| CVE ID | CVSS Score | Severity | Description |
|---|---|---|---|
| CVE-2023-28004 | 0.0 | unknown |
No description available.
|
| CVE-2026-2404 | 0.0 | unknown |
CVE-2026-2404. CWE-116 Improper Encoding or Escaping of Output vulnerability exists that could cause log injection and
forged log when an attacker alters the POST /j_security check request payload.
|
| CVE-2026-9650 | 0.0 | unknown |
No description available.
|
| CVE-2026-9716 | 0.0 | unknown |
CVE-2026-9716. CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition,
rendering the device’s HMI and configuration functionality unavailable when malformed requests are received
over exposed network interfaces.
|
| CVE-2026-6865 | 0.0 | unknown |
CVE-2026-6865. CWE-22: Improper Limitation of a Pathname to a Restricted Directory (“Path Traversal”) vulnerability that could
cause unauthorized access to sensitive files when user-supplied input is improperly handled during server-side
file path processing.
|
| CVE-2026-4832 | 0.0 | unknown |
CVE-2026-4832. CWE-798 Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to sensitive device information when an unauthenticated attacker is able to interrogate the SNMP port.
|
| CVE-2026-8045 | 0.0 | unknown |
CVE-2026-8045. CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert user account submits crafted XML payloads to SOAP service endpoints
|
| CVE-2025-13901 | 0.0 | unknown |
CVE-2025-13901. CWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of
Service on Machine Expert protocol when an unauthenticated attacker sends malicious payload to occupy
active communication channels.
|
| CVE-2026-6866 | 0.0 | unknown |
CVE-2026-6866. CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause
unauthorized disclosure of sensitive information when credentials revert to initial settings in rare
circumstances, enabling unauthorized authentication using known credentials
|
| CVE-2026-9651 | 0.0 | unknown |
No description available.
|
| CVE-2026-14354 | 0.0 | unknown |
No description available.
|
| CVE-2025-13902 | 0.0 | unknown |
CVE-2025-13902. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability
exists that could cause condition where authenticated attackers can have a victim’s browser run arbitrary
JavaScript when the victim hovers over a maliciously crafted element on a web server containing the injected
payload.
|
| CVE-2026-2405 | 0.0 | unknown |
CVE-2026-2405. CWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting
zip file creation and denial of service when a Web Admin user floods the system with POST /helpabout
requests.
|
| CVE-2026-2399 | 0.0 | unknown |
CVE-2026-2399. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that
could cause critical files overwritten with text data when a Web Admin user alters the POST /REST/upssleep
request payload.
|
| CVE-2025-11739 | 0.0 | unknown |
CVE-2025-11739. A deserialization of untrusted data vulnerability exists that could cause arbitrary code execution with administrative privileges when a locally authenticated attacker sends a crafted data stream, triggering unsafe deserialization.
|
| CVE-2026-2401 | 0.0 | unknown |
CVE-2026-2401. CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential
information to be exposed when a Web Admin user executes a malicious file provided by an attacker.
|
| CVE-2026-2403 | 0.0 | unknown |
CVE-2026-2403. CWE-1284 Improper Validation of Specified Quantity in Input vulnerability exists that could cause Event and
Data Log truncation impacting log integrity when a Web Admin user alters the POST /logsettings request
payload.
|
| CVE-2026-9717 | 0.0 | unknown |
CVE-2026-9717. CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability
exists that could allow unauthorized execution of commands with elevated privileges, impacting system
integrity, confidentiality, and availability when a privileged authenticated user interacts with a vulnerable
network-exposed service.
|
| CVE-2026-2400 | 0.0 | unknown |
CVE-2026-2400. CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists that could cause
application user credentials to reset when a Web Admin user alters the POST /setPCBEDesc request
payload.
|
| CVE-2026-9718 | 0.0 | unknown |
CVE-2026-9718. CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a
denial-of-service condition, impacting system availability when a specially crafted request is sent to a
vulnerable network-exposed service.
|
| CVE-2024-3596 | 0.0 | unknown |
CVE-2024-3596. RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify responses Access-Reject or Access-Accept using a chosen-prefix collision attack against MD5 Response Authenticator signature.
|
| CVE-2026-2402 | 0.0 | unknown |
CVE-2026-2402. CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an
attacker to gain access to the user account by performing an arbitrary number of authentication attempts with
different credentials on a sequence of requests to multiple endpoints.
|
| CVE-2026-1286 | 0.0 | unknown |
CVE-2026-1286. A deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote code execution on workstation when an admin authenticated user opens a malicious project file.
|
| CVE-2026-4827 | 0.0 | unknown |
CVE-2026-4827. CWE-331 Insufficient Entropy vulnerability exists that could lead to unauthorized access when an attacker on
the network can exploit weaknesses in session‑management protections.
|
| CVE-2025-13957 | 0.0 | unknown |
CVE-2025-13957. A hard-coded credentials vulnerability exists that could lead to information disclosure and remote code execution when SOCKS Proxy is enabled, and administrator credentials and PostgreSQL database credentials are known. SOCKS Proxy is disabled by default.
|
| CVE-2026-12927 | 0.0 | unknown |
No description available.
|
| CVE-2026-6332 | 0.0 | unknown |
No description available.
|
| CVE-2026-2273 | 0.0 | unknown |
CVE-2026-2273. CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause
execution of untrusted commands on the engineering workstation which could result in a limited compromise of
the workstation and a potential loss of Confidentiality, Integrity and Availability of the subsequent system when
an authenticated user opens a malicious project file.
|
| CVE-2019-8963 | 0.0 | unknown |
No description available.
|
| CVE-2022-47393 | 0.0 | unknown |
CVE-2022-47393. An authenticated, remote attacker may use a Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple versions of multiple CODESYS products to force a denial-of-service situation.
|
| CVE-2024-8531 | 0.0 | unknown |
CVE-2024-8531. CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could
compromise the Data Center Expert software when an upgrade bundle is manipulated to
include arbitrary bash scripts that are executed as root.
|
| CVE-2022-2329 | 0.0 | unknown |
No description available.
|
| CVE-2021-22816 | 0.0 | unknown |
No description available.
|
| CVE-2022-41666 | 0.0 | unknown |
No description available.
|
| CVE-2020-7572 | 6.7 | medium |
CVE-2020-7572. An improper restriction of XML external entity reference vulnerability could allow an authenticated remote user to inject arbitrary XML code and obtain disclosure of confidential data, cause a denial-of-service condition, or execute server-side request forgery due to improper configuration of the XML parser.CVE-2020-7572 has been assigned to this vulnerability. A CVSS v3 base score of 6.7 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:H).
|
| CVE-2018-7809 | 0.0 | unknown |
No description available.
|
| CVE-2025-5742 | 0.0 | unknown |
CVE-2025-5742. CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
vulnerability exists when an authenticated user modifies configuration parameters on the web server
|
| CVE-2022-32528 | 0.0 | unknown |
No description available.
|
| CVE-2020-7551 | 7.8 | high |
An improper restriction of operations within the bounds of a memory buffer vulnerability could cause remote code execution when a malicious CGF (Configuration Group File) is imported to IGSS Definition.CVE-2020-7551 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2023-37198 | 0.0 | unknown |
No description available.
|
| CVE-2020-7539 | 0.0 | unknown |
No description available.
|
| CVE-2025-54926 | 0.0 | unknown |
CVE-2025-54926. CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution when an authenticated attacker with admin privileges uploads a malicious file over HTTP which then gets executed.
|
| CVE-2020-11900 | 0.0 | unknown |
Possible double free in IPv4 tunneling component when handling a packet sent by a network attacker. This vulnerability may result in use after free.
|
| CVE-2021-22785 | 0.0 | unknown |
No description available.
|
| CVE-2021-21866 | 0.0 | unknown |
CVE-2021-21866. A unsafe deserialization vulnerability exists in the ObjectManager.plugin ProfileInformation.ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.
|
| CVE-2022-24311 | 9.8 | critical |
A vulnerability exists that could cause modification of an existing file by inserting data at the beginning of the file or creating a new file in the context of the data server. This could potentially lead to remote code execution when an attacker sends a specially crafted message.CVE-2022-24311 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2025-13844 | 0.0 | unknown |
CVE-2025-13844. A double-free vulnerability may lead to heap memory corruption when an end user imports a malicious SSD project file shared by an attacker into Rapsody.
|
| CVE-2019-1225 | 0.0 | unknown |
No description available.
|
| CVE-2021-22809 | 4.4 | medium |
This vulnerability may cause arbitrary code execution when a malicious *.gd1 configuration file is loaded into the GUIcon tool.CVE-2021-22809 has been assigned to this vulnerability. A CVSS v3 base score of 4.4 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L).
|
| CVE-2021-22711 | 7.8 | high |
This vulnerability could result in arbitrary read or write conditions due to missing validation of input data when a malicious CGF file is imported into an IGSS Definition.CVE-2021-22711 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2020-0601 | 0.0 | unknown |
No description available.
|
| CVE-2025-50121 | 0.0 | unknown |
CVE-2025-50121. CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
vulnerability exists that could cause unauthenticated remote code execution when a malicious folder is created
over the web interface HTTP when enabled. HTTP is disabled by default.
|
| CVE-2022-22727 | 0.0 | unknown |
No description available.
|
| CVE-2021-21829 | 0.0 | unknown |
A heap-based buffer overflow vulnerability exists in the XML Decompression EnumerationUncompressor::UncompressItem functionality of AT&T Labs ' Xmill 0.7. A specially crafted XMI file can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.CVE-2021-21829 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2019-0708 | 0.0 | unknown |
The affected product is vulnerable to a remote code execution vulnerability that exists in Remote Desktop Services (formerly known as Terminal Services) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would need to send a specially crafted request to the target system 's Remote Desktop Service via RDP.CVE-2019-0708 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2024-8938 | 0.0 | unknown |
CVE-2024-8938. CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
vulnerability exists that could cause potential arbitrary code execution after a successful Man-In
-The Middle attack followed by sending crafted Modbus command in order to tamper with a
function call used to evaluate memory size.
|
| CVE-2021-22760 | 7.8 | high |
Exploitation of this vulnerability could result in loss of data or remote code execution due to missing checks of user-supplied input data when a malicious CGF file is imported to IGSS Definition.CVE-2021-22760 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2020-7503 | 0.0 | unknown |
No description available.
|
| CVE-2023-37558 | 0.0 | unknown |
CVE-2023-37558. After successful authentication as a user in multiple CODESYS products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of-service condition.
|
| CVE-2021-22727 | 0.0 | unknown |
No description available.
|
| CVE-2024-2602 | 0.0 | unknown |
CVE-2024-2602. CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path
Traversal') vulnerability exists that could result in remote code execution when an authenticated
user executes a saved project file that has been tampered by a malicious actor.
|
| CVE-2022-22811 | 0.0 | unknown |
No description available.
|
| CVE-2020-7571 | 6.1 | medium |
CVE-2020-7571. Multiple improper neutralizations of an input during webpage generation vulnerabilities could allow a remote attacker to inject arbitrary web script or HTML due to incorrect sanitization of user supplied data and achieve a reflected cross-site scripting attack against other WebReport users.CVE-2020-7571 has been assigned to this vulnerability. A CVSS v3 base score of 6.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
|
| CVE-2023-25553 | 0.0 | unknown |
No description available.
|
| CVE-2024-12142 | 0.0 | unknown |
CVE-2024-12142. CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could
cause information disclosure of restricted web page, modification of web page and denial of
service when specific web pages are modified and restricted functions are invoked.
|
| CVE-2024-37039 | 0.0 | unknown |
CVE-2024-37039. CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the
device when an attacker sends a specially crafted HTTP request.
|
| CVE-2025-2002 | 0.0 | unknown |
CVE-2025-2002. CWE-532: Insertion of Sensitive Information into Log Files vulnerability exists that could cause the disclosure of FTP server credentials when the FTP server is deployed, and the device is placed in debug mode by an administrative user and the debug files are exported from the device.
|
| CVE-2021-22736 | 0.0 | unknown |
No description available.
|
| CVE-2020-7486 | 7.5 | high |
A vulnerability could cause TCMs installed in Tricon system Versions 10.0.0 through 10.4.x to reset when under high network load. This reset could result in a denial of service behavior with the SIS.CVE-2020-7486 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
|
| CVE-2024-6351 | 0.0 | unknown |
CVE-2024-6351. A CWE-120: A buffer overflow vulnerability exists that could cause a denial of service when a
malicious device joins the network.
|
| CVE-2020-28213 | 0.0 | unknown |
No description available.
|
| CVE-2018-7844 | 0.0 | unknown |
CVE-2018-7844. An information exposure vulnerability exists, which could cause the disclosure of SNMP information when reading memory blocks from the controller over Modbus.
|
| CVE-2025-7746 | 0.0 | unknown |
CVE-2025-7746. CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability
exists that could cause an unvalidated data injected by a malicious user potentially leading to modify or read
data in a victim’s browser.
|
| CVE-2024-5680 | 0.0 | unknown |
CVE-2024-5680. CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denialof-
service when a malicious actor with local user access crafts a script/program using an IOCTL
call in the Foxboro.sys driver.
|
| CVE-2021-30061 | 0.0 | unknown |
No description available.
|
| CVE-2023-29410 | 0.0 | unknown |
No description available.
|
| CVE-2021-22773 | 0.0 | unknown |
No description available.
|
| CVE-2021-22789 | 0.0 | unknown |
No description available.
|
| CVE-2020-7540 | 0.0 | unknown |
No description available.
|
| CVE-2022-24324 | 0.0 | unknown |
No description available.
|
| CVE-2024-10085 | 0.0 | unknown |
CVE-2024-10085. CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause denial of service of EcoStruxure OPCUA Server Expert when a large number of OPC UA requests are sent to the server.
|
| CVE-2021-21864 | 0.0 | unknown |
CVE-2021-21864. A unsafe deserialization vulnerability exists in the ComponentModel ComponentManager.StartupCultureSettings functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.
|
| CVE-2022-22804 | 0.0 | unknown |
No description available.
|
| CVE-2022-47392 | 0.0 | unknown |
CVE-2022-47392. An authenticated, remote attacker may use a improper input validation vulnerability in the CmpApp/CmpAppBP/CmpAppForce Components of multiple CODESYS products in multiple versions to read from an invalid address which can lead to a denial-of-service condition.
|
| CVE-2025-13905 | 0.0 | unknown |
CVE-2025-13905. CWE-276 : Incorrect Default Permissions vulnerability exists that could cause privilege escalation through the
reverse shell when one or more executable service binaries are modified in the installation folder by a local
user with normal privilege upon service restart.
|
| CVE-2021-22810 | 6.8 | medium |
A vulnerability could cause arbitrary script execution when a privileged account clicks on a malicious URL specifically crafted for the NMC pointing to a delete policy file.CVE-2021-22810 has been assigned to this vulnerability. A CVSS v3 base score of 6.8 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N).
|
| CVE-2022-47391 | 0.0 | unknown |
CVE-2022-47391. In multiple CODESYS products in multiple versions an unauthorized, remote attacker may use a improper input validation vulnerability to read from invalid addresses leading to a denial of service.
|
| CVE-2020-28214 | 3.3 | low |
A use of a one-way hash with a predictable salt vulnerability exists that could allow the attacker to pre-compute the hash value using a dictionary attack, effectively disabling the protection that an unpredictable salt would provide.CVE-2020-28214 has been assigned to this vulnerability. A CVSS v3 base score of 3.3 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
|
| CVE-2021-21865 | 0.0 | unknown |
CVE-2021-21865. A unsafe deserialization vulnerability exists in the PackageManagement.plugin ExtensionMethods.Clone() functionality of CODESYS GmbH CODESYS Development System 3.5.16. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.
|
| CVE-2021-22709 | 7.8 | high |
This vulnerability could result in loss of data or remote code execution when a malicious CGF (configuration group file) file is imported into an IGSS Definition.CVE-2021-22709 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2023-44487 | 0.0 | unknown |
CVE-2023-44487. The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
|
| CVE-2023-27981 | 0.0 | unknown |
A vulnerability in Schneider Electric Custom Reports could cause remote code execution if an unsuspecting user opens a malicious report. CVE-2023-27981 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2020-25180 | 5.3 | medium |
ISaGRAF Runtime includes the functionality of setting a password that is required to execute privileged commands. The password value passed to ISaGRAF Runtime is the result of encryption performed with a fixed key value using the Tiny Encryption Algorithm (TEA) on an entered or saved password. A remote, unauthenticated attacker could pass their own encrypted password to the ISaGRAF 5 Runtime, which may result in information disclosure on the device.CVE-2020-25180 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N).
|
| CVE-2022-43376 | 0.0 | unknown |
No description available.
|
| CVE-2021-21826 | 0.0 | unknown |
A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7. Within `DecodeTreeBlock,` which is called during the decompression of an XMI file, a UINT32 is loaded from the file and used as trusted input as the length of a buffer.CVE-2021-21826 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2024-2229 | 0.0 | unknown |
All versions of Schneider Electric EcoStruxure Power Design - Ecodial NL, INT, and FR deserializes untrusted data which could allow an attacker to perform code execution when a malicious project file is loaded into the application by a valid user.
|
| CVE-2021-21811 | 0.0 | unknown |
A memory corruption vulnerability exists in the XML-parsing CreateLabelOrAttrib functionality of AT&T Labs ' Xmill 0.7. The product subtracts one value from another such that the result is less than the minimum allowable integer value, which produces a value not equal to the correct result. CVE-2021-21811 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2023-2570 | 0.0 | unknown |
No description available.
|
| CVE-2025-50125 | 0.0 | unknown |
CVE-2025-50125. CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthenticated remote
code execution when the server is accessed via the network with knowledge of hidden URLs and manipulation
of host request header.
|
| CVE-2020-7505 | 0.0 | unknown |
No description available.
|
| CVE-2021-22724 | 0.0 | unknown |
No description available.
|
| CVE-2022-32516 | 0.0 | unknown |
No description available.
|
| CVE-2021-22717 | 8.8 | high |
The affected product is vulnerable to Path Traversal, which could allow remote code execution when processing config files.CVE-2021-22717 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2020-28211 | 0.0 | unknown |
No description available.
|
| CVE-2021-22710 | 7.8 | high |
This vulnerability could result in loss of data or remote code execution when a malicious CGF file is imported into an IGSS Definition.CVE-2021-22710 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2022-41668 | 0.0 | unknown |
No description available.
|
| CVE-2022-47378 | 0.0 | unknown |
CVE-2022-47378. Multiple CODESYS products in multiple versions are prone to a improper input validation vulnerability. An authenticated remote attacker may craft specific requests that use the vulnerability leading to a denial-of-service condition.
|
| CVE-2020-11905 | 0.0 | unknown |
Possible out-of-bounds read in DHCPv6 component when handling a packet sent by an unauthorized network attacker. This vulnerability may allow exposure of sensitive information.
|
| CVE-2022-42971 | 0.0 | unknown |
Schneider Electric APC Easy UPS Online versions 2.5-GA and prior deploy the improperly secured UpLoadAction.execute method. An unauthenticated user could use this method to upload a maliciously crafted JSF file to the images directory, which is located in the application web root directory, to enable unauthenticated remote code execution.CVE-2022-42971 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2022-32515 | 0.0 | unknown |
No description available.
|
| CVE-2024-0865 | 0.0 | unknown |
No description available.
|
| CVE-2024-2747 | 0.0 | unknown |
No description available.
|
| CVE-2025-1060 | 0.0 | unknown |
CVE-2025-1060. CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists that could result in the exposure
of data when network traffic is being sniffed by an attacker.
|
| CVE-2020-7485 | 5.5 | medium |
A vulnerability related to a legacy support account in TriStation 1131 versions 1.0 through 4.9.0 and 4.10.0 could allow inappropriate access to the TriStation 1131 project file.CVE-2020-7485 has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N).
|
| CVE-2018-7812 | 0.0 | unknown |
No description available.
|
| CVE-2022-37302 | 0.0 | unknown |
No description available.
|
| CVE-2021-21825 | 0.0 | unknown |
A heap-based buffer overflow vulnerability exists in the XML Decompression. PlainTextUncompressor::UncompressItem functionality of AT&T Labs ' Xmill 0.7. A specially crafted XMI file could lead to remote code execution. An attacker could provide a malicious file to trigger this vulnerability.CVE-2021-21825 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2021-22706 | 0.0 | unknown |
No description available.
|
| CVE-2023-2161 | 0.0 | unknown |
No description available.
|
| CVE-2020-7544 | 7.4 | high |
An improper privilege management vulnerability exists that could cause privilege escalation on the workstation when interacting directly with a driver installed by the runtime software of EcoStruxure Operator Terminal Expert.CVE-2020-7544 has been assigned to this vulnerability. A CVSS v3 base score of 7.4 has been calculated; the CVSS vector string is (AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2024-2052 | 0.0 | unknown |
No description available.
|
| CVE-2022-34765 | 0.0 | unknown |
No description available.
|
| CVE-2022-32520 | 0.0 | unknown |
No description available.
|
| CVE-2024-8530 | 0.0 | unknown |
CVE-2024-8530. CWE-306: Missing Authentication for Critical Function vulnerability exists that could
cause exposure of private data when an already generated “logcaptures” archive is accessed
directly by HTTPS.
|
| CVE-2022-45789 | 0.0 | unknown |
An authentication bypass by capture-replay vulnerability exists that could execute unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session.
|
| CVE-2023-5985 | 0.0 | unknown |
No description available.
|
| CVE-2024-5558 | 0.0 | unknown |
No description available.
|
| CVE-2020-7534 | 0.0 | unknown |
No description available.
|
| CVE-2023-5986 | 0.0 | unknown |
No description available.
|
| CVE-2025-0327 | 0.0 | unknown |
CVE-2025-0327. CWE-269: Improper Privilege Management vulnerability exists for two services (of which one managing audit trail data and the other acting as server managing client request) that could cause a loss of Confidentiality, Integrity and Availability of engineering workstation when an attacker with standard privilege modifies the executable path of the windows services. To be exploited, services need to be restarted.
|
| CVE-2021-1675 | 0.0 | unknown |
No description available.
|
| CVE-2022-22723 | 8.8 | high |
A buffer copy without checking size of input vulnerability exists in Easergy P5 devices that could lead to a buffer overflow, causing program crashes and arbitrary code execution when specially crafted packets are sent to the device over the network. Protection functions and tripping functions via GOOSE can be impacted. CVE-2022-22723 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2019-12265 | 0.0 | unknown |
The IGMPv3 reception handler does not expect packets to be spread across multiple IP-fragments.CVE-2019-12265 has been assigned to this vulnerability. A CVSS v3 base score of 5.4 has been calculated; the CVSS vector string is (AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L).
|
| CVE-2018-7773 | 0.0 | unknown |
No description available.
|
| CVE-2019-12264 | 0.0 | unknown |
This vulnerability requires that at least one IPv4 multicast address has been assigned to the target in an incorrect way (e.g., using the API intended for assigning unicast addresses). An attacker may use CVE-2019-12264 to incorrectly assign a multicast IP-address.. An attacker on the same LAN as the target system may use this vulnerability to cause a NULL pointer dereference, which most likely will crash the tNet0 task. An attacker on the same LAN as the target system may use this vulnerability to cause a NULL pointer dereference, which most likely will crash the tNet0 task.. CVE-2019-12259 has been assigned to this vulnerability. A CVSS v3 base score of 6.3 has been calculated; the CVSS vector string is (AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H).An attacker may use CVE-2019-12264 to incorrectly assign a multicast IP-address.
|
| CVE-2023-27978 | 0.0 | unknown |
A vulnerability in Schneider Electric Dashboard module could cause an interpretation of malicious payload data if a malicious file is opened by an unsuspecting user. This could lead to remote code execution. CVE-2023-27978 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2019-6806 | 0.0 | unknown |
CVE-2019-6806. An information exposure vulnerability exists which could cause the disclosure of SNMP information when reading variables in the controller using Modbus.
|
| CVE-2026-1226 | 0.0 | unknown |
CVE-2026-1226. An improper control of generation of code vulnerability exists that could result in the execution of untrusted or unintended code within the application. This occurs when maliciously crafted design content is processed through a TGML graphics file.
|
| CVE-2020-11904 | 0.0 | unknown |
Possible integer overflow or wraparound in memory allocation component when handling a packet sent by an unauthorized network attacker may result in out-of-bounds write.
|
| CVE-2025-8453 | 0.0 | unknown |
CVE-2025-8453. CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation and
arbitrary code execution when a privileged engineer user with console access modifies a configuration file
used by a root-level daemon to execute custom scripts.
|
| CVE-2020-7487 | 0.0 | unknown |
No description available.
|
| CVE-2019-6828 | 0.0 | unknown |
CVE-2019-6828. An uncaught exception vulnerability exists, which could cause a possible denial of service when reading specific coils and registers in the controller over Modbus.
|
| CVE-2023-27980 | 0.0 | unknown |
A vulnerability in Schneider Electric Data Server TCP interface could allow the creation of a malicious report file in the IGSS project report directory, and this could lead to remote code execution when an unsuspecting user opens the malicious report. CVE-2023-27980 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2024-10497 | 0.0 | unknown |
An authorization bypass through user-controlled key vulnerability exists that could allow an authorized attacker to modify values outside those defined by their privileges (Elevation of Privileges) when the attacker sends modified HTTPS requests to the device.
|
| CVE-2022-30237 | 0.0 | unknown |
No description available.
|
| CVE-2021-22726 | 0.0 | unknown |
No description available.
|
| CVE-2022-30790 | 0.0 | unknown |
CVE-2022-30790. Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552.
|
| CVE-2022-43378 | 0.0 | unknown |
No description available.
|
| CVE-2020-10245 | 0.0 | unknown |
CVE-2020-10245. CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control runtime systems, has a buffer overflow.
|
| CVE-2021-22702 | 0.0 | unknown |
No description available.
|
| CVE-2020-17438 | 7.0 | high |
The function in open-iscsi and uIP that reassembles fragmented packets does not validate the total length of an incoming packet specified in its IP header, as well as the fragmentation offset value specified in the IP header. This could lead to memory corruption.CVE-2020-17438 has been assigned to this vulnerability. A CVSS v3 base score of 7.0 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H).
|
| CVE-2020-7549 | 0.0 | unknown |
No description available.
|
| CVE-2025-9317 | 0.0 | unknown |
The vulnerability, if exploited, could allow a miscreant with read access to Edge Project files or Edge Offline Cache files to reverse engineer Edge users' app-native or Active Directory passwords through computational brute-forcing of weak hashes.
|
| CVE-2025-1059 | 0.0 | unknown |
CVE-2025-1059. CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could
cause communications to stop when malicious packets are sent to the webserver of the device.
|
| CVE-2020-7500 | 0.0 | unknown |
No description available.
|
| CVE-2020-7491 | 10.0 | critical |
A legacy debug port account in TCMs installed in Tricon system Versions 10.2.0 through 10.5.3 is visible on the network and could allow inappropriate access.CVE-2020-7491 has been assigned to this vulnerability. A CVSS v3 base score of 10.0 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
|
| CVE-2020-14509 | 0.0 | unknown |
CVE-2020-14509. Multiple memory corruption vulnerabilities exist where the packet parser mechanism does not verify length fields. An attacker could send specially crafted packets to exploit these vulnerabilities.
|
| CVE-2018-7776 | 0.0 | unknown |
No description available.
|
| CVE-2019-1223 | 0.0 | unknown |
No description available.
|
| CVE-2023-37553 | 0.0 | unknown |
CVE-2023-37553. In multiple versions of multiple CODESYS products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition.
|
| CVE-2021-22775 | 0.0 | unknown |
No description available.
|
| CVE-2022-24312 | 9.8 | critical |
A vulnerability exists that could cause modification of an existing file by adding data at the end of the file or creating a new file in the context of the data server. This could potentially lead to remote code execution when an attacker sends a specially crafted message.CVE-2022-24312 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2020-7474 | 0.0 | unknown |
No description available.
|
| CVE-2022-22807 | 0.0 | unknown |
No description available.
|
| CVE-2020-7507 | 0.0 | unknown |
No description available.
|
| CVE-2020-7519 | 0.0 | unknown |
No description available.
|
| CVE-2023-6032 | 0.0 | unknown |
No description available.
|
| CVE-2024-5056 | 0.0 | unknown |
CVE-2024-5056. CWE-552: Files or Directories Accessible to External Parties vulnerability exists which may
prevent user to update the device firmware and prevent proper behavior of the webserver when
specific files or directories are removed from the filesystem.
|
| CVE-2021-22791 | 0.0 | unknown |
No description available.
|
| CVE-2019-6848 | 0.0 | unknown |
No description available.
|
| CVE-2020-7560 | 0.0 | unknown |
No description available.
|
| CVE-2022-22809 | 0.0 | unknown |
No description available.
|
| CVE-2021-22716 | 7.8 | high |
The affected product is vulnerable to Improper Privilege Management, which could allow remote code execution when an unprivileged user modifies a file.CVE-2021-22716 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2020-11908 | 0.0 | unknown |
Improper null termination in DHCP component when handling a packet sent by an unauthorized network attacker. This vulnerability may allow exposure of sensitive information.
|
| CVE-2021-22793 | 0.0 | unknown |
No description available.
|
| CVE-2021-22783 | 0.0 | unknown |
No description available.
|
| CVE-2021-22737 | 0.0 | unknown |
No description available.
|
| CVE-2023-3670 | 0.0 | unknown |
CVE-2023-3670. In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe directory permissions would allow an attacker with local access to the workstation to place potentially harmful and disguised scripts that could be executed by legitimate users.
|
| CVE-2023-37551 | 0.0 | unknown |
CVE-2023-37551. In multiple Codesys products in multiple versions, after successful authentication as a user, specially crafted network communication requests can utilize the CmpApp component to download files with any file extensions to the controller. In contrast to the regular file download via CmpFileTransfer, no filtering of certain file types is performed here. As a result, the integrity of the CODESYS control runtime system may be compromised by the files loaded onto the controller.
|
| CVE-2024-6407 | 0.0 | unknown |
CVE-2024-6407. CWE-200: Information Exposure vulnerability exists that could cause disclosure of
credentials when a specially crafted message is sent to the device.
|
| CVE-2020-10664 | 0.0 | unknown |
No description available.
|
| CVE-2021-22725 | 0.0 | unknown |
No description available.
|
| CVE-2021-22756 | 7.8 | high |
Exploitation of this vulnerability could result in disclosure of information or remote code execution due to lack of user-supplied data validation when a malicious CGF file is imported to IGSS Definition.CVE-2021-22756 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2023-3001 | 0.0 | unknown |
A deserialization of untrusted data vulnerability that could cause an interpretation of malicious payload data exists in the Dashboard module, which could lead to arbitrary code execution if an attacker gets the user to open a malicious file.
|
| CVE-2018-7846 | 0.0 | unknown |
CVE-2018-7846. A trust boundary violation vulnerability on connection to the controller exists which could cause unauthorized access by conducting a brute force attack on Modbus protocol to the controller.
|
| CVE-2023-37548 | 0.0 | unknown |
CVE-2023-37548. In multiple CODESYS products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition.
|
| CVE-2022-22810 | 0.0 | unknown |
No description available.
|
| CVE-2022-34760 | 0.0 | unknown |
No description available.
|
| CVE-2022-30552 | 0.0 | unknown |
CVE-2022-30552. Das U-Boot 2022.01 has a Buffer Overflow.
|
| CVE-2021-22746 | 0.0 | unknown |
No description available.
|
| CVE-2020-11907 | 0.0 | unknown |
Improper handling of length parameter inconsistency in TCP component, from a packet sent by an unauthorized network attacker.
|
| CVE-2025-8449 | 0.0 | unknown |
CVE-2025-8449. CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service when
an authenticated user sends a specially crafted request to a specific endpoint from within the BMS network.
|
| CVE-2025-54924 | 0.0 | unknown |
CVE-2025-54924. CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized access to
sensitive data when an attacker sends a specially crafted document to a vulnerable endpoint.
|
| CVE-2021-22718 | 7.8 | high |
The affected product is vulnerable to Path Traversal, which could allow remote code execution when restoring project files.CVE-2021-22718 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2025-6788 | 0.0 | unknown |
CVE-2025-6788. CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that exposes TGML diagram resources
to the wrong control sphere, providing other authenticated users with potentially inappropriate access to TGML
diagrams.
|
| CVE-2022-42970 | 0.0 | unknown |
Schneider Electric APC Easy UPS Online versions 2.5-GA and prior are missing authentication for the updatePassword endpoint implemented in the LoginAction.updatePassword method. An unauthenticated user could exploit this vulnerability to modify administrator passwords.CVE-2022-42970 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2020-28215 | 7.7 | high |
The affected product is vulnerable to a missing authorization vulnerability, which may allow an attacker to gain access to sensitive information, cause a denial-of-service condition, and remotely execute arbitrary code when access control checks are not applied consistently.CVE-2020-28215 has been assigned to this vulnerability. A CVSS v3 base score of 7.7 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H).
|
| CVE-2022-34756 | 0.0 | unknown |
No description available.
