AzeoTech Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with AzeoTech products.
Products
- DAQFactory11 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-12921HIGH | Use after free in AzeoTech DAQFactoryIn AzeoTech DAQFactory versions 21.1 and prior, a Use After Free vulnerability can be exploited by an attacker using specially crafted .ctl files which can result in code execution. CWE-416Jun 25, 2026 | CVSS8.4v4.0 | EPSS0.128% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-12390HIGH | Access of resource using incompatible type ('type confusion') in AzeoTech DAQFactoryIn AzeoTech DAQFactory versions 21.1 and prior, a Type Confusion vulnerability can be exploited by an attacker using specially crafted .ctl files which can result in code execution. CWE-843Jun 18, 2026 | CVSS8.4v4.0 | EPSS0.135% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-66585HIGH | Use After Free vulnerability in AzeoTech DAQFactoryIn AzeoTech DAQFactory release 20.7 (Build 2555), a use after free vulnerability can be exploited to cause memory corruption while parsing specially crafted .ctl files. This could allow an attacker to execute code in the context of the current process. CWE-416Dec 11, 2025 | CVSS7.3v4.0 | EPSS0.232% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-66586HIGH | Type Confusion vulnerability in AzeoTech DAQFactoryIn AzeoTech DAQFactory release 20.7 (Build 2555), an access of resource using incompatible type vulnerability can be exploited to cause memory corruption while parsing specially crafted .ctl files. This could allow an attacker to execute code in the context of the current process. CWE-843Dec 11, 2025 | CVSS7.3v4.0 | EPSS0.216% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-66588HIGH | Access of Uninitialized Pointer vulnerability in AzeoTech DAQFactoryIn AzeoTech DAQFactory release 20.7 (Build 2555), an access of uninitialized pointer vulnerability can be exploited by an attacker which can lead to arbitrary code execution. CWE-824Dec 11, 2025 | CVSS8.4v4.0 | EPSS0.291% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-66589HIGH | Out-of-bounds Read vulnerability in AzeoTech DAQFactoryIn AzeoTech DAQFactory release 20.7 (Build 2555), an Out-of-bounds Read vulnerability can be exploited by an attacker to cause the program to read data past the end of an allocated buffer. This could allow an attacker to disclose information or cause a system crash. CWE-125Dec 11, 2025 | CVSS8.4v4.0 | EPSS0.347% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-66590HIGH | Out-of-bounds Write vulnerability in AzeoTech DAQFactoryIn AzeoTech DAQFactory release 20.7 (Build 2555), an out-of-bounds write vulnerability can be exploited by an attacker to cause the program to write data past the end of an allocated memory buffer. This can lead to arbitrary code execution or a system crash. CWE-787Dec 11, 2025 | CVSS8.4v4.0 | EPSS0.374% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-42698HIGH | AzeoTech DAQFactoryProject files are stored memory objects in the form of binary serialized data that can later be read and deserialized again to instantiate the original objects in memory. Malicious manipulation of these files may allow an attacker to corrupt memory. CWE-502Nov 5, 2021 | CVSS7.8v3.1 | EPSS0.765% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-42701MEDIUM | AzeoTech DAQFactoryAn attacker could prepare a specially crafted project file that, if opened, would attempt to connect to the cloud and trigger a man in the middle (MiTM) attack. This could allow an attacker to obtain credentials and take over the user’s cloud account. CWE-471Nov 5, 2021 | CVSS5.0v3.1 | EPSS0.57% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-42543HIGH | AzeoTech DAQFactoryThe affected application uses specific functions that could be abused through a crafted project file, which could lead to code execution, system reboot, and system shutdown. CWE-242Nov 5, 2021 | CVSS7.8v3.1 | EPSS0.766% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-42699MEDIUM | AzeoTech DAQFactoryThe affected product is vulnerable to cookie information being transmitted as cleartext over HTTP. An attacker can capture network traffic, obtain the user’s cookie and take over the account. CWE-319Nov 5, 2021 | CVSS5.7v3.1 | EPSS0.48% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |