Danfoss
Danfoss Ak-em100 Firmware: vulnerabilidades y CVE
Danfoss Ak-em100 Firmware tiene 7 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-25912 | Media (5.3) | 0.60% | — | 11 jun 2023 | The webreport generation feature in the Danfoss AK-EM100 allows an unauthorized actor to generate a web report that discloses sensitive information such as the internal IP address, usernames and internal device values. |
| CVE-2023-25911 | Alta (8.8) | 2.3% | — | 11 jun 2023 | The Danfoss AK-EM100 web applications allow for an authenticated user to perform OS command injection through the web application parameters. |
| CVE-2023-22586 | Alta (7.5) | 0.67% | — | 11 jun 2023 | The Danfoss AK-EM100 web applications allow for Local File Inclusion in the file parameter. |
| CVE-2023-22585 | Media (6.1) | 0.60% | — | 11 jun 2023 | The Danfoss AK-EM100 web applications allow for Reflected Cross-Site Scripting in the title parameter. |
| CVE-2023-22584 | Alta (7.5) | 0.45% | — | 11 jun 2023 | The Danfoss AK-EM100 stores login credentials in cleartext. |
| CVE-2023-22583 | Crítica (9.8) | 0.76% | — | 11 jun 2023 | The Danfoss AK-EM100 web forms allow for SQL injection in the login forms. |
| CVE-2023-22582 | Media (6.1) | 0.60% | — | 11 jun 2023 | The Danfoss AK-EM100 web applications allow for Reflected Cross-Site Scripting. |