ICS Advisories
by Cisagov
CVEs (29)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-31147 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users. | ||
| CVE-2025-25276 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | An unauthenticated attacker can hijack other users' devices and potentially control them. | ||
| CVE-2025-24315 | Med | 0.34 | 5.3 | 0.01 | Apr 15, 2025 | Unauthenticated attackers can add devices of other users to their scenes (or arbitrary scenes of other arbitrary users). | ||
| CVE-2025-31357 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | An unauthenticated attacker can obtain a user's plant list by knowing the username. | ||
| CVE-2025-30514 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "scenes"). | ||
| CVE-2025-27938 | Med | 0.34 | 5.3 | 0.00 | Apr 15, 2025 | Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "rooms"). | ||
| CVE-2022-2137 | Med | 0.32 | 4.9 | 0.01 | Jul 22, 2022 | The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an unauthorized attacker to disclose information | ||
| CVE-2024-38279 | Med | 0.30 | 4.6 | 0.00 | Jun 13, 2024 | The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system and obtain password hashes. | ||
| CVE-2024-39278 | Med | 0.27 | 4.2 | 0.00 | Sep 5, 2024 | Credentials to access device configuration information stored unencrypted in flash memory. These credentials would allow read-only access to network configuration information and terminal configuration data. |
- risk 0.34cvss 5.3epss 0.00
Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users.
- risk 0.34cvss 5.3epss 0.00
An unauthenticated attacker can hijack other users' devices and potentially control them.
- risk 0.34cvss 5.3epss 0.01
Unauthenticated attackers can add devices of other users to their scenes (or arbitrary scenes of other arbitrary users).
- risk 0.34cvss 5.3epss 0.00
An unauthenticated attacker can obtain a user's plant list by knowing the username.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "scenes").
- risk 0.34cvss 5.3epss 0.00
Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "rooms").
- risk 0.32cvss 4.9epss 0.01
The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an unauthorized attacker to disclose information
- risk 0.30cvss 4.6epss 0.00
The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system and obtain password hashes.
- risk 0.27cvss 4.2epss 0.00
Credentials to access device configuration information stored unencrypted in flash memory. These credentials would allow read-only access to network configuration information and terminal configuration data.
Page 2 of 2