Loading HuntDB...

prior

50 Versions 110 CVEs

Versions

WebAccess Versions 8.3.2 and prior.

OTHER 2 CVEs

SCADAPack 7x Remote Connect V3.6.3.574 and prior.

OTHER 4 CVEs

SCADAPack x70 Security Administrator V1.2.0 and prior.

OTHER 1 CVE

Schneider Electric Software Update (SESU) V2.4.0 and prior.

OTHER 1 CVE

EcoStruxure Power Build-Rapsody software V2.1.13 and prior.

OTHER 2 CVEs

ClamAV AntiVirus software versions 0.99.2 and prior

OTHER 7 CVEs

Hanwha Techwin Smart Security Manager Versions 1.5 and prior

OTHER 1 CVE

Schneider Electric Wonderware Intelligence 2014R3 and prior

OTHER 1 CVE

Fixed in EdgeMarx Edge Switch firmware v1.9.1

OTHER 1 CVE

Easergy T300 Firmware V1.5.2 and prior

OTHER 1 CVE

C-Bus Toolkit v1.15.8 and prior

OTHER 1 CVE

Fixed in EdgeMax EdgeSwitch firmware v1.9.1

OTHER 1 CVE

Hanwha Techwin Smart Security Manager 1.5 and prior

OTHER 1 CVE

IGSS Definition (Def.exe) V15.0.0.21041 and prior

OTHER 1 CVE

IGSS Definition (Def.exe) version 14.0.0.20247 and prior

OTHER 7 CVEs

Fazecast jSerialComm, Version 2.2.2 and prior

OTHER 1 CVE

C-Bus Toolkit V1.15.7 and prior

OTHER 4 CVEs

Cisco Umbrella Virtual Appliance Version 2.0.3 and prior

OTHER 1 CVE

Modicon M218 Logic Controller V5.0.0.7 and prior

OTHER 1 CVE

Fuji Electric FRENIC Loader 3.5.0.0 and prior

OTHER 1 CVE

INTERSCHALT VDR G4e 5.220 and prior

OTHER 1 CVE

Modicon X80 BMXNOR0200H RTU SV1.70 IR22 and prior

OTHER 1 CVE

Druva inSync macOS Client Installers for v6.8.0 and prior

OTHER 1 CVE

Modicon Managed Switch MCSESM* and MCSESP* V8.21 and prior

OTHER 1 CVE

Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior

OTHER 4 CVEs

GP-Pro EX V4.09.250 and prior

OTHER 1 CVE

Fixed version EdgeSwitch firmware v1.9.1

OTHER 1 CVE

Belden Hirschmann GECKO 2.0.00 and prior

OTHER 1 CVE

LCDS LAquis SCADA Versions 4.3.1 and prior

OTHER 2 CVEs

Versions 5.1.3 and prior

OTHER 1 CVE

Fuji Electric V-Server 4.0.6 and prior

OTHER 1 CVE

IGSS Definition (Def.exe) V15.0.0.21140 and prior

OTHER 12 CVEs

VASA Provider Virtual Appliance versions 8.3.x and prior

OTHER 1 CVE

homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior

OTHER 9 CVEs

Rockwell Automation RSLinx Classic versions 4.1.00 and prior

OTHER 1 CVE

Advantech SUSIAccess Server 3.0 and prior

OTHER 3 CVEs

SoMove V2.8.1 and prior

OTHER 1 CVE

Easergy Builder V1.4.7.2 and prior

OTHER 2 CVEs

Interactive Graphical SCADA System (IGSS) Version 14 and prior

OTHER 1 CVE

ProSoft Configurator v1.002 and prior, for the PMEPXM0100 (H) module

OTHER 1 CVE

Vijeo Designer Basic (V1.1 HotFix 15 and prior) and Vijeo Designer (V6.9 SP9 and prior)

OTHER 1 CVE

Modicon M218 Logic Controller (V5.1.0.6 and prior)

OTHER 1 CVE

Modicon M218 Logic Controller (Firmware version 4.3 and prior)

OTHER 1 CVE

EcoStruxure Power Monitoring Expert (Versions 2020 and prior)

OTHER 3 CVEs

Vijeo Designer Basic (V1.1 HotFix 16 and prior) and Vijeo Designer (V6.2 SP9 and prior)

OTHER 1 CVE

C-Bus Toolkit (V1.15.9 and prior), C-Gate Server (V2.11.7 and prior)

OTHER 2 CVEs

Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior)

OTHER 4 CVEs

Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21320 and prior)

OTHER 2 CVEs

Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior)

OTHER 8 CVEs

spaceLYnk (V2.6.1 and prior), Wiser for KNX (V2.6.1 and prior), fellerLYnk (V2.6.1 and prior)

OTHER 1 CVE

Recent CVEs

CVE-2021-22824

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in denial of service, due to missing length check on user-supplied data from a constructed message received on the network. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21320 and prior)

UNKNOWN Feb 11, 2022

CVE-2021-22800

A CWE-20: Improper Input Validation vulnerability exists that could cause a Denial of Service when a crafted packet is sent to the controller over network port 1105/TCP. Affected Product: Modicon M218 Logic Controller (V5.1.0.6 and prior)

UNKNOWN Feb 11, 2022

CVE-2021-22823

A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user running IGSS due to lack of validation of network messages. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21320 and prior)

UNKNOWN Feb 11, 2022

CVE-2021-22805

A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user running IGSS due to lack of validation of network messages. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior)

UNKNOWN Feb 11, 2022

CVE-2021-22804

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause disclosure of arbitrary files being read in the context of the user running IGSS, due to missing validation of user supplied data in network messages. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior)

UNKNOWN Feb 11, 2022

CVE-2021-22803

A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could lead to remote code execution through a number of paths, when an attacker, writes arbitrary files to folders in context of the DC module, by sending constructed messages on the network. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior)

UNKNOWN Feb 11, 2022

CVE-2021-22802

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution due to missing length check on user supplied data, when a constructed message is received on the network. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior)

UNKNOWN Feb 11, 2022