|
| CVE-2021-22730 | 0.0 | unknown |
No description available.
|
| CVE-2021-30188 | 9.8 | critical |
A crafted request may cause a stack-based buffer overflow in the affected CODESYS products, resulting in a denial-of-service condition or remote code execution.CVE-2021-30188 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2022-32748 | 0.0 | unknown |
No description available.
|
| CVE-2024-12476 | 0.0 | unknown |
The affected product is vulnerable to an improper restriction of XML external entity reference vulnerability that could cause information disclosure, impacts to workstation integrity and potential remote code execution on the compromised computer, when a specifically crafted XML file is imported in the Web Designer configuration tool.
|
| CVE-2022-22805 | 0.0 | unknown |
No description available.
|
| CVE-2023-29413 | 0.0 | unknown |
A vulnerability exists that could cause a denial-of-service condition when accessed by an unauthenticated user on the Schneider UPS Monitor service.
|
| CVE-2021-22811 | 6.8 | medium |
A vulnerability could cause script execution when the request of a privileged account accessing the vulnerable web page is intercepted.CVE-2021-22811 has been assigned to this vulnerability. A CVSS v3 base score of 6.8 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N).
|
| CVE-2021-22752 | 7.8 | high |
Exploitation of this vulnerability could result in loss of data or remote code execution due to missing size checks when a malicious WSP (Workspace) file is being parsed by IGSS Definition.CVE-2021-22752 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2021-22780 | 7.1 | high |
An insufficiently protected credentials vulnerability exists that could cause unauthorized access to a project file protected by a password when this file is shared with untrusted sources. An attacker may bypass the password protection and be able to view and modify a project file.CVE-2021-22780 has been assigned to this vulnerability. A CVSS v3 base score of 7.1 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
|
| CVE-2019-8961 | 0.0 | unknown |
No description available.
|
| CVE-2021-22819 | 0.0 | unknown |
No description available.
|
| CVE-2023-25555 | 0.0 | unknown |
No description available.
|
| CVE-2023-37546 | 0.0 | unknown |
CVE-2023-37546. In multiple CODESYS products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition.
|
| CVE-2018-7771 | 0.0 | unknown |
No description available.
|
| CVE-2024-37040 | 0.0 | unknown |
CVE-2024-37040. CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability
exists that could allow a user with access to the device’s web interface to cause a fault on the
device when sending a malformed HTTP request.
|
| CVE-2025-54925 | 0.0 | unknown |
CVE-2025-54925. CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized access to sensitive data when an attacker configures the application to access a malicious url.
|
| CVE-2019-1040 | 0.0 | unknown |
No description available.
|
| CVE-2021-22771 | 0.0 | unknown |
No description available.
|
| CVE-2024-8884 | 0.0 | unknown |
CVE-2024-8884. CWE-200: Information Exposure vulnerability exists that could cause exposure of credentials
when attacker has access to application on network over http.
|
| CVE-2020-7559 | 0.0 | unknown |
No description available.
|
| CVE-2021-22764 | 0.0 | unknown |
CVE-2021-22764. CWE-287: Improper Authentication vulnerability exists that could cause loss of connectivity to
the device via Modbus TCP protocol when an attacker sends a specially crafted HTTP request.
|
| CVE-2021-22720 | 6.5 | medium |
The affected product is vulnerable to Path Traversal, which could allow remote code execution when restoring a project.CVE-2021-22720 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
|
| CVE-2019-12260 | 0.0 | unknown |
This vulnerability could lead to a buffer overflow of up to a full TCP receive window (by default, 10k-64k depending on version). The buffer overflow happens in the task calling recv()/recvfrom()/recvmsg(). Applications that pass a buffer equal to or larger than a full TCP window are not susceptible to this attack. Applications passing a stack-allocated variable as a buffer are the easiest to exploit. The most likely outcome is a crash of the application reading from the affected socket, which could result in remote code execution.. CVE-2019-12260 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).The most likely outcome is a crash of the application reading from the affected socket, which could result in remote code execution.
|
| CVE-2019-6830 | 0.0 | unknown |
CVE-2019-6830. An uncaught exception vulnerability exists, which could cause a possible denial of service when sending an appropriately timed HTTP request to the controller.
|
| CVE-2020-7499 | 0.0 | unknown |
No description available.
|
| CVE-2024-11737 | 0.0 | unknown |
CVE-2024-11737. CWE-20: Improper Input Validation vulnerability exists that could lead to a denial of service and a loss of confidentiality, integrity of the controller when an unauthenticated crafted Modbus packet is sent to the device.
|
| CVE-2018-7833 | 0.0 | unknown |
No description available.
|
| CVE-2022-30235 | 0.0 | unknown |
No description available.
|
| CVE-2023-7032 | 0.0 | unknown |
A deserialization of untrusted data vulnerability exists in Schneider Electric Easergy Studio versions prior to v9.3.5 that could allow an attacker logged in with a user level account to gain higher privileges by providing a harmful serialized object.
|
| CVE-2021-22803 | 9.8 | critical |
By sending constructed messages on the network, an attacker could write arbitrary files to folders in context of the DC module that could lead to remote code execution.CVE-2021-22803 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2025-11566 | 0.0 | unknown |
CVE-2025-11566. CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an
attacker on the local network to gain access to the user account by performing an arbitrary number of
authentication attempts with different credentials on the /REST/shutdownnow endpoint.
|
| CVE-2025-0814 | 0.0 | unknown |
CVE-2025-0814. CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the network
services running on the product when malicious IEC61850-MMS packets are sent to the device. The core
functionality of the breaker remains intact during the attack.
|
| CVE-2023-25547 | 0.0 | unknown |
No description available.
|
| CVE-2020-7511 | 0.0 | unknown |
No description available.
|
| CVE-2018-7768 | 0.0 | unknown |
No description available.
|
| CVE-2024-8933 | 0.0 | unknown |
CVE-2024-8933. CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel
vulnerability exists that could cause retrieval of password hash that could lead to denial of service and loss of
confidentiality and integrity of controllers. To be successful, the attacker needs to inject themself inside the
logical network while a valid user uploads or downloads a project file into the controller.
|
| CVE-2021-29241 | 0.0 | unknown |
CVE-2021-29241. CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS).
|
| CVE-2020-7488 | 0.0 | unknown |
No description available.
|
| CVE-2025-3112 | 0.0 | unknown |
CVE-2025-3112. CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause Denial of Service when an
authenticated malicious user sends manipulated HTTPS Content-Length header to the webserver.
|
| CVE-2021-21830 | 0.0 | unknown |
A heap-based buffer overflow vulnerability exists in the XML Decompression LabelDict::Load functionality of AT&T Labs ' Xmill 0.7. A specially crafted XML file can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.CVE-2021-21830 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2023-28003 | 0.0 | unknown |
No description available.
|
| CVE-2021-22801 | 7.8 | high |
The affected product has an issue with privilege management, which could cause an arbitrary command execution when the software is configured with specially crafted event actions.CVE-2021-22801 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2023-27984 | 0.0 | unknown |
A vulnerability in Schneider Electric Custom Reports could result in macro execution if a malicious report file is opened by an unsuspecting user, potentially leading to remote code execution. CVE-2023-27984 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2025-50122 | 0.0 | unknown |
CVE-2025-50122. CWE-331: Insufficient Entropy vulnerability exists that could cause root password discovery when the
password generation algorithm is reverse engineered with access to installation or upgrade artifacts.
|
| CVE-2024-5560 | 0.0 | unknown |
CVE-2024-5560. CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service of the
device’s web interface when an attacker sends a specially crafted HTTP request.
|
| CVE-2021-22767 | 0.0 | unknown |
No description available.
|
| CVE-2020-7497 | 6.3 | medium |
A vulnerability exists that could cause arbitrary application execution when the computer starts.CVE-2020-7497 has been assigned to this vulnerability. A CVSS v3 base score of 6.3 has been calculated; the CVSS vector string is (AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2024-9002 | 0.0 | unknown |
CVE-2024-9002. CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized
access, loss of confidentiality, integrity, and availability of the workstation when non-admin
authenticated user tries to perform privilege escalation by tampering with the binaries.
|
| CVE-2024-5557 | 0.0 | unknown |
No description available.
|
| CVE-2022-0223 | 0.0 | unknown |
No description available.
|
| CVE-2024-28219 | 0.0 | unknown |
In _imagingcms.c in Pillow prior to 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.
|
| CVE-2023-37200 | 0.0 | unknown |
No description available.
|
| CVE-2024-11425 | 0.0 | unknown |
CVE-2024-11425. CWE-131: Incorrect Calculation of Buffer Size vulnerability exists that could cause Denial-of-Service of the
product when an unauthenticated user is sending a crafted HTTPS packet to the webserver.
|
| CVE-2021-22808 | 7.8 | high |
This vulnerability may cause arbitrary code execution when a malicious *.gd1 configuration file is loaded into the GUIcon tool.CVE-2021-22808 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2025-54923 | 0.0 | unknown |
CVE-2025-54923. CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution and compromise of system integrity when authenticated users send crafted data to a network-exposed service that performs unsafe deserialization.
|
| CVE-2020-1472 | 0.0 | unknown |
No description available.
|
| CVE-2022-24317 | 5.3 | medium |
A vulnerability exists that could cause information exposure when an attacker sends a specific message.CVE-2022-24317 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
|
| CVE-2020-7548 | 0.0 | unknown |
No description available.
|
| CVE-2025-3898 | 0.0 | unknown |
CVE-2025-3898. CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an
authenticated malicious user sends HTTPS request containing invalid data type to the webserver.
|
| CVE-2023-27977 | 0.0 | unknown |
A vulnerability in Schneider Electric Data Server could grant an unauthorized user access to delete files in the IGSS project report directory if specific crafted messages are sent to the Data Server TCP port. CVE-2023-27977 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L).
|
| CVE-2023-25619 | 0.0 | unknown |
No description available.
|
| CVE-2021-30062 | 0.0 | unknown |
No description available.
|
| CVE-2020-7496 | 3.3 | low |
A remote attacker can trick a victim to open a specially crafted project file and gain unauthorized write access to the target system.CVE-2020-7496 has been assigned to this vulnerability. A CVSS v3 base score of 3.3 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).
|
| CVE-2020-7501 | 0.0 | unknown |
No description available.
|
| CVE-2022-34755 | 0.0 | unknown |
No description available.
|
| CVE-2018-7766 | 0.0 | unknown |
No description available.
|
| CVE-2018-7804 | 0.0 | unknown |
No description available.
|
| CVE-2020-7538 | 7.5 | high |
A vulnerability exists that could cause a crash of the PLC simulator present in EcoStruxure Control Expert software when receiving a specially crafted request over Modbus.CVE-2020-7538 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
|
| CVE-2020-7556 | 7.8 | high |
An out-of-bounds write vulnerability could cause remote code execution when a malicious CGF (Configuration Group File) is imported to IGSS Definition.CVE-2020-7556 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2020-9403 | 0.0 | unknown |
No description available.
|
| CVE-2020-11911 | 0.0 | unknown |
The affected product is vulnerable to improper access control, which may allow an attacker to change one specific configuration value.
|
| CVE-2023-22611 | 0.0 | unknown |
No description available.
|
| CVE-2025-2442 | 0.0 | unknown |
CVE-2025-2442. CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could potentially lead to
unauthorized access which could result in the loss of confidentially, integrity and availability when a malicious
user, having physical access, sets the radio to the factory default mode.
|
| CVE-2018-7810 | 0.0 | unknown |
No description available.
|
| CVE-2021-22797 | 7.8 | high |
When a malicious project file is loaded on the engineering workstation software, it deploys a malicious script to execute arbitrary code in unauthorized locations.CVE-2021-22797has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2019-1224 | 0.0 | unknown |
No description available.
|
| CVE-2023-4516 | 0.0 | unknown |
A missing authentication for critical function vulnerability that could allow a local attacker to change the update source exists in the IGSS Update Service, which could lead to remote code execution the attacker force an update containing malicious content.
|
| CVE-2022-47384 | 0.0 | unknown |
CVE-2022-47384. An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
|
| CVE-2018-7494 | 0.0 | unknown |
No description available.
|
| CVE-2021-22781 | 6.2 | medium |
An insufficiently protected credentials vulnerability exists that could cause a leak of SMTP credentials used for mailbox authentication when an attacker can access a project file.CVE-2021-22781 has been assigned to this vulnerability. A CVSS v3 base score of 6.2 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
|
| CVE-2018-7850 | 0.0 | unknown |
CVE-2018-7850. A reliance on untrusted inputs in a security decision vulnerability exists which could cause invalid information displayed in Unity Pro software.
|
| CVE-2025-2875 | 0.0 | unknown |
CVE-2025-2875. CWE-610: Externally Controlled Reference to a Resource in Another Sphere vulnerability exists that could
cause a loss of confidentiality when an unauthenticated attacker manipulates controller’s webserver URL to
access resources.
|
| CVE-2018-7845 | 0.0 | unknown |
CVE-2018-7845. An out-of-bounds read vulnerability exists, which could cause the disclosure of unexpected data from the controller when reading specific memory blocks in the controller over Modbus.
|
| CVE-2022-32518 | 0.0 | unknown |
No description available.
|
| CVE-2019-11135 | 0.0 | unknown |
No description available.
|
| CVE-2020-12525 | 7.3 | high |
M&M Software fdtCONTAINER component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.
Note: This vulnerability could cause local code execution on the engineering workstation when a malicious project file is loaded into the engineering software.CVE-2020-12525 has been assigned to this vulnerability. A CVSS v3 base score of 7.3 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2025-46819 | 0.0 | unknown |
CVE-2025-46819. Additional information about CVE-2025-46819 can be found here: https://www.cve.org/CVERecord?id=CVE-2025-46819
|
| CVE-2021-21868 | 0.0 | unknown |
CVE-2021-21868. An unsafe deserialization vulnerability exists in the ObjectManager.plugin Project.get_MissingTypes() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.
|
| CVE-2025-5740 | 0.0 | unknown |
CVE-2025-5740. CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that
could cause arbitrary file writes when an authenticated user on the web server manipulates file path.
|
| CVE-2020-11906 | 0.0 | unknown |
Improper input validation CWE-20 in ethernet link layer component from a packet sent by an unauthorized user.
|
| CVE-2019-6842 | 0.0 | unknown |
No description available.
|
| CVE-2020-7490 | 0.0 | unknown |
No description available.
|
| CVE-2020-11910 | 0.0 | unknown |
Improper input validation in ICMPv4 component when handling a packet sent by an unauthorized network attacker. This vulnerability may allow out-of-bounds read.
|
| CVE-2023-29412 | 0.0 | unknown |
Prior versions of Schneider Electric APC Easy UPS Online contain an OS Command Injection vulnerability that could cause remote code execution when manipulating internal methods through Java RMI interface.
|
| CVE-2018-7240 | 0.0 | unknown |
No description available.
|
| CVE-2025-5743 | 0.0 | unknown |
CVE-2025-5743. CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could
cause remote control over the charging station when an authenticated user modifies configuration parameters
on the web server.
|
| CVE-2024-11999 | 0.0 | unknown |
CVE-2024-11999. CWE-1104: Use of Unmaintained Third-Party Components exists that could cause complete control of the
device when an authenticated user installs malicious code into HMI product.
|
| CVE-2022-24318 | 0.0 | unknown |
No description available.
|
| CVE-2020-11896 | 0.0 | unknown |
Improper handling of length parameter inconsistency in IPv4/UDP component when handling a packet sent by an unauthorized network attacker. This vulnerability may result in remote code execution.
|
| CVE-2021-22779 | 9.8 | critical |
An authentication bypass by spoofing vulnerability exists that could cause unauthorized access in read and write mode to the controller by spoofing the Modbus communication between the engineering software and the controller. CVE-2021-22779 has been assigned to this vulnerability. A CVSS v3 base score of 9.8has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).. --------- End Update A Part 2 of 2 --------CVE-2021-22779 has been assigned to this vulnerability. A CVSS v3 base score of 9.8has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2021-22728 | 0.0 | unknown |
No description available.
|
| CVE-2022-0221 | 0.0 | unknown |
An improper restriction of XML external entity reference vulnerability exists that could result in information disclosure when opening a malicious solution file provided by an attacker with SCADAPack Workbench. This could be exploited to pass data from local files to a remote system controlled by an attacker.CVE-2022-0221 has been assigned to this vulnerability. A CVSS v3 base score of 5.5 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).
|
| CVE-2023-1548 | 0.0 | unknown |
No description available.
|
| CVE-2021-22823 | 0.0 | unknown |
No description available.
|
| CVE-2020-7513 | 0.0 | unknown |
No description available.
|
| CVE-2020-7570 | 6.4 | medium |
CVE-2020-7570. An improper neutralization of an input during webpage generation vulnerability could allow an authenticated remote user to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a stored cross-site scripting attack against other WebReport users.CVE-2020-7570 has been assigned to this vulnerability. A CVSS v3 base score of 6.4 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L).
|
| CVE-2019-0803 | 0.0 | unknown |
No description available.
|
| CVE-2018-12130 | 0.0 | unknown |
CVE-2018-12130. Microarchitectural Fill Buffer Data Sampling (MFBDS): Fill buffers on some microprocessors utilizing
speculative execution may allow an authenticated user to potentially enable information disclosure via
a side channel with local access.
