Vulnerabilities > Ovarro

DATE CVE VULNERABILITY TITLE RISK
2022-07-28 CVE-2021-22648 Incorrect Permission Assignment for Critical Resource vulnerability in Ovarro products
Ovarro TBox proprietary Modbus file access functions allow attackers to read, alter, or delete the configuration file.
network
low complexity
ovarro CWE-732
critical
9.8
2022-07-28 CVE-2021-22650 Path Traversal vulnerability in Ovarro products
An attacker may use TWinSoft and a malicious source project file (TPG) to extract files on machine executing Ovarro TWinSoft, which could lead to code execution.
network
low complexity
ovarro CWE-22
critical
9.8