.8
In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 manipulated PC Worx or Config+ f…Nov 15, 2022›
CVE-2022-2069HIGH
7.8
The APDFL.dll in Siemens JT2Go prior to V13.3.0.5 and Siemens Teamcenter Visualization prior to V14.…Oct 20, 2022›
CVE-2022-3398HIGH
7.8
OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attac…Oct 6, 2022›
CVE-2022-3397HIGH
7.8
OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attac…Oct 6, 2022›
CVE-2022-3396HIGH
7.8
OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attac…Oct 6, 2022›
CVE-2022-33320HIGH
7.8
Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 1…Jul 20, 2022›
CVE-2022-33317HIGH
7.8
Inclusion of Functionality from Untrusted Control Sphere vulnerability in Mitsubishi Electric GENESI…Jul 20, 2022›
CVE-2022-33316HIGH
7.8
Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 1…Jul 20, 2022›
CVE-2022-33315HIGH
7.8
Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 1…Jul 20, 2022›
CVE-2022-29483HIGH
7.8
Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious sof…Jun 2, 2022›
CVE-2021-32969HIGH
7.8
Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to an out-of-bounds write conditi…May 24, 2022›
CVE-2021-32965HIGH
7.8
Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to type confusion, which may allo…May 24, 2022›
CVE-2022-22516HIGH
7.8
The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system use…Apr 7, 2022›
CVE-2022-26419HIGH
7.8
Omron CX-Position (versions 2.5.3 and prior) is vulnerable to multiple stack-based buffer overflow c…Apr 1, 2022›
CVE-2022-26417HIGH
7.8
Omron CX-Position (versions 2.5.3 and prior) is vulnerable to a use after free memory condition whil…Apr 1, 2022›
CVE-2022-26022HIGH
7.8
Omron CX-Position (versions 2.5.3 and prior) is vulnerable to an out-of-bounds write while processin…Apr 1, 2022›
CVE-2022-25959HIGH
7.8
Omron CX-Position (versions 2.5.3 and prior) is vulnerable to memory corruption while processing a s…Apr 1, 2022›
CVE-2022-1098HIGH
7.8
Delta Electronics DIAEnergie (all versions prior to 1.8.02.004) are vulnerable to a DLL hijacking co…Apr 1, 2022›
CVE-2022-26839HIGH
7.8
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to an incorrect defaul…Mar 29, 2022›
CVE-2020-25184HIGH
7.8
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file …Mar 18, 2022›
CVE-2022-23401HIGH
7.8
The following Yokogawa Electric products contain insecure DLL loading issues. CENTUM CS 3000 version…Mar 11, 2022›
CVE-2022-22148HIGH
7.8
'Root Service' service implemented in the following Yokogawa Electric products creates some named pi…Mar 11, 2022›
CVE-2022-22141HIGH
7.8
'Long-term Data Archive Package' service implemented in the following Yokogawa Electric products cre…Mar 11, 2022›
CVE-2021-40397HIGH
7.8
A privilege escalation vulnerability exists in the installation of Advantech WISE-PaaS/OTA Server 3.…Jan 28, 2022›
CVE-2021-22808HIGH
7.8
A CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution when a mali…Jan 28, 2022›
CVE-2021-22807HIGH
7.8
A CWE-787: Out-of-bounds Write vulnerability exists that could cause arbitrary code execution when a…Jan 28, 2022›
CVE-2022-21137HIGH
7.8
Omron CX-One Versions 4.60 and prior are vulnerable to a stack-based buffer overflow while processin…Jan 14, 2022›
CVE-2021-21912HIGH
7.8
A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-S…Dec 22, 2021›
CVE-2021-21911HIGH
7.8
A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-S…Dec 22, 2021›
CVE-2021-21910HIGH
7.8
A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-S…Dec 22, 2021›
CVE-2021-43982HIGH
7.8
Delta Electronics CNCSoft Versions 1.01.30 and prior are vulnerable to a stack-based buffer overflow…Dec 9, 2021›
CVE-2021-34597HIGH
7.8
Improper Input Validation vulnerability in PC Worx Automation Suite of Phoenix Contact up to version…Nov 4, 2021›
CVE-2021-38422HIGH
7.8
Delta Electronics DIALink versions 1.2.4.0 and prior stores sensitive information in cleartext, whic…Nov 3, 2021›
CVE-2021-38420HIGH
7.8
Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions …Nov 3, 2021›
CVE-2021-38416HIGH
7.8
Delta Electronics DIALink versions 1.2.4.0 and prior insecurely loads libraries, which may allow an …Nov 3, 2021›
CVE-2021-33019HIGH
7.8
A stack-based buffer overflow vulnerability in Delta Electronics DOPSoft Version 4.00.11 and prior m…Aug 30, 2021›
CVE-2021-33007HIGH
7.8
A heap-based buffer overflow in Delta Electronics TPEditor: v1.98.06 and prior may be exploited by p…Aug 30, 2021›
CVE-2021-21869HIGH
7.8
An unsafe deserialization vulnerability exists in the Engine.plugin ProfileInformation ProfileData f…Aug 25, 2021›
CVE-2021-21868HIGH
7.8
An unsafe deserialization vulnerability exists in the ObjectManager.plugin Project.get_MissingTypes(…Aug 18, 2021›
CVE-2021-21867HIGH
7.8
An unsafe deserialization vulnerability exists in the ObjectManager.plugin ObjectStream.ProfileByteA…Aug 18, 2021›
CVE-2021-21863HIGH
7.8
A unsafe deserialization vulnerability exists in the ComponentModel Profile.FromFile() functionality…Aug 5, 2021›
CVE-2021-21866HIGH
7.8
A unsafe deserialization vulnerability exists in the ObjectManager.plugin ProfileInformation.Profile…Aug 2, 2021›
CVE-2021-21865HIGH
7.8
A unsafe deserialization vulnerability exists in the PackageManagement.plugin ExtensionMethods.Clone…Aug 2, 2021›
CVE-2021-21864HIGH
7.8
A unsafe deserialization vulnerability exists in the ComponentModel ComponentManager.StartupCultureS…Aug 2, 2021›
CVE-2021-27412HIGH
7.8
Delta Electronics DOPSoft Versions 4.0.10.17 and prior are vulnerable to an out-of-bounds read, whic…Jul 2, 2021›
CVE-2021-33542HIGH
7.8
Phoenix Contact Classic Automation Worx Software Suite in Version 1.87 and below is affected by a re…Jun 25, 2021›
CVE-2021-27413HIGH
7.8
Omron CX-One Versions 4.60 and prior, including CX-Server Versions 5.0.29.0 and prior, are vulnerabl…May 13, 2021›
CVE-2021-22672HIGH
7.8
Delta Electronics' CNCSoft ScreenEditor in versions prior to v1.01.30 could allow the corruption of …May 10, 2021›
CVE-2021-29240HIGH
7.8
The Package Manager of CODESYS Development System 3 before 3.5.17.0 does not check the validity of p…May 4, 2021›
CVE-2021-29239HIGH
7.8
CODESYS Development System 3 before 3.5.17.0 displays or executes malicious documents or files embed…May 3, 2021›
CVE-2021-22665HIGH
7.8
Rockwell Automation DriveTools SP v5.13 and below and Drives AOP v4.12 and below both contain a vuln…Mar 18, 2021›
CVE-2020-13554HIGH
7.8
An exploitable local privilege elevation vulnerability exists in the file system permissions of Adva…Mar 3, 2021›
CVE-2020-27257HIGH
7.8
This vulnerability allows local attackers to execute arbitrary code due to the lack of proper valida…Feb 9, 2021›
CVE-2020-27293HIGH
7.8
Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior has a type confusion issue while processing p…Jan 11, 2021›
CVE-2020-27291HIGH
7.8
Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior is vulnerable to an out-of-bounds read while …Jan 11, 2021›
CVE-2020-27289HIGH
7.8
Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior has a null pointer dereference issue while pr…Jan 11, 2021›
CVE-2020-27287HIGH
7.8
Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior is vulnerable to an out-of-bounds write while…Jan 11, 2021›
CVE-2020-27281HIGH
7.8
A stack-based buffer overflow may exist in Delta Electronics CNCSoft ScreenEditor versions 1.01.26 a…Jan 11, 2021›
CVE-2020-27277HIGH
7.8
Delta Electronics DOPSoft Version 4.0.8.21 and prior has a null pointer dereference issue while proc…Jan 11, 2021›
CVE-2020-27275HIGH
7.8
Delta Electronics DOPSoft Version 4.0.8.21 and prior is vulnerable to an out-of-bounds write while p…Jan 11, 2021›
CVE-2020-13537HIGH
7.8
An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa…Nov 5, 2020›
CVE-2020-13536HIGH
7.8
An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa…Nov 5, 2020›
CVE-2020-7523HIGH
7.8
Improper Privilege Management vulnerability exists in Schneider Electric Modbus Serial Driver (see s…Aug 31, 2020›
CVE-2019-20383HIGH
7.8
ABBYY network license server in ABBYY FineReader 15 before Release 4 (aka 15.0.112.2130) allows esca…Aug 13, 2020›
CVE-2020-16227HIGH
7.8
Delta Electronics TPEditor Versions 1.97 and prior. An improper input validation may be exploited by…Aug 7, 2020›
CVE-2020-16225HIGH
7.8
Delta Electronics TPEditor Versions 1.97 and prior. A write-what-where condition may be exploited by…Aug 7, 2020›
CVE-2020-16223HIGH
7.8
Delta Electronics TPEditor Versions 1.97 and prior. A heap-based buffer overflow may be exploited by…Aug 7, 2020›
CVE-2020-16221HIGH
7.8
Delta Electronics TPEditor Versions 1.97 and prior. A stack-based buffer overflow may be exploited b…Aug 7, 2020›
CVE-2020-16219HIGH
7.8
Delta Electronics TPEditor Versions 1.97 and prior. An out-of-bounds read may be exploited by proces…Aug 7, 2020›
CVE-2020-16229HIGH
7.8
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project …Aug 6, 2020›
CVE-2020-16217HIGH
7.8
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. A double free vulnerability caused by…Aug 6, 2020›
CVE-2020-16215HIGH
7.8
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project …Aug 6, 2020›
CVE-2020-16213HIGH
7.8
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project …Aug 6, 2020›
CVE-2020-16207HIGH
7.8
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Multiple heap-based buffer overflow v…Aug 6, 2020›
CVE-2020-12498HIGH
7.8
mwe file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier is vulnerab…Jul 1, 2020›
CVE-2020-12497HIGH
7.8
PLCopen XML file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier can…Jul 1, 2020›
CVE-2020-8482HIGH
7.8
Insecure storage of sensitive information in ABB Device Library Wizard versions 6.0.X, 6.0.3.1 and 6…May 29, 2020›
CVE-2019-5621HIGH
7.8
ABBS Software Audio Media Player version 3.1 suffers from an instance of CWE-121: Stack-based Buffer…Apr 29, 2020›
CVE-2020-8489HIGH
7.8
Insufficient protection of the inter-process communication functions in ABB System 800xA Information…Apr 29, 2020›
CVE-2020-8488HIGH
7.8
Insufficient protection of the inter-process communication functions in ABB System 800xA Batch Manag…Apr 29, 2020›
CVE-2020-8485HIGH
7.8
Insufficient protection of the inter-process communication functions in ABB System 800xA for MOD 300…Apr 29, 2020›
CVE-2020-8484HIGH
7.8
Insufficient protection of the inter-process communication functions in ABB System 800xA for DCI (al…Apr 29, 2020›
CVE-2020-8471HIGH
7.8
For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and relate…Apr 29, 2020›
CVE-2020-8474HIGH
7.8
Weak Registry permissions in ABB System 800xA Base allow low privileged users to read and modify reg…Apr 22, 2020›
CVE-2020-10642HIGH
7.8
In Rockwell Automation RSLinx Classic versions 4.11.00 and prior, an authenticated local attacker co…Apr 13, 2020›
CVE-2020-10940HIGH
7.8
Local Privilege Escalation can occur in PHOENIX CONTACT PORTICO SERVER through 3.0.7 when installed …Mar 27, 2020›
CVE-2020-10939HIGH
7.8
Insecure, default path permissions in PHOENIX CONTACT PC WORX SRT through 1.14 allow for local privi…Mar 27, 2020›
CVE-2019-5184HIGH
7.8
