Vulnerabilities in ICS-CERT

93 results
Vexday analysis

Com 93 CVEs catalogadas e nenhuma em exploração ativa confirmada no CISA KEV, o perfil do ICS-CERT apresenta taxa de exploração abaixo da média geral do catálogo, o que não elimina atenção necessária dado que quatro vulnerabilidades possuem PoC pública disponível. A falha mais comum é CWE-121 (Stack-based Buffer Overflow), característica preocupante em ambientes de tecnologia operacional onde a estabilidade e disponibilidade são críticas. O CVE mais relevante no momento, CVE-2018-10594, registra EPSS de 0,69 — valor expressivo que indica probabilidade elevada de exploração —, merecendo atenção prioritária mesmo na ausência de registro formal no KEV. A ausência de novas CVEs nos últimos 90 dias sugere estabilidade recente no volume de descobertas, mas o histórico acumulado exige monitoramento contínuo, especialmente em contextos industriais.

CVE-2017-7931In ABB IP GATEWAY 3.39 and prior, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to acceEPSS 1.9%CVE-2019-6537Multiple stack-based buffer overflow vulnerabilities in WECON LeviStudioU version 1.8.56 and prior may be exploited when parsing strings witEPSS 1.9%CVE-2018-18992LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper sanitation, which may allow an attacker to execute EPSS 1.8%CVE-2018-14795DeltaV Versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, and R5 is vulnerable due to improper path validation which may allow an attacker to replace EPSS 1.8%CVE-2018-8866In Vecna VGo Robot versions prior to 3.0.3.52164, an attacker on an adjacent network could perform command injection.EPSS 1.8%CVE-2019-6563Moxa IKS and EDS generate a predictable cookie calculated with an MD5 hash, allowing an attacker to capture the administrator's password, whEPSS 1.7%CVE-2018-14785NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The directory of the device is listed openly EPSS 1.7%CVE-2019-6555Cscape, 9.80 SP4 and prior. An improper input validation vulnerability may be exploited by processing specially crafted POC files. This may EPSS 1.7%CVE-2019-6520Moxa IKS and EDS does not properly check authority on server side, which results in a read-only user being able to perform arbitrary configuEPSS 1.7%CVE-2018-7506The private key of the web server in Moxa MXview versions 2.8 and prior is able to be read and accessed via an HTTP GET request, which may aEPSS 1.6%CVE-2019-6541A memory corruption vulnerability has been identified in WECON LeviStudioU version 1.8.56 and prior, which may allow arbitrary code executioEPSS 1.6%CVE-2018-19018An access of uninitialized pointer vulnerability in CX-Supervisor (Versions 3.42 and prior) could lead to type confusion when processing proEPSS 1.5%CVE-2018-19015An attacker could inject commands to launch programs and create, write, and read files on CX-Supervisor (Versions 3.42 and prior) through a EPSS 1.5%CVE-2018-14782NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device allows access to configuration filEPSS 1.4%CVE-2018-14784NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device is vulnerable to several cross-sitEPSS 1.3%CVE-2019-6518Moxa IKS and EDS store plaintext passwords, which may allow sensitive information to be read by someone with access to the device.EPSS 1.2%CVE-2018-19004LCDS Laquis SCADA prior to version 4.1.0.4150 allows out of bounds read when opening a specially crafted project file, which may allow data EPSS 1.2%CVE-2019-6533Registers used to store Modbus values can be read and written from the web interface without authentication in the PR100088 Modbus gateway vEPSS 1.2%CVE-2019-6561Cross-site request forgery has been identified in Moxa IKS and EDS, which may allow for the execution of unauthorized actions on the device.EPSS 1.2%CVE-2019-6527PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) may allow an attacker to be able to change the passworEPSS 1.2%