VYPR

ICS Advisories

by Cisagov

CVEs (29)

  • CVE-2023-41084CriSep 18, 2023
    risk 0.65cvss 10.0epss 0.01

    Session management within the web application is incorrect and allows attackers to steal session cookies to perform a multitude of actions that the web app allows on the device.

  • CVE-2024-47138CriNov 22, 2024
    risk 0.64cvss 9.8epss 0.01

    The administrative interface listens by default on all interfaces on a TCP port and does not require authentication when being accessed.

  • CVE-2022-2197CriJun 30, 2022
    risk 0.64cvss 9.8epss 0.01

    By using a specific credential string, an attacker with network access to the device’s web interface could circumvent the authentication scheme and perform administrative operations.

  • CVE-2022-2103CriJun 24, 2022
    risk 0.64cvss 9.8epss 0.01

    An attacker with weak credentials could access the TCP port via an open FTP port, allowing an attacker to read sensitive files and write to remotely executable directories.

  • CVE-2021-38477CriOct 22, 2021
    risk 0.64cvss 9.8epss 0.01

    There are multiple API function codes that permit reading and writing data to or from files and directories, which could lead to the manipulation and/or the deletion of files.

  • CVE-2022-1521CriJun 24, 2022
    risk 0.59cvss 9.1epss 0.01

    LRM does not implement authentication or authorization by default. A malicious actor can inject, replay, modify, and/or intercept sensitive data.

  • CVE-2024-25574HigApr 1, 2024
    risk 0.58cvss 8.8epss 0.09

    SQL injection vulnerability exists in GetDIAE_usListParameters.

  • CVE-2025-14751HigJan 22, 2026
    risk 0.57cvss epss 0.00

    A low-privileged user can bypass account credentials without confirming the user's current authentication state, which may lead to unauthorized privilege escalation.

  • CVE-2024-43099HigSep 13, 2024
    risk 0.57cvss 8.8epss 0.00

    The session hijacking attack targets the application layer's control mechanism, which manages authenticated sessions between a host PC and a PLC. During such sessions, a session key is utilized to maintain security. However, if an attacker captures this session key, they can…

  • CVE-2024-28029HigMar 21, 2024
    risk 0.57cvss 8.8epss 0.01

    Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged functionality.

  • CVE-2025-49850HigJun 17, 2025
    risk 0.55cvss epss 0.00

    A Heap-based Buffer Overflow vulnerability exists within the parsing of PRJ files. The issues result from the lack of proper validation of user-supplied data, which can result in different memory corruption issues within the application, such as reading and writing past the end…

  • CVE-2021-42536HigOct 22, 2021
    risk 0.52cvss 8.0epss 0.01

    The affected product is vulnerable to a disclosure of peer username and password by allowing all users access to read global variables.

  • CVE-2023-39452HigSep 18, 2023
    risk 0.49cvss 7.5epss 0.01

    The web application that owns the device clearly stores the credentials within the user management section. Obtaining this information can be done remotely due to the incorrect management of the sessions in the web application.

  • CVE-2022-1704HigAug 5, 2022
    risk 0.49cvss 7.6epss 0.01

    Due to an XML external entity reference, the software parses XML in the backup/restore functionality without XML security flags, which may lead to a XXE attack while restoring the backup.

  • CVE-2021-38455HigOct 22, 2021
    risk 0.48cvss 7.3epss 0.01

    The affected product’s OS Service does not verify any given parameter. A user can supply any type of parameter that will be passed to inner calls without checking the type of the parameter or the value.

  • CVE-2025-30512MedApr 15, 2025
    risk 0.42cvss 6.5epss 0.01

    Unauthenticated attackers can send configuration settings to device and possible perform physical actions remotely (e.g., on/off).

  • CVE-2023-50703MedDec 20, 2023
    risk 0.41cvss 6.3epss 0.00

    An attacker with network access could perform a man-in-the-middle (MitM) attack and capture sensitive information to gain unauthorized access to the application.

  • CVE-2021-42699MedNov 5, 2021
    risk 0.37cvss 5.7epss 0.00

    The affected product is vulnerable to cookie information being transmitted as cleartext over HTTP. An attacker can capture network traffic, obtain the user’s cookie and take over the account.

  • CVE-2022-2569MedAug 24, 2022
    risk 0.36cvss 5.5epss 0.00

    The affected device stores sensitive information in cleartext, which may allow an authenticated user to access session data stored in the OAuth database belonging to legitimate users

  • CVE-2020-14479MedApr 1, 2022
    risk 0.35cvss 5.3epss 0.01

    Sensitive information can be obtained through the handling of serialized data. The issue results from the lack of proper authentication required to query the server

Page 1 of 2