Endress+Hauser
Products
6- 2 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
Recent CVEs
5| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-6596 | Cri | 0.64 | 9.8 | 0.01 | Sep 10, 2024 | An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context. | ||
| CVE-2020-12495 | Cri | 0.59 | 9.1 | 0.01 | Nov 19, 2020 | Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) with Firmware version prior to V2.0.0 is prone to improper privilege management. The affected device has a web-based user interface with a role-based access system. Users with different roles have different write… | ||
| CVE-2020-12496 | Med | 0.42 | 6.5 | 0.01 | Nov 19, 2020 | Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) and Memograph M (Neutral/Private Label) (RSG45, ORSG45) with Firmware version V2.0.0 and above is prone to exposure of sensitive information to an unauthorized actor. The firmware release has a dynamic token for… | ||
| CVE-2018-16059 | Med | 0.40 | 5.3 | 0.30 | Sep 7, 2018 | Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename parameter. | ||
| CVE-2015-6463 | 0.00 | — | 0.01 | Sep 28, 2015 | CodeWrights HART Comm DTM components, as used with Endress+Hauser FieldCare, allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a longtag XML schema containing an external entity… |
- risk 0.64cvss 9.8epss 0.01
An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.
- risk 0.59cvss 9.1epss 0.01
Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) with Firmware version prior to V2.0.0 is prone to improper privilege management. The affected device has a web-based user interface with a role-based access system. Users with different roles have different write…
- risk 0.42cvss 6.5epss 0.01
Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) and Memograph M (Neutral/Private Label) (RSG45, ORSG45) with Firmware version V2.0.0 and above is prone to exposure of sensitive information to an unauthorized actor. The firmware release has a dynamic token for…
- risk 0.40cvss 5.3epss 0.30
Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename parameter.
- CVE-2015-6463Sep 28, 2015risk 0.00cvss —epss 0.01
CodeWrights HART Comm DTM components, as used with Endress+Hauser FieldCare, allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a longtag XML schema containing an external entity…