Common Vulnerability Scoring System is a standardized framework for assigning numeric severity scores to software and hardware security vulnerabilities, enabling enterprises to compare issues consistently, prioritize remediation, automate vulnerability management workflows, and align technical findings with organizational risk and compliance practices.
Related Signals
147 articles about Common Vulnerability Scoring System
A vulnerability in Shelly Pro 4PM smart DIN rail switches prior to version 1.6 allows attackers to cause denial of service by exploiting a resource allocation flaw in the JSON parser. The issue has a CVSS v4 score of 8.3. Mitigations include software updates and network security measures.
Schneider Electric's PowerChute Serial Shutdown versions 1.3 and earlier have vulnerabilities including path traversal, excessive authentication attempts, and incorrect default permissions. Version 1.4 fixes these issues. Users are advised to apply the update and follow recommended security measures to reduce risk.
A vulnerability related to weak cryptographic algorithms in Schneider Electric's EcoStruxure Machine SCADA Expert and Pro-face BLUE Open Studio products was detailed. Patches are available in version 2023.1 Patch 1. Mitigation steps and best cybersecurity practices are recommended by Schneider Electric and CISA.
Zenitel's TCIV-3+ devices prior to version 9.3.3.0 have vulnerabilities including OS command injection, out-of-bounds write, and cross-site scripting. These issues could allow arbitrary code execution or denial of service. Mitigations include upgrading firmware and network security measures.
Opto 22's groov View software and firmware versions prior to R4.5e and 4.0.3 respectively have a vulnerability exposing sensitive metadata such as API keys. The company has released patches and CISA advises network isolation and VPN use to mitigate potential exploitation risks.
As of January 10, 2023, CISA will cease updates for Siemens product vulnerabilities. Multiple vulnerabilities affecting Siemens LOGO! 8 BM Devices have been reported, allowing for potential remote code execution and device manipulation. Mitigations have been suggested while Siemens prepares fixes.