Vulnerabilidades em ICS-CERT

93 resultados
Análise Vexday

Com 93 CVEs catalogadas e nenhuma em exploração ativa confirmada no CISA KEV, o perfil do ICS-CERT apresenta taxa de exploração abaixo da média geral do catálogo, o que não elimina atenção necessária dado que quatro vulnerabilidades possuem PoC pública disponível. A falha mais comum é CWE-121 (Stack-based Buffer Overflow), característica preocupante em ambientes de tecnologia operacional onde a estabilidade e disponibilidade são críticas. O CVE mais relevante no momento, CVE-2018-10594, registra EPSS de 0,69 — valor expressivo que indica probabilidade elevada de exploração —, merecendo atenção prioritária mesmo na ausência de registro formal no KEV. A ausência de novas CVEs nos últimos 90 dias sugere estabilidade recente no volume de descobertas, mas o histórico acumulado exige monitoramento contínuo, especialmente em contextos industriais.

CVE-2018-7494WPLSoft in Delta Electronics versions 2.45.0 and prior utilizes a fixed length stack buffer where a value larger than the buffer can be readEPSS 2.7%CVE-2018-17937gpsd versions 2.90 to 3.17 and microjson versions 1.0 to 1.3, an open source project, allow a stack-based buffer overflow, which may allow rEPSS 2.7%CVE-2018-18990LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation. An attacker can levEPSS 2.6%CVE-2018-18988LCDS Laquis SCADA prior to version 4.1.0.4150 allows execution of script code by opening a specially crafted report format file. This may alEPSS 2.6%CVE-2018-7509WPLSoft in Delta Electronics versions 2.45.0 and prior writes data from a file outside the bounds of the intended buffer space, which could EPSS 2.6%CVE-2019-6528PSI GridConnect GmbH Telecontrol Gateway and Smart Telecontrol Unit family, IEC104 Security Proxy versions Telecontrol Gateway 3G Versions 4EPSS 2.6%CVE-2018-10619An unquoted search path or element in RSLinx Classic Versions 3.90.01 and prior and FactoryTalk Linx Gateway Versions 3.90.00 and prior may EPSS 2.6%CVE-2019-6522Moxa IKS and EDS fails to properly check array bounds which may allow an attacker to read device memory on arbitrary addresses, and may alloEPSS 2.5%CVE-2018-19000LCDS Laquis SCADA prior to version 4.1.0.4150 allows an authentication bypass, which may allow an attacker access to sensitive data.EPSS 2.5%CVE-2019-6559Moxa IKS and EDS allow remote authenticated users to cause a denial of service via a specially crafted packet, which may cause the switch toEPSS 2.4%CVE-2018-19008The TextEditor 2.0 in ABB CP400 Panel Builder versions 2.0.7.05 and earlier contain a vulnerability in the file parser of the Text Editor whEPSS 2.3%CVE-2018-19019A type confusion vulnerability exists when processing project files in CX-Supervisor (Versions 3.42 and prior). An attacker could use a specEPSS 2.2%CVE-2018-19017Several use after free vulnerabilities have been identified in CX-Supervisor (Versions 3.42 and prior). When processing project files, the aEPSS 2.2%CVE-2018-19011CX-Supervisor (Versions 3.42 and prior) can execute code that has been injected into a project file. An attacker could exploit this to execuEPSS 2.2%CVE-2018-8833Heap-based buffer overflow vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by processing specially crafted .pmEPSS 2.2%CVE-2017-5175Advantech WebAccess 8.1 and earlier contains a DLL hijacking vulnerability which may allow an attacker to run a malicious DLL file within thEPSS 2.2%CVE-2018-18996LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper authorization or sanitation, which may allow an attEPSS 2.2%CVE-2019-6539Several heap-based buffer overflow vulnerabilities in WECON LeviStudioU version 1.8.56 and prior have been identified, which may allow arbitEPSS 2.1%CVE-2018-18998LCDS Laquis SCADA prior to version 4.1.0.4150 uses hard coded credentials, which may allow an attacker unauthorized access to the system witEPSS 2.1%CVE-2017-9664In ABB SREA-01 revisions A, B, C: application versions up to 3.31.5, and SREA-50 revision A: application versions up to 3.32.8, an attacker EPSS 2.0%