Known Vulnerabilities for products from Danfoss
Listed below are 10 of the newest known vulnerabilities associated with the vendor "Danfoss".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-25915 json | Due to improper input validation, a remote attacker could execute arbitrary commands on the target system. | 9.8 - CRITICAL | 2023-08-21 | 2023-08-24 |
| CVE-2023-25914 json | Due to improper restriction, attackers could retrieve and read system files of the underlying server through the XML interfac... | 7.5 - HIGH | 2023-08-21 | 2023-08-24 |
| CVE-2023-25913 json | Because of an authentication flaw an attacker would be capable of generating a web report that discloses sensitive informatio... | 7.5 - HIGH | 2023-08-21 | 2023-08-24 |
| CVE-2023-25912 json | The webreport generation feature in the Danfoss AK-EM100 allows an unauthorized actor to generate a web report that discloses... | 5.3 - MEDIUM | 2023-06-11 | 2023-06-16 |
| CVE-2023-25911 json | The Danfoss AK-EM100 web applications allow for OS command injection through the web application parameters. | 9.8 - CRITICAL | 2023-06-11 | 2023-06-16 |
| CVE-2023-22586 json | The Danfoss AK-EM100 web applications allow for Local File Inclusion in the file parameter. | 7.5 - HIGH | 2023-06-11 | 2023-06-16 |
| CVE-2023-22585 json | The Danfoss AK-EM100 web applications allow for Reflected Cross-Site Scripting in the title parameter. | 6.1 - MEDIUM | 2023-06-11 | 2023-06-16 |
| CVE-2023-22584 json | The Danfoss AK-EM100 stores login credentials in cleartext. | 7.5 - HIGH | 2023-06-11 | 2023-06-16 |
| CVE-2023-22583 json | The Danfoss AK-EM100 web forms allow for SQL injection in the login forms. | 9.8 - CRITICAL | 2023-06-11 | 2023-06-16 |
| CVE-2023-22582 json | The Danfoss AK-EM100 web applications allow for Reflected Cross-Site Scripting. | 6.1 - MEDIUM | 2023-06-11 | 2023-06-16 |