An exploitable double free vulnerability exists in the iocheckd service "I/O-Check" functionality of…Mar 23, 2020›
CVE-2019-5181HIGH
7.8
An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O…Mar 12, 2020›
CVE-2019-5180HIGH
7.8
An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O…Mar 12, 2020›
CVE-2019-5179HIGH
7.8
An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O…Mar 12, 2020›
CVE-2019-5178HIGH
7.8
An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O…Mar 12, 2020›
CVE-2019-5171HIGH
7.8
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function o…Mar 12, 2020›
CVE-2019-5170HIGH
7.8
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function o…Mar 12, 2020›
CVE-2019-5169HIGH
7.8
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function o…Mar 12, 2020›
CVE-2019-5175HIGH
7.8
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function o…Mar 11, 2020›
CVE-2019-5174HIGH
7.8
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function o…Mar 11, 2020›
CVE-2019-5173HIGH
7.8
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function o…Mar 11, 2020›
CVE-2019-5172HIGH
7.8
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function o…Mar 11, 2020›
CVE-2019-5168HIGH
7.8
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function o…Mar 11, 2020›
CVE-2019-5167HIGH
7.8
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function o…Mar 11, 2020›
CVE-2019-5166HIGH
7.8
An exploitable stack buffer overflow vulnerability exists in the iocheckd service ‘I/O-Check’ functi…Mar 11, 2020›
CVE-2019-5159HIGH
7.8
An exploitable improper input validation vulnerability exists in the firmware update functionality o…Mar 11, 2020›
CVE-2019-5158HIGH
7.8
An exploitable firmware downgrade vulnerability exists in the firmware update package functionality …Mar 11, 2020›
CVE-2020-6968HIGH
7.8
Honeywell INNCOM INNControl 3 allows workstation users to escalate application user privileges throu…Feb 20, 2020›
CVE-2019-13521HIGH
7.8
A maliciously crafted program file opened by an unsuspecting user of Rockwell Automation Arena Simul…Jan 27, 2020›
CVE-2019-13519HIGH
7.8
A maliciously crafted program file opened by an unsuspecting user of Rockwell Automation Arena Simul…Jan 27, 2020›
CVE-2019-6008HIGH
7.8
An unquoted search path vulnerability in Multiple Yokogawa products for Windows (Exaopc (R1.01.00 ? …Dec 26, 2019›
CVE-2019-16675HIGH
7.8
An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and C…Oct 31, 2019›
CVE-2019-13527HIGH
7.8
In Rockwell Automation Arena Simulation Software Cat. 9502-Ax, Versions 16.00.00 and earlier, a mali…Sep 24, 2019›
CVE-2019-13544HIGH
7.8
Delta Electronics TPEditor, Versions 1.94 and prior. Multiple out-of-bounds write vulnerabilities ma…Sep 11, 2019›
CVE-2019-13540HIGH
7.8
Delta Electronics TPEditor, Versions 1.94 and prior. Multiple stack-based buffer overflow vulnerabil…Sep 11, 2019›
CVE-2019-13536HIGH
7.8
Delta Electronics TPEditor, Versions 1.94 and prior. Multiple heap-based buffer overflow vulnerabili…Sep 11, 2019›
CVE-2019-13510HIGH
7.8
Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain a USE AFTER FREE…Aug 15, 2019›
CVE-2019-10982HIGH
7.8
Delta Electronics CNCSoft ScreenEditor, Versions 1.00.89 and prior. Multiple heap-based buffer overf…Jul 24, 2019›
CVE-2018-19008HIGH
7.8
The TextEditor 2.0 in ABB CP400 Panel Builder versions 2.0.7.05 and earlier contain a vulnerability …Feb 13, 2019›
CVE-2018-7815HIGH
7.8
A Type Confusion (CWE-843) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold…Feb 6, 2019›
CVE-2018-7814HIGH
7.8
A Stack-based Buffer Overflow (CWE-121) vulnerability exists in Eurotherm by Schneider Electric GUIc…Feb 6, 2019›
CVE-2018-7813HIGH
7.8
A Type Confusion (CWE-843) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold…Feb 6, 2019›
CVE-2018-17913HIGH
7.8
A type confusion vulnerability exists when processing project files in Omron CX-Supervisor Versions …Nov 5, 2018›
CVE-2018-17909HIGH
7.8
When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior, the application fai…Nov 5, 2018›
CVE-2018-17905HIGH
7.8
When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with a…Nov 5, 2018›
CVE-2018-7799HIGH
7.8
A DLL hijacking vulnerability exists in Schneider Electric Software Update (SESU), all versions prio…Nov 2, 2018›
CVE-2018-14828HIGH
7.8
Advantech WebAccess 8.3.1 and earlier has an improper privilege management vulnerability, which may …Oct 23, 2018›
CVE-2018-14800HIGH
7.8
Delta Electronics ISPSoft version 3.0.5 and prior allow an attacker, by opening a crafted file, to c…Oct 3, 2018›
CVE-2018-13806HIGH
7.8
A vulnerability has been identified in SIEMENS TD Keypad Designer (All versions). A DLL hijacking vu…Sep 12, 2018›
CVE-2018-10616HIGH
7.8
ABB Panel Builder 800 all versions has an improper input validation vulnerability which may allow an…Jul 18, 2018›
CVE-2018-4858HIGH
7.8
A vulnerability has been identified in IEC 61850 system configurator (All versions < V5.80), DIGSI 5…Jul 9, 2018›
CVE-2018-8841HIGH
7.8
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAcc…May 15, 2018›
CVE-2017-6015HIGH
7.8
Without quotation marks, any whitespace in the file path for Rockwell Automation FactoryTalk Activat…May 11, 2018›
CVE-2017-5175HIGH
7.8
Advantech WebAccess 8.1 and earlier contains a DLL hijacking vulnerability which may allow an attack…May 9, 2018›
CVE-2018-8839HIGH
7.8
Delta PMSoft versions 2.10 and prior have multiple stack-based buffer overflow vulnerabilities where…Apr 30, 2018›
CVE-2018-8837HIGH
7.8
Processing specially crafted .pm3 files in Advantech WebAccess HMI Designer 2.1.7.32 and prior may c…Apr 25, 2018›
CVE-2018-8835HIGH
7.8
Double free vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by process…Apr 25, 2018›
CVE-2018-8833HIGH
7.8
Heap-based buffer overflow vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior ca…Apr 25, 2018›
CVE-2018-8834HIGH
7.8
Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following app…Apr 17, 2018›
CVE-2018-7530HIGH
7.8
Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following app…Apr 17, 2018›
CVE-2018-7514HIGH
7.8
Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following app…Apr 17, 2018›
CVE-2018-7502HIGH
7.8
Kernel drivers in Beckhoff TwinCAT 3.1 Build 4022.4, TwinCAT 2.11 R3 2259, and TwinCAT 3.1 lack prop…Mar 23, 2018›
CVE-2018-5476HIGH
7.8
A Stack-based Buffer Overflow issue was discovered in Delta Electronics Delta Industrial Automation …Mar 15, 2018›
CVE-2017-16751HIGH
7.8
A Stack-based Buffer Overflow issue was discovered in Delta Electronics Delta Industrial Automation …Mar 15, 2018›
CVE-2017-16749HIGH
7.8
A Use-after-Free issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor…Mar 15, 2018›
CVE-2017-16747HIGH
7.8
An Out-of-bounds Write issue was discovered in Delta Electronics Delta Industrial Automation Screen …Mar 15, 2018›
CVE-2017-16745HIGH
7.8
A Type Confusion issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor…Mar 15, 2018›
CVE-2018-7239HIGH
7.8
A DLL hijacking vulnerability exists in Schneider Electric's SoMove Software and associated DTM soft…Mar 9, 2018›
CVE-2018-1168HIGH
7.8
This vulnerability allows local attackers to escalate privileges on vulnerable installations of ABB …Feb 21, 2018›
CVE-2017-9967HIGH
7.8
A security misconfiguration vulnerability exists in Schneider Electric's IGSS SCADA Software version…Feb 12, 2018›
CVE-2018-5441HIGH
7.8
An Improper Validation of Integrity Check Value issue was discovered in PHOENIX CONTACT mGuard firmw…Jan 30, 2018›
CVE-2017-14030HIGH
7.8
An issue was discovered in Moxa MXview v2.8 and prior. The unquoted service path escalation vulnerab…Jan 12, 2018›
CVE-2017-12705HIGH
7.8
A Heap-Based Buffer Overflow issue was discovered in Advantech WebOP. A maliciously crafted project …Oct 25, 2017›
CVE-2017-9961HIGH
7.8
A vulnerability exists in Schneider Electric's Pro-Face GP Pro EX version 4.07.000 that allows an at…Sep 26, 2017›
CVE-2017-9958HIGH
7.8
An improper access control vulnerability exists in Schneider Electric's U.motion Builder software ve…Sep 26, 2017›
CVE-2017-12717HIGH
7.8
An Uncontrolled Search Path Element issue was discovered in Advantech WebAccess versions prior to V8…Aug 30, 2017›
CVE-2017-12713HIGH
7.8
An Incorrect Permission Assignment for Critical Resource issue was discovered in Advantech WebAccess…Aug 30, 2017›
CVE-2017-12711HIGH
7.8
An Incorrect Privilege Assignment issue was discovered in Advantech WebAccess versions prior to V8.2…Aug 30, 2017›
CVE-2017-9942HIGH
7.8
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could a…Aug 8, 2017›
CVE-2017-7968HIGH
7.8
An Incorrect Default Permissions issue was discovered in Schneider Electric Wonderware InduSoft Web …May 19, 2017›
CVE-2017-6033HIGH
7.8
A DLL Hijacking issue was discovered in Schneider Electric Interactive Graphical SCADA System (IGSS)…Apr 7, 2017›
CVE-2016-9356HIGH
7.8
An issue was discovered in Moxa DACenter Versions 1.4 and older. The application may suffer from an …Feb 13, 2017›
CVE-2016-9353HIGH
7.8
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The admin password is …Feb 13, 2017›
CVE-2016-8566HIGH
7.8
An issue was discovered in Siemens SICAM PAS before 8.00. Because of Storing Passwords in a Recovera…Feb 13, 2017›
CVE-2016-5805HIGH
7.8
An issue was discovered in Delta Electronics WPLSoft, Versions prior to V2.42.11, ISPSoft, Versions …Feb 13, 2017›
CVE-2016-5802HIGH
7.8
An issue was discovered in Delta Electronics WPLSoft, Versions prior to V2.42.11, ISPSoft, Versions …Feb 13, 2017›
CVE-2016-6486HIGH
7.8
Siemens SINEMA Server uses weak permissions for the application folder, which allows local users to …Aug 8, 2016›
CVE-2015-3938HIGH
7.8
The HTTP application on Mitsubishi Electric MELSEC FX3G PLC devices before April 2015 allows remote …Oct 6, 2015›
CVE-2015-2177HIGH
7.8
Siemens SIMATIC S7-300 CPU devices allow remote attackers to cause a denial of service (defect-mode …Mar 7, 2015›
CVE-2014-9369HIGH
7.8
Siemens SPC controllers SPC4000, SPC5000, and SPC6000 before 3.6.0 allow remote attackers to cause a…Mar 7, 2015›
CVE-2014-8478HIGH
7.8
The web server on Siemens SCALANCE X-300 switches with firmware before 4.0 and SCALANCE X 408 switch…Jan 21, 2015›
CVE-2014-2380HIGH
7.8
Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encrypti…Aug 28, 2014›
CVE-2014-2258HIGH
7.8
Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a d…Mar 24, 2014›
CVE-2014-2254HIGH
7.8
Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a d…Mar 24, 2014›
CVE-2014-2256HIGH
7.8
Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a d…Mar 24, 2014›
CVE-2014-2259HIGH
7.8
Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a…Mar 16, 2014›
CVE-2014-2257HIGH
7.8
Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a…Mar 16, 2014›
CVE-2014-2255HIGH
7.8
Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a…Mar 16, 2014›
CVE-2013-2824HIGH
7.8
Schneider Electric StruxureWare SCADA Expert Vijeo Citect 7.40, Vijeo Citect 7.20 through 7.30SP1, C…Feb 26, 2014›
CVE-2014-1966HIGH
7.8
The SNMP implementation in Siemens RuggedCom ROS before 3.11, ROS 3.11 for RS950G, ROS 3.12 before 3…Feb 24, 2014›
CVE-2013-4780HIGH
7.8
core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Co…Jul 18, 2013›
CVE-2013-4778HIGH
7.8
core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Co…Jul 18, 2013›
CVE-2013-2780HIGH
7.8
Siemens SIMATIC S7-1200 PLCs 2.x and 3.x allow remote attackers to cause a denial of service (defect…Apr 22, 2013›
CVE-2013-0700HIGH
7.8
Siemens SIMATIC S7-1200 PLCs 2.x and 3.x allow remote attackers to cause a denial of service (defect…Apr 22, 2013›
CVE-2012-4714HIGH
7.8
Integer overflow in RNADiagnostics.dll in Rockwell Automation FactoryTalk Services Platform (FTSP) C…Apr 18, 2013›
CVE-2012-4713HIGH
7.8
Integer signedness error in RNADiagnostics.dll in Rockwell Automation FactoryTalk Services Platform …Apr 18, 2013›
CVE-2013-1627HIGH
7.8
Absolute path traversal vulnerability in NTWebServer.exe in Indusoft Studio 7.0 and earlier and Adva…Mar 11, 2013›
CVE-2012-4706HIGH
7.8
Integer signedness error in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to cau…Feb 24, 2013›
CVE-2012-6442HIGH
7.8
When an affected product receives a valid CIP message from an unauthorized or unintended source to P…Jan 24, 2013›
CVE-2012-6438HIGH
7.8
The device does not properly validate the data being sent to the buffer. An attacker can send a malf…Jan 24, 2013›
CVE-2012-6436HIGH
7.8
The device does not properly validate the data being sent to the buffer. An attacker can send a malf…Jan 24, 2013›
CVE-2012-6435HIGH
7.8
When an affected product receives a valid CIP message from an unauthorized or unintended source to P…Jan 24, 2013›
CVE-2012-3017HIGH
7.8
Siemens SIMATIC S7-400 PN CPU devices with firmware 5.x allow remote attackers to cause a denial of …Jul 31, 2012›
CVE-2012-3016HIGH
7.8
Siemens SIMATIC S7-400 PN CPU devices with firmware 6 before 6.0.3 allow remote attackers to cause a…Jul 31, 2012›
CVE-2012-1802HIGH
7.8
Buffer overflow in the embedded web server on the Siemens Scalance X Industrial Ethernet switch X414…Apr 18, 2012›
CVE-2011-4878HIGH
7.8
Directory traversal vulnerability in miniweb.exe in the HMI web server in Siemens WinCC flexible 200…Feb 3, 2012›
CVE-2010-2772HIGH
7.8
Siemens Simatic WinCC and PCS 7 SCADA system uses a hard-coded password, which allows local users to…Jul 22, 2010›
CVE-2010-2568HIGH
7.8
Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R…Jul 22, 2010›
CVE-2009-3322HIGH
7.8
The Siemens Gigaset SE361 WLAN router allows remote attackers to cause a denial of service (device r…Sep 23, 2009›
CVE-2008-7065HIGH
7.8
Siemens C450 IP and C475 IP VoIP devices allow remote attackers to cause a denial of service (discon…Aug 25, 2009›
CVE-2008-1546HIGH
7.8
servlet/MIMEReceiveServlet in the web controller for Mitsubishi Electric GB-50 and GB-50A air-condit…Mar 28, 2008›
CVE-2008-1267HIGH
7.8
The Siemens SpeedStream 6520 router allows remote attackers to cause a denial of service (web interf…Mar 10, 2008›
CVE-2003-1464HIGH
7.8
Buffer overflow in Siemens 45 series mobile phones allows remote attackers to cause a denial of serv…Dec 31, 2003›
CVE-2025-10089HIGH
7.7
Uncontrolled Search Path Element Vulnerability in Setting and Operation Application for Lighting Con…Nov 18, 2025›
CVE-2024-48844HIGH
7.7
Denial of Service vulnerabilities where found providing a potiential for device service disruptions.…Dec 5, 2024›
CVE-2024-48843HIGH
7.7
Denial of Service vulnerabilities where found providing a potiential for device service disruptions.…Dec 5, 2024›
CVE-2024-7847HIGH
7.7
VULNERABILITY DETAILS Rockwell Automation used the latest versions of the CVSS scoring system to as…Oct 14, 2024›
CVE-2022-4048HIGH
7.7
Inadequate Encryption Strength in CODESYS Development System V3 versions prior to V3.5.18.40 allows …May 15, 2023›
CVE-2022-2464HIGH
7.7
Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Tra…Aug 25, 2022›
CVE-2022-1159HIGH
7.7
Rockwell Automation Studio 5000 Logix Designer (all versions) are vulnerable when an attacker who ac…Apr 1, 2022›
CVE-2021-27471HIGH
7.7
The parsing mechanism that processes certain file types does not provide input sanitization for file…Mar 23, 2022›
CVE-2021-35529HIGH
7.7
Insufficiently Protected Credentials vulnerability in client environment of Hitachi ABB Power Grids …Aug 20, 2021›
CVE-2020-13550HIGH
7.7
A local file inclusion vulnerability exists in the installation functionality of Advantech WebAccess…Feb 17, 2021›
CVE-2016-4514HIGH
7.7
Moxa PT-7728 devices with software 3.4 build 15081113 allow remote authenticated users to change the…Jun 19, 2016›
CVE-2015-3977HIGH
7.7
Buffer overflow in Schneider Electric IMT25 Magnetic Flow DTM before 1.500.004 for the HART Protocol…Nov 15, 2015›
CVE-2012-1801HIGH
7.7
Multiple stack-based buffer overflows in (1) COM and (2) ActiveX controls in ABB WebWare Server, Web…Apr 18, 2012›
CVE-2025-48891HIGH
7.6
A vulnerability exists in Advantech iView that could allow for SQL injection through the CUtils.che…Jul 11, 2025›
CVE-2023-1257HIGH
7.6
An attacker with physical access to the affected Moxa UC Series devices can initiate a restart of th…Mar 7, 2023›
CVE-2019-19094HIGH
7.6
Lack of input checks for SQL queries in ABB eSOMS versions 3.9 to 6.0.3 might allow an attacker SQL …Apr 2, 2020›
CVE-2014-2717HIGH
7.6
Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe contro…Jul 24, 2014›
CVE-2012-4694HIGH
7.6
Moxa EDR-G903 series routers with firmware before 2.11 do not use a sufficient source of entropy for…Feb 15, 2013›
CVE-2026-3631HIGH
7.5
Delta Electronics COMMGR2 has Buffer Over-read DoS vulnerability.Mar 9, 2026›
CVE-2024-55027HIGH
7.5
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext i…Mar 3, 2026›
CVE-2024-55021HIGH
7.5
Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in …Mar 3, 2026›
CVE-2024-55019HIGH
7.5
Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version…Mar 3, 2026›
CVE-2025-66598HIGH
7.5
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This prod…Feb 9, 2026›
CVE-2025-66597HIGH
7.5
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This prod…Feb 9, 2026›
CVE-2025-66608HIGH
7.5
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This prod…Feb 9, 2026›
CVE-2025-13373HIGH
7.5
Advantech iView versions 5.7.05.7057 and prior do not properly sanitize SNMP v1 trap (Port 162) requ…Dec 4, 2025›
CVE-2025-41738HIGH
7.5
An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime…Dec 1, 2025›
CVE-2022-50594HIGH
7.5
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP managem…Nov 6, 2025›
CVE-2025-7731HIGH
7.5
Cleartext Transmission of Sensitive Information vulnerability in Mitsubishi Electric Corporation MEL…Sep 1, 2025›
CVE-2025-8754HIGH
7.5
Missing Authentication for Critical Function vulnerability in ABB ABB AbilityTM zenon.This issue aff…Aug 13, 2025›
CVE-2025-41691HIGH
7.5
An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Co…Aug 4, 2025›
CVE-2025-2520HIGH
7.5
The Honeywell Experion PKS contains an Uninitialized Variable in the common Epic Platform Analyzer (…Jul 10, 2025›
CVE-2025-6073HIGH
7.5
Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface…Jul 3, 2025›
CVE-2025-6072HIGH
7.5
Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interfa…Jul 3, 2025›
CVE-2025-3511HIGH
7.5
Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation …Apr 25, 2025›
CVE-2025-1468HIGH
7.5
An unauthenticated remote attacker can gain access to sensitive information including authentication…Mar 18, 2025›
CVE-2024-8603HIGH
7.5
A “Use of a Broken or Risky Cryptographic Algorithm” vulnerability in the SSL/TLS component used in …Jan 15, 2025›
CVE-2024-51546HIGH
7.5
Credentials Disclosure vulnerabilities allow access to on board project back-up bundles.  Affected p…Dec 5, 2024›
CVE-2024-11316HIGH
7.5
Fileszie Check vulnerabilities allow a malicious user to bypass size limits or overload to the produ…Dec 5, 2024›
CVE-2024-9404HIGH
7.5
This vulnerability could lead to denial-of-service or service crashes. Exploitation of the moxa_cmd …Dec 4, 2024›
CVE-2023-52335HIGH
7.5
Advantech iView ConfigurationServlet SQL Injection Information Disclosure Vulnerability. This vulner…Nov 22, 2024›
CVE-2024-8403HIGH
7.5
Improper Validation of Specified Type of Input vulnerability in Mitsubishi Electric Corporation MELS…Nov 19, 2024›
CVE-2024-48989HIGH
7.5
A vulnerability in the PROFINET stack implementation of the IndraDrive (all versions) of Bosch Rexro…Nov 13, 2024›
CVE-2024-9124HIGH
7.5
A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 600T. If the device i…Oct 8, 2024›
CVE-2024-8626HIGH
7.5
Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected p…Oct 8, 2024›
CVE-2024-8175HIGH
7.5
An unauthenticated remote attacker can causes the CODESYS web server to access invalid memory which …Sep 25, 2024›
CVE-2024-6077HIGH
7.5
A denial-of-service vulnerability exists in the Rockwell Automation affected products when specially…Sep 12, 2024›
CVE-2024-7986HIGH
7.5
A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor…Aug 23, 2024›
CVE-2024-5800HIGH
7.5
Diffie-Hellman groups with insufficient strength are used in the SSL/TLS stack of B&R Automation Run…Aug 12, 2024›
CVE-2024-6089HIGH
7.5
An input validation vulnerability exists in the Rockwell Automation 5015 - AENFTXT when a manipulate…Jul 16, 2024›
CVE-2024-5990HIGH
7.5
Due to an improper input validation, an unauthenticated threat actor can send a malicious message to…Jun 25, 2024›
CVE-2024-37368HIGH
7.5
A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vuln…Jun 14, 2024›
CVE-2024-37367HIGH
7.5
A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The …Jun 14, 2024›
CVE-2024-5000HIGH
7.5
An unauthenticated remote attacker can use a malicious OPC UA client to send a crafted request to af…Jun 4, 2024›
CVE-2024-4549HIGH
7.5
A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. Whe…May 6, 2024›
CVE-2023-27336HIGH
7.5
Softing edgeConnector Siemens OPC UA Server Null Pointer Dereference Denial-of-Service Vulnerability…May 3, 2024›
CVE-2023-27334HIGH
7.5
Softing edgeConnector Siemens ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. …May 3, 2024›
CVE-2024-2424HIGH
7.5
An input validation vulnerability exists in the Rockwell Automation 5015-AENFTXT that causes the se…Apr 15, 2024›
CVE-2023-5392HIGH
7.5
C300 information leak due to an analysis feature which allows extracting more memory over the networ…Apr 11, 2024›
CVE-2024-0335HIGH
7.5
ABB has internally identified a vulnerability in the ABB VPNI feature of the S+ Control API componen…Apr 3, 2024›
CVE-2024-2427HIGH
7.5
A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper …Mar 25, 2024›
CVE-2024-2426HIGH
7.5
A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper …Mar 25, 2024›
CVE-2024-2425HIGH
7.5
A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper …Mar 25, 2024›
CVE-2023-6942HIGH
7.5
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation EZSock…Jan 30, 2024›
CVE-2023-43817HIGH
7.5
A buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when par…Jan 18, 2024›
CVE-2023-5592HIGH
7.5
Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT…Dec 14, 2023›
CVE-2023-46143HIGH
7.5
Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows a…Dec 14, 2023›
CVE-2023-5188HIGH
7.5
The MMS Interpreter of WagoAppRTU in versions below 1.4.6.0 which is used by the WAGO Telecontrol Co…Dec 5, 2023›
CVE-2023-47279HIGH
7.5
In Delta Electronics InfraSuite Device Master v.1.0.7, A vulnerability exists that allows an unauthe…Nov 30, 2023›
CVE-2023-46590HIGH
7.5
A vulnerability has been identified in Siemens OPC UA Modelling Editor (SiOME) (All versions < V2.8)…Nov 14, 2023›
CVE-2023-46289HIGH
7.5
Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could …Oct 27, 2023›
CVE-2023-2915HIGH
7.5
The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerabi…Aug 17, 2023›
CVE-2023-2914HIGH
7.5
The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerabi…Aug 17, 2023›
CVE-2023-37860HIGH
7.5
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote unauthenticated a…Aug 9, 2023›
CVE-2023-0525HIGH
7.5
Weak Encoding for Password vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 mode…Aug 4, 2023›
CVE-2023-34429HIGH
7.5
Weintek Weincloud v0.13.6 could allow an attacker to cause a denial-of-service condition for …Jul 19, 2023›
CVE-2023-2913HIGH
7.5
An executable used in Rockwell Automation ThinManager ThinServer can be configured to enable an API…Jul 18, 2023›
CVE-2023-2263HIGH
7.5
The Rockwell Automation Kinetix 5700 DC Bus Power Supply Series A is vulnerable to CIP fuzzing.  Th…Jul 18, 2023›
CVE-2023-26597HIGH
7.5
Controller DoS due to buffer overflow in the handling of a specially crafted message received by the…Jul 13, 2023›
CVE-2023-25948HIGH
7.5
Server information leak of configuration data when an error is generated in response to a specially …Jul 13, 2023›
CVE-2023-3596HIGH
7.5
Where this vulnerability exists in the Rockwell Automation 1756-EN4* Ethernet/IP communication prod…Jul 12, 2023›
CVE-2023-2846HIGH
7.5
Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F…Jun 30, 2023›
CVE-2023-1150HIGH
7.5
Uncontrolled resource consumption in Series WAGO 750-3x/-8x products may allow an unauthenticated re…Jun 26, 2023›
CVE-2023-2778HIGH
7.5
A denial-of-service vulnerability exists in Rockwell Automation FactoryTalk Transaction Manager. Th…Jun 13, 2023›
CVE-2023-2060HIGH
7.5
Weak Password Requirements vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC i…Jun 2, 2023›
CVE-2023-1618HIGH
7.5
Active Debug Code vulnerability in Mitsubishi Electric Corporation MELSEC WS Series WS0-GETH00200 Se…May 19, 2023›
CVE-2022-47391HIGH
7.5
In multiple CODESYS products in multiple versions an unauthorized, remote attacker may use a imprope…May 15, 2023›
CVE-2023-2443HIGH
7.5
Rockwell Automation ThinManager product allows the use of medium strength ciphers.  If the client r…May 11, 2023›
CVE-2023-1285HIGH
7.5
Signal Handler Race Condition vulnerability in Mitsubishi Electric India GC-ENET-COM whose first 2 d…Apr 14, 2023›
CVE-2023-1142HIGH
7.5
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could use URL dec…Mar 27, 2023›
CVE-2023-1138HIGH
7.5
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain an improper access contro…Mar 27, 2023›
CVE-2023-27857HIGH
7.5
In affected versions, a heap-based buffer over-read condition occurs when the message field indica…Mar 22, 2023›
CVE-2023-27856HIGH
7.5
In affected versions, path traversal exists when processing a message of type 8 in Rockwell Aut…Mar 22, 2023›
CVE-2023-0457HIGH
7.5
Plaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series,…Mar 3, 2023›
CVE-2022-40693HIGH
7.5
A cleartext transmission vulnerability exists in the web application functionality of Moxa SDS-3008 …Feb 7, 2023›
CVE-2022-40224HIGH
7.5
A denial of service vulnerability exists in the web server functionality of Moxa SDS-3008 Series Ind…Feb 7, 2023›
CVE-2022-33323HIGH
7.5
Active Debug Code vulnerability in robot controller of Mitsubishi Electric Corporation industrial ro…Feb 2, 2023›
CVE-2020-12067HIGH
7.5
In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's passw…Dec 26, 2022›
CVE-2022-33324HIGH
7.5
Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R S…Dec 23, 2022›
CVE-2022-3166HIGH
7.5
Rockwell Automation was made aware that the webservers of the Micrologix 1100 and 1400 controllers …Dec 16, 2022›
CVE-2022-29831HIGH
7.5
Use of Hard-coded Password vulnerability in Mitsubishi Electric Corporation GX Works3 versions from …Nov 25, 2022›
CVE-2022-3480HIGH
7.5
A remote, unauthenticated attacker could cause a denial-of-service of PHOENIX CONTACT FL MGUARD and …Nov 15, 2022›
CVE-2021-34579HIGH
7.5
In Phoenix Contact: FL MGUARD DM version 1.12.0 and 1.13.0 access to the Apache web server being ins…Nov 9, 2022›
CVE-2021-34568HIGH
7.5
In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a special…Nov 9, 2022›
CVE-2022-41776HIGH
7.5
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users…Oct 31, 2022›
CVE-2022-41629HIGH
7.5
Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users…Oct 31, 2022›
CVE-2021-38399HIGH
7.5
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to relative path traver…Oct 28, 2022›
CVE-2022-38744HIGH
7.5
An unauthenticated attacker with network access to a victim's Rockwell Automation FactoryTalk Alarm…Oct 27, 2022›
CVE-2022-3281HIGH
7.5
WAGO Series PFC100/PFC200, Series Touch Panel 600, Compact Controller CC100 and Edge Controller in m…Oct 17, 2022›
CVE-2022-3323HIGH
7.5
An SQL injection vulnerability in Advantech iView 5.7.04.6469. The specific flaw exists within the C…Sep 27, 2022›
CVE-2022-2043HIGH
7.5
MOXA NPort 5110: Firmware Versions 2.10 is vulnerable to an out-of-bounds write that can cause the d…Aug 31, 2022›
CVE-2022-30313HIGH
7.5
Honeywell Experion PKS Safety Manager through 2022-05-06 has Missing Authentication for a Critical F…Jul 28, 2022›
CVE-2022-31205HIGH
7.5
In Omron CS series, CJ series, and CP series PLCs through 2022-05-18, the password for access to the…Jul 26, 2022›
CVE-2022-31204HIGH
7.5
Omron CS series, CJ series, and CP series PLCs through 2022-05-18 use cleartext passwords. They feat…Jul 26, 2022›
CVE-2022-29834HIGH
7.5
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mits…Jul 20, 2022›
CVE-2022-30792HIGH
7.5
In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows …Jul 11, 2022›
CVE-2022-30791HIGH
7.5
In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an u…Jul 11, 2022›
CVE-2022-33971HIGH
7.5
Authentication bypass by capture-replay vulnerability exists in Machine automation controller NX7 se…Jul 4, 2022›
CVE-2022-32284HIGH
7.5
Use of insufficiently random values vulnerability exists in Vnet/IP communication module VI461 of YO…Jul 4, 2022›
CVE-2022-31805HIGH
7.5
In the CODESYS Development System multiple components in multiple versions transmit the passwords fo…Jun 24, 2022›
CVE-2022-31804HIGH
7.5
The CODESYS Gateway Server V2 does not verifiy that the size of a request is within expected limits.…Jun 24, 2022›
CVE-2022-24946HIGH
7.5
Improper Resource Locking vulnerability in Mitsubishi Electric MELSEC iQ-R Series R12CCPU-V firmware…Jun 15, 2022›
CVE-2021-40392HIGH
7.5
An information disclosure vulnerability exists in the Web Application functionality of Moxa MXView S…Apr 14, 2022›
CVE-2022-22519HIGH
7.5
A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buff…Apr 7, 2022›
CVE-2022-22517HIGH
7.5
An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS prod…Apr 7, 2022›
CVE-2021-30065HIGH
7.5
On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and …Apr 3, 2022›
CVE-2021-30063HIGH
7.5
On Schneider Electric ConneXium Tofino OPCLSM TCSEFM0000 before 03.23 and Belden Tofino Xenon Securi…Apr 3, 2022›
CVE-2021-30062HIGH
7.5
On Schneider Electric ConneXium Tofino OPCLSM TCSEFM0000 before 03.23 and Belden Tofino Xenon Securi…Apr 3, 2022›
CVE-2021-32970HIGH
7.5
Data can be copied without validation in the built-in web server in Moxa NPort IAW5000A-I/O series f…Apr 1, 2022›
CVE-2021-32968HIGH
7.5
Two buffer overflows in the built-in web server in Moxa NPort IAW5000A-I/O Series firmware version 2…Apr 1, 2022›
CVE-2021-22277HIGH
7.5
Improper Input Validation vulnerability in ABB 800xA, Control Software for AC 800M, Control Builder …Apr 1, 2022›
CVE-2020-25178HIGH
7.5
ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using T…Mar 18, 2022›
CVE-2021-39364HIGH
7.5
Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow command spoofing (for camera…Feb 24, 2022›
CVE-2021-46082HIGH
7.5
Moxa TN-5900 v3.1 series routers, MGate 5109 v2.2 series protocol gateways, and MGate 5101-PBM-MN v2…Feb 18, 2022›
CVE-2021-22288HIGH
7.5
Improper Input Validation vulnerability in the ABB SPIET800 and PNI800 module allows an attacker to …Feb 4, 2022›
CVE-2021-22286HIGH
7.5
Improper Input Validation vulnerability in the ABB SPIET800 and PNI800 module allows an attacker to …Feb 4, 2022›
CVE-2021-22285HIGH
7.5
Improper Handling of Exceptional Conditions, Improper Check for Unusual or Exceptional Conditions vu…Feb 4, 2022›
CVE-2022-22510HIGH
7.5
Codesys Profinet in version V4.2.0.0 is prone to null pointer dereference that allows a denial of se…Feb 2, 2022›
CVE-2021-46559HIGH
7.5
The firmware on Moxa TN-5900 devices through 3.1 has a weak algorithm that allows an attacker to def…Jan 26, 2022›
CVE-2021-20608HIGH
7.5
Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric GX Works2 v…Dec 17, 2021›
CVE-2021-20611HIGH
7.5
Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELS…Dec 1, 2021›
CVE-2021-20610HIGH
7.5
Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric MELSEC iQ-R…Dec 1, 2021›
CVE-2021-20609HIGH
7.5
Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02C…Dec 1, 2021›
CVE-2021-34598HIGH
7.5
In Phoenix Contact FL MGUARD 1102 and 1105 in Versions 1.4.0, 1.4.1 and 1.5.0 the remote logging fun…Nov 10, 2021›
CVE-2021-34593HIGH
7.5
In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated c…Oct 26, 2021›
CVE-2021-34586HIGH
7.5
In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests may cause a Null pointer…Oct 26, 2021›
CVE-2021-34585HIGH
7.5
In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser err…Oct 26, 2021›
CVE-2021-34583HIGH
7.5
Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a den…Oct 26, 2021›
CVE-2018-16060HIGH
7.5
Mitsubishi Electric Europe B.V. SmartRTU devices allow remote attackers to obtain sensitive informat…Oct 15, 2021›
CVE-2021-38460HIGH
7.5
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 …Oct 12, 2021›
CVE-2021-38452HIGH
7.5
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 …Oct 12, 2021›
CVE-2021-34570HIGH
7.5
Multiple Phoenix Contact PLCnext control devices in versions prior to 2021.0.5 LTS are prone to a Do…Sep 27, 2021›
CVE-2021-34581HIGH
7.5
Missing Release of Resource after Effective Lifetime vulnerability in OpenSSL implementation of WAGO…Aug 31, 2021›
CVE-2021-20594HIGH
7.5
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Mitsubishi Electric MELS…Aug 6, 2021›
CVE-2021-36765HIGH
7.5
In CODESYS EtherNetIP before 4.1.0.0, specific EtherNet/IP requests may cause a null pointer derefer…Aug 4, 2021›
CVE-2021-36764HIGH
7.5
In CODESYS Gateway V3 before 3.5.17.10, there is a NULL Pointer Dereference. Crafted communication r…Aug 4, 2021›
CVE-2021-36763HIGH
7.5
In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties.Aug 3, 2021›
CVE-2021-33486HIGH
7.5
All versions of the CODESYS V3 Runtime Toolkit for VxWorks from version V3.5.8.0 and before version …Aug 3, 2021›
