CVE-2025-0327
- EPSS 0.03%
- Published 13.02.2025 07:15:10
- Last modified 13.02.2025 07:15:10
CWE-269: Improper Privilege Management vulnerability exists for two services (of which one managing audit trail data and the other acting as server managing client request) that could cause a loss of Confidentiality, Integrity and Availability of eng...
CVE-2023-6408
- EPSS 0.16%
- Published 14.02.2024 17:15:11
- Last modified 23.01.2025 19:39:42
CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a denial of service and loss of confidentiality, integrity of controllers when conducting a Man in the Middle att...
CVE-2023-6409
- EPSS 0.06%
- Published 14.02.2024 17:15:11
- Last modified 11.12.2024 19:33:54
CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to a project file protected with application password when opening the file with EcoStruxure Control Expert.
CVE-2023-27975
- EPSS 0.07%
- Published 14.02.2024 17:15:08
- Last modified 11.12.2024 19:33:27
CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized access to the project file in EcoStruxure Control Expert when a local user tampers with the memory of the engineering workstation.
CVE-2022-45789
- EPSS 0.06%
- Published 31.01.2023 06:15:07
- Last modified 21.11.2024 07:29:43
A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller when hijacking an authenticated Modbus session. Affected Products: EcoStruxure Control Expert (All V...
CVE-2022-45788
- EPSS 0.29%
- Published 30.01.2023 13:15:09
- Last modified 21.11.2024 07:29:43
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when a malicious project file is loaded onto the controller. Aff...
CVE-2022-37300
- EPSS 0.54%
- Published 12.09.2022 18:15:08
- Last modified 21.11.2024 07:14:42
A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode to the controller when communicating over Modbus. Affected Products: EcoStruxure Control Expert Includ...
CVE-2022-26507
- EPSS 6.7%
- Published 14.04.2022 13:15:11
- Last modified 21.11.2024 06:54:04
A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any of: CVE-2021-21810, CVE-2021-21811, CVE-2021-21812, CVE-2021-21815, C...
CVE-2021-22797
- EPSS 0.45%
- Published 13.04.2022 16:15:09
- Last modified 21.11.2024 05:50:41
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be deployed in an unauthorized location and may result in code execution on the engineering workstation ...
CVE-2022-24323
- EPSS 0.22%
- Published 09.03.2022 23:15:07
- Last modified 21.11.2024 06:50:10
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause a disruption of communication between the Modicon controller and the engineering software, when an attacker is able to intercept and manipulate spec...