Additional information about the vulnerabilities can be found in the INTEL website:
[INTEL-SA-00233](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00233.html)
|
| CVE-2022-32517 | 0.0 | unknown |
No description available.
|
| CVE-2022-34753 | 0.0 | unknown |
No description available.
|
| CVE-2024-8070 | 0.0 | unknown |
CVE-2024-8070. CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that exposes test
credentials in the firmware binary.
|
| CVE-2025-0813 | 0.0 | unknown |
The Schneider Electric EcoStruxure Power Automation System User Interface (EPAS-UI) is vulnerable to authentication bypass. This occurs when an unauthorized user, without permission rights, has physical access to the EPAS-UI computer and is able to reboot the workstation and interrupt the normal boot process.
|
| CVE-2020-16233 | 0.0 | unknown |
CVE-2020-16233. An attacker could send a specially crafted packet that could have the server send back packets containing data from the heap.
|
| CVE-2020-7510 | 0.0 | unknown |
No description available.
|
| CVE-2019-19193 | 0.0 | unknown |
No description available.
|
| CVE-2020-11901 | 0.0 | unknown |
Improper input validation in DNS resolver component when handling a packet sent by an unauthorized network attacker. This vulnerability may result in remote code execution.
|
| CVE-2022-34759 | 0.0 | unknown |
No description available.
|
| CVE-2026-0667 | 0.0 | unknown |
CVE-2026-0667. CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code
execution, denial of service and loss of confidentiality & integrity when communicating over the Modbus TCP
protocol.
|
| CVE-2022-41669 | 0.0 | unknown |
No description available.
|
| CVE-2026-1227 | 0.0 | unknown |
CVE-2026-1227. An improper restriction of XML external entity reference vulnerability exists that could result in unauthorized disclosure of local files, unauthorized interaction with the EBO system, or denial-of-service conditions. This occurs when a local user uploads a maliciously crafted TGML graphics file to the EBO server from Workstation.
|
| CVE-2023-37550 | 0.0 | unknown |
CVE-2023-37550. In multiple CODESYS products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition.
|
| CVE-2024-5679 | 0.0 | unknown |
CVE-2024-5679. CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, or
kernel memory leak when a malicious actor with local user access crafts a script/program using
an IOCTL call in the Foxboro.sys driver.
|
| CVE-2021-22703 | 0.0 | unknown |
No description available.
|
| CVE-2023-3669 | 0.0 | unknown |
CVE-2023-3669. A missing Brute-Force protection in CODESYS Development System prior to 3.5.19.20 allows a local attacker to have unlimited attempts of guessing the password within an import dialog.
|
| CVE-2025-59287 | 0.0 | unknown |
CVE-2025-59287. Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
|
| CVE-2021-22790 | 0.0 | unknown |
No description available.
|
| CVE-2025-6438 | 0.0 | unknown |
CVE-2025-6438. CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could
cause manipulation of SOAP API calls and XML external entities injection resulting in unauthorized file access
when the server is accessed via the network using an application account.
|
| CVE-2015-7937 | 0.0 | unknown |
Stack-based buffer overflow in the GoAhead Web Server on Schneider Electric Modicon M340 PLC BMXNOx and BMXPx devices allows remote attackers to execute arbitrary code via a long password in HTTP Basic Authentication data.
|
| CVE-2021-22782 | 6.2 | medium |
A missing encryption of sensitive data vulnerability exists that could cause an information leak allowing disclosure of network and process information, credentials, or intellectual property when an attacker can access a project file.CVE-2021-22782 has been assigned to this vulnerability. A CVSS v3 base score of 6.2 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
|
| CVE-2018-7772 | 0.0 | unknown |
No description available.
|
| CVE-2020-7520 | 0.0 | unknown |
No description available.
|
| CVE-2020-7509 | 0.0 | unknown |
No description available.
|
| CVE-2019-12258 | 0.0 | unknown |
An attacker with the source and destination TCP-port and IP-addresses of a session can inject invalid TCP segments into the flow, causing the TCP-session to be reset. An application will see this as an ECONNRESET error message when using the socket after such an attack. The most likely outcome is a crash of the application reading from the affected socket.. CVE-2019-12258 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).The most likely outcome is a crash of the application reading from the affected socket.
|
| CVE-2025-54927 | 0.0 | unknown |
CVE-2025-54927. CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause unauthorized access to sensitive files when an authenticated attackers uses a crafted path input that is processed by the system.
|
| CVE-2022-34763 | 0.0 | unknown |
No description available.
|
| CVE-2021-22799 | 3.8 | low |
An insufficient entropy vulnerability exists, which could cause unintended connection from an internal network to an external network when an attacker manages to decrypt the SESU proxy password from the registry.CVE-2021-22799 has been assigned to this vulnerability. A CVSS v3 base score of 3.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N).
|
| CVE-2019-12259 | 0.0 | unknown |
An attacker residing on the LAN may choose to hijack a DHCP-client session that requests an IPv4 address. The attacker can send a multicast IP address in the DHCP offer/ack message, which the victim system then incorrectly assigns. This vulnerability can be combined with CVE-2019-12259 to create a denial-of-service condition.. CVE-2019-12264 has been assigned to this vulnerability. A CVSS v3 base score of 7.1 has been calculated; the CVSS vector string is (AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).This vulnerability can be combined with CVE-2019-12259 to create a denial-of-service condition.
|
| CVE-2021-22741 | 0.0 | unknown |
No description available.
|
| CVE-2021-22821 | 0.0 | unknown |
No description available.
|
| CVE-2022-32514 | 0.0 | unknown |
No description available.
|
| CVE-2021-22806 | 0.0 | unknown |
No description available.
|
| CVE-2020-11899 | 0.0 | unknown |
Improper input validation in IPv6 component when handling a packet sent by an unauthorized network attacker. This vulnerability may allow out-of-bounds read and a possible denial of service.
|
| CVE-2021-22822 | 0.0 | unknown |
No description available.
|
| CVE-2022-47388 | 0.0 | unknown |
CVE-2022-47388. An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
|
| CVE-2020-7568 | 3.1 | low |
An exposure of sensitive information to an unauthorized actor vulnerability exists that could allow non-sensitive information disclosure when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller.CVE-2020-7568 has been assigned to this vulnerability. A CVSS v3 base score of 3.1 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
|
| CVE-2021-30064 | 0.0 | unknown |
No description available.
|
| CVE-2022-30236 | 0.0 | unknown |
No description available.
|
| CVE-2019-8960 | 0.0 | unknown |
No description available.
|
| CVE-2020-7564 | 6.3 | medium |
A classic buffer overflow vulnerability exists which could cause write access and the execution of commands when uploading a specially crafted file on the controller over FTP. CVE-2020-7564 has been assigned to this vulnerability. A CVSS v3 base score of 6.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:H).
|
| CVE-2020-7546 | 0.0 | unknown |
No description available.
|
| CVE-2019-6829 | 0.0 | unknown |
CVE-2019-6829. An uncaught exception vulnerability exists which could cause a possible denial of service when writing to specific memory addresses in the controller over Modbus.
|
| CVE-2022-47386 | 0.0 | unknown |
CVE-2022-47386. An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
|
| CVE-2022-30232 | 0.0 | unknown |
No description available.
|
| CVE-2021-22753 | 7.8 | high |
Exploitation of this vulnerability could result in loss of data or remote code execution due to missing length checks when a malicious WSP file is being parsed by IGSS Definition.CVE-2021-22753 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2023-37555 | 0.0 | unknown |
CVE-2023-37555. In multiple versions of multiple CODESYS products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition.
|
| CVE-2023-37554 | 0.0 | unknown |
CVE-2023-37554. In multiple versions of multiple CODESYS products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition.
|
| CVE-2020-27337 | 9.1 | critical |
An out-of-bounds write in the IPv6 component may allow an unauthenticated user to potentially cause a possible denial-of-service via network access.CVE-2020-27337 has been assigned to this vulnerability. A CVSS v3 base score of 9.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).
|
| CVE-2019-6809 | 0.0 | unknown |
CVE-2019-6809. An uncaught exception vulnerability exists, which could cause a possible denial of service when reading invalid data from the controller.
|
| CVE-2020-7537 | 0.0 | unknown |
No description available.
|
| CVE-2024-37037 | 0.0 | unknown |
CVE-2024-37037. CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path
Traversal’) vulnerability exists that could allow an authenticated user with access to the device’s
web interface to corrupt files and impact device functionality when sending a crafted HTTP
request.
|
| CVE-2021-22698 | 7.8 | high |
When a malicious SSD file is uploaded and improperly parsed, an attacker could cause a use-after-free condition or stack-based buffer overflow resulting in remote code execution.
|
| CVE-2019-9008 | 0.0 | unknown |
CVE-2019-9008. An issue was discovered in 3S-Smart CODESYS V3 through 3.5.12.30. A user with low privileges can take full control over the runtime.
|
| CVE-2023-5987 | 0.0 | unknown |
No description available.
|
| CVE-2021-22735 | 0.0 | unknown |
No description available.
|
| CVE-2023-5629 | 0.0 | unknown |
No description available.
|
| CVE-2022-34762 | 0.0 | unknown |
No description available.
|
| CVE-2020-7493 | 8.6 | high |
An attacker could exploit an SQL injection vulnerability by enticing a user to open a maliciously crafted project file.CVE-2020-7493 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
|
| CVE-2021-22729 | 0.0 | unknown |
No description available.
|
| CVE-2021-22721 | 0.0 | unknown |
No description available.
|
| CVE-2020-14519 | 0.0 | unknown |
CVE-2020-14519. This vulnerability could allow an attacker to use an internal API via a specifically crafted Java Script payload, which may allow alteration or creation of license files.
|
| CVE-2018-7848 | 0.0 | unknown |
CVE-2018-7848. An information exposure vulnerability exists, which could cause the disclosure of SNMP information when reading files from the controller over Modbus.
|
| CVE-2020-25066 | 9.8 | critical |
A vulnerability in Treck HTTP Server components allow an attacker to cause a denial-of-service condition. This vulnerability may also result in arbitrary code execution.CVE-2020-25066 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2020-7561 | 10.0 | critical |
The affected product is vulnerable to a missing authentication for critical function vulnerability, which may allow an attacker to expose information, cause a denial-of-service condition, and remotely execute arbitrary code.CVE-2020-7561 has been assigned to this vulnerability. A CVSS v3 base score of 10.0 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H).
|
| CVE-2018-7830 | 0.0 | unknown |
No description available.
|
| CVE-2020-7517 | 0.0 | unknown |
No description available.
|
| CVE-2021-22723 | 0.0 | unknown |
No description available.
|
| CVE-2023-37552 | 0.0 | unknown |
CVE-2023-37552. In multiple versions of multiple CODESYS products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition.
|
| CVE-2020-35685 | 7.5 | high |
TCP ISNs are insufficiently randomized, which may result in TCP spoofing by an attacker.CVE-2020-35685 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
|
| CVE-2020-7536 | 0.0 | unknown |
No description available.
|
| CVE-2020-7529 | 0.0 | unknown |
No description available.
|
| CVE-2021-22800 | 0.0 | unknown |
No description available.
|
| CVE-2018-7831 | 0.0 | unknown |
No description available.
|
| CVE-2020-28209 | 2.0 | low |
CVE-2020-28209. An unquoted search path vulnerability could allow any local Windows user with write permissions on at least one of the subfolders of the connect agent service binary path to gain the privilege of the user who started the service. By default, the Enterprise Server and Enterprise Central is always installed at a location requiring Administrator privileges, so this vulnerability is only valid if the application has been installed on a non-secure location. CVE-2020-28209 has been assigned to this vulnerability. A CVSS v3 base score of 2.0 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N).
|
| CVE-2020-7481 | 0.0 | unknown |
No description available.
|
| CVE-2024-12399 | 0.0 | unknown |
CVE-2024-12399. CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel
vulnerability exists that could cause partial loss of confidentiality, loss of integrity and availability of the
HMI when attacker performs man in the middle attack by intercepting the communication.
|
| CVE-2022-42973 | 0.0 | unknown |
Schneider Electric APC Easy UPS Online versions 2.5-GA and prior use hard-coded MySQL database credentials. A local unauthorized user with access to the database could use the select into dumpfile operation to create arbitrary files, which could be used to execute commands with system privileges.CVE-2022-42973 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2023-25551 | 0.0 | unknown |
No description available.
|
| CVE-2023-37196 | 0.0 | unknown |
No description available.
|
| CVE-2021-22813 | 6.8 | medium |
A vulnerability could cause arbitrary script execution when a privileged account clicks on a malicious URL specifically crafted for the NMC pointing to an edit policy file.CVE-2021-22813 has been assigned to this vulnerability. A CVSS v3 base score of 6.8 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N).
|
| CVE-2019-12257 | 0.0 | unknown |
DHCP packets may go past the local area network (LAN) via DHCP-relays, but are otherwise confined to the LAN.
The DHCP-client may be used by VxWorks and in the bootrom. Bootrom, using DHCP/BOOTP, is only vulnerable during the boot-process. This vulnerability may be used to overwrite the heap, which could result in a later crash when a task requests memory from the heap. This vulnerability can result in remote code execution.CVE-2019-12257 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2020-28216 | 7.6 | high |
The affected product is vulnerable to a missing encryption of sensitive data vulnerability, which may allow an attacker to read network traffic over HTTP protocol.CVE-2020-28216 has been assigned to this vulnerability. A CVSS v3 base score of 7.6 has been calculated; the CVSS vector string is (AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
|
| CVE-2022-32526 | 0.0 | unknown |
No description available.
|
| CVE-2019-1182 | 0.0 | unknown |
No description available.
|
| CVE-2022-43377 | 0.0 | unknown |
No description available.
|
| CVE-2019-1226 | 0.0 | unknown |
No description available.
|
| CVE-2021-22759 | 7.8 | high |
Exploitation of this vulnerability could result in loss of data or remote code execution due to use of unchecked input data when a malicious CGF file is imported to IGSS Definition.CVE-2021-22759 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2023-25549 | 0.0 | unknown |
No description available.
|
| CVE-2021-22714 | 0.0 | unknown |
No description available.
|
| CVE-2024-6528 | 0.0 | unknown |
A Cross-site Scripting vulnerability exists where an attacker could cause a victim's browser run arbitrary JavaScript when they visit a page containing the injected payload.
|
| CVE-2022-47389 | 0.0 | unknown |
CVE-2022-47389. An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
|
| CVE-2025-2440 | 0.0 | unknown |
CVE-2025-2440. CWE-922: Insecure Storage of Sensitive Information vulnerability exists that could potentially lead to unauthorized
access of confidential data when a malicious user, having physical access and advanced information on the file
system, sets the radio in factory default mode.
|
| CVE-2025-8448 | 0.0 | unknown |
CVE-2025-8448. CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause
unauthorized access to sensitive credential data when an attacker is able to capture local SMB traffic between
a valid user within the BMS network and the vulnerable products.
|
| CVE-2023-37547 | 0.0 | unknown |
CVE-2023-37547. In multiple CODESYS products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition.
|
| CVE-2020-28210 | 4.3 | medium |
CVE-2020-28210. An improper neutralization of an input during webpage generation vulnerability could allow an attacker to inject HTML and JavaScript code into the user's browser. CVE-2020-28210 has been assigned to this vulnerability. A CVSS v3 base score of 4.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).
|
| CVE-2020-7563 | 6.3 | medium |
An out-of-bounds write vulnerability exists which could cause corruption of data, a crash, or code execution when uploading a specially crafted file on the controller over FTP. CVE-2020-7563 has been assigned to this vulnerability. A CVSS v3 base score of 6.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:H).
|
| CVE-2024-6352 | 0.0 | unknown |
CVE-2024-6352. A CWE-120: A buffer overflow vulnerability exists that could cause a denial of service when a
malicious device joins the network.