CVE-2021-35527HIGH
7.5
Password autocomplete vulnerability in the web application password field of Hitachi ABB Power Grids…Jul 14, 2021›
CVE-2021-33541HIGH
7.5
Phoenix Contact Classic Line Controllers ILC1x0 and ILC1x1 in all versions/variants are affected by …Jun 25, 2021›
CVE-2021-21005HIGH
7.5
In Phoenix Contact FL SWITCH SMCS series products in multiple versions if an attacker sends a hand-c…Jun 25, 2021›
CVE-2021-21002HIGH
7.5
In Phoenix Contact FL COMSERVER UNI in versions < 2.40 a invalid Modbus exception response can lead …Jun 25, 2021›
CVE-2021-33824HIGH
7.5
An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attackers can use slowhttpt…Jun 18, 2021›
CVE-2021-33823HIGH
7.5
An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attacker could send a huge …Jun 18, 2021›
CVE-2021-27196HIGH
7.5
Improper Input Validation vulnerability in Hitachi ABB Power Grids Relion 670 Series, Relion 670/650…Jun 14, 2021›
CVE-2021-26845HIGH
7.5
Information Exposure vulnerability in Hitachi ABB Power Grids eSOMS allows unauthorized user to gain…Jun 14, 2021›
CVE-2021-20591HIGH
7.5
Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric MELSEC iQ-R series CPU module…Jun 11, 2021›
CVE-2021-30195HIGH
7.5
CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation.May 25, 2021›
CVE-2021-30191HIGH
7.5
CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input.May 25, 2021›
CVE-2021-30186HIGH
7.5
CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow.May 25, 2021›
CVE-2020-27185HIGH
7.5
Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devi…May 14, 2021›
CVE-2021-20997HIGH
7.5
In multiple managed switches by WAGO in different versions it is possible to read out the password h…May 13, 2021›
CVE-2021-25849HIGH
7.5
An integer underflow was discovered in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, ver…May 10, 2021›
CVE-2021-25846HIGH
7.5
Improper validation of the ChassisID TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series…May 10, 2021›
CVE-2021-25845HIGH
7.5
Improper validation of the ChassisID TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series…May 10, 2021›
CVE-2021-29241HIGH
7.5
CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of ser…May 3, 2021›
CVE-2019-18231HIGH
7.5
Advantech Spectre RT ERT351 Versions 5.1.3 and prior logins and passwords are transmitted in clear t…Mar 17, 2021›
CVE-2020-24686HIGH
7.5
The vulnerabilities can be exploited to cause the web visualization component of the PLC to stop and…Feb 26, 2021›
CVE-2021-20588HIGH
7.5
Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineer…Feb 19, 2021›
CVE-2021-20587HIGH
7.5
Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module …Feb 19, 2021›
CVE-2021-22656HIGH
7.5
Advantech iView versions prior to v5.7.03.6112 are vulnerable to directory traversal, which may allo…Feb 11, 2021›
CVE-2021-22654HIGH
7.5
Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an…Feb 11, 2021›
CVE-2020-13573HIGH
7.5
A denial-of-service vulnerability exists in the Ethernet/IP server functionality of Rockwell Automat…Jan 7, 2021›
CVE-2020-25190HIGH
7.5
The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower stores and transmi…Dec 23, 2020›
CVE-2020-12516HIGH
7.5
Older firmware versions (FW1 up to FW10) of the WAGO PLC family 750-88x and 750-352 are vulnerable f…Dec 10, 2020›
CVE-2020-12524HIGH
7.5
Uncontrolled Resource Consumption can be exploited to cause the Phoenix Contact HMIs BTP 2043W, BTP …Dec 2, 2020›
CVE-2020-7524HIGH
7.5
Out-of-bounds Write vulnerability exists in Modicon M218 Logic Controller (V5.0.0.7 and prior) which…Aug 31, 2020›
CVE-2020-15806HIGH
7.5
CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation.Jul 22, 2020›
CVE-2020-12031HIGH
7.5
In all versions of FactoryTalk View SE, after bypassing memory corruption mechanisms found in the op…Jul 20, 2020›
CVE-2020-12015HIGH
7.5
A specially crafted communication packet sent to the affected systems could cause a denial-of-servic…Jul 16, 2020›
CVE-2020-12009HIGH
7.5
A specially crafted communication packet sent to the affected device could cause a denial-of-service…Jul 16, 2020›
CVE-2020-14499HIGH
7.5
Advantech iView, versions 5.6 and prior, has an improper access control vulnerability. Successful ex…Jul 15, 2020›
CVE-2020-5600HIGH
7.5
TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version …Jul 7, 2020›
CVE-2020-5598HIGH
7.5
TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version …Jul 7, 2020›
CVE-2020-5597HIGH
7.5
TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version …Jul 7, 2020›
CVE-2020-5596HIGH
7.5
TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version …Jul 7, 2020›
CVE-2020-12018HIGH
7.5
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. An out-of-bounds vulnerability exi…May 8, 2020›
CVE-2020-12014HIGH
7.5
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Input is not properly sanitized an…May 8, 2020›
CVE-2019-19100HIGH
7.5
A privilege escalation vulnerability in the upgrade service in B&R Automation Studio versions 4.0.x,…Apr 29, 2020›
CVE-2019-3942HIGH
7.5
Advantech WebAccess 8.3.4 does not properly restrict an RPC call that allows unauthenticated, remote…Apr 1, 2020›
CVE-2020-5527HIGH
7.5
When MELSOFT transmission port (UDP/IP) of Mitsubishi Electric MELSEC iQ-R series (all versions), ME…Mar 30, 2020›
CVE-2019-5105HIGH
7.5
An exploitable memory corruption vulnerability exists in the Name Service Client functionality of 3S…Mar 26, 2020›
CVE-2020-7001HIGH
7.5
In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the affected products use a weak cryptograp…Mar 24, 2020›
CVE-2020-6997HIGH
7.5
In Moxa EDS-G516E Series firmware, Version 5.2 or lower, sensitive information is transmitted over s…Mar 24, 2020›
CVE-2020-6979HIGH
7.5
In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the affected products use a hard-coded cryp…Mar 24, 2020›
CVE-2020-6993HIGH
7.5
In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or l…Mar 24, 2020›
CVE-2020-6987HIGH
7.5
In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or l…Mar 24, 2020›
CVE-2020-6983HIGH
7.5
In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or l…Mar 24, 2020›
CVE-2020-7003HIGH
7.5
In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Vers…Mar 24, 2020›
CVE-2019-18242HIGH
7.5
In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Vers…Mar 24, 2020›
CVE-2020-6988HIGH
7.5
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, …Mar 16, 2020›
CVE-2020-6984HIGH
7.5
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, …Mar 16, 2020›
CVE-2020-9464HIGH
7.5
A Denial-of-Service vulnerability exists in BECKHOFF Ethernet TCP/IP Bus Coupler BK9000. After an at…Mar 12, 2020›
CVE-2020-9435HIGH
7.5
PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002…Mar 12, 2020›
CVE-2019-5149HIGH
7.5
The WBM web application on firmwares prior to 03.02.02 and 03.01.07 on the WAGO PFC100 and PFC2000, …Mar 11, 2020›
CVE-2019-5134HIGH
7.5
An exploitable regular expression without anchors vulnerability exists in the Web-Based Management (…Mar 11, 2020›
CVE-2019-5107HIGH
7.5
A cleartext transmission vulnerability exists in the network communication functionality of WAGO e!C…Mar 11, 2020›
CVE-2019-9104HIGH
7.5
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 device…Mar 11, 2020›
CVE-2019-9101HIGH
7.5
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 device…Mar 11, 2020›
CVE-2019-9098HIGH
7.5
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 device…Mar 11, 2020›
CVE-2019-19279HIGH
7.5
A vulnerability has been identified in SIPROTEC 4 and SIPROTEC Compact relays equipped with EN100 Et…Mar 10, 2020›
CVE-2020-6986HIGH
7.5
In all versions of Omron PLC CJ Series, an attacker can send a series of specific data packets withi…Mar 5, 2020›
CVE-2019-18238HIGH
7.5
In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Vers…Feb 26, 2020›
CVE-2019-5148HIGH
7.5
An exploitable denial-of-service vulnerability exists in ServiceAgent functionality of the Moxa AWK-…Feb 25, 2020›
CVE-2019-5137HIGH
7.5
The usage of hard-coded cryptographic keys within the ServiceAgent binary allows for the decryption …Feb 25, 2020›
CVE-2018-16994HIGH
7.5
An issue was discovered on PHOENIX CONTACT AXL F BK PN <=1.0.4, AXL F BK ETH <= 1.12, and AXL F BK E…Feb 18, 2020›
CVE-2019-13537HIGH
7.5
The IEC870IP driver for AVEVA’s Vijeo Citect and Citect SCADA and Schneider Electric’s Power SCADA O…Jan 14, 2020›
CVE-2019-19707HIGH
7.5
On Moxa EDS-G508E, EDS-G512E, and EDS-G516E devices (with firmware through 6.0), denial of service c…Dec 11, 2019›
CVE-2019-5637HIGH
7.5
When Beckhoff TwinCAT is configured to use the Profinet driver, a denial of service of the controlle…Nov 21, 2019›
CVE-2019-18230HIGH
7.5
Honeywell equIP and Performance series IP cameras, multiple versions, A vulnerability exists where t…Oct 31, 2019›
CVE-2019-18228HIGH
7.5
Honeywell equIP series IP cameras Multiple equIP Series Cameras, A vulnerability exists in the affec…Oct 31, 2019›
CVE-2019-18227HIGH
7.5
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. XXE vulnerabilities exist that may allow disclos…Oct 31, 2019›
CVE-2019-14927HIGH
7.5
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-R…Oct 28, 2019›
CVE-2019-16901HIGH
7.5
Advantech WebAccess/HMI Designer 2.1.9.31 has Exception Handler Chain corruption starting at Unknown…Sep 26, 2019›
CVE-2019-16900HIGH
7.5
Advantech WebAccess/HMI Designer 2.1.9.31 has a User Mode Write AV starting at MSVCR90!memcpy+0x0000…Sep 26, 2019›
CVE-2019-16899HIGH
7.5
In Advantech WebAccess/HMI Designer 2.1.9.31, Data from a Faulting Address controls Code Flow starti…Sep 26, 2019›
CVE-2019-9009HIGH
7.5
An issue was discovered in 3S-Smart CODESYS before 3.5.15.0 . Crafted network packets cause the Cont…Sep 17, 2019›
CVE-2019-13532HIGH
7.5
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted…Sep 13, 2019›
CVE-2019-9012HIGH
7.5
An issue was discovered in 3S-Smart CODESYS V3 products. A crafted communication request may cause u…Aug 15, 2019›
CVE-2018-11424HIGH
7.5
There is Memory corruption in the web interface of Moxa OnCell G3470A-LTE Series version 1.6 Build 1…Jul 3, 2019›
CVE-2018-11423HIGH
7.5
There is Memory corruption in the web interface Moxa OnCell G3100-HSPA Series version 1.6 Build 1710…Jul 3, 2019›
CVE-2019-6571HIGH
7.5
A vulnerability has been identified in SIEMENS LOGO!8 (6ED1052-xyyxx-0BA8 FS:01 to FS:06 / Firmware …Jun 12, 2019›
CVE-2018-10691HIGH
7.5
An issue was discovered on Moxa AWK-3121 1.14 devices. It is intended that an administrator can down…Jun 7, 2019›
CVE-2019-10977HIGH
7.5
In Mitsubishi Electric MELSEC-Q series Ethernet module QJ71E71-100 serial number 20121 and prior, an…May 23, 2019›
CVE-2018-13994HIGH
7.5
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is vulnerable to a deni…May 7, 2019›
CVE-2019-10953HIGH
7.5
ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple v…Apr 17, 2019›
CVE-2018-16561HIGH
7.5
A vulnerability has been identified in SIMATIC S7-300 CPUs (All versions < V3.X.16). The affected CP…Apr 17, 2019›
CVE-2019-3941HIGH
7.5
Advantech WebAccess 8.3.4 allows unauthenticated, remote attackers to delete arbitrary files via IOC…Apr 9, 2019›
