arcinfo 漏洞與 CVE 列表(21)

產品(CPE): — CVE 數: 21

arcinfo 漏洞概覽

彙總 arcinfo 相關全部產品的 CVE 與安全漏洞情報,包括 CVSS、EPSS、公開時間與漏洞情報資料。

歷史漏洞主要涉及 路徑處理缺陷與緩衝區溢位 等問題,部分漏洞可能導致 檔案覆寫,並影響 生產負載與軟體部署 相關場景。

相關漏洞資料主要來源於公開漏洞披露與安全公告,可用於評估歷史漏洞暴露面與修補優先順序。

漏洞分布趨勢(近 24 個月)

顯示 12021 CVE 數
«« 第一頁 « 上一頁 第 1 / 2 頁 下一頁 »
CVE 摘要 來源 最高 CVSS EPSS % 公開時間 更新時間
CVE-2026-14868 The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of PcVue projects, all versions prior to 17.0.0, is not strong enough for the level of protection required. A local attacker could alter the existing configuration and ultimately gain privileged access to the PcVue application. 87c8e6ad-f0f5-4ca8-89e2-89f26d6ed932 8.4 0.06% 2026-07-07 2026-07-09
CVE-2026-14867 Credentials of built-in users are insecurely stored in the User directory of PcVue projects, all versions prior to 17.0.0. A local attacker could retrieve users’ credentials.  Active Directory accounts are not affected by this vulnerability. 87c8e6ad-f0f5-4ca8-89e2-89f26d6ed932 6.8 0.13% 2026-07-07 2026-07-09
CVE-2026-1698 A HTTP Host header attack vulnerability affects WebClient and the WebScheduler web apps of PcVue in version 15.0.0 through 16.3.3 included, allowing a remote attacker to inject harmful payloads that manipulate server-side behavior. This vulnerability only affects the endpoints /Authentication/ExternalLogin, /Authentication/AuthorizationCodeCallback and /Authentication/Logout of the WebClient and WebScheduler web apps. 87c8e6ad-f0f5-4ca8-89e2-89f26d6ed932 5.3 0.21% 2026-02-26 2026-07-09
CVE-2026-1697 The Secure and SameSite attribute are missing in the GraphicalData web services and WebClient web app of PcVue in version 12.0.0 through 16.3.3 included. 87c8e6ad-f0f5-4ca8-89e2-89f26d6ed932 5.3 0.12% 2026-02-26 2026-07-09
CVE-2026-1696 Some HTTP security headers are not properly set by the web server when sending responses to the client application. 87c8e6ad-f0f5-4ca8-89e2-89f26d6ed932 2.3 0.14% 2026-02-26 2026-07-09
CVE-2026-1695 An XSS vulnerability affects the OAuth web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote attacker to trick a legitimate user into loