Vulnerabilities

Summary — last 7 days

New vulnerabilities2,952▲ 10 vs. last week
Critical / high1,451▲ 185 vs. last week
New active exploitation (KEV)5▼ 3 vs. last week
Unscored (no CVSS)272▼ 254 vs. last week
–

2 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedMedium (6.5)0.83%—Endress Rsg35 FirmwareEndress Rsg45 FirmwareEndress Orsg35 FirmwareEndress Orsg45 Firmware11/19/20206/17/2026
Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) and Memograph M (Neutral/Private Label) (RSG45, ORSG45) with Firmware version V2.0.0 and above is prone to exposure of sensitive information to an unauthorized actor. The firmware release has a dynamic token for each request submitted to the server,…
ModifiedHigh (8.8)0.92%—Endress Rsg35 FirmwareEndress Rsg45 FirmwareEndress Orsg35 FirmwareEndress Orsg45 Firmware11/19/20206/17/2026
Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) with Firmware version prior to V2.0.0 is prone to improper privilege management. The affected device has a web-based user interface with a role-based access system. Users with different roles have different write and read privileges. The access system…