CVE-2014-5436HIGH
7.5
A directory traversal vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x be…Apr 8, 2019›
CVE-2019-6554HIGH
7.5
Advantech WebAccess/SCADA, Versions 8.3.5 and prior. An improper access control vulnerability may al…Apr 5, 2019›
CVE-2018-19016HIGH
7.5
Rockwell Automation EtherNet/IP Web Server Modules 1756-EWEB (includes 1756-EWEBK) Version 5.001 and…Mar 27, 2019›
CVE-2013-2805HIGH
7.5
Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3,…Mar 26, 2019›
CVE-2013-2807HIGH
7.5
Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3,…Mar 26, 2019›
CVE-2013-2806HIGH
7.5
Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3,…Mar 26, 2019›
CVE-2019-6520HIGH
7.5
Moxa IKS and EDS does not properly check authority on server side, which results in a read-only user…Mar 5, 2019›
CVE-2019-6518HIGH
7.5
Moxa IKS and EDS store plaintext passwords, which may allow sensitive information to be read by some…Mar 5, 2019›
CVE-2018-20026HIGH
7.5
Improper Communication Address Filtering exists in CODESYS V3 products versions prior V3.5.14.0.Feb 19, 2019›
CVE-2018-20025HIGH
7.5
Use of Insufficiently Random Values exists in CODESYS V3 products versions prior V3.5.14.0.Feb 19, 2019›
CVE-2019-6535HIGH
7.5
Mitsubishi Electric Q03/04/06/13/26UDVCPU: serial number 20081 and prior, Q04/06/13/26UDPVCPU: seria…Feb 5, 2019›
CVE-2018-18981HIGH
7.5
In Rockwell Automation FactoryTalk Services Platform 2.90 and earlier, a remote unauthenticated atta…Jan 24, 2019›
CVE-2018-20720HIGH
7.5
ABB Relion 630 devices 1.1 before 1.1.0.C0, 1.2 before 1.2.0.B3, and 1.3 before 1.3.0.A6 allow remot…Jan 16, 2019›
CVE-2018-16196HIGH
7.5
Multiple Yokogawa products that contain Vnet/IP Open Communication Driver (CENTUM CS 3000(R3.05.00 -…Jan 9, 2019›
CVE-2018-14820HIGH
7.5
Advantech WebAccess 8.3.1 and earlier has a .dll component that is susceptible to external control o…Oct 23, 2018›
CVE-2018-18390HIGH
7.5
User Enumeration in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1…Oct 19, 2018›
CVE-2018-17898HIGH
7.5
Yokogawa STARDOM Controllers FCJ,FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The contro…Oct 12, 2018›
CVE-2018-14827HIGH
7.5
Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. A remote, unauthenticated threat acto…Sep 20, 2018›
CVE-2018-14821HIGH
7.5
Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. This vulnerability may allow a remote…Sep 20, 2018›
CVE-2018-7792HIGH
7.5
A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M…Aug 29, 2018›
CVE-2018-7789HIGH
7.5
An Improper Check for Unusual or Exceptional Conditions vulnerability exists in Schneider Electric's…Aug 29, 2018›
CVE-2018-10632HIGH
7.5
In Moxa NPort 5210, 5230, and 5232 versions 2.9 build 17030709 and prior, the amount of resources re…Jul 24, 2018›
CVE-2018-7783HIGH
7.5
Schneider Electric SoMachine Basic prior to v1.6 SP1 suffers from an XML External Entity (XXE) vulne…Jul 3, 2018›
CVE-2018-7779HIGH
7.5
In Schneider Electric Wiser for KNX V2.1.0 and prior, homeLYnk V2.0.1 and prior; and spaceLYnk V2.1.…Jul 3, 2018›
CVE-2018-1000531HIGH
7.5
inversoft prime-jwt version prior to commit abb0d479389a2509f939452a6767dc424bb5e6ba contains a CWE-…Jun 26, 2018›
CVE-2018-7503HIGH
7.5
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAcc…May 15, 2018›
CVE-2018-7501HIGH
7.5
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAcc…May 15, 2018›
CVE-2018-7495HIGH
7.5
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAcc…May 15, 2018›
CVE-2018-10590HIGH
7.5
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAcc…May 15, 2018›
CVE-2017-14439HIGH
7.5
Exploitable denial of service vulnerabilities exists in the Service Agent functionality of Moxa EDR-…May 14, 2018›
CVE-2017-14438HIGH
7.5
Exploitable denial of service vulnerabilities exists in the Service Agent functionality of Moxa EDR-…May 14, 2018›
CVE-2017-14437HIGH
7.5
An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-81…May 14, 2018›
CVE-2017-14436HIGH
7.5
An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-81…May 14, 2018›
CVE-2017-14435HIGH
7.5
An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-81…May 14, 2018›
CVE-2017-12128HIGH
7.5
An exploitable information disclosure vulnerability exists in the Server Agent functionality of Moxa…May 14, 2018›
CVE-2017-6021HIGH
7.5
In Schneider Electric ClearSCADA 2014 R1 (build 75.5210) and prior, 2014 R1.1 (build 75.5387) and pr…May 14, 2018›
CVE-2018-7762HIGH
7.5
A vulnerability exists in the web services to process SOAP requests in Schneider Electric's Modicon …Apr 18, 2018›
CVE-2018-7759HIGH
7.5
A buffer overflow vulnerability exists in Schneider Electric's Modicon M340, Modicon Premium, Modico…Apr 18, 2018›
CVE-2014-8421HIGH
7.5
Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 allow rem…Apr 12, 2018›
CVE-2018-7506HIGH
7.5
The private key of the web server in Moxa MXview versions 2.8 and prior is able to be read and acces…Apr 6, 2018›
CVE-2018-7235HIGH
7.5
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions pri…Mar 9, 2018›
CVE-2018-7234HIGH
7.5
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions pri…Mar 9, 2018›
CVE-2018-5453HIGH
7.5
An Improper Handling of Length Parameter Inconsistency issue was discovered in Moxa OnCell G3100-HSP…Mar 5, 2018›
CVE-2017-16736HIGH
7.5
An Unrestricted Upload Of File With Dangerous Type issue was discovered in Advantech WebAccess versi…Jan 12, 2018›
CVE-2017-16753HIGH
7.5
An Improper Input Validation issue was discovered in Advantech WebAccess versions prior to 8.3. WebA…Jan 5, 2018›
CVE-2017-16728HIGH
7.5
An Untrusted Pointer Dereference issue was discovered in Advantech WebAccess versions prior to 8.3. …Jan 5, 2018›
CVE-2017-14022HIGH
7.5
An Improper Input Validation issue was discovered in Rockwell Automation FactoryTalk Alarms and Even…Dec 23, 2017›
CVE-2017-13699HIGH
7.5
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The password encryption method…Nov 23, 2017›
CVE-2017-13698HIGH
7.5
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. An attacker could extract publ…Nov 23, 2017›
CVE-2017-13703HIGH
7.5
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. A denial of service may occur.Nov 17, 2017›
CVE-2017-16719HIGH
7.5
An Injection issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, NPort 5110…Nov 16, 2017›
CVE-2017-16715HIGH
7.5
An Information Exposure issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4,…Nov 16, 2017›
CVE-2017-14028HIGH
7.5
A Resource Exhaustion issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, N…Nov 16, 2017›
CVE-2017-12719HIGH
7.5
An Untrusted Pointer Dereference issue was discovered in Advantech WebAccess versions prior to V8.2_…Nov 6, 2017›
CVE-2017-9946HIGH
7.5
A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers…Oct 23, 2017›
CVE-2017-9962HIGH
7.5
Schneider Electric's ClearSCADA versions released prior to August 2017 are susceptible to a memory a…Sep 26, 2017›
CVE-2017-7924HIGH
7.5
An Improper Input Validation issue was discovered in Rockwell Automation MicroLogix 1100 controllers…Sep 20, 2017›
CVE-2017-12734HIGH
7.5
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V1.81.2). …Aug 30, 2017›
CVE-2017-12710HIGH
7.5
A SQL Injection issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. By subm…Aug 30, 2017›
CVE-2017-9938HIGH
7.5
A vulnerability was discovered in Siemens SIMATIC Logon (All versions before V1.6) that could allow …Aug 8, 2017›
CVE-2017-7920HIGH
7.5
An Improper Authentication issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and p…Aug 7, 2017›
CVE-2017-9631HIGH
7.5
A Null Pointer Dereference issue was discovered in Schneider Electric Wonderware ArchestrA Logger, v…Jul 7, 2017›
CVE-2017-6017HIGH
7.5
A Resource Exhaustion issue was discovered in Schneider Electric Modicon M340 PLC BMXNOC0401, BMXNOE…Jun 30, 2017›
CVE-2017-7935HIGH
7.5
A Resource Exhaustion issue was discovered in Phoenix Contact GmbH mGuard firmware versions 8.3.0 to…May 19, 2017›
CVE-2017-7456HIGH
7.5
Moxa MXView 2.8 allows remote attackers to cause a Denial of Service by sending overly long junk pay…Apr 14, 2017›
CVE-2017-7455HIGH
7.5
Moxa MXView 2.8 allows remote attackers to read web server's private key file, no access control.Apr 14, 2017›
CVE-2016-8727HIGH
7.5
An exploitable information disclosure vulnerability exists in the Web Application functionality of M…Apr 13, 2017›
CVE-2016-8726HIGH
7.5
An exploitable null pointer dereference vulnerability exists in the Web Application /forms/web_runSc…Apr 13, 2017›
CVE-2016-8723HIGH
7.5
An exploitable null pointer dereference exists in the Web Application functionality of Moxa AWK-3131…Apr 13, 2017›
CVE-2016-8716HIGH
7.5
An exploitable Cleartext Transmission of Password vulnerability exists in the Web Application functi…Apr 12, 2017›
CVE-2017-6019HIGH
7.5
An issue was discovered in Schneider Electric Conext ComBox, model 865-1058, all firmware versions p…Apr 7, 2017›
CVE-2016-9367HIGH
7.5
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions pr…Feb 13, 2017›
CVE-2016-9349HIGH
7.5
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. An attacker could trav…Feb 13, 2017›
CVE-2016-9344HIGH
7.5
An issue was discovered in Moxa MiiNePort E1 versions prior to 1.8, E2 versions prior to 1.4, and E3…Feb 13, 2017›
CVE-2016-9332HIGH
7.5
An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. Moxa SoftCMS Webserver does n…Feb 13, 2017›
CVE-2016-8374HIGH
7.5
An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all v…Feb 13, 2017›
CVE-2016-8370HIGH
7.5
An issue was discovered in Mitsubishi Electric Automation MELSEC-Q series Ethernet interface modules…Feb 13, 2017›
CVE-2016-8346HIGH
7.5
An issue was discovered in Moxa EDR-810 Industrial Secure Router. By accessing a specific uniform re…Feb 13, 2017›
CVE-2016-7987HIGH
7.5
An issue was discovered in Siemens ETA4 firmware (all versions prior to Revision 08) of the SM-2558 …Feb 13, 2017›
CVE-2016-9154HIGH
7.5
Siemens Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 for Desigo PX automation controllers PXC0…Dec 23, 2016›
CVE-2016-8563HIGH
7.5
Siemens Automation License Manager (ALM) before 5.3 SP3 Update 1 allows remote attackers to cause a …Oct 13, 2016›
CVE-2016-4526HIGH
7.5
ABB DataManagerPro 1.x before 1.7.1 allows local users to gain privileges by replacing a DLL file in…Sep 19, 2016›
CVE-2016-5874HIGH
7.5
Siemens SIMATIC NET PC-Software before 13 SP2 allows remote attackers to cause a denial of service (…Jul 22, 2016›
CVE-2016-5744HIGH
7.5
Siemens SIMATIC WinCC 7.0 through SP3 and 7.2 allows remote attackers to read arbitrary WinCC statio…Jul 22, 2016›
CVE-2016-3949HIGH
7.5
Siemens SIMATIC S7-300 Profinet-enabled CPU devices with firmware before 3.2.12 and SIMATIC S7-300 P…Jun 27, 2016›
CVE-2016-2295HIGH
7.5
Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with f…May 31, 2016›
CVE-2016-2286HIGH
7.5
Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with f…May 31, 2016›
CVE-2016-0879HIGH
7.5
Moxa Secure Router EDR-G903 devices before 3.4.12 do not delete copies of configuration and log file…May 31, 2016›
CVE-2016-0878HIGH
7.5
Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to cause a denial of servic…May 31, 2016›
