CVE Vulnerability Database

Search and browse 58 known security vulnerabilities. Filter by severity, vendor, product, and year.

58 vulnerabilities found
CVE-2021-44732
9.8 critical

Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.

Arm Mbed Tls Dec 20, 2021
CVE-2019-25052
9.1 critical

In Linaro OP-TEE before 3.7.0, by using inconsistent or malformed data, it is possible to call update and final cryptographic functions directly, causing a crash that could leak sensitive information.

Trustedfirmware Op-Tee Aug 11, 2021
CVE-2021-33485
9.8 critical

CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow.

Codesys Control Aug 3, 2021
CVE-2021-22779
9.1 critical

Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Control Expert V15.0 SP1, EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), SCADAPack Re

Schneider-Electric Ecostruxure Control Expert Jul 14, 2021
CVE-2021-22768
9.8 critical

A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service or remote code execution via a specially crafted HTTP packet.This CVE ID is unique from CVE-2021-22767

Schneider-Electric Powerlogic Egx100 Firmware Jun 11, 2021
CVE-2021-22767
9.8 critical

A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service or remote code execution via a specially crafted HTTP packet.This CVE ID is unique from CVE-2021-2276

Schneider-Electric Powerlogic Egx100 Firmware Jun 11, 2021
CVE-2021-22765
9.8 critical

A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service or remote code execution via a specially crafted HTTP packet

Schneider-Electric Powerlogic Egx100 Firmware Jun 11, 2021
CVE-2021-22763
9.8 critical

A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could allow an attacker administrator level access to a device.

Schneider-Electric Powerlogic Pm5560 Firmware Jun 11, 2021
CVE-2020-15782
9.8 critical

A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V21.9), SIMATIC S7-1200 CPU f

Siemens Simatic Driver Controller Firmware May 28, 2021
CVE-2021-27384
9.8 critical

A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl.

Siemens Simatic Wincc Runtime Advanced May 12, 2021
CVE-2020-15798
9.8 critical

A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V16 Update 3a), SIMATIC HMI KTP Mobile Panels (All versions < V16 Update 3a), SINAMICS GH150 (All versions), SINAMICS GL150 (with option X30) (All versions), SINAMICS GM150 (with option X30) (Al

Siemens Simatic Hmi Comfort Panels Firmware Feb 9, 2021
CVE-2020-27285
9.1 critical

The default configuration of Crimson 3.1 (Build versions prior to 3119.001) allows a user to be able to read and modify the database without authentication.

Redlion Crimson Jan 6, 2021
CVE-2020-28271
9.8 critical

Prototype pollution vulnerability in 'deephas' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution.

Sharpred Deephas Nov 12, 2020
CVE-2020-15786
9.8 critical

A vulnerability has been identified in SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions < V16), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions <= V16), SIMATIC HMI Mobile Panels (All versions <= V16), SIMATIC HMI Unified Comfort Panels (All versions <=

Siemens Simatic Hmi Basic Panels 2Nd Generation Firmware Sep 9, 2020
CVE-2020-7489
9.8 critical

A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability exists on EcoStruxure Machine Expert – Basic or SoMachine Basic programming software (versions in security notification). The result of this vulnerability, DLL substitution, cou

Schneider-Electric Ecostruxure Machine Expert Apr 22, 2020
CVE-2020-6990
9.8 critical

Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, The cryptographic key utilized to help protect the account password is hard coded into the RSLogix 500 binary file. An

Rockwellautomation Micrologix 1400 A Firmware Mar 16, 2020
CVE-2019-17571
9.8 critical

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2

Apache Log4J Dec 20, 2019
CVE-2019-18269
9.8 critical

Omron’s CS and CJ series PLCs have an unrestricted externally accessible lock vulnerability.

Omron Plc Cj Firmware Dec 16, 2019
CVE-2019-1010292
9.8 critical

Linaro/OP-TEE OP-TEE Prior to version v3.4.0 is affected by: Boundary checks. The impact is: This could lead to corruption of any memory which the TA can access. The component is: optee_os. The fixed version is: v3.4.0.

Trustedfirmware Op-Tee Jul 16, 2019
CVE-2019-1010298
9.8 critical

Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Code execution in the context of TEE core (kernel). The component is: optee_os. The fixed version is: 3.4.0 and later.

Trustedfirmware Op-Tee Jul 15, 2019
CVE-2019-1010297
9.8 critical

Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Execution of code in TEE core (kernel) context. The component is: optee_os. The fixed version is: 3.4.0 and later.

Trustedfirmware Op-Tee Jul 15, 2019
CVE-2019-1010296
9.8 critical

Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Code execution in context of TEE core (kernel). The component is: optee_os. The fixed version is: 3.4.0 and later.

Trustedfirmware Op-Tee Jul 15, 2019
CVE-2019-1010295
9.8 critical

Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Memory corruption and disclosure of memory content. The component is: optee_os. The fixed version is: 3.4.0 and later.

Trustedfirmware Op-Tee Jul 15, 2019
CVE-2019-1010293
9.8 critical

Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Boundary crossing. The impact is: Memory corruption of the TEE itself. The component is: optee_os. The fixed version is: 3.4.0 and later.

Trustedfirmware Op-Tee Jul 15, 2019