Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3042▲ 436 respecto a la semana anterior
Críticas / altas1431▲ 190 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 168 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.5) | 0.54% | — | Automatedlogic WebctrlAIBacnetAI | 21/3/2026 | 17/6/2026 | WebCTRL systems that communicate over BACnet inherit the protocol's lack of network layer authentication. WebCTRL does not implement additional validation of BACnet traffic so an attacker with network access could spoof BACnet packets directed at either the WebCTRL server or associated AutomatedLogic controllers.… | |
| Pendiente de análisis | Alta (7.7) | 0.15% | — | Johnsoncontrols WebctrlAI | 21/3/2026 | 17/6/2026 | Under certain conditions, an attacker could bind to the same port used by WebCTRL. This could allow the attacker to craft and send malicious packets and impersonate the WebCTRL service without requiring code injection into the WebCTRL software. | |
| Pendiente de análisis | Crítica (9.1) | 0.20% | — | BacnetAIWiresharkAIJohnsoncontrols WebctrlAI | 21/3/2026 | 17/6/2026 | Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted, and modified by an attacker. Valuable information such as the File Start Position and File Data can be sniffed from network traffic using Wireshark's BACnet dissector filter. The proprietary format… | |
| Aplazada | Alta (7) | 0.16% | — | Carrier I-vuAIAutomatedlogic WebctrlAI | 22/1/2026 | 17/6/2026 | Storing Passwords in a Recoverable Format vulnerability in Automated Logic WebCTRL on Windows, Carrier i-Vu on Windows. Storing Passwords in a Recoverable Format vulnerability (CWE-257) in the Web session management component allows an attacker to access stored passwords in a recoverable format which makes them… | |
| Aplazada | Media (6.9) | 0.31% | — | Carrier I-vuAIAutomatedlogic WebctrlAI | 27/11/2025 | 17/6/2026 | The reflective cross-site scripting vulnerability found in ALC WebCTRL and Carrier i-Vu in versions older than 8.0 affects login panels allowing a malicious actor to compromise the client browser . | |
| Aplazada | Crítica (9.2) | 0.33% | — | Carrier I-vuAIAutomatedlogic WebctrlAI | 27/11/2025 | 17/6/2026 | The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to and including 8.5 allows a malicious actor to bypass intended access restrictions and expose sensitive information via the web based building automation server. | |
| Aplazada | Media (5.4) | 0.12% | — | Carrier I-vuAIAutomatedlogic WebctrlAI | 19/11/2025 | 17/6/2026 | Reflected XSS using a specific URL in Automated Logic WebCTRL and Carrier i-VU can allow delivery of malicious payload due to a specific GET parameter not being sanitized. | |
| Aplazada | Alta (8.6) | 0.16% | — | Carrier I-vuAIAutomatedlogic WebctrlAI | 19/11/2025 | 17/6/2026 | Open Redirect in URL parameter in Automated Logic WebCTRL and Carrier i-Vu versions 6.0, 6.5, 7.0, 8.0, 8.5, 9.0 may allow attackers to exploit user sessions. | |
| Aplazada | Media (5.9) | 0.66% | — | Automatedlogic WebctrlAI | 21/11/2024 | 17/6/2026 | A vulnerability in Automated Logic WebCTRL 7.0 could allow an attacker to send a maliciously crafted URL, which when visited by an authenticated WebCTRL user, could result in the redirection of the user to a malicious webpage via "index.jsp" | |
| Aplazada | Crítica (10) | 1.4% | — | Automatedlogic WebctrlAI | 21/11/2024 | 17/6/2026 | An unrestricted upload of file with dangerous type in Automated Logic WebCTRL 7.0 could allow an unauthenticated user to perform remote command execution via a crafted HTTP POST request which could lead to uploading a malicious file. | |
| Modificada | Media (6.1) | 0.68% | — | Automatedlogic Webctrl Server | 19/4/2022 | 17/6/2026 | Automated Logic's WebCtrl Server Version 6.1 'Help' index pages are vulnerable to open redirection. The vulnerability allows an attacker to send a maliciously crafted URL which could result in redirecting the user to a malicious webpage or downloading a malicious file. | |
| Modificada | Media (6.1) | 11% | — | Automatedlogic Webctrl | 22/10/2021 | 17/6/2026 | The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for reflected XSS attacks due to the operatorlocale GET parameter not being sanitized. This issue impacts versions 6.5 and below. This issue works by passing in a basic XSS payload to a vulnerable GET… | |
| Modificada | Media (6.1) | 1.0% | — | Carrier Webctrl System | 22/2/2021 | 17/6/2026 | Automated Logic Corporation (ALC) WebCTRL System 6.5 and prior allows remote attackers to execute any JavaScript code via a XSS payload for the first parameter in a GET request. | |
| Modificada | Alta (7.5) | 3.0% | — | Carrier Automatedlogic Webctrl | 14/6/2018 | 17/6/2026 | An XXE issue was discovered in Automated Logic Corporation (ALC) WebCTRL Versions 6.0, 6.1 and 6.5. An unauthenticated attacker could enter malicious input to WebCTRL and a weakly configured XML parser will allow the application to disclose full file contents from the underlying web server OS via the "X-Wap-Profile"… | |
| Modificada | Alta (7.3) | 2.2% | — | Automatedlogic I-vuAutomatedlogic Sitescan WEBCarrier Automatedlogic Webctrl | 31/8/2017 | 17/6/2026 | An XXE issue was discovered in Automated Logic Corporation (ALC) Liebert SiteScan Web Version 6.5 and prior, ALC WebCTRL Version 6.5 and prior, and Carrier i-Vu Version 6.5 and prior. An attacker could enter malicious input to WebCTRL, i-Vu, or SiteScan Web through a weakly configured XML parser causing the… | |
| Modificada | Alta (7.8) | 2.4% | — | Automatedlogic I-vuAutomatedlogic Sitescan WEBCarrier Automatedlogic Webctrl | 25/8/2017 | 17/6/2026 | An Unrestricted Upload of File with Dangerous Type issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2… | |
| Modificada | Alta (7) | 1.4% | — | Automatedlogic I-vuAutomatedlogic Sitescan WEBCarrier Automatedlogic Webctrl | 25/8/2017 | 17/6/2026 | An Unquoted Search Path or Element issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An… | |
| Modificada | Media (6.3) | 8.5% | — | Automatedlogic I-vuAutomatedlogic Sitescan WEBCarrier Automatedlogic Webctrl | 25/8/2017 | 17/6/2026 | A Path Traversal issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web prior to 6.5; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An authenticated attacker… |