CISA
56 exploits
Active since Aug 2014
Horner Automation Cscape and XL4, XL7 PLC Weak password requirements
CVSS 9.1
Welker OdorEyes EcoSystem Pulse Bypass System with XL4 Controller - Unauthenticated Remote PLC Manipulation
CVSS 8.2
Schneider Electric Wonderware Information Server - Info Disclosure
Schneider Electric Wonderware Information Server - Info Disclosure
Schneider Electric Wonderware Information Server Portal 4.0 SP1-5.5 - Cross-Site Scripting
Schneider Electric Wonderware Information Server Portal 4.0 SP1-5.5 - XML External Entity Injection
Schneider Electric Wonderware Information Server Portal 4.0 SP1-5.5 - SQL Injection
Hospira MedNet < 6.1 - Cleartext Credentials Exposure
Hospira MedNet < 5.8 - Unauthenticated Remote Code Execution via JBoss Enterprise Application Platform
CVSS 9.8
Hospira MedNet <6.1 - Info Disclosure
Hospira MedNet < 5.8 and >= 6.1 - Authenticated Exposure of Sensitive Information via Hardcoded SQL Password
Hospira LifeCare PCA Infusion System < 7.0 - Unauthenticated Data Modification via Network Traffic
Schneider Electric VAMPSET < 2.2.136 - Denial of Service via Malformed Setting or Disturbance Recording File
Nordex Control 2 SCADA < 15 - Cross-Site Scripting via Login Username Parameter
GE Digital Energy Hydran M2 - Info Disclosure
Rockwell Automation Allen-Bradley MicroLogix 1400 < Series B FRN 15.001 - Denial of Service via Malformed DNP3 Packets
Schneider Electric ClearSCADA 2010 R3-2014 R1 - Authenticated Cross-Site Scripting
Schneider Electric ClearSCADA 2010 R3-2014 R1 - Unauthenticated Database Record Read via Guest Account
Schneider Electric ClearSCADA 2010 R3-2014 R1 - Remote Server Spoofing via MD5 X.509 Certificate
Beckhoff Embedded PC Images < 2014-10-22 and TwinCAT ADS Components - Unauthenticated Brute-Force Authentication Bypass
CVSS 9.1
Beckhoff Embedded PC <2014-10-22 - RCE
CVSS 9.1
Meinberg LANTIME M-Series < 6.15.019 - Cross-Site Scripting
GE Multilink ML800/1200/1600/2400 < 4.2.1 and ML810/3000/3100 < 5.2.0 - Denial of Service via Crafted Packets
GE Multilink ML800/1200/1600/2400 < 4.2.1 & ML810/3000/3100 < 5.2.0 - Unauthenticated Traffic Decryption
GE Multilink ML800/1200/1600/2400 <4.2.1 and ML810/3000/3100 <5.2.0 - Cross-Site Scripting
CVSS 5.4