Vulnerabilities > Endress

DATE CVE VULNERABILITY TITLE RISK
2024-09-10 CVE-2024-6596 Code Injection vulnerability in Endress products
An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.
network
low complexity
endress CWE-94
critical
9.8
2020-11-19 CVE-2020-12496 Information Exposure vulnerability in Endress products
Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) and Memograph M (Neutral/Private Label) (RSG45, ORSG45) with Firmware version V2.0.0 and above is prone to exposure of sensitive information to an unauthorized actor.
network
low complexity
endress CWE-200
6.5
2020-11-19 CVE-2020-12495 Improper Privilege Management vulnerability in Endress products
Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) with Firmware version prior to V2.0.0 is prone to improper privilege management.
network
low complexity
endress CWE-269
8.8
2018-09-07 CVE-2018-16059 Path Traversal vulnerability in Endress Wirelesshart Fieldgate Swg70 Firmware 3.00.07
Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename parameter.
network
low complexity
endress CWE-22
5.3