CVE-2016-0877HIGH
7.5
Memory leak on Moxa Secure Router EDR-G903 devices before 3.4.12 allows remote attackers to cause a …May 31, 2016›
CVE-2016-0876HIGH
7.5
Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to discover cleartext passw…May 31, 2016›
CVE-2016-0875HIGH
7.5
Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to read configuration and l…May 31, 2016›
CVE-2016-2280HIGH
7.5
Buffer overflow in RDISERVER in Honeywell Uniformance Process History Database (PHD) R310, R320, and…Apr 21, 2016›
CVE-2016-2200HIGH
7.5
Siemens SIMATIC S7-1500 CPU devices before 1.8.3 allow remote attackers to cause a denial of service…Feb 8, 2016›
CVE-2016-0860HIGH
7.5
Buffer overflow in the BwpAlarm subsystem in Advantech WebAccess before 8.1 allows remote attackers …Jan 15, 2016›
CVE-2016-0855HIGH
7.5
Directory traversal vulnerability in Advantech WebAccess before 8.1 allows remote attackers to list …Jan 15, 2016›
CVE-2016-0853HIGH
7.5
Advantech WebAccess before 8.1 allows remote attackers to obtain sensitive information via crafted i…Jan 15, 2016›
CVE-2016-0852HIGH
7.5
Advantech WebAccess before 8.1 allows remote attackers to bypass an intended administrative requirem…Jan 15, 2016›
CVE-2016-0851HIGH
7.5
Advantech WebAccess before 8.1 allows remote attackers to cause a denial of service (out-of-bounds m…Jan 15, 2016›
CVE-2015-7375HIGH
7.5
Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code …Sep 25, 2015›
CVE-2015-7374HIGH
7.5
The Remote Agent component in Schneider Electric InduSoft Web Studio before 8.0 allows remote attack…Sep 25, 2015›
CVE-2015-6460HIGH
7.5
Multiple heap-based buffer overflows in 3S-Smart CODESYS Gateway Server before 2.3.9.34 allow remote…Sep 18, 2015›
CVE-2015-5698HIGH
7.5
Cross-site request forgery (CSRF) vulnerability in the web server on Siemens SIMATIC S7-1200 CPU dev…Aug 30, 2015›
CVE-2015-0986HIGH
7.5
Multiple stack-based buffer overflows in Moxa VPort ActiveX SDK Plus before 2.8 allow remote attacke…May 26, 2015›
CVE-2015-0982HIGH
7.5
Buffer overflow in an unspecified DLL in Schneider Electric Pelco DS-NVs before 7.8.90 allows remote…Mar 14, 2015›
CVE-2014-9200HIGH
7.5
Stack-based buffer overflow in an unspecified DLL file in a DTM development kit in Schneider Electri…Feb 1, 2015›
CVE-2014-8386HIGH
7.5
Multiple stack-based buffer overflows in Advantech AdamView 4.3 and earlier allow remote attackers t…Jan 20, 2015›
CVE-2014-8514HIGH
7.5
Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 all…Dec 27, 2014›
CVE-2014-8513HIGH
7.5
Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 all…Dec 27, 2014›
CVE-2014-8512HIGH
7.5
Buffer overflow in an ActiveX control in Atx45.ocx in Schneider Electric ProClima before 6.1.7 allow…Dec 27, 2014›
CVE-2014-5208HIGH
7.5
BKBCopyD.exe in the Batch Management Packages in Yokogawa CENTUM CS 3000 through R3.09.50 and CENTUM…Dec 22, 2014›
CVE-2014-8269HIGH
7.5
Multiple stack-based buffer overflows in (1) HWOPOSScale.ocx and (2) HWOPOSSCANNER.ocx in Honeywell …Dec 13, 2014›
CVE-2014-5424HIGH
7.5
Rockwell Automation Connected Components Workbench (CCW) before 7.00.00 allows remote attackers to c…Nov 14, 2014›
CVE-2014-5399HIGH
7.5
SQL injection vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1…Aug 28, 2014›
CVE-2014-5397HIGH
7.5
Cross-site scripting (XSS) vulnerability in Schneider Electric Wonderware Information Server (WIS) P…Aug 28, 2014›
CVE-2014-2368HIGH
7.5
The BrowseFolder method in the bwocxrun ActiveX control in Advantech WebAccess before 7.2 allows rem…Jul 19, 2014›
CVE-2014-2367HIGH
7.5
The ChkCookie subroutine in an ActiveX control in broadweb/include/gChkCook.asp in Advantech WebAcce…Jul 19, 2014›
CVE-2014-2364HIGH
7.5
Multiple stack-based buffer overflows in Advantech WebAccess before 7.2 allow remote attackers to ex…Jul 19, 2014›
CVE-2014-1697HIGH
7.5
The integrated web server in Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attacke…Feb 7, 2014›
CVE-2013-3958HIGH
7.5
The login implementation in the Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMAT…Jun 14, 2013›
CVE-2013-3957HIGH
7.5
SQL injection vulnerability in the login screen in the Web Navigator in Siemens WinCC before 7.2 Upd…Jun 14, 2013›
CVE-2012-3032HIGH
7.5
SQL injection vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC…Sep 18, 2012›
CVE-2012-0254HIGH
7.5
Stack-based buffer overflow in the HMIWeb Browser HSCDSPRenderDLL ActiveX control in Honeywell Proce…Sep 8, 2012›
CVE-2012-3020HIGH
7.5
The Siemens Synco OZW Web Server devices OZW672.*, OZW772.*, and OZW775 with firmware before 4 have …Aug 6, 2012›
CVE-2012-0244HIGH
7.5
Multiple SQL injection vulnerabilities in Advantech/BroadWin WebAccess before 7.0 allow remote attac…Feb 21, 2012›
CVE-2012-0234HIGH
7.5
SQL injection vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to ex…Feb 21, 2012›
CVE-2011-4521HIGH
7.5
SQL injection vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to ex…Feb 21, 2012›
CVE-2012-0929HIGH
7.5
Multiple buffer overflows in Schneider Electric Modicon Quantum PLC allow remote attackers to cause …Jan 28, 2012›
CVE-2011-4529HIGH
7.5
Multiple buffer overflows in Siemens Automation License Manager (ALM) 4.0 through 5.1+SP1+Upd1 allow…Jan 8, 2012›
CVE-2011-5008HIGH
7.5
Integer overflow in the GatewayService component in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attacke…Dec 25, 2011›
CVE-2010-0985HIGH
7.5
Directory traversal vulnerability in the Abbreviations Manager (com_abbrev) component 1.1 for Joomla…Mar 16, 2010›
CVE-2006-3344HIGH
7.5
Siemens Speedstream Wireless Router 2624 allows local users to bypass authentication and access prot…Jul 3, 2006›
CVE-2005-2424HIGH
7.5
The management interface for Siemens SANTIS 50 running firmware 4.2.8.0, and possibly other products…Aug 3, 2005›
CVE-2025-9970HIGH
7.4
Cleartext Storage of Sensitive Information in Memory vulnerability in ABB MConfig.This issue affects…Oct 8, 2025›
CVE-2023-5396HIGH
7.4
Server receiving a malformed message creates connection for a hostname that may cause a stack overfl…Apr 17, 2024›
CVE-2023-5394HIGH
7.4
Server receiving a malformed message that where the GCL message hostname may be too large which may …Apr 11, 2024›
CVE-2023-5393HIGH
7.4
Server receiving a malformed message that causes a disconnect to a hostname may causing a stack over…Apr 11, 2024›
CVE-2023-35134HIGH
7.4
Weintek Weincloud v0.13.6 could allow an attacker to reset a password with the corresponding ac…Jul 19, 2023›
CVE-2022-27048HIGH
7.4
A vulnerability has been discovered in Moxa MGate which allows an attacker to perform a man-in-the-m…Apr 15, 2022›
CVE-2021-34599HIGH
7.4
Affected versions of CODESYS Git in Versions prior to V1.1.0.0 lack certificate validation in HTTPS …Dec 1, 2021›
CVE-2021-21004HIGH
7.4
In Phoenix Contact FL SWITCH SMCS series products in multiple versions an attacker may insert malici…Jun 25, 2021›
CVE-2018-4849HIGH
7.4
A vulnerability has been identified in Siveillance VMS Video for Android (All versions < V12.1a (201…May 3, 2018›
CVE-2017-9941HIGH
7.4
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could a…Aug 8, 2017›
CVE-2017-6873HIGH
7.4
A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could…Aug 8, 2017›
CVE-2017-6870HIGH
7.4
A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before…Aug 8, 2017›
CVE-2017-2685HIGH
7.4
Siemens SINUMERIK Integrate Operate Clients between 2.0.3.00.016 (including) and 2.0.6 (excluding) a…Mar 1, 2017›
CVE-2026-2364HIGH
7.3
If a legitimate user confirms a self-update prompt or initiate an installation of a CODESYS Developm…Mar 10, 2026›
CVE-2025-11918HIGH
7.3
Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific fl…Nov 14, 2025›
CVE-2025-58320HIGH
7.3
Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.Sep 11, 2025›
CVE-2025-7405HIGH
7.3
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC…Sep 1, 2025›
CVE-2025-47728HIGH
7.3
Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a ma…Jun 4, 2025›
CVE-2025-47727HIGH
7.3
Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malic…Jun 4, 2025›
CVE-2025-47726HIGH
7.3
Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malic…Jun 4, 2025›
CVE-2025-47725HIGH
7.3
Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malic…Jun 4, 2025›
CVE-2025-47724HIGH
7.3
Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malic…Jun 4, 2025›
CVE-2024-9876HIGH
7.3
: Modification of Assumed-Immutable Data (MAID) vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.Th…Apr 30, 2025›
CVE-2024-12672HIGH
7.3
A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor…Dec 19, 2024›
CVE-2024-11364HIGH
7.3
Another “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Aren…Dec 19, 2024›
CVE-2024-11157HIGH
7.3
A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor…Dec 19, 2024›
CVE-2024-50376HIGH
7.3
A CWE-79 "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" was …Nov 26, 2024›
CVE-2023-3662HIGH
7.3
In CODESYS Development System versions from 3.5.17.0 and prior to 3.5.19.20 a vulnerability allows f…Aug 3, 2023›
CVE-2023-3670HIGH
7.3
In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe di…Jul 28, 2023›
CVE-2023-2637HIGH
7.3
Rockwell Automation's FactoryTalk System Services uses a hard-coded cryptographic key to generate a…Jun 13, 2023›
CVE-2023-2866HIGH
7.3
If an attacker can trick an authenticated user into loading a maliciously crafted .zip file onto Ad…Jun 7, 2023›
CVE-2019-6834HIGH
7.3
A CWE-502: Deserialization of Untrusted Data vulnerability exists which could allow an attacker to e…Apr 13, 2022›
CVE-2021-33540HIGH
7.3
In certain devices of the Phoenix Contact AXL F BK and IL BK product families an undocumented passwo…Jun 25, 2021›
CVE-2021-29242HIGH
7.3
CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send cra…May 3, 2021›
CVE-2020-12510HIGH
7.3
The default installation path of the TwinCAT XAR 3.1 software in all versions is underneath C:\TwinC…Nov 19, 2020›
CVE-2020-12028HIGH
7.3
In all versions of FactoryTalk View SEA remote, an authenticated attacker may be able to utilize cer…Jul 20, 2020›
CVE-2020-8473HIGH
7.3
Insufficient folder permissions used by system functions in ABB System 800xA Base (version 6.1 and e…Apr 29, 2020›
CVE-2019-7227HIGH
7.3
In the ABB IDAL FTP server, an authenticated attacker can traverse to arbitrary directories on the h…Jun 27, 2019›
CVE-2015-1014HIGH
7.3
A successful exploit of these vulnerabilities requires the local user to load a crafted DLL file in …Mar 25, 2019›
CVE-2016-8380HIGH
7.3
The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without aut…Apr 5, 2018›
CVE-2016-8371HIGH
7.3
The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authen…Apr 5, 2018›
CVE-2016-8366HIGH
7.3
Webvisit in Phoenix Contact ILC PLCs offers a password macro to protect HMI pages on the PLC against…Apr 5, 2018›
CVE-2017-9956HIGH
7.3
An authentication bypass vulnerability exists in Schneider Electric's U.motion Builder software vers…Sep 26, 2017›
CVE-2017-7965HIGH
7.3
A buffer overflow vulnerability exists in Programming Software executable AlTracePrint.exe, in Schne…Jun 7, 2017›
CVE-2017-5155HIGH
7.3
