Vulnerabilidades en Carlo Gavazzi Automation

22 resultados
Análisis Vexday

Carlo Gavazzi Automation apresenta baixo volume de vulnerabilidades conhecidas (2 CVEs), nenhuma sob exploração ativa, e nenhuma crítica registrada. A fraqueza dominante é hardcoding de credenciais (CWE-798), indicando problemas de segurança em design que demandam revisão arquitetural, sem pressão de risco imediato pela ausência de ataques ativos ou vulnerabilidades recentes.

CVE-2026-27561HIGHCommand Injection via GET in /api/iodd/configEPSS 2.2%CVE-2026-27562HIGHCommand Injection via PUT in /api/iodd/configEPSS 2.2%CVE-2026-27560HIGHCommand Injection via DELETE in /api/status/dataEPSS 2.2%CVE-2026-27549HIGHCommand Injection in /index.php/attached_devices_tab/do_uploadEPSS 2.1%CVE-2026-27547HIGHCommand Injection in /index.php/ajax/get_iodd_menu_infoEPSS 2.1%CVE-2026-27554HIGHCommand Injection in /index.php/ajax/save_iodd_parametersEPSS 2.1%CVE-2026-27558HIGHCommand Injection in /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_filesEPSS 2.1%CVE-2026-27550HIGHCommand Injection in Field_Shadow_Password ClassEPSS 2.1%CVE-2026-27548HIGHCommand Injection in /index.php/ajax/get_iodd_port_infoEPSS 2.1%CVE-2026-27559HIGHCommand Injection via GET in /api/status/dataEPSS 2.1%CVE-2026-27551HIGHCommand Injection in /index.php/ajax/parameterManageEPSS 2.1%CVE-2026-27564HIGHCommand Injection via PUT in /api/datastorage/dataEPSS 2.0%CVE-2026-27563HIGHCommand Injection via GET in /api/datastorage/dataEPSS 2.0%CVE-2012-6428Carlo Gavazzi EOS Box Hard-Coded CredentialsEPSS 1.5%CVE-2012-6427Carlo Gavazzi EOS Box SQL InjectionEPSS 1.3%CVE-2026-27546CRITICALAuthentication Bypass in _account_logEPSS 1.0%CVE-2026-27565CRITICALRemote code execution via uploading a malicious IODD fileEPSS 0.9%CVE-2026-27556HIGHLocal File Inclusion in /index.php/ajax/save_iodd_parametersEPSS 0.9%CVE-2026-27555HIGHLocal File Inclusion in /index.php/ajax/get_iodd_port_infoEPSS 0.8%CVE-2026-27557HIGHPath Traversal in /index.php/view_uploaded_iodd_fileEPSS 0.7%