|
| CVE-2021-21828 | 0.0 | unknown |
In the command-line-parsing HandleFileArg functionality of AT&T Labs ' Xmill 0.7, an attacker could trigger the vulnerability by using a specially crafted command-line argument that can lead to code execution.CVE-2021-21828 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2019-12262 | 0.0 | unknown |
An attacker residing on the LAN can send reverse-ARP responses to the victim system to assign unicast IPv4 addresses to the target.CVE-2019-12262 has been assigned to this vulnerability. A CVSS v3 base score of 7.1 has been calculated; the CVSS vector string is (AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).
|
| CVE-2022-37300 | 0.0 | unknown |
No description available.
|
| CVE-2018-7769 | 0.0 | unknown |
No description available.
|
| CVE-2019-6833 | 7.4 | high |
When the device receives a high rate of frames, the HMI may temporarily freeze. When the attack stops, the buffered commands are processed by the HMI.CVE-2019-6833 has been assigned to this vulnerability. A CVSS v3 base score of 7.4 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H).
|
| CVE-2022-22724 | 0.0 | unknown |
No description available.
|
| CVE-2020-7515 | 0.0 | unknown |
No description available.
|
| CVE-2021-22805 | 5.3 | medium |
An issue exists that could allow disclosure and read access of arbitrary files in the context of the user running IGSS, due to missing validation of user supplied data in network messages.CVE-2021-22805 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).
|
| CVE-2020-7479 | 7.8 | high |
The affected product could allow a local user to execute processes that otherwise require escalation privileges when sending local network commands to the IGSS update service.CVE-2020-7479 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2020-7553 | 7.8 | high |
An out-of-bounds write vulnerability could cause remote code execution when a malicious CGF (Configuration Group File) is imported to IGSS Definition.CVE-2020-7553 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2023-37557 | 0.0 | unknown |
CVE-2023-37557. After successful authentication as a user in multiple CODESYS products in multiple versions, specific crafted remote communication requests can cause the CmpAppBP component to overwrite a heap-based buffer, which can lead to a denial-of-service condition.
|
| CVE-2022-34764 | 0.0 | unknown |
No description available.
|
| CVE-2018-7855 | 0.0 | unknown |
CVE-2018-7855. An uncaught exception vulnerability exists, which could cause a denial of service when sending invalid breakpoint parameters to the controller over Modbus.
|
| CVE-2022-38138 | 0.0 | unknown |
CVE-2022-38138 . A vulnerability exists in the 3rd party library included in the product versions listed as affected in this advisory. An attacker could exploit the vulnerability by sending a specially crafted message to the system node, causing the node to stop or become inaccessible.
|
| CVE-2020-7504 | 0.0 | unknown |
No description available.
|
| CVE-2022-24319 | 0.0 | unknown |
No description available.
|
| CVE-2023-25556 | 0.0 | unknown |
No description available.
|
| CVE-2020-7555 | 7.8 | high |
An out-of-bounds write vulnerability could cause remote code execution when a malicious CGF (Configuration Group File) file is imported to IGSS Definition.CVE-2020-7555 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2021-22732 | 0.0 | unknown |
No description available.
|
| CVE-2021-22795 | 9.1 | critical |
The affected product is vulnerable to an OS command injection, which may allow an attacker to remotely execute code over the network.CVE-2021-22795 has been assigned to this vulnerability. A CVSS v3 base score of 9.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
|
| CVE-2022-30233 | 0.0 | unknown |
No description available.
|
| CVE-2023-25550 | 0.0 | unknown |
No description available.
|
| CVE-2020-7495 | 3.3 | low |
An attacker could exploit this path traversal vulnerability by getting a user to visit a malicious page or open a malicious file.CVE-2020-7495 has been assigned to this vulnerability. A CVSS v3 base score of 3.3 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).
|
| CVE-2021-22712 | 7.8 | high |
This vulnerability could result in arbitrary read or write conditions due to an unchecked pointer address when a malicious CGF file is imported into an IGSS Definition.CVE-2021-22712 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2018-12126 | 0.0 | unknown |
No description available.
|
| CVE-2025-5296 | 0.0 | unknown |
CVE-2025-5296. CWE-59: Improper Link Resolution Before File Access ('Link Following') vulnerability exists that could cause
arbitrary data to be written to protected locations, potentially leading to escalation of privilege, arbitrary file
corruption, exposure of application and system information or persistent denial of service when a low-privileged
attacker tampers with the installation folder.
|
| CVE-2022-46680 | 0.0 | unknown |
A cleartext transmission of sensitive information vulnerability exists that could cause disclosure of sensitive information, denial of service, or modification of data if an attacker is able to intercept network traffic.
|
| CVE-2023-3953 | 0.0 | unknown |
No description available.
|
| CVE-2025-46817 | 0.0 | unknown |
CVE-2025-46817. Additional information about CVE-2025-46817 can be found here: https://www.cve.org/CVERecord?id=CVE-2025-46817
|
| CVE-2022-34761 | 0.0 | unknown |
No description available.
|
| CVE-2020-7533 | 0.0 | unknown |
No description available.
|
| CVE-2022-32523 | 0.0 | unknown |
No description available.
|
| CVE-2025-3899 | 0.0 | unknown |
CVE-2025-3899. CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability
exists in Certificates page on Webserver that could cause an unvalidated data injected by authenticated
malicious user leading to modify or read data in a victim’s browser.
|
| CVE-2025-3905 | 0.0 | unknown |
CVE-2025-3905. CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability
exists impacting PLC system variables that could cause an unvalidated data injected by authenticated
malicious user leading to modify or read data in a victim’s browser.
|
| CVE-2020-7052 | 0.0 | unknown |
CVE-2020-7052. CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition.
|
| CVE-2022-37301 | 0.0 | unknown |
No description available.
|
| CVE-2020-25184 | 7.8 | high |
ISaGRAF Runtime stores the password in plaintext in a file that is in the same directory as the executable file. ISaGRAF Runtime reads the file and saves the data in a variable without any additional modification. A local, unauthenticated attacker could compromise the user passwords, resulting in information disclosure.CVE-2020-25184 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2020-13987 | 8.2 | high |
The function in open-iscsi, uIP-Contiki-OS, and uIP that parses incoming transport layer packets (TCP/UDP) does not check the length fields of packet headers against the data available in the packets. Given arbitrary lengths, an out-of-bounds memory read may be performed during the checksum computation.CVE-2020-13987 has been assigned to this vulnerability. A CVSS v3 base score of 8.2 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).
|
| CVE-2018-7242 | 0.0 | unknown |
No description available.
|
| CVE-2018-7853 | 0.0 | unknown |
CVE-2018-7853. An uncaught exception vulnerability exists, which could cause denial of service when reading invalid physical memory blocks in the controller over Modbus.
|
| CVE-2021-22754 | 7.8 | high |
Exploitation of this vulnerability could result in loss of data or remote code execution due to lack of proper validation of user-supplied data when a malicious CGF file is imported to IGSS Definition.CVE-2021-22754 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2020-7535 | 0.0 | unknown |
No description available.
|
| CVE-2021-22744 | 0.0 | unknown |
No description available.
|
| CVE-2024-2051 | 0.0 | unknown |
No description available.
|
| CVE-2021-22719 | 8.8 | high |
The affected product is vulnerable to Path Traversal, which could allow remote code execution when a file is uploaded.CVE-2021-22719 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2019-6843 | 0.0 | unknown |
No description available.
|
| CVE-2020-25178 | 7.5 | high |
ISaGRAF Workbench communicates with ISaGRAF Runtime using TCP/IP. This communication protocol provides various file system operations, as well as the uploading of applications. Data is transferred over this protocol unencrypted, which could allow a remote unauthenticated attacker to upload, read, and delete files.CVE-2020-25178 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2020-11914 | 0.0 | unknown |
Improper input validation in ARP component when handling a packet sent by an unauthorized network attacker. This vulnerability may allow out-of-bounds read.
|
| CVE-2020-7476 | 0.0 | unknown |
No description available.
|
| CVE-2020-7541 | 0.0 | unknown |
No description available.
|
| CVE-2024-10498 | 0.0 | unknown |
An improper restriction of operations within the bounds of a memory buffer vulnerability exists that could allow an unauthorized attacker to modify configuration values outside of the normal range when the attacker sends specific Modbus write packets to the device, which could result in invalid data or loss of web interface functionality.
|
| CVE-2021-22758 | 7.8 | high |
Exploitation of this vulnerability could result in loss of data or remote code execution due to lack of validation of user-supplied input data when a malicious CGF file is imported to IGSS Definition.CVE-2021-22758 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2021-22820 | 0.0 | unknown |
No description available.
|
| CVE-2022-47385 | 0.0 | unknown |
CVE-2022-47385. An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpAppForce Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
|
| CVE-2023-3663 | 0.0 | unknown |
CVE-2023-3663. In CODESYS Development System versions from 3.5.11.20 and before 3.5.19.20 a missing integrity check might allow an unauthenticated remote attacker to manipulate the content of notifications received via HTTP by the CODESYS notification server.
|
| CVE-2025-0816 | 0.0 | unknown |
CVE-2025-0816. CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the
product when malicious IPV6 packets are sent to the device.
|
| CVE-2022-47380 | 0.0 | unknown |
CVE-2022-47380. An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
|
| CVE-2021-22768 | 0.0 | unknown |
No description available.
|
| CVE-2024-37038 | 0.0 | unknown |
CVE-2024-37038. CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated
user with access to the device’s web interface to perform unauthorized file and firmware
uploads when crafting custom web requests.
|
| CVE-2025-6625 | 0.0 | unknown |
CVE-2025-6625. CWE-20: Improper Input Validation vulnerability exists that could cause a Denial Of Service when specific
crafted FTP command is sent to the device.
|
| CVE-2023-37197 | 0.0 | unknown |
No description available.
|
| CVE-2020-35198 | 0.0 | unknown |
CVE-2020-35198. An issue was discovered in Wind River VxWorks 7. The memory al-locator has a possible integer overflow in calculating a memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer size specified by the arguments, leading to memory corruption.
|
| CVE-2019-6807 | 0.0 | unknown |
CVE-2019-6807. An uncaught exception vulnerability exists which could cause a possible denial of service when writing sensitive application variables to the controller over Modbus.
|
| CVE-2025-3116 | 0.0 | unknown |
CVE-2025-3116. CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an
authenticated malicious user sends special malformed HTTPS request containing improper formatted body
data to the controller.
|
| CVE-2020-7525 | 0.0 | unknown |
No description available.
|
| CVE-2021-4104 | 0.0 | unknown |
No description available.
|
| CVE-2021-22748 | 0.0 | unknown |
No description available.
|
| CVE-2020-25182 | 6.7 | medium |
ISaGRAF Runtime searches for and loads DLLs as dynamic libraries. Uncontrolled loading of dynamic libraries could allow a local, unauthenticated attacker to execute arbitrary code. This vulnerability only affects ISaGRAF Runtime when running on Microsoft Windows systems.CVE-2020-25182 has been assigned to this vulnerability. A CVSS v3 base score of 6.7 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2021-22704 | 0.0 | unknown |
No description available.
|
| CVE-2021-22766 | 0.0 | unknown |
No description available.
|
| CVE-2021-22792 | 0.0 | unknown |
No description available.
|
| CVE-2021-22707 | 0.0 | unknown |
No description available.
|
| CVE-2020-28220 | 0.0 | unknown |
No description available.
|
| CVE-2020-7557 | 7.8 | high |
An out-of-bounds read vulnerability could cause remote code execution when a malicious CGF (Configuration Group File) is imported to IGSS Definition.CVE-2020-7557 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2021-22774 | 0.0 | unknown |
No description available.
|
| CVE-2021-31400 | 7.5 | high |
The TCP urgent data processing function may invoke a panic function, which may result in an infinite loop.CVE-2021-31400 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
|
| CVE-2020-7521 | 9.8 | critical |
A vulnerability exists when accessing a vulnerable method of `FileUploadServlet` that may lead to uploading executable files to non-specified directories.CVE-2020-7521 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2020-7512 | 0.0 | unknown |
No description available.
|
| CVE-2021-21814 | 0.0 | unknown |
Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line. filepattern is passed directly to strlen to determine the ending location of the char* passed in by the user, no checks are done to see if the passed in char* is longer than the staticly sized buffer data is memcpy-d into, but after the memcpy a null byte is written to what is assumed to be the end of the buffer to terminate the char*, but without length checks, this null write occurs at an arbitrary offset from the buffer. An attacker can provide malicious input to trigger this vulnerability.CVE-2021-21814 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2021-22814 | 6.8 | medium |
A vulnerability could cause arbitrary script execution when a malicious file is read and displayed.CVE-2021-22814 has been assigned to this vulnerability. A CVSS v3 base score of 6.8 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N).
|
| CVE-2021-22794 | 9.1 | critical |
The affected product is vulnerable to directory traversal, which may allow an attacker to remotely execute code.CVE-2021-22794 has been assigned to this vulnerability. A CVSS v3 base score of 9.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
|
| CVE-2022-4224 | 0.0 | unknown |
CVE-2022-4224. In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files and OS resources or DoS the device.
|
| CVE-2024-8401 | 0.0 | unknown |
CVE-2024-8401. CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
vulnerability exists when an authenticated attacker modifies folder names within the context of
the product.
|
| CVE-2022-45198 | 0.0 | unknown |
Versions of Pillow before 9.2.0 improperly handle highly compressed GIF data (data amplification).
|
| CVE-2023-5217 | 0.0 | unknown |
A heap buffer overflow in vp8 encoding in libvpx, used by Google Chrome versions prior to 117.0.5938.132 and libvpx Version 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
| CVE-2021-22761 | 7.8 | high |
Exploitation of this vulnerability could result in disclosure of information or remote code execution due to missing length check on user supplied data when a malicious CGF file is imported to IGSS Definition.CVE-2021-22761 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2021-22826 | 0.0 | unknown |
No description available.
|
| CVE-2023-1049 | 0.0 | unknown |
Schneider Electric EcoStruxure operator Terminal Expert versions 3.3 SP1 and prior are vulnerable to a code injection attack that could allow an attacker to execute arbitrary code and gain access to all information on the machine.
|
| CVE-2020-7542 | 0.0 | unknown |
No description available.
|
| CVE-2023-3662 | 0.0 | unknown |
CVE-2023-3662. In CODESYS Development System versions from 3.5.17.0 and prior to 3.5.19.20 a vulnerability allows for execution of binaries from the current working directory in the users context .
|
| CVE-2020-0610 | 0.0 | unknown |
No description available.
|
| CVE-2019-12261 | 0.0 | unknown |
The impact of this vulnerability is a buffer overflow of up to a full TCP receive window (by default, 10k-64k depending on version). The buffer overflow happens in the task calling recv()/recvfrom()/recvmsg(). Applications that pass a buffer equal to or larger than a full TCP window are not susceptible to this attack. Applications passing a stack-allocated variable as a buffer are the easiest to exploit. The most likely outcome is a crash of the application reading from the affected socket, which could result in remote code execution.. CVE-2019-12261 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).The most likely outcome is a crash of the application reading from the affected socket, which could result in remote code execution.
|
| CVE-2022-22808 | 0.0 | unknown |
No description available.
|
| CVE-2025-46818 | 0.0 | unknown |
CVE-2025-46818. Additional information about CVE-2025-46818 can be found here: https://www.cve.org/CVERecord?id=CVE-2025-46818
|
| CVE-2022-42972 | 0.0 | unknown |
Schneider Electric APC Easy UPS Online versions 2.5-GA and prior run the Tomcat instance with SYSTEM privileges. NT AUTHORITY\Authenticated Users could create new files in the Tomcat web root directory and could create and execute a maliciously crafted JSP file to escalate privileges and execute commands with system privileges.CVE-2022-42972 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2018-7770 | 0.0 | unknown |
No description available.
|
| CVE-2020-11912 | 0.0 | unknown |
Improper input validation in TCP component when handling a packet sent by an unauthorized network attacker. This vulnerability may allow out-of-bounds read.
|
| CVE-2023-27976 | 0.0 | unknown |
No description available.
|
| CVE-2021-22743 | 0.0 | unknown |
No description available.
|
| CVE-2025-2223 | 0.0 | unknown |
CVE-2025-2223. CWE-20: Improper Input Validation vulnerability exists that could cause a loss of Confidentiality, Integrity and
Availability of engineering workstation when a malicious project file is loaded by a user from the local system.
|
| CVE-2020-7475 | 0.0 | unknown |
No description available.
|
| CVE-2020-7566 | 7.1 | high |
A small space of random values vulnerability exists that could allow the attacker to break the encryption keys when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller.CVE-2020-7566 has been assigned to this vulnerability. A CVSS v3 base score of 7.1 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2021-21827 | 0.0 | unknown |
A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7. Within `DecodeTreeBlock` which is called during the decompression of an XMI file, a UINT32 is loaded from the file and used as trusted input as the length of a buffer. An attacker can provide a malicious file to trigger this vulnerability.CVE-2021-21827 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2020-7530 | 0.0 | unknown |
No description available.
