VYPR
Vendor

Tormach

Products
2
CVEs
6
Across products
8
Status
Private

Products

2

Recent CVEs

6
  • CVE-2024-22811HigApr 22, 2024
    risk 0.53cvss 8.2epss 0.00

    An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) by disrupting the communication between the PathPilot controller and the CNC router via overwriting the Hostmot2 configuration cookie in the device memory.

  • CVE-2024-22808HigApr 22, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) by disrupting the communication between the PathPilot controller and the CNC router via overwriting the card's name in the device memory.

  • CVE-2024-22809MedApr 22, 2024
    risk 0.42cvss 6.5epss 0.00

    Incorrect access control in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to access the G code's shared folder and view sensitive information.

  • CVE-2024-22807MedApr 22, 2024
    risk 0.42cvss 6.5epss 0.00

    An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to erase a critical sector of the flash memory, causing the machine to lose network connectivity and suffer from firmware corruption.

  • CVE-2024-22815MedApr 22, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue in the communication protocol of Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) via crafted commands.

  • CVE-2024-22813MedApr 22, 2024
    risk 0.29cvss 4.4epss 0.00

    An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to overwrite the hardcoded IP address in the device memory, disrupting network connectivity between the router and the controller.