haascnc CVE Vulnerabilities & CVE List (3)

Products (CPE): — CVEs: 3

haascnc vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to haascnc, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 13 of 3 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2022-41636 Communication traffic involving "Ethernet Q Commands" service of Haas Controller version 100.20.000.1110 is transmitted in cleartext. This allows an attacker to obtain sensitive information being passed to and from the controller. [email protected] 9.1 0.10% 2022-10-28 2024-11-21
CVE-2022-2475 Haas Controller version 100.20.000.1110 has insufficient granularity of access control when using the "Ethernet Q Commands" service. Any user is able to write macros into registers outside of the authorized accessible range. This could allow a user to access privileged resources or resources out of context. [email protected] 9.8 0.15% 2022-10-28 2024-11-21
CVE-2022-2474 Authentication is currently unsupported in Haas Controller version 100.20.000.1110 when using the “Ethernet Q Commands” service, which allows any user on the same network segment as the controller (even while connected remotely) to access the service and write unauthorized macros to the device. [email protected] 9.8 0.17% 2022-10-28 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence