danfoss CVE Vulnerabilities & CVE List (10)

Products (CPE): — CVEs: 10

danfoss vulnerability overview

Aggregates CVE and security vulnerability intelligence across all danfoss-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk cross-site scripting, vendor risk sql injection, and vendor risk input validation; exposure may include vendor impact session compromise in vendor surface production workloads contexts.

Vulnerability distribution trend (last 24 months)

Showing 110 of 10 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2023-25915 Due to improper input validation, an authenticated remote attacker could execute arbitrary commands on the target system. [email protected] 9.9 0.56% 2023-08-21 2025-01-17
CVE-2023-25914 Due to improper restriction, authenticated attackers could retrieve and read system files of the underlying server through the XML interface. The information that can be read can lead to a full system compromise. [email protected] 8.8 0.18% 2023-08-21 2025-01-17
CVE-2023-25913 Because of an authentication flaw an attacker would be capable of generating a web report that discloses sensitive information such as internal IP addresses, usernames, store names and other sensitive information. [email protected] 7.5 0.08% 2023-08-21 2024-11-21
CVE-2023-25912 The webreport generation feature in the Danfoss AK-EM100 allows an unauthorized actor to generate a web report that discloses sensitive information such as the internal IP address, usernames and internal device values. [email protected] 5.3 0.10% 2023-06-11 2024-11-21
CVE-2023-25911 The Danfoss AK-EM100 web applications allow for an authenticated user to perform OS command injection through the web application parameters. [email protected] 9.9 0.66% 2023-06-11 2025-01-17
CVE-2023-22586 The Danfoss AK-EM100 web applications allow for Local File Inclusion in the file parameter. [email protected] 7.7 0.10% 2023-06-11 2024-11-21
CVE-2023-22585 The Danfoss AK-EM100 web applications allow for Reflected Cross-Site Scripting in the title parameter. [email protected] 9.0 0.10% 2023-06-11 2024-11-21
CVE-2023-22584 The Danfoss AK-EM100 stores login credentials in cleartext. [email protected] 7.5 0.06% 2023-06-11 2024-11-21
CVE-2023-22583 The Danfoss AK-EM100 web forms allow for SQL injection in the login forms. [email protected] 10.0 0.07% 2023-06-11 2024-11-21
CVE-2023-22582 The Danfoss AK-EM100 web applications allow for Reflected Cross-Site Scripting. [email protected] 9.0 0.10% 2023-06-11 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence