Trianglemicroworks
Trianglemicroworks Scada Data Gateway: vulnerabilidades y CVE
Trianglemicroworks Scada Data Gateway tiene 22 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-0369 | Alta (8.8) | 2.3% | — | 7 may 2024 | Triangle MicroWorks SCADA Data Gateway Restore Workspace Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of… |
| CVE-2023-39468 | Alta (7.2) | 1.9% | — | 3 may 2024 | Triangle MicroWorks SCADA Data Gateway DbasSectorFileToExecuteOnReset Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected… |
| CVE-2023-39467 | Media (5.3) | 0.58% | — | 3 may 2024 | Triangle MicroWorks SCADA Data Gateway certificate Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Triangle MicroWorks… |
| CVE-2023-39466 | Media (5.3) | 1.0% | — | 3 may 2024 | Triangle MicroWorks SCADA Data Gateway get_config Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of… |
| CVE-2023-39465 | Alta (7.5) | 0.76% | — | 3 may 2024 | Triangle MicroWorks SCADA Data Gateway Use of Hard-coded Cryptograhic Key Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of… |
| CVE-2023-39464 | Alta (7.2) | 2.0% | — | 3 may 2024 | Triangle MicroWorks SCADA Data Gateway GTWWebMonitorService Unquoted Search Path Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute code on affected installations of Triangle… |
| CVE-2023-39463 | Alta (7.2) | 1.2% | — | 3 may 2024 | Triangle MicroWorks SCADA Data Gateway Trusted Certification Unrestricted Upload of File Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected… |
| CVE-2023-39462 | Media (6.5) | 1.5% | — | 3 may 2024 | Triangle MicroWorks SCADA Data Gateway Workspace Unrestricted Upload Vulnerability. This vulnerability allows remote attackers to upload arbitrary files on affected installations of Triangle MicroWorks SCADA Data… |
| CVE-2023-39461 | Media (4.4) | 1.3% | — | 3 may 2024 | Triangle MicroWorks SCADA Data Gateway Event Log Improper Output Neutralization For Logs Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to write arbitrary files on affected installations… |
| CVE-2023-39460 | Alta (7.2) | 3.4% | — | 3 may 2024 | Triangle MicroWorks SCADA Data Gateway Event Log Directory Traversal Arbitrary File Creation Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Triangle… |
| CVE-2023-39459 | Alta (7.8) | 0.96% | — | 3 may 2024 | Triangle MicroWorks SCADA Data Gateway Directory Traversal Arbitrary File Creation Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Triangle MicroWorks… |
| CVE-2023-39458 | Media (5.3) | 0.24% | — | 3 may 2024 | Triangle MicroWorks SCADA Data Gateway Use of Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of… |
| CVE-2023-39457 | Crítica (9.8) | 2.0% | — | 3 may 2024 | Triangle MicroWorks SCADA Data Gateway Missing Authentication Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Triangle MicroWorks SCADA Data Gateway.… |
| CVE-2023-2187 | Media (5.3) | 0.59% | — | 7 jun 2023 | On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send broadcast events to any user via the WebMonitor.An unauthenticated user can use this vulnerability to forcefully log… |
| CVE-2023-2186 | Crítica (9.8) | 0.71% | — | 7 jun 2023 | On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send a specially crafted broadcast message including format string characters to the SCADA Data Gateway to perform… |
| CVE-2020-10615 | Alta (7.5) | 2.6% | — | 15 abr 2020 | Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers cause a denial-of-service condition due to a lack of proper validation of the length of user-supplied… |
| CVE-2020-10613 | Alta (7.5) | 2.5% | — | 15 abr 2020 | Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers to disclose sensitive information due to the lack of proper validation of user-supplied data, which can… |
| CVE-2020-10611 | Crítica (9.8) | 5.2% | — | 15 abr 2020 | Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, which can result… |
| CVE-2014-2343 | Baja (2.1) | 0.35% | — | 30 may 2014 | Triangle MicroWorks SCADA Data Gateway before 3.00.0635 allows physically proximate attackers to cause a denial of service (excessive data processing) via a crafted DNP request over a serial line. |
| CVE-2014-2342 | Media (5) | 1.8% | — | 30 may 2014 | Triangle MicroWorks SCADA Data Gateway before 3.00.0635 allows remote attackers to cause a denial of service (excessive data processing) via a crafted DNP3 packet. |
| CVE-2013-2794 | Media (4.9) | 0.32% | — | 9 sept 2013 | Triangle MicroWorks SCADA Data Gateway 2.50.0309 through 3.00.0616, DNP3 .NET Protocol components 3.06.0.171 through 3.15.0.369, and DNP3 C libraries 3.06.0000 through 3.15.0000 allow physically proximate attackers to… |
| CVE-2013-2793 | Alta (7.8) | 1.5% | — | 9 sept 2013 | Triangle MicroWorks SCADA Data Gateway 2.50.0309 through 3.00.0616, DNP3 .NET Protocol components 3.06.0.171 through 3.15.0.369, and DNP3 C libraries 3.06.0000 through 3.15.0000 allow remote attackers to cause a denial… |