Common Vulnerability Scoring System is a standardized framework for assigning numeric severity scores to software and hardware security vulnerabilities, enabling enterprises to compare issues consistently, prioritize remediation, automate vulnerability management workflows, and align technical findings with organizational risk and compliance practices.
Related Signals
147 articles about Common Vulnerability Scoring System
Festo has reported a vulnerability in its Didactic products related to Siemens TIA-Portal, affecting versions prior to updates V17 Update 6 and V18 Update 1. The vulnerability could allow arbitrary file creation or overwriting. Users are advised to update their systems accordingly.
Emerson's Appleton UPSMON-PRO is vulnerable to a stack-based buffer overflow that can allow remote code execution. The product is end-of-life, and users are advised to replace or implement specific mitigations to protect their systems. Recommended actions include blocking UDP port 2601 and isolating monitoring networks.
Opto 22 has addressed a critical vulnerability in its GRV-EPIC and groov RIO products that could allow remote code execution with root privileges. Users are advised to update to firmware version 4.0.3. Recommended cybersecurity measures for organizations have been outlined by CISA.
A vulnerability affecting Shelly Pro 4PM smart switches (versions prior to v1.6) has been reported, allowing potential Denial of Service conditions due to memory overallocation. Users are advised to update their devices and follow CISA's mitigation recommendations.
Schneider Electric has issued a security alert for vulnerabilities in EcoStruxure Machine SCADA Expert and Pro-face BLUE Open Studio related to cryptographic algorithms. Users are advised to update to version 2023.1 Patch 1 or apply risk mitigations to safeguard sensitive data.
Schneider Electric disclosed vulnerabilities in PowerChute Serial Shutdown versions 1.3 and prior, rated CVSS 7.8. Issues include path traversal, excessive authentication attempts, and incorrect permissions. Users should upgrade to version 1.4 to mitigate risks. CISA recommends several defensive measures.
The report details a vulnerability in the Shelly Pro 3EM smart DIN rail switch, indicating a CVSS v4 score of 8.3 due to potential Denial of Service conditions. Mitigation recommendations include securing network exposure and employing firewalls and VPNs. No public exploitation has been reported.
Ubia's Ubox camera system has a vulnerability that allows unauthorized access to camera feeds due to insufficiently protected API credentials. CISA advises users on mitigation strategies, including minimizing network exposure and implementing firewall protections.
ABB's FLXeon Controllers are identified with multiple vulnerabilities, including hard-coded credentials and improper input validation, allowing potential remote exploitation. Users are advised to implement mitigation strategies and update firmware to enhance security.