Azeotech
Azeotech Daqfactory: vulnerabilidades y CVE
Azeotech Daqfactory tiene 16 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses7
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-12921 | Alta (8.4) | 0.19% | — | 25 jun 2026 | In AzeoTech DAQFactory versions 21.1 and prior, a Use After Free vulnerability can be exploited by an attacker using specially crafted .ctl files which can result in code execution. |
| CVE-2026-12390 | Alta (8.4) | 0.18% | — | 18 jun 2026 | In AzeoTech DAQFactory versions 21.1 and prior, a Type Confusion vulnerability can be exploited by an attacker using specially crafted .ctl files which can result in code execution. |
| CVE-2025-66590 | Alta (8.4) | 0.38% | — | 11 dic 2025 | In AzeoTech DAQFactory release 20.7 (Build 2555), an out-of-bounds write vulnerability can be exploited by an attacker to cause the program to write data past the end of an allocated memory buffer. This can lead to… |
| CVE-2025-66588 | Alta (8.4) | 0.30% | — | 11 dic 2025 | In AzeoTech DAQFactory release 20.7 (Build 2555), an access of uninitialized pointer vulnerability can be exploited by an attacker which can lead to arbitrary code execution. |
| CVE-2025-66586 | Alta (7.3) | 0.22% | — | 11 dic 2025 | In AzeoTech DAQFactory release 20.7 (Build 2555), an access of resource using incompatible type vulnerability can be exploited to cause memory corruption while parsing specially crafted .ctl files. This could allow an… |
| CVE-2025-66585 | Alta (7.3) | 0.24% | — | 11 dic 2025 | In AzeoTech DAQFactory release 20.7 (Build 2555), a use after free vulnerability can be exploited to cause memory corruption while parsing specially crafted .ctl files. This could allow an attacker to execute code in… |
| CVE-2025-66589 | Alta (8.4) | 0.35% | — | 11 dic 2025 | In AzeoTech DAQFactory release 20.7 (Build 2555), an Out-of-bounds Read vulnerability can be exploited by an attacker to cause the program to read data past the end of an allocated buffer. This could allow an attacker… |
| CVE-2021-42701 | Media (6.3) | 0.61% | — | 5 nov 2021 | An attacker could prepare a specially crafted project file that, if opened, would attempt to connect to the cloud and trigger a man in the middle (MiTM) attack. This could allow an attacker to obtain credentials and… |
| CVE-2021-42699 | Media (5.9) | 0.51% | — | 5 nov 2021 | The affected product is vulnerable to cookie information being transmitted as cleartext over HTTP. An attacker can capture network traffic, obtain the user’s cookie and take over the account. |
| CVE-2021-42698 | Alta (7.8) | 0.81% | — | 5 nov 2021 | Project files are stored memory objects in the form of binary serialized data that can later be read and deserialized again to instantiate the original objects in memory. Malicious manipulation of these files may allow… |
| CVE-2021-42543 | Alta (7.8) | 0.81% | — | 5 nov 2021 | The affected application uses specific functions that could be abused through a crafted project file, which could lead to code execution, system reboot, and system shutdown. |
| CVE-2017-5147 | Media (5.3) | 0.34% | — | 9 sept 2017 | An Uncontrolled Search Path Element issue was discovered in AzeoTech DAQFactory versions prior to 17.1. An uncontrolled search path element vulnerability has been identified, which may execute malicious DLL files that… |
| CVE-2017-12699 | Alta (7.1) | 0.32% | — | 9 sept 2017 | An Incorrect Default Permissions issue was discovered in AzeoTech DAQFactory versions prior to 17.1. Local, non-administrative users may be able to replace or modify original application files with malicious ones. |
| CVE-2011-3492 | Alta (10) | 71% | — | 16 sept 2011 | Stack-based buffer overflow in Azeotech DAQFactory 5.85 build 1853 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a crafted NETB packet to UDP port 20034. |
| CVE-2011-2956 | Alta (7.8) | 6.7% | — | 28 jul 2011 | AzeoTech DAQFactory before 5.85 (Build 1842) does not perform authentication for certain signals, which allows remote attackers to cause a denial of service (system reboot or shutdown) via a signal. |
| CVE-2009-4480 | Alta (9.3) | 3.3% | — | 30 dic 2009 | Buffer overflow in the web service in AzeoTech DAQFactory 5.77 might allow remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a certain module in VulnDisco Pack Professional 7.16… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.