Common Vulnerability Scoring System is a standardized framework for assigning numeric severity scores to software and hardware security vulnerabilities, enabling enterprises to compare issues consistently, prioritize remediation, automate vulnerability management workflows, and align technical findings with organizational risk and compliance practices.
Related Signals
147 articles about Common Vulnerability Scoring System
Rockwell Automation's Verve Asset Manager has a vulnerability, CVE-2025-11862, identified as incorrect authorization, affecting multiple versions. Users are advised to update to versions 1.41.4 and 1.42. CISA recommends defensive measures to reduce exploitation risks.
CISA will cease updates on Siemens ICS security advisories for product vulnerabilities, initially reporting on issues affecting the SICAM P850 and P855 families, specifically vulnerabilities related to CSRF and incorrect permission assignments. Users are encouraged to update and implement security measures to mitigate risks.
Rockwell Automation identified a vulnerability in FactoryTalk Policy Manager that may allow remote exploitation leading to Denial of Service. Versions 6.51.00 and prior are affected, with a fix available in 6.60.00 and later. Users are advised to implement security best practices.
Rockwell Automation's Studio 5000 Simulation Interface has vulnerabilities allowing unauthorized access and potential exploitation. Users are advised to upgrade to version 3.0.0 or later to mitigate risks associated with path traversal and SSRF vulnerabilities. CISA offers defensive measures and best practices for cyber defense.
AVEVA has reported a vulnerability in its Application Server Immutable Deployment Environment that could allow attackers to exploit improper HTML script neutralization. Users are advised to update to secure versions and implement defensive measures to minimize risk.
CISA will no longer update advisories for Siemens vulnerabilities. Two critical vulnerabilities in COMOS were identified, allowing for potential code execution and data infiltration. Siemens recommends updating to version 10.4.5 or later and provides mitigations to reduce risks of exploitation.
Siemens has identified a vulnerability in Solid Edge SE2025 that allows man-in-the-middle attacks due to improper certificate validation. Users are advised to update to V225.0 Update 11 or later versions and implement protective measures to minimize exploitation risks.
General Industrial Controls' Lynx+ Gateway faces multiple vulnerabilities, including weak password requirements and missing authentication. These issues could lead to unauthorized access and denial of service. Users are advised to enhance security measures and follow CISA's recommendations to mitigate risks.
Festo identified a critical vulnerability in its MSE6 product line affecting remote access. The vulnerability, CVE-2023-3634, poses risks to confidentiality, integrity, and availability. Mitigation measures include updated documentation and network security recommendations.
Automated Logic's WebCTRL Premium Server has vulnerabilities including Open Redirect and Cross-Site Scripting (XSS). Users are advised to upgrade to version 9.0 as previous versions are affected. CISA recommends security practices to mitigate potential exploitation.