|
| CVE-2021-21869 | 0.0 | unknown |
CVE-2021-21869. An unsafe deserialization vulnerability exists in the Engine.plugin ProfileInformation ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.
|
| CVE-2019-6841 | 0.0 | unknown |
No description available.
|
| CVE-2024-5559 | 0.0 | unknown |
CVE-2024-5559. CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists that could
cause denial of service, device reboot, or an attacker gaining full control of the relay when a
specially crafted reset token is entered into the front panel of the device.
|
| CVE-2024-10511 | 0.0 | unknown |
CVE-2024-10511. CWE-287: Improper Authentication vulnerability exists that could cause Denial of access to the web interface
when someone on the local network repeatedly requests the /accessdenied URL.
|
| CVE-2025-3916 | 0.0 | unknown |
A CWE-121 Stack-based Buffer Overflow vulnerability exists that could cause local attackers being able to exploit these issues to potentially execute arbitrary code while the end user opens a malicious project file (SSD file) provided by the attacker.
|
| CVE-2020-8597 | 9.8 | critical |
CVE-2020-8597. The version of pppd shipped with this product has a vulnerability that may allow an unauthenticated remote attacker to cause a stack buffer overflow, which may allow arbitrary code execution on the target system.
|
| CVE-2020-14517 | 0.0 | unknown |
CVE-2020-14517. Protocol encryption can be easily broken and the server accepts external connections, which may allow an attacker to remotely communicate with the CodeMeter API.
|
| CVE-2023-27982 | 0.0 | unknown |
A vulnerability in Schneider Electric Data Server could cause manipulation of dashboard files in the IGSS project report directory when an attacker sends specific crafted messages to the Data Server TCP port. This could lead to remote code execution if an unsuspecting user opens the malicious dashboard file. CVE-2023-27982 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2025-9996 | 0.0 | unknown |
A OS command injection vulnerability exists that could cause the execution of any shell command when executing a netstat command using BLMon Console in anSSH session.
|
| CVE-2020-11898 | 0.0 | unknown |
Improper handling of length parameter inconsistency in IPv4/ICMPv4 component when handling a packet sent by an unauthorized network attacker. This vulnerability may result in out-of-bounds read.
|
| CVE-2022-4046 | 0.0 | unknown |
CVE-2022-4046. The CODESYS Control runtime system does not restrict the memory access. An improper restriction of operations within the bounds of a memory buffer allows an attacker with access to the drive with user privileges to gain full access of the drive.
|
| CVE-2022-24310 | 9.8 | critical |
A vulnerability exists that could cause heap-based buffer overflow, leading to denial of service and potentially remote code execution when an attacker sends multiple specially crafted messages.CVE-2022-24310 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2021-22739 | 0.0 | unknown |
No description available.
|
| CVE-2021-22770 | 0.0 | unknown |
No description available.
|
| CVE-2022-0715 | 0.0 | unknown |
No description available.
|
| CVE-2021-22755 | 7.8 | high |
Exploitation of this vulnerability could result in disclosure of information or remote code execution due to lack of sanity checks on user-supplied data when a malicious CGF file is imported to IGSS Definition.CVE-2021-22755 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2022-30234 | 0.0 | unknown |
No description available.
|
| CVE-2021-22802 | 9.8 | critical |
The affected product is vulnerable to remote code execution, due to missing length check on user supplied data, when a constructed message is received on the network.CVE-2021-22802 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2020-27336 | 3.7 | low |
Improper input validation in the IPv6 component may allow an unauthenticated user to cause an out-of-bounds read of up to three bytes via network access.CVE-2020-27336 has been assigned to this vulnerability. A CVSS v3 base score of 3.7 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
|
| CVE-2022-22726 | 0.0 | unknown |
No description available.
|
| CVE-2024-0568 | 0.0 | unknown |
No description available.
|
| CVE-2023-5630 | 0.0 | unknown |
No description available.
|
| CVE-2020-7482 | 0.0 | unknown |
No description available.
|
| CVE-2021-22824 | 0.0 | unknown |
No description available.
|
| CVE-2021-22762 | 7.8 | high |
Exploitation of this vulnerability could result in remote code execution when a malicious CGF or WSP file is being parsed by IGSS Definition.CVE-2021-22762 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2020-11913 | 0.0 | unknown |
Improper input validation in IPv6 component when handling a packet sent by an unauthorized network attacker. This vulnerability may allow out-of-bounds read.
|
| CVE-2025-0815 | 0.0 | unknown |
CVE-2025-0815. CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the
product when malicious ICMPV6 packets are sent to the device.
|
| CVE-2021-30065 | 0.0 | unknown |
No description available.
|
| CVE-2018-12127 | 0.0 | unknown |
No description available.
|
| CVE-2022-47382 | 0.0 | unknown |
CVE-2022-47382. An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
|
| CVE-2025-11565 | 0.0 | unknown |
CVE-2025-11565. CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that
could cause elevated system access when a Web Admin user on the local network tampers with the POST
/REST/UpdateJRE request payload.
|
| CVE-2022-34758 | 5.1 | medium |
An Improper Input Validation vulnerability exists in Easergy P5 devices that cause the device watchdog function to be disabled if the attacker had access to privileged user credentials. CVE-2022-34758 has been assigned to this vulnerability. A CVSS v3 base score of 5.1 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L).
|
| CVE-2019-12256 | 0.0 | unknown |
This vulnerability resides in the IPv4 option parsing and may be triggered by IPv4 packets containing invalid options.
The most likely outcome of triggering this defect is that the tNet0 task crashes. This vulnerability can result in remote code execution.CVE-2019-12256 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2024-8935 | 0.0 | unknown |
CVE-2024-8935. CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss
of confidentiality and integrity of controllers when conducting a Man-In-The-Middle attack between the
controller and the engineering workstation while a valid user is establishing a communication session. This
vulnerability is inherent to Diffie Hellman algorithm which does not protect against Man-In-The-Middle attacks.
|
| CVE-2021-22804 | 7.5 | high |
An issue exists that could allow disclosure and read access of arbitrary files in the context of the user running IGSS, due to missing validation of user supplied data in network messages.CVE-2021-22804 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
|
| CVE-2021-22807 | 7.8 | high |
This vulnerability may cause arbitrary code execution when a malicious *.gd1 configuration file is loaded into the GUIcon tool.CVE-2021-22807 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2020-7484 | 7.5 | high |
A vulnerability related to the "password" feature in TriStation 1131 Versions 1.0 through 4.12.0 could allow a denial of service attack if the user is not following documented guidelines pertaining to dedicated TriStation 1131 connection and key-switch protection.CVE-2020-7484 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
|
| CVE-2022-32521 | 0.0 | unknown |
No description available.
|
| CVE-2023-37559 | 0.0 | unknown |
CVE-2023-37559. After successful authentication as a user in multiple CODESYS products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of-service condition.
|
| CVE-2018-7842 | 0.0 | unknown |
CVE-2018-7842. An authentication bypass by spoofing vulnerability exists which could cause an elevation of privilege by conducting a brute force attack on Modbus parameters sent to the controller.
|
| CVE-2020-28218 | 6.3 | medium |
The affected product is vulnerable due to an improper restriction of rendered UI layers or frames vulnerability, which may allow an attacker to trick a user into initiating an unintended action.CVE-2020-28218 has been assigned to this vulnerability. A CVSS v3 base score of 6.3 has been calculated; the CVSS vector string is (AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:L).
|
| CVE-2020-7528 | 0.0 | unknown |
No description available.
|
| CVE-2020-11909 | 0.0 | unknown |
Improper input validation in IPv4 component when handling a packet sent by an unauthorized network attacker.
|
| CVE-2019-6808 | 0.0 | unknown |
CVE-2019-6808. An improper access control vulnerability exists, which could cause a remote code execution by overwriting configuration settings of the controller over Modbus.
|
| CVE-2022-32529 | 0.0 | unknown |
No description available.
|
| CVE-2022-32512 | 0.0 | unknown |
No description available.
|
| CVE-2020-1020 | 0.0 | unknown |
No description available.
|
| CVE-2018-7241 | 0.0 | unknown |
No description available.
|
| CVE-2019-6849 | 0.0 | unknown |
No description available.
|
| CVE-2025-50123 | 0.0 | unknown |
CVE-2025-50123. CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote
command execution by a privileged account when the server is accessed via a console and through
exploitation of the hostname input.
|
| CVE-2018-7843 | 0.0 | unknown |
CVE-2018-7843. An uncaught exception vulnerability exists which could cause denial of service when reading memory blocks with an invalid data size or with an invalid data offset in the controller over Modbus.
|
| CVE-2024-5313 | 0.0 | unknown |
No description available.
|
| CVE-2020-35684 | 7.5 | high |
The code that parses TCP packets relies on an unchecked value of the IP payload size to compute the length of the TCP payload within the TCP checksum computation function, which may result in an out-of-bounds read.CVE-2020-35684 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
|
| CVE-2021-22812 | 6.8 | medium |
A vulnerability could cause arbitrary script execution when a privileged account clicks on a malicious URL specifically crafted for the NMC.CVE-2021-22812 has been assigned to this vulnerability. A CVSS v3 base score of 6.8 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N).
|
| CVE-2018-7852 | 0.0 | unknown |
CVE-2018-7852. An uncaught exception vulnerability exists which could cause denial of service when an invalid private command parameter is sent to the controller over Modbus.
|
| CVE-2020-7550 | 7.8 | high |
An improper restriction of operations within the bounds of a memory buffer vulnerability could cause remote code execution when a malicious CGF (Configuration Group File) is imported to IGSS Definition.CVE-2020-7550 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2021-22825 | 6.5 | medium |
An attacker could access the system with elevated privileges when a privileged account clicks on a malicious URL that compromises the security token. CVE-2021-22825 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:L).. --------- End Update A Part 3 of 3 ---------CVE-2021-22825 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:L).
|
| CVE-2021-22818 | 0.0 | unknown |
No description available.
|
| CVE-2025-2441 | 0.0 | unknown |
CVE-2025-2441. CWE-1188: Incorrect Initialization of Resource vulnerability exists that could lead to loss of confidentiality when a
malicious user, having physical access, sets the radio in factory default mode where the product does not
correctly initialize all data.
|
| CVE-2021-22734 | 0.0 | unknown |
No description available.
|
| CVE-2022-24315 | 7.5 | high |
A vulnerability exists that could cause denial of service when an attacker repeatedly sends a specially crafted message.CVE-2022-24315 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
|
| CVE-2020-7567 | 7.1 | high |
A missing encryption of sensitive data vulnerability exists that could allow the attacker to find the password hash when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller and has broken the encryption keys.CVE-2020-7567 has been assigned to this vulnerability. A CVSS v3 base score of 7.1 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2020-11902 | 0.0 | unknown |
Improper input validation in IPv6 over IPv4 tunneling component when handling a packet sent by an unauthorized network attacker. This vulnerability may allow out-of-bounds read.
|
| CVE-2025-3117 | 0.0 | unknown |
CVE-2025-3117. CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability
exists impacting configuration file paths that could cause an unvalidated data injected by authenticated
malicious user leading to modify or read data in a victim’s browser.
|
| CVE-2022-2463 | 0.0 | unknown |
A crafted malicious .7z exchange file may allow an attacker to gain the privileges of the ISaGRAF Workbench software when opened. If the software is running at the SYSTEM level, then the attacker will gain admin level privileges. User interaction is required for this exploit to be successful.CVE-2022-2463 has been assigned to this vulnerability. A CVSS v3 base score of 6.1 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L).
|
| CVE-2019-6844 | 0.0 | unknown |
No description available.
|
| CVE-2019-6847 | 0.0 | unknown |
No description available.
|
| CVE-2023-5402 | 0.0 | unknown |
Schneider Electric's SpaceLogic C-Bus Toolkit product is vulnerable due to improper privilege management, which could cause remote code execution when the transfer command is used over the network.
|
| CVE-2021-21863 | 0.0 | unknown |
CVE-2021-21863. A unsafe deserialization vulnerability exists in the ComponentModel Profile.FromFile() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.
|
| CVE-2021-22817 | 0.0 | unknown |
No description available.
|
| CVE-2024-8936 | 0.0 | unknown |
CVE-2024-8936. CWE-20: Improper Input Validation vulnerability exists that could lead to tampering a parameter
of the controller memory after a successful Man In The Middle attack followed by Read Physical
Memory operation leading to loss of confidentiality of controller memory.
|
| CVE-2022-22812 | 0.0 | unknown |
No description available.
|
| CVE-2020-7545 | 0.0 | unknown |
No description available.
|
| CVE-2023-6409 | 0.0 | unknown |
CVE-2023-6409. A CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized
access to a project file protected with application password when opening the file with
EcoStruxure Control Expert.
|
| CVE-2022-41670 | 0.0 | unknown |
No description available.
|
| CVE-2021-22745 | 0.0 | unknown |
No description available.
|
| CVE-2022-34754 | 0.0 | unknown |
No description available.
|
| CVE-2021-22827 | 0.0 | unknown |
No description available.
|
| CVE-2023-50447 | 0.0 | unknown |
Pillow Version 10.1.0 allows PIL.ImageMath.eval arbitrary code execution via the environment parameter. This is a different vulnerability from CVE-2022-22817, which pertains to the expression parameter.
|
| CVE-2020-7524 | 0.0 | unknown |
No description available.
|
| CVE-2020-7514 | 0.0 | unknown |
No description available.
|
| CVE-2025-11567 | 0.0 | unknown |
CVE-2025-11567. CWE-276: Incorrect Default Permissions vulnerability exists that could cause elevated system access when
the target installation folder is not properly secured.
|
| CVE-2022-41671 | 0.0 | unknown |
No description available.
|
| CVE-2021-22777 | 0.0 | unknown |
No description available.
|
| CVE-2021-22787 | 0.0 | unknown |
No description available.
|
| CVE-2020-0609 | 0.0 | unknown |
No description available.
|
| CVE-2021-22765 | 0.0 | unknown |
No description available.
|
| CVE-2021-22788 | 0.0 | unknown |
No description available.
|
| CVE-2020-11897 | 0.0 | unknown |
Improper handling of length parameter inconsistency in IPv6 component when handling a packet sent by an unauthorized network attacker. This vulnerability may result in possible out-of-bounds write.
|
| CVE-2022-24313 | 9.8 | critical |
A vulnerability exists that could cause a stack-based buffer overflow potentially leading to remote code execution when an attacker sends a specially crafted message.CVE-2022-24313 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2020-7562 | 6.3 | medium |
An out-of-bounds read vulnerability exists which could cause a segmentation fault or a buffer overflow when uploading a specially crafted file on the controller over FTP. CVE-2020-7562 has been assigned to this vulnerability. A CVSS v3 base score of 6.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:H).
|
| CVE-2019-11091 | 0.0 | unknown |
No description available.
|
| CVE-2024-6918 | 0.0 | unknown |
CVE-2024-6918. CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability
exists that could cause a crash of the Accutech Manager when receiving a specially crafted
request over port 2536/TCP.
|
| CVE-2020-0796 | 0.0 | unknown |
No description available.
|
| CVE-2020-7483 | 5.3 | medium |
A vulnerability related to the "password" feature in TriStation 1131 Versions 1.0 through 4.12.0 could cause certain data to be visible on the network when the feature was enabled.CVE-2020-7483 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N).
|
| CVE-2020-7478 | 7.5 | high |
The affected product could allow a remote unauthenticated attacker to read arbitrary files on the device.CVE-2020-7478 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
|
| CVE-2023-22610 | 0.0 | unknown |
No description available.
|
| CVE-2021-33485 | 0.0 | unknown |
CVE-2021-33485. CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow.
|
| CVE-2023-6408 | 0.0 | unknown |
CVE-2023-6408. A CWE-924: Improper Enforcement of Message Integrity During Transmission in a
Communication Channel vulnerability exists that could cause a denial of service and loss of
confidentiality, integrity of controllers when conducting a Man in the Middle attack.
|
| CVE-2021-22705 | 0.0 | unknown |
No description available.
|
| CVE-2021-21815 | 0.0 | unknown |
A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs' Xmill 0.7. Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line. filepattern is passed directly to strcpy copying the path provided by the user into a staticly sized buffer without any length checks resulting in a stack-buffer overflow. An attacker can provide malicious input to trigger this vulnerability.CVE-2021-21815 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2020-7480 | 0.0 | unknown |
No description available.
|
| CVE-2019-9009 | 0.0 | unknown |
CVE-2019-9009. An issue was discovered in 3S-Smart CODESYS before 3.5.15.0 . Crafted network packets cause the Control Runtime to crash.
|
| CVE-2022-24323 | 0.0 | unknown |
No description available.
|
| CVE-2021-22772 | 0.0 | unknown |
No description available.
|
| CVE-2020-7518 | 0.0 | unknown |
No description available.
|
| CVE-2024-10106 | 0.0 | unknown |
CVE-2024-10106. A CWE-120: A buffer overflow vulnerability exists that could cause a denial of service when a
malicious device joins the network.
|
| CVE-2020-25176 | 9.1 | critical |
Some commands used by the ISaGRAF eXchange Layer (IXL) protocol perform various file operations in the file system. Since the parameter pointing to the file name is not checked for reserved characters, it is possible for a remote, unauthenticated attacker to traverse an application 's directory, which could lead to remote code execution.CVE-2020-25176 has been assigned to this vulnerability. A CVSS v3 base score of 9.1 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
|
| CVE-2021-22699 | 0.0 | unknown |
No description available.
|
| CVE-2023-37199 | 0.0 | unknown |
No description available.
|
| CVE-2020-7522 | 9.8 | critical |
A vulnerability exists when accessing a vulnerable method of `SoundUploadServlet` that may lead to uploading executable files to non-specified directories.CVE-2020-7522 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2021-34527 | 0.0 | unknown |
No description available.
|
| CVE-2022-22813 | 0.0 | unknown |
No description available.
|
| CVE-2019-6855 | 0.0 | unknown |
No description available.
|
| CVE-2022-22731 | 0.0 | unknown |
No description available.
|
| CVE-2020-7506 | 0.0 | unknown |
No description available.
|
| CVE-2023-5399 | 0.0 | unknown |
Schneider Electric's SpaceLogic C-Bus Toolkit product contains a path traversal vulnerability, which could cause tampering of files on the personal computer running C-Bus when using the File Command.
|
| CVE-2021-45046 | 0.0 | unknown |
CVE-2021-45046. The fix to address CVE-2021-44228 was incomplete in certain non-default configurations, when the logging configuration uses a non-default Pattern Layout with a Context Lookup (for example, ${ctx:loginId}).
