Arcinfo

Pcvue

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 26.02.2026 07:58:00
  • Zuletzt bearbeitet 27.02.2026 14:06:59

A HTTP Host header attack vulnerability affects WebClient and the WebScheduler web apps of PcVue in version 15.0.0 through 16.3.3 included, allowing a remote attacker to inject harmful payloads that manipulate server-side behavior. This vulnerabilit...

  • EPSS 0.03%
  • Veröffentlicht 26.02.2026 07:57:46
  • Zuletzt bearbeitet 27.02.2026 14:06:59

The Secure and SameSite attribute are missing in the GraphicalData web services and WebClient web app of PcVue in version 12.0.0 through 16.3.3 included.

  • EPSS 0.05%
  • Veröffentlicht 26.02.2026 07:57:29
  • Zuletzt bearbeitet 27.02.2026 14:06:59

Some HTTP security headers are not properly set by the web server when sending responses to the client application.

  • EPSS 0.21%
  • Veröffentlicht 26.02.2026 07:57:11
  • Zuletzt bearbeitet 27.02.2026 14:06:59

An XSS vulnerability affects the OAuth web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote attacker to trick a legitimate user into loading content f...

  • EPSS 0.04%
  • Veröffentlicht 26.02.2026 07:56:57
  • Zuletzt bearbeitet 27.02.2026 14:06:59

HTTP headers are added by the default configuration of IIS and ASP.net, and are not removed at the deployment phase of the webservices used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included....

  • EPSS 0.14%
  • Veröffentlicht 26.02.2026 07:56:10
  • Zuletzt bearbeitet 27.02.2026 14:06:59

The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in version 12.0.0 through 16.3.3 included despite being deprecated. It mig...

  • EPSS 0.05%
  • Veröffentlicht 26.02.2026 07:55:18
  • Zuletzt bearbeitet 27.02.2026 14:06:59

A missing origin validation in WebSockets vulnerability affects the GraphicalData web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote attacker to lur...

  • EPSS 0.03%
  • Veröffentlicht 05.09.2025 16:41:01
  • Zuletzt bearbeitet 05.09.2025 17:47:10

Some payload elements of the messages sent between two stations in a networking architecture are not properly checked on the receiving station allowing an attacker to execute unauthorized commands in the application.

  • EPSS 0.02%
  • Veröffentlicht 05.09.2025 16:40:13
  • Zuletzt bearbeitet 05.09.2025 17:47:10

The sequence of packets received by a Networking server are not correctly checked. An attacker could exploit this vulnerability to send specially crafted messages to force the application to stop.

  • EPSS 0.07%
  • Veröffentlicht 06.05.2025 15:59:27
  • Zuletzt bearbeitet 07.05.2025 14:13:20

The MQTT add-on of PcVue fails to verify that a remote device’s certificate has not already expired or has not yet become valid. This allows malicious devices to present certificates that are not rejected properly. The use of a client certificate re...