Vulnerabilidades em ICS-CERT

93 resultados
Análise Vexday

Com 93 CVEs catalogadas e nenhuma em exploração ativa confirmada no CISA KEV, o perfil do ICS-CERT apresenta taxa de exploração abaixo da média geral do catálogo, o que não elimina atenção necessária dado que quatro vulnerabilidades possuem PoC pública disponível. A falha mais comum é CWE-121 (Stack-based Buffer Overflow), característica preocupante em ambientes de tecnologia operacional onde a estabilidade e disponibilidade são críticas. O CVE mais relevante no momento, CVE-2018-10594, registra EPSS de 0,69 — valor expressivo que indica probabilidade elevada de exploração —, merecendo atenção prioritária mesmo na ausência de registro formal no KEV. A ausência de novas CVEs nos últimos 90 dias sugere estabilidade recente no volume de descobertas, mas o histórico acumulado exige monitoramento contínuo, especialmente em contextos industriais.

CVE-2018-10594Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPSimulator EH2, EH3, EEPSS 62.8%CVE-2019-6543AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 20EPSS 17.3%CVE-2019-6545AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 20EPSS 13.9%CVE-2018-10630For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication diEPSS 11.1%CVE-2018-10636CNCSoft Version 1.00.83 and prior with ScreenEditor Version 1.00.54 has multiple stack-based buffer overflow vulnerabilities that could causEPSS 9.5%CVE-2018-17930A stack-based buffer overflow vulnerability has been identified in Teledyne DALSA Sherlock Version 7.2.7.4 and prior, which may allow remoteEPSS 7.3%CVE-2018-8840A remote attacker could send a carefully crafted packet in InduSoft Web Studio v8.1 and prior versions, and/or InTouch Machine Edition 2017 EPSS 7.2%CVE-2018-8847Eaton 9000X DriveA versions 2.0.29 and prior has a stack-based buffer overflow vulnerability, which may allow remote code execution.EPSS 6.8%CVE-2019-6557Several buffer overflow vulnerabilities have been identified in Moxa IKS and EDS, which may allow remote code execution.EPSS 5.0%CVE-2017-16744A path traversal vulnerability in Tridium Niagara AX Versions 3.8 and prior and Niagara 4 systems Versions 4.4 and prior installed on MicrosEPSS 4.8%CVE-2017-16748An attacker can log into the local Niagara platform (Niagara AX Framework Versions 3.8 and prior or Niagara 4 Framework Versions 4.4 and priEPSS 4.1%CVE-2018-10598CNCSoft Version 1.00.83 and prior with ScreenEditor Version 1.00.54 has two out-of-bounds read vulnerabilities could cause the software to cEPSS 3.7%CVE-2018-14805ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP is set to allow anonymous authentication, and specific key valEPSS 3.6%CVE-2019-6551Pangea Communications Internet FAX ATA all Versions 3.1.8 and prior allow an attacker to bypass user authentication using a specially crafteEPSS 3.3%CVE-2018-8867In GE PACSystems RX3i CPE305/310 version 9.20 and prior, RX3i CPE330 version 9.21 and prior, RX3i CPE 400 version 9.30 and prior, PACSystemsEPSS 3.2%CVE-2018-8843Rockwell Automation Arena versions 15.10.00 and prior contains a use after free vulnerability caused by processing specially crafted Arena SEPSS 2.9%CVE-2019-6524Moxa IKS and EDS do not implement sufficient measures to prevent multiple failed authentication attempts, which may allow an attacker to disEPSS 2.7%CVE-2018-8835Double free vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by processing specially crafted .pm3 files may allEPSS 2.7%CVE-2018-8837Processing specially crafted .pm3 files in Advantech WebAccess HMI Designer 2.1.7.32 and prior may cause the system to write outside the intEPSS 2.7%CVE-2018-7507WPLSoft in Delta Electronics versions 2.45.0 and prior utilizes a fixed length heap buffer where a value larger than the buffer can be read EPSS 2.7%