ICS Advisories
by Cisagov
CVEs (31)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-14479 | Med | 0.35 | 5.3 | 0.01 | Apr 1, 2022 | Sensitive information can be obtained through the handling of serialized data. The issue results from the lack of proper authentication required to query the server | ||
| CVE-2025-71411 | Med | 0.34 | 5.3 | 0.00 | Aug 7, 2026 | Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type of attack can be carried out remotely over radio frequency. | ||
| CVE-2025-31147 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users. | ||
| CVE-2025-25276 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | An unauthenticated attacker can hijack other users' devices and potentially control them. | ||
| CVE-2025-24315 | Med | 0.34 | 5.3 | 0.01 | Apr 15, 2025 | Unauthenticated attackers can add devices of other users to their scenes (or arbitrary scenes of other arbitrary users). | ||
| CVE-2025-31357 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | An unauthenticated attacker can obtain a user's plant list by knowing the username. | ||
| CVE-2025-30514 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "scenes"). | ||
| CVE-2025-27938 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "rooms"). | ||
| CVE-2022-2137 | Med | 0.32 | 4.9 | 0.01 | Jul 22, 2022 | The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an unauthorized attacker to disclose information | ||
| CVE-2024-38279 | Med | 0.30 | 4.6 | 0.00 | Jun 13, 2024 | The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system and obtain password hashes. | ||
| CVE-2024-39278 | Med | 0.27 | 4.2 | 0.00 | Sep 5, 2024 | Credentials to access device configuration information stored unencrypted in flash memory. These credentials would allow read-only access to network configuration information and terminal configuration data. |
- risk 0.35cvss 5.3epss 0.01
Sensitive information can be obtained through the handling of serialized data. The issue results from the lack of proper authentication required to query the server
- risk 0.34cvss 5.3epss 0.00
Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type of attack can be carried out remotely over radio frequency.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users.
- risk 0.34cvss 5.3epss 0.00
An unauthenticated attacker can hijack other users' devices and potentially control them.
- risk 0.34cvss 5.3epss 0.01
Unauthenticated attackers can add devices of other users to their scenes (or arbitrary scenes of other arbitrary users).
- risk 0.34cvss 5.3epss 0.00
An unauthenticated attacker can obtain a user's plant list by knowing the username.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "scenes").
- risk 0.34cvss 5.3epss 0.00
Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "rooms").
- risk 0.32cvss 4.9epss 0.01
The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an unauthorized attacker to disclose information
- risk 0.30cvss 4.6epss 0.00
The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system and obtain password hashes.
- risk 0.27cvss 4.2epss 0.00
Credentials to access device configuration information stored unencrypted in flash memory. These credentials would allow read-only access to network configuration information and terminal configuration data.
Page 2 of 2