An issue was discovered in Schneider Electric Wonderware Historian 2014 R2 SP1 P01 and earlier. Wond…Feb 13, 2017›
CVE-2016-9363HIGH
7.3
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions pr…Feb 13, 2017›
CVE-2016-9334HIGH
7.3
An issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 controller 1763-L16AWA,…Feb 13, 2017›
CVE-2016-9156HIGH
7.3
A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to up…Dec 5, 2016›
CVE-2016-4860HIGH
7.3
Yokogawa STARDOM FCN/FCJ controller R1.01 through R4.01 does not require authentication for Logic De…Sep 19, 2016›
CVE-2016-5645HIGH
7.3
Rockwell Automation MicroLogix 1400 PLC 1766-L32BWA, 1766-L32AWA, 1766-L32BXB, 1766-L32BWAA, 1766-L3…Aug 24, 2016›
CVE-2016-4531HIGH
7.3
Rockwell Automation FactoryTalk EnergyMetrix before 2.20.00 does not invalidate credentials upon a l…Jul 28, 2016›
CVE-2016-4529HIGH
7.3
An unspecified ActiveX control in Schneider Electric SoMachine HVAC Programming Software for M171/M1…Jul 15, 2016›
CVE-2009-1152HIGH
7.3
Siemens Gigaset SE461 WiMAX router 1.5-BL024.9.6401, and possibly other versions, allows remote atta…Mar 26, 2009›
CVE-2026-2670HIGH
7.2
A vulnerability was identified in Advantech WISE-6610 1.2.1_20251110. Affected is an unknown functio…Feb 18, 2026›
CVE-2025-34239HIGH
7.2
Advantech WebAccess/VPN versions prior to 1.1.5 contain a command injection vulnerability in AppMana…Nov 6, 2025›
CVE-2022-50595HIGH
7.2
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP managem…Nov 6, 2025›
CVE-2022-50592HIGH
7.2
Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP managem…Nov 6, 2025›
CVE-2025-10207HIGH
7.2
Improper Validation of Specified Type of Input vulnerability in ABB FLXEON.This issue affects FLXEON…Sep 18, 2025›
CVE-2024-48851HIGH
7.2
Improper Validation of Specified Type of Input vulnerability in ABB FLXEON.A remote code execution i…Sep 18, 2025›
CVE-2024-9138HIGH
7.2
Moxa’s cellular routers, secure routers, and network security appliances are affected by a high-seve…Jan 3, 2025›
CVE-2024-50369HIGH
7.2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…Nov 26, 2024›
CVE-2024-50368HIGH
7.2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…Nov 26, 2024›
CVE-2024-50367HIGH
7.2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…Nov 26, 2024›
CVE-2024-50366HIGH
7.2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…Nov 26, 2024›
CVE-2024-50365HIGH
7.2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…Nov 26, 2024›
CVE-2024-50364HIGH
7.2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…Nov 26, 2024›
CVE-2024-50363HIGH
7.2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…Nov 26, 2024›
CVE-2024-50362HIGH
7.2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…Nov 26, 2024›
CVE-2024-50361HIGH
7.2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…Nov 26, 2024›
CVE-2024-50360HIGH
7.2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…Nov 26, 2024›
CVE-2024-50359HIGH
7.2
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')…Nov 26, 2024›
CVE-2024-50358HIGH
7.2
A CWE-15 "External Control of System or Configuration Setting" was discovered affecting the followin…Nov 26, 2024›
CVE-2021-22280HIGH
7.2
Improper DLL loading algorithms in B&R Automation Studio versions >=4.0 and <4.12 may allow an authe…May 14, 2024›
CVE-2023-37864HIGH
7.2
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNM…Aug 9, 2023›
CVE-2023-37863HIGH
7.2
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNM…Aug 9, 2023›
CVE-2023-37859HIGH
7.2
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 the SNMP daemon is running…Aug 9, 2023›
CVE-2023-37362HIGH
7.2
Weintek Weincloud v0.13.6 could allow an attacker to abuse the registration functionality to log…Jul 19, 2023›
CVE-2023-32628HIGH
7.2
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability t…Jun 6, 2023›
CVE-2023-32540HIGH
7.2
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, w…Jun 6, 2023›
CVE-2023-22450HIGH
7.2
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability tha…Jun 6, 2023›
CVE-2023-0636HIGH
7.2
Improper Input Validation vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux …Jun 5, 2023›
CVE-2022-42140HIGH
7.2
Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Command Injection via lform/net_diagnose.Dec 14, 2022›
CVE-2020-16244HIGH
7.2
GE Digital APM Classic, Versions 4.4 and prior. Salt is not used for hash calculation of passwords, …Sep 23, 2020›
CVE-2020-6090HIGH
7.2
An exploitable code execution vulnerability exists in the Web-Based Management (WBM) functionality o…Jun 11, 2020›
CVE-2020-6978HIGH
7.2
In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable due to the us…Mar 24, 2020›
CVE-2019-5157HIGH
7.2
An exploitable command injection vulnerability exists in the Cloud Connectivity functionality of WAG…Mar 11, 2020›
CVE-2019-5156HIGH
7.2
An exploitable command injection vulnerability exists in the cloud connectivity functionality of WAG…Mar 11, 2020›
CVE-2019-5155HIGH
7.2
An exploitable command injection vulnerability exists in the cloud connectivity feature of WAGO PFC2…Mar 11, 2020›
CVE-2019-5165HIGH
7.2
An exploitable authentication bypass vulnerability exists in the hostname processing of the Moxa AWK…Feb 25, 2020›
CVE-2019-5142HIGH
7.2
An exploitable command injection vulnerability exists in the hostname functionality of the Moxa AWK-…Feb 25, 2020›
CVE-2019-10969HIGH
7.2
Moxa EDR 810, all versions 5.1 and prior, allows an authenticated attacker to abuse the ping feature…Oct 8, 2019›
CVE-2017-9970HIGH
7.2
A remote code execution vulnerability exists in Schneider Electric's StruxureOn Gateway versions 1.1…Feb 12, 2018›
CVE-2017-5170HIGH
7.2
An Uncontrolled Search Path Element issue was discovered in Moxa SoftNVR-IA Live Viewer, Version 3.3…Jan 18, 2018›
CVE-2016-2281HIGH
7.2
Untrusted search path vulnerability in ABB Panel Builder 800 5.1 allows local users to gain privileg…Mar 18, 2016›
CVE-2016-2278HIGH
7.2
Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.…Mar 2, 2016›
CVE-2014-8388HIGH
7.2
Stack-based buffer overflow in Advantech WebAccess, formerly BroadWin WebAccess, before 8.0 allows r…Nov 21, 2014›
CVE-2013-4943HIGH
7.2
The client application in Siemens COMOS before 9.1 Update 458, 9.2 before 9.2.0.6.37, and 10.0 befor…Aug 9, 2013›
CVE-2011-3330HIGH
7.2
Buffer overflow in the UnitelWay Windows Device Driver, as used in Schneider Electric Unity Pro 6 an…Nov 4, 2011›
CVE-2003-1528HIGH
7.2
nsr_shutdown in Fujitsu Siemens NetWorker 6.0 allows local users to overwrite arbitrary files via a …Dec 31, 2003›
CVE-2025-3465HIGH
7.1
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB …Oct 20, 2025›
CVE-2025-5023HIGH
7.1
Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Corporation photovoltaic system m…Jul 10, 2025›
CVE-2025-3395HIGH
7.1
Incorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vu…Apr 30, 2025›
CVE-2024-48846HIGH
7.1
Cross Site Request Forgery vulnerabilities where found providing a potiential for exposing sensitive…Dec 5, 2024›
CVE-2023-43815HIGH
7.1
A buffer overflow vulnerability exists in Delta Electronics Delta Industrial Automation DOPSoft vers…Jan 18, 2024›
CVE-2023-0864HIGH
7.1
Cleartext Transmission of Sensitive Information vulnerability in ABB Terra AC wallbox (UL40/80A), AB…May 17, 2023›
CVE-2023-2444HIGH
7.1
A cross site request forgery vulnerability exists in Rockwell Automation's FactoryTalk Vantagepoint…May 11, 2023›
CVE-2023-1134HIGH
7.1
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a path traversal …Mar 27, 2023›
CVE-2022-46670HIGH
7.1
Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institu…Dec 16, 2022›
CVE-2022-0988HIGH
7.1
Delta Electronics DIAEnergie (Version 1.7.5 and prior) is vulnerable to cleartext transmission as th…Mar 25, 2022›
CVE-2021-20593HIGH
7.1
Incorrect Implementation of Authentication Algorithm in Mitsubishi Electric Air Conditioning System/…Jul 13, 2021›
CVE-2020-12010HIGH
7.1
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal v…May 8, 2020›
CVE-2019-5139HIGH
7.1
An exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities of the …Feb 25, 2020›
CVE-2019-18998HIGH
7.1
Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior t…Feb 17, 2020›
CVE-2019-18996HIGH
7.1
Path settings in HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier a…Dec 18, 2019›
CVE-2017-9966HIGH
7.1
A privilege escalation vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise vers…Jan 2, 2018›
CVE-2017-7929HIGH
7.1
An Absolute Path Traversal issue was discovered in Advantech WebAccess Version 8.1 and prior. The ab…May 6, 2017›
CVE-2014-5410HIGH
7.1
The DNP3 feature on Rockwell Automation Allen-Bradley MicroLogix 1400 1766-Lxxxxx A FRN controllers …Oct 3, 2014›
CVE-2014-5074HIGH
7.1
Siemens SIMATIC S7-1500 CPU devices with firmware before 1.6 allow remote attackers to cause a denia…Aug 17, 2014›
CVE-2014-0757HIGH
7.1
Smart Software Solutions (3S) CoDeSys Runtime Toolkit before 2.4.7.44 allows remote attackers to cau…Jan 31, 2014›
CVE-2012-3039HIGH
7.1
Moxa OnCell Gateway G3111, G3151, G3211, and G3251 devices with firmware before 1.4 do not use a suf…Aug 9, 2013›
CVE-2012-4695HIGH
7.1
LogReceiver.exe in Rockwell Automation RSLinx Enterprise CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR…Apr 18, 2013›
CVE-2012-4690HIGH
7.1
Rockwell Automation Allen-Bradley MicroLogix controller 1100, 1200, 1400, and 1500; SLC 500 controll…Dec 8, 2012›
CVE-2011-4877HIGH
7.1
HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka T…Feb 3, 2012›
CVE-2024-48842HIGH
7.0
Use of Hard-coded Credentials vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5 a…Sep 17, 2025›
CVE-2024-8300HIGH
7.0
Dead Code vulnerability in Mitsubishi Electric GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2…Nov 28, 2024›
CVE-2024-1182HIGH
7.0
Uncontrolled Search Path Element vulnerability in Mitsubishi Electric Iconics Digital Solutions GENE…Jul 4, 2024›
CVE-2023-3322HIGH
7.0
A vulnerability exists by allowing low-privileged users to read and update the data in various dire…Jul 24, 2023›
CVE-2023-3321HIGH
7.0
A vulnerability exists by allowing low-privileged users to read and update the data in various dire…Jul 24, 2023›
CVE-2023-29031HIGH
7.0
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product …May 11, 2023›
CVE-2023-29030HIGH
7.0
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product …May 11, 2023›
CVE-2023-29023HIGH
7.0
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product …May 11, 2023›
CVE-2019-5186HIGH
7.0
An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service "I/O…Mar 23, 2020›
CVE-2019-5185HIGH
7.0
An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service "I/O…Mar 23, 2020›
CVE-2019-11486HIGH
7.0
The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c in the Linux kernel before 5.0.8 h…Apr 23, 2019›
CVE-2017-5176HIGH
7.0
A DLL Hijack issue was discovered in Rockwell Automation Connected Components Workbench (CCW). The f…May 19, 2017›
CVE-2016-9351HIGH
7.0
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The directory traversa…Feb 13, 2017›
CVE-2016-8354HIGH
7.0
An issue was discovered in Schneider Electric Unity PRO prior to V11.1. Unity projects can be compil…Feb 13, 2017›