This could allow attackers with control over Thread Context Map (MDC) input data to craft malicious input data using a JNDI Lookup pattern, resulting in an information leak and remote code execution in some environments and local code execution in all environments.
|
| CVE-2021-22747 | 0.0 | unknown |
No description available.
|
| CVE-2021-22740 | 0.0 | unknown |
No description available.
|
| CVE-2025-1058 | 0.0 | unknown |
CVE-2025-1058. CWE-494: Download of Code Without Integrity Check vulnerability exists that could render the device
inoperable when malicious firmware is downloaded.
|
| CVE-2023-25620 | 0.0 | unknown |
No description available.
|
| CVE-2024-10083 | 0.0 | unknown |
CVE-2024-10083. CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of engineering
workstation when specific driver interface is invoked locally by an authenticated user with crafted input.
|
| CVE-2018-7849 | 0.0 | unknown |
CVE-2018-7849. An uncaught exception vulnerability exists which could cause a possible denial of service due to improper data integrity check when sending files to the controller over Modbus.
|
| CVE-2021-21867 | 0.0 | unknown |
CVE-2021-21867. An unsafe deserialization vulnerability exists in the ObjectManager.plugin ObjectStream.ProfileByteArray functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.
|
| CVE-2020-7498 | 0.0 | unknown |
No description available.
|
| CVE-2020-27338 | 5.9 | medium |
An issue was discovered in Treck IPv6. An out-of-bound read in the DHCPv6 client component may allow an unauthenticated user to cause a possible denial-of-service via adjacent network access.CVE-2020-27338 has been assigned to this vulnerability. A CVSS v3 base score of 5.9 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H).
|
| CVE-2024-12703 | 0.0 | unknown |
CVE-2024-12703. CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity
and potential remote code execution on workstation when a non-admin authenticated user opens a malicious
project file.
|
| CVE-2022-32525 | 0.0 | unknown |
No description available.
|
| CVE-2021-22742 | 0.0 | unknown |
No description available.
|
| CVE-2020-7531 | 0.0 | unknown |
No description available.
|
| CVE-2023-27983 | 0.0 | unknown |
A vulnerability in Schneider Electric Data Server TCP interface could allow deletion of reports from the IGSS project report directory. CVE-2023-27983 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L).
|
| CVE-2020-7508 | 0.0 | unknown |
No description available.
|
| CVE-2020-14513 | 0.0 | unknown |
CVE-2020-14513. CodeMeter and the software using it may crash while processing a specifically crafted license file due to unverified length fields.
|
| CVE-2020-7516 | 0.0 | unknown |
No description available.
|
| CVE-2020-7492 | 0.0 | unknown |
No description available.
|
| CVE-2021-22815 | 5.3 | medium |
A vulnerability could allow the troubleshooting archive to be accessed.CVE-2021-22815 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
|
| CVE-2022-47381 | 0.0 | unknown |
CVE-2022-47381. An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
|
| CVE-2022-22806 | 0.0 | unknown |
No description available.
|
| CVE-2020-11903 | 0.0 | unknown |
Possible out-of-bounds read in DHCP component when handling a packet sent by an unauthorized network attacker. This vulnerability may allow exposure of sensitive information.
|
| CVE-2018-7764 | 0.0 | unknown |
No description available.
|
| CVE-2025-50124 | 0.0 | unknown |
CVE-2025-50124. CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation when the
server is accessed by a privileged account via a console and through exploitation of a setup script.
|
| CVE-2021-22778 | 8.6 | high |
An insufficiently protected credentials vulnerability exists that could cause protected derived function blocks to be read or modified by unauthorized users when accessing a project file. CVE-2021-22778 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).. --------- Begin Update A Part 2 of 2 --------CVE-2021-22778 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
|
| CVE-2022-32747 | 0.0 | unknown |
No description available.
|
| CVE-2021-30186 | 7.5 | high |
A crafted request may cause a heap-based buffer overflow in the affected CODESYS products, resulting in a denial-of-service condition.CVE-2021-30186 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
|
| CVE-2021-22733 | 0.0 | unknown |
No description available.
|
| CVE-2019-12263 | 0.0 | unknown |
This vulnerability relies on a race-condition between the network task (tNet0) and the receiving application. It is very difficult to trigger the race on a system with a single CPU-thread enabled, and there is no way to reliably trigger a race on SMP targets.CVE-2019-12263 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2020-1350 | 0.0 | unknown |
No description available.
|
| CVE-2021-22751 | 7.8 | high |
Exploitation of this vulnerability could result in disclosure of information or execution of arbitrary code due to lack of input validation when a malicious CGF (Configuration Group File) is imported to IGSS Definition.CVE-2021-22751 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2020-7523 | 0.0 | unknown |
No description available.
|
| CVE-2022-45788 | 0.0 | unknown |
The affected components contain a vulnerability that could cause arbitrary code execution, a denial-of-service condition, and loss of confidentiality & integrity when a malicious project file is loaded onto the controller.
|
| CVE-2024-9005 | 0.0 | unknown |
CVE-2024-9005. CWE-502: Deserialization of Untrusted Data vulnerability exists that could allow code to be
remotely executed on the server when unsafely deserialized data is posted to the web server.
|
| CVE-2024-37036 | 0.0 | unknown |
CVE-2024-37036. CWE-787: Out-of-bounds Write vulnerability exists that could result in an authentication bypass
when sending a malformed POST request and particular configuration parameters are set.
|
| CVE-2023-2569 | 0.0 | unknown |
No description available.
|
| CVE-2019-13538 | 8.6 | high |
The system displays active library content without checking the validity, which may allow the contents of manipulated libraries to be displayed or executed. The issue also exists for source libraries, but 3S-Smart Software Solutions GmbH strongly recommends distributing compiled libraries only.CVE-2019-13538 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
|
| CVE-2024-8937 | 0.0 | unknown |
CVE-2024-8937. CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
vulnerability exists that could cause potential arbitrary code execution after a successful Man In The Middle attack followed by sending crafted Modbus command to tamper with a function call
used for authentication process.
|
| CVE-2023-29411 | 0.0 | unknown |
A vulnerability exists that could allow changes to administrative credentials, leading to potential remote code execution without requiring prior authentication on the Java RMI interface.
|
| CVE-2021-22763 | 0.0 | unknown |
CVE-2021-22763. CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists
that could allow an attacker administrator level access to a device.
|
| CVE-2021-22750 | 7.8 | high |
Exploitation of this vulnerability could result in loss of data or remote code execution due to missing length checks when a malicious CGF file is imported to IGSS Definition.CVE-2021-22750 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2023-5391 | 0.0 | unknown |
A deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by sending a specifically crafted packet to the application.
|
| CVE-2022-22732 | 0.0 | unknown |
No description available.
|
| CVE-2021-30195 | 7.5 | high |
A crafted request may cause a buffer over-read in the affected CODESYS products, resulting in a denial-of-service condition.CVE-2021-30195 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
|
| CVE-2020-28219 | 0.0 | unknown |
No description available.
|
| CVE-2021-45105 | 0.0 | unknown |
CVE-2021-45105. Apache Log4j2 versions 2.0-alpha1 through 2.16.0 did not protect from uncontrolled recursion from self-referential lookups, when the logging configuration uses a non-default Pattern Layout with a Context Lookup (for example, $${ctx:loginId}).
This could allow attackers with control over Thread Context Map (MDC) input data to craft malicious input data that contains a recursive lookup, resulting in a denial of service condition.
|
| CVE-2018-7774 | 0.0 | unknown |
No description available.
|
| CVE-2021-22697 | 7.8 | high |
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior) that could allow a use-after-free condition which could result in remote code execution when a malicious SSD file is uploaded and improperly parsed.
|
| CVE-2022-1467 | 0.0 | unknown |
Windows OS can be configured to overlay a language bar on top of any application. When this OS functionality is enabled, the OS language bar UI will be viewable in the browser alongside the InTouch Access Anywhere and Plant SCADA Access Anywhere applications. It is possible to manipulate the Windows OS language bar to launch an OS command prompt, resulting in a context-escape from application into OS.CVE-2022-1467 has been assigned to this vulnerability. A CVSS v3 base score of 7.4 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L).
|
| CVE-2018-7847 | 0.0 | unknown |
CVE-2018-7847. An improper access control vulnerability exists which could cause denial of service or potential code execution by overwriting configuration settings of the controller over Modbus.
|
| CVE-2021-21812 | 0.0 | unknown |
A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs ' Xmill 0.7. Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line. filepattern is passed directly to strcpy copying the path provided by the user into a static sized buffer without any length checks resulting in a stack-buffer overflow. An attacker can provide malicious input to trigger these vulnerabilities.CVE-2021-21812 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2020-7569 | 4.6 | medium |
CVE-2020-7569. An unrestricted upload of a file with dangerous type vulnerability could allow an authenticated remote user to upload arbitrary files due to incorrect verification of user supplied files and achieve remote code execution.CVE-2020-7569 has been assigned to this vulnerability. A CVSS v3 base score of 4.6 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L).
|
| CVE-2022-24316 | 5.3 | medium |
A vulnerability exists that could cause information exposure when an attacker sends a specially crafted message.CVE-2022-24316 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
|
| CVE-2018-7811 | 0.0 | unknown |
No description available.
|
| CVE-2019-12255 | 0.0 | unknown |
An attacker can either hijack an existing TCP session and inject bad TCP segments or establish a new TCP session on any TCP port listened to by the target. This vulnerability could lead to a buffer overflow of up to a full TCP receive-window (by default, 10k-64k depending on version). The buffer overflow occurs in the task calling recv()/recvfrom()/recvmsg(). Applications that pass a buffer equal to or larger than a full TCP window are not susceptible to this attack. Applications passing a stack-allocated variable as a buffer are the easiest to exploit. The most likely outcome is a crash of the application reading from the affected socket, which could result in remote code execution.. CVE-2019-12255 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).Applications that pass a buffer equal to or larger than a full TCP window are not susceptible to this attack. Applications passing a stack-allocated variable as a buffer are the easiest to exploit. The most likely outcome is a crash of the application reading from the affected socket, which could result in remote code execution.
|
| CVE-2023-6407 | 0.0 | unknown |
A path traversal vulnerability exists that could cause arbitrary file deletion upon service restart when accessed by a local and low-privileged attacker.
|
| CVE-2021-22786 | 0.0 | unknown |
No description available.
|
| CVE-2023-27975 | 0.0 | unknown |
CVE-2023-27975. A CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause
unauthorized access to the project file in EcoStruxure™ Control Expert when a local user
tampers with the memory of the engineering workstation.
|
| CVE-2019-6846 | 0.0 | unknown |
No description available.
|
| CVE-2021-21810 | 0.0 | unknown |
A memory corruption vulnerability exists in the XML-parsing ParseAttribs functionality of AT&T Labs ' Xmill 0.7. A specially crafted XML file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.CVE-2021-21810 has been assigned to this vulnerability. A CVSS v3 base score of 8.1 has been assigned; the CVSS vector string is (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2021-22701 | 0.0 | unknown |
No description available.
|
| CVE-2022-32522 | 0.0 | unknown |
No description available.
|
| CVE-2020-7552 | 7.8 | high |
An improper restriction of operations within the bounds of a memory buffer vulnerability could cause remote code execution when a malicious CGF (Configuration Group File) is imported to IGSS Definition.CVE-2020-7552 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2018-7777 | 0.0 | unknown |
No description available.
|
| CVE-2020-7565 | 7.1 | high |
An inadequate encryption strength vulnerability exists that could allow the attacker to break the encryption key when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller.CVE-2020-7565 has been assigned to this vulnerability. A CVSS v3 base score of 7.1 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2025-49844 | 0.0 | unknown |
CVE-2025-49844. Additional information about CVE-2025-49844 can be found here: https://www.cve.org/CVERecord?id=CVE-2025-49844
|
| CVE-2022-47379 | 0.0 | unknown |
CVE-2022-47379. An authenticated, remote attacker may use a out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into memory which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
|
| CVE-2022-32524 | 0.0 | unknown |
No description available.
|
| CVE-2021-31166 | 0.0 | unknown |
No description available.
|
| CVE-2023-5984 | 0.0 | unknown |
No description available.
|
| CVE-2020-7526 | 0.0 | unknown |
No description available.
|
| CVE-2023-25548 | 0.0 | unknown |
No description available.
|
| CVE-2020-7527 | 0.0 | unknown |
No description available.
|
| CVE-2023-28355 | 0.0 | unknown |
CVE-2023-28355. The PLC application code executed by the CODESYS Control Runtime contains a checksum. This enables the CODESYS development system to check at login whether its loaded project matches the PLC application code executed on the controller. This checksum is not sufficient to reliably detect PLC application code that has been modified in memory or boot application files that have been manipulated.
|
| CVE-2018-7767 | 0.0 | unknown |
No description available.
|
| CVE-2020-7543 | 0.0 | unknown |
No description available.
|
| CVE-2023-35945 | 0.0 | unknown |
Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy's HTTP/2 codec may leak a header map and bookkeeping structures upon receiving RST_STREAM immediately followed by the GOAWAY frames from an upstream server. In nghttp2, cleanup of pending requests due to receipt of the GOAWAY frame skips de-allocation of the bookkeeping structure and pending compressed header. The error return [code path] is taken if the connection is already marked for not sending more requests due to GOAWAY frame. The clean-up code is right after the return statement, causing a memory leak. This results in denial of service through memory exhaustion. This vulnerability was patched in Versions 1.26.3, 1.25.8, 1.24.9, 1.23.11.
|
| CVE-2021-22749 | 5.3 | medium |
This vulnerability could cause an information leak concerning the current RTU configuration including communication parameters dedicated to telemetry when a specially crafted HTTP request is sent to the web server of the module.CVE-2021-22749 has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
|
| CVE-2018-7763 | 0.0 | unknown |
No description available.
|
| CVE-2021-22708 | 0.0 | unknown |
No description available.
|
| CVE-2021-22713 | 0.0 | unknown |
No description available.
|
| CVE-2024-7322 | 0.0 | unknown |
CVE-2024-7322. A CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial
of service when a malicious device joins the network.
|
| CVE-2020-7502 | 0.0 | unknown |
No description available.
|
| CVE-2020-28217 | 6.7 | medium |
The affected product is vulnerable to a missing encryption of sensitive data vulnerability, which may allow an attacker to read network traffic over IEC60870-5-104 protocol.CVE-2020-28217 has been assigned to this vulnerability. A CVSS v3 base score of 6.7 has been calculated; the CVSS vector string is (AV:P/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L).
|
| CVE-2022-24320 | 0.0 | unknown |
No description available.
|
| CVE-2024-2658 | 0.0 | unknown |
CVE-2024-2658
|
| CVE-2020-28895 | 0.0 | unknown |
In Wind River VxWorks, memory allocator has a possible overflow in calculating the memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer size specified by the arguments, leading to memory corruption.
|
| CVE-2022-47390 | 0.0 | unknown |
CVE-2022-47390. An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
|
| CVE-2021-44832 | 0.0 | unknown |
CVE-2021-44832. Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to code execution attacks if the JDBC Appender is being used and configured to allow the use of protocols other than Java.
This could allow attackers with permission to modify the logging configuration file to execute code via a data source referencing a JNDI URI. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.
|
| CVE-2022-32527 | 0.0 | unknown |
No description available.
|
| CVE-2025-5741 | 0.0 | unknown |
CVE-2025-5741. CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause
arbitrary file reads from the charging station. The exploitation of this vulnerability does require an authenticated
session of the web server.
|
| CVE-2023-37545 | 0.0 | unknown |
CVE-2023-37545. In multiple CODESYS products in multiple versions, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpApp component to read internally from an invalid address, potentially leading to a denial-of-service condition.
|
| CVE-2024-5681 | 0.0 | unknown |
CVE-2024-5681. CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service,
privilege escalation, and potentially kernel execution when a malicious actor with local user
access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
|
| CVE-2020-7532 | 0.0 | unknown |
No description available.
|
| CVE-2020-0938 | 0.0 | unknown |
No description available.
|
| CVE-2020-7494 | 7.7 | high |
An attacker could exploit this path traversal vulnerability by getting a user to visit a malicious page or open a malicious file.CVE-2020-7494 has been assigned to this vulnerability. A CVSS v3 base score of 7.7 has been calculated; the CVSS vector string is (AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).
|
| CVE-2023-27979 | 0.0 | unknown |
A vulnerability in Schneider Electric Data Server could allow an unauthorized user to rename files in the IGSS project report directory. This could lead to a denial-of-service condition if an attacker sends specific crafted messages to the Data Server TCP port. CVE-2023-27979 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L).
|
| CVE-2020-35683 | 7.5 | high |
The code that parses ICMP packets relies on an unchecked value of the IP payload size to compute the ICMP checksum, which may result in an out-of-bounds read.CVE-2020-35683 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
|
| CVE-2019-6850 | 0.0 | unknown |
No description available.
|
| CVE-2021-22784 | 6.5 | medium |
An improper authentication issue exists and could allow an attacker to use a crafted webpage that can enable remote access to the system.CVE-2021-22784 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N).
|
| CVE-2018-7854 | 0.0 | unknown |
CVE-2018-7854. An uncaught exception vulnerability exists which could cause a denial of service when sending invalid debug parameters to the controller over Modbus.
|
| CVE-2018-7856 | 0.0 | unknown |
CVE-2018-7856. An uncaught exception vulnerability exists which could cause a possible denial of service when writing invalid memory blocks to the controller over Modbus.
|
| CVE-2023-25552 | 0.0 | unknown |
No description available.
|
| CVE-2020-14515 | 0.0 | unknown |
CVE-2020-14515. There is an issue in the license-file signature checking mechanism, which could allow attackers to build arbitrary license files, including forging a valid license file as if it were a valid license file of an existing vendor. Only CmActLicense update files with CmActLicense Firm Code are affected.
|
| CVE-2020-7477 | 0.0 | unknown |
No description available.
|
| CVE-2021-30066 | 0.0 | unknown |
No description available.
|
| CVE-2020-7489 | 0.0 | unknown |
No description available.
|
| CVE-2018-7765 | 0.0 | unknown |
No description available.
|
| CVE-2022-32513 | 0.0 | unknown |
No description available.
|
| CVE-2021-31401 | 7.5 | high |
An attacker could send a specially crafted IP packet to trigger an integer overflow due to the lack of IP length validation.CVE-2021-31401 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
|
| CVE-2022-24321 | 0.0 | unknown |
No description available.
|
| CVE-2022-24314 | 7.5 | high |
A vulnerability exists that could cause memory leaks potentially resulting in denial of service when an attacker repeatedly sends a specially crafted message.CVE-2022-24314 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
|
| CVE-2022-34757 | 0.0 | unknown |
No description available.
|
| CVE-2024-2050 | 0.0 | unknown |
No description available.
|
| CVE-2022-2465 | 0.0 | unknown |
ISaGRAF Workbench does not limit the objects that can be deserialized. This vulnerability allows attackers to craft a malicious serialized object that, if opened by a local user in ISaGRAF Workbench, may result in remote code execution. This vulnerability requires user interaction to be successfully exploited.CVE-2022-2465 has been assigned to this vulnerability. A CVSS v3 base score of 8.6 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
|
| CVE-2022-32519 | 0.0 | unknown |
No description available.
|
| CVE-2025-2222 | 0.0 | unknown |
CVE-2025-2222. CWE-552: Files or Directories Accessible to External Parties vulnerability over https exists that could leak
information and potential privilege escalation following man in the middle attack.
|
| CVE-2019-1181 | 0.0 | unknown |
No description available.
|
| CVE-2021-22722 | 0.0 | unknown |
No description available.
|
| CVE-2022-26507 | 0.0 | unknown |
A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file could lead to remote code execution.CVE-2022-26507 has been assigned to this vulnerability. A CVSS v3 base score of 9.8 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2021-22731 | 0.0 | unknown |
No description available.
|
| CVE-2019-6858 | 0.0 | unknown |
No description available.
|
| CVE-2022-24322 | 0.0 | unknown |
No description available.
|
| CVE-2021-22156 | 0.0 | unknown |
No description available.
|
| CVE-2022-22725 | 8.8 | high |
A buffer copy without checking size of input vulnerability exists in Easergy P3 devices that could lead to a buffer overflow, causing program crashes and arbitrary code execution when specially crafted packets are sent to the device over the network. Protection functions and tripping functions via GOOSE can be impacted. CVE-2022-22725 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2021-21813 | 0.0 | unknown |
Within the function HandleFileArg, the argument filepattern is under control of the user who passes it in from the command line. filepattern is passed directly to memcpy copying the path provided by the user into a staticly sized buffer without any length checks resulting in a stack-buffer overflow.CVE-2021-21813 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2022-32530 | 0.0 | unknown |
No description available.
|
| CVE-2021-30063 | 0.0 | unknown |
No description available.
|
| CVE-2022-47383 | 0.0 | unknown |
CVE-2022-47383. An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
|
| CVE-2022-2988 | 0.0 | unknown |
No description available.
|
| CVE-2020-7554 | 7.8 | high |
An improper restriction of operations within the bounds of a memory buffer vulnerability could cause remote code execution when a malicious CGF (Configuration Group File) is imported to IGSS Definition.CVE-2020-7554 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2020-9404 | 0.0 | unknown |
No description available.
|
| CVE-2023-29414 | 0.0 | unknown |
No description available.
|
| CVE-2021-22769 | 8.5 | high |
This vulnerability may allow disclosure of device configuration information to any authenticated user when a specially crafted request is sent to the device.CVE-2021-22769 has been assigned to this vulnerability. A CVSS v3 base score of 8.5 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
|
| CVE-2020-7558 | 7.8 | high |
An out-of-bounds write vulnerability could cause remote code execution when a malicious CGF (Configuration Group File) is imported to IGSS Definition.CVE-2020-7558 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2024-8518 | 0.0 | unknown |
An Improper Input Validation vulnerability exists that could cause a crash of the Zelio Soft 2 application if a specially crafted project file is loaded by an application user.
|
| CVE-2024-10575 | 0.0 | unknown |
CVE-2024-10575. CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access
when enabled on the network and potentially impacting connected devices.
|
| CVE-2024-11139 | 0.0 | unknown |
CVE-2024-11139. CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could allow local attackers to exploit these issues to potentially execute arbitrary code when opening a malicious project file.
|
| CVE-2021-44228 | 10.0 | critical |
The affected product does not properly validate user input, allowing an attacker to enter malicious input and potentially gain remote code execution.CVE-2021-44228 has been assigned to this vulnerability. A CVSS v3 base score of 10.0 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
|
| CVE-2024-9409 | 0.0 | unknown |
CVE-2024-9409. CWE-400: An Uncontrolled Resource Consumption vulnerability exists that could cause the device to become
unresponsive resulting in communication loss when a large amount of IGMP packets is present in the network.
|
| CVE-2025-1070 | 0.0 | unknown |
CVE-2025-1070. CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could render the device
inoperable when a malicious file is downloaded.
|
| CVE-2025-13845 | 0.0 | unknown |
CVE-2025-13845. A use-after-free vulnerability may allow remote code execution when an end user imports a malicious SSD project file into Rapsody.
|
| CVE-2019-1222 | 0.0 | unknown |
No description available.
|
| CVE-2021-22757 | 7.8 | high |
Exploitation of this vulnerability could result in disclosure of information or remote code execution due to lack of validation on user-supplied input data when a malicious CGF file is imported to IGSS Definition.CVE-2021-22757 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
|
| CVE-2021-22796 | 0.0 | unknown |
No description available.
|
| CVE-2023-0595 | 0.0 | unknown |
No description available.
|
| CVE-2018-7857 | 0.0 | unknown |
CVE-2018-7857. An uncaught exception vulnerability exists, which could cause a possible denial of service when writing out of bounds variables to the controller over Modbus.
|
| CVE-2021-22798 | 0.0 | unknown |
No description available.
|
| CVE-2021-29240 | 0.0 | unknown |
CVE-2021-29240. The Package Manager of CODESYS Development System 3 before 3.5.17.0 does not check the validity of packages before installation and may be used to install CODESYS packages with malicious content.
|
| CVE-2022-4062 | 0.0 | unknown |
No description available.
|
| CVE-2020-28212 | 0.0 | unknown |
No description available.
|
| CVE-2021-22738 | 0.0 | unknown |
No description available.
|
| CVE-2020-7573 | 5.0 | medium |
CVE-2020-7573. An improper access control vulnerability could allow a remote attacker access to restricted web resources due to improper access control.CVE-2020-7573 has been assigned to this vulnerability. A CVSS v3 base score of 5.0 has been calculated; the CVSS vector string is (AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L).
|
| CVE-2022-0222 | 0.0 | unknown |
No description available.
|
| CVE-2022-22722 | 7.5 | high |
If an attacker were to obtain the SSH cryptographic key for the device and take active control of the local operational network connected to this product, they could observe and manipulate traffic associated with product configuration. This could result in information disclosure. CVE-2022-22722 has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is (AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
|
| CVE-2024-8422 | 0.0 | unknown |
A Use After Free vulnerability exists that could cause arbitrary code execution, denial-of-service and loss of confidentiality & integrity if an application user opens a malicious Zelio Soft 2 project file.
|
| CVE-2020-7547 | 0.0 | unknown |
No description available.
|
| CVE-2020-6996 | 7.5 | high |
A specially crafted message may cause a stack-based buffer overflow. Authentication is not required to exploit this vulnerability.CVE-2020-6996 has been assigned to this vulnerability. A CVSS v3 base score of 7.5has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
|
| CVE-2022-30238 | 0.0 | unknown |
No description available.
|
| CVE-2022-2464 | 0.0 | unknown |
Crafted malicious files can allow an attacker to traverse the file system when opened by ISaGRAF Workbench. If successfully exploited, an attacker could overwrite existing files and create additional files with the same permissions of the ISaGRAF Workbench software. User interaction is required for this exploit to be successful.CVE-2022-2464 has been assigned to this vulnerability. A CVSS v3 base score of 7.7 has been calculated; the CVSS vector string is (AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).
|
| Vendor | Product | Asset Type | Purdue Level | Firmware |
|---|---|---|---|---|
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
2023 |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
2024 |
| Siemens | Unknown | network_device | -- | -- |
| Schneider Electric | Unknown | network_device | -- | -- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Schneider Electric | Unknown | dcs |
L2
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | hmi |
L2
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | hmi |
L2
|
-- |
| Schneider Electric | Unknown | hmi |
L2
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric Software, LLC | Unknown | scada_server |
L2
|
vers:all/* |
| Schneider Electric Software, LLC | Unknown | engineering_workstation |
L3
|
vers:all/* |
| Schneider Electric Software, LLC | Unknown | engineering_workstation |
L3
|
vers:all/* |
| Schneider Electric | Unknown | rtu |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | rtu |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric Software, LLC | Unknown | safety_system |
L1
|
-- |
| Schneider Electric | Unknown | network_device | -- | -- |
| Schneider Electric | Unknown | network_device | -- | -- |
| Schneider Electric | Unknown | network_device | -- | -- |
| Schneider Electric | Unknown | network_device | -- | -- |
| Schneider Electric | Unknown | network_device | -- | -- |
| Schneider Electric | Unknown | network_device | -- | -- |
| Schneider Electric | Unknown | network_device | -- | -- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | dcs |
L2
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
2020_R2 |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
2020_R2 |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric Software, LLC | Unknown | network_device | -- | -- |
| Schneider Electric Software, LLC | Unknown | plc |
L1
|
vers:all/* |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Siemens | Unknown | scada_server |
L2
|
-- |
| Siemens | Unknown | plc |
L1
|
-- |
| Siemens | Unknown | plc |
L1
|
-- |
| Siemens | Unknown | plc |
L1
|
-- |
| Siemens | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
2024_CU3 |
| Rockwell Automation | Unknown | plc |
L1
|
vers:all/* |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric Software, LLC | Unknown | hmi |
L2
|
-- |
| Schneider Electric Software, LLC | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
2020_R2 |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
2020_R2 |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
2023_v4.8.0.5715 |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | rtu |
L1
|
-- |
| Schneider Electric | Unknown | rtu |
L1
|
-- |
| Schneider Electric | Unknown | scada_server |
L2
|
-- |
| Siemens | Unknown | hmi |
L2
|
-- |
| Siemens | Unknown | historian |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
2022 |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
2023 |
| CODESYS, GmbH | Unknown | engineering_workstation |
L3
|
-- |
| CODESYS, GmbH | Unknown | plc |
L1
|
-- |
| Schneider Electric Software, LLC | Unknown | plc |
L1
|
vers:all/* |
| Schneider Electric Software, LLC | Unknown | plc |
L1
|
vers:all/* |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric Software, LLC | Unknown | engineering_workstation |
L3
|
3.1 SP1 |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric Software, LLC | Unknown | plc |
L1
|
vers:all/* |
| Schneider Electric Software, LLC | Unknown | plc |
L1
|
vers:all/* |
| Schneider Electric | Unknown | hmi |
L2
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric Software, LLC | Unknown | scada_server |
L2
|
-- |
| Schneider Electric | Unknown | scada_server |
L2
|
-- |
| CODESYS, GmbH | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
BMXNOC0401 |
| Schneider Electric Software, LLC | Unknown | engineering_workstation |
L3
|
-- |
| Siemens | Unknown | network_device | -- | -- |
| Schneider Electric | Unknown | hmi |
L2
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric Software, LLC | Unknown | hmi |
L2
|
vers:all/* |
| Schneider Electric Software, LLC | Unknown | hmi |
L2
|
vers:all/* |
| Schneider Electric Software, LLC | Unknown | hmi |
L2
|
vers:all/* |
| Schneider Electric Software, LLC | Unknown | hmi |
L2
|
vers:all/* |
| Schneider Electric Software, LLC | Unknown | hmi |
L2
|
vers:all/* |
| Schneider Electric Software, LLC | Unknown | hmi |
L2
|
vers:all/* |
| Schneider Electric Software, LLC | Unknown | hmi |
L2
|
vers:all/* |
| Schneider Electric Software, LLC | Unknown | hmi |
L2
|
vers:all/* |
| Schneider Electric Software, LLC | Unknown | scada_server |
L2
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | rtu |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | -- |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Siemens | Unknown | network_device | -- | vers:all/* |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | scada_server |
L2
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Siemens | Unknown | network_device | -- | -- |
| Schneider Electric | Unknown | rtu |
L1
|
-- |
| Schneider Electric | Unknown | rtu |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | scada_server |
L2
|
-- |
| Schneider Electric | Unknown | scada_server |
L2
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| 3S-Smart Software Solutions GmbH | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | scada_server |
L2
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| AVEVA Software, LLC | Unknown | scada_server |
L2
|
vers:all/* |
| AVEVA Software, LLC | Unknown | historian |
L3
|
vers:all/* |
| Schneider Electric Software, LLC | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | scada_server |
L2
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
2025 |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | scada_server |
L2
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
-- |
| Schneider Electric | Unknown | engineering_workstation |
L3
|
1.21.0.6 |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |
| Schneider Electric | Unknown | plc |
L1
|
-- |