CVE Tools

Ics-cert

52 CVEs tracked since 2018. Since Mar 2018, none of them reached CISA KEV.

Ics-cert CVEs per month

Mar 2018 to Feb 2019. Point at a month, or focus the strip and use the arrow keys.
Ics-cert CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2018-0380
2018-04null or fewer
2018-05null or fewer
2018-06100
2018-07null or fewer
2018-08120
2018-09null or fewer
2018-10null or fewer
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02220

Products

The products that kept showing up in Ics-cert's monthly top three, with their CVEs summed over those months.

  1. Lcds Laquis Scada71 month
  2. Omron Cx-supervisor61 month
  3. Netcomm Wireless G Lte Light Industrial M2M Router (Nwl-25) With Firmware 2.0.29.11 and Prior.41 month
  4. Intellivue Patient Monitors, Avalon Fetal/maternal Monitors31 month
  5. PR100088 Modbus Gateway31 month
  6. Wecon Levistudiou31 month
  7. Abb Ip Gateway21 month
  8. Beckhoff Twincat21 month
  9. Cncsoft With Screeneditor21 month
  10. Deltav21 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Ics-cert.

  1. CVE-2018-17937gpsd versions 2.90 to 3.17 and microjson versions 1.0 to 1.3, an open source project, allow a stack-based buffer overflow, which may allow remote attackers to execute arbitrary code on embedded pla...8.8
  2. CVE-2019-6559Moxa IKS and EDS allow remote authenticated users to cause a denial of service via a specially crafted packet, which may cause the switch to crash.6.5
  3. CVE-2019-6565Moxa IKS and EDS fails to properly validate user input, giving unauthenticated and authenticated attackers the ability to perform XSS attacks, which may be used to send a malicious script.6.1
  4. CVE-2019-6557Several buffer overflow vulnerabilities have been identified in Moxa IKS and EDS, which may allow remote code execution.9.8
  5. CVE-2019-6524Moxa IKS and EDS do not implement sufficient measures to prevent multiple failed authentication attempts, which may allow an attacker to discover passwords via brute force attack.9.8
  6. CVE-2019-6520Moxa IKS and EDS does not properly check authority on server side, which results in a read-only user being able to perform arbitrary configuration changes.7.5
  7. CVE-2019-6518Moxa IKS and EDS store plaintext passwords, which may allow sensitive information to be read by someone with access to the device.7.5
  8. CVE-2019-6563Moxa IKS and EDS generate a predictable cookie calculated with an MD5 hash, allowing an attacker to capture the administrator's password, which could lead to a full compromise of the device.9.8
  9. CVE-2019-6522Moxa IKS and EDS fails to properly check array bounds which may allow an attacker to read device memory on arbitrary addresses, and may allow an attacker to retrieve sensitive data or cause device ...9.1
  10. CVE-2019-6561Cross-site request forgery has been identified in Moxa IKS and EDS, which may allow for the execution of unauthorized actions on the device.8.8
  11. CVE-2019-6528PSI GridConnect GmbH Telecontrol Gateway and Smart Telecontrol Unit family, IEC104 Security Proxy versions Telecontrol Gateway 3G Versions 4.2.21, 5.0.27, 5.1.19, 6.0.16 and prior, and Telecontrol ...8.8
  12. CVE-2019-6547Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.84 and prior. An out-of-bounds read vulnerability may cause the software to crash due to lacking user input validation for pro...5.5
  13. CVE-2019-6551Pangea Communications Internet FAX ATA all Versions 3.1.8 and prior allow an attacker to bypass user authentication using a specially crafted URL to cause the device to reboot, which may be used to...7.5
  14. CVE-2019-6555Cscape, 9.80 SP4 and prior. An improper input validation vulnerability may be exploited by processing specially crafted POC files. This may allow an attacker to read confidential information and re...7.8
  15. CVE-2018-19008The TextEditor 2.0 in ABB CP400 Panel Builder versions 2.0.7.05 and earlier contain a vulnerability in the file parser of the Text Editor wherein the application doesn't properly prevent the insert...7.8

The record

Peak rank
#21 in Feb 2019
Busiest month shown
Feb 2019, 22 CVEs
Months with a KEV entry
0 since Mar 2018
Monthly snapshots
4 since 2018
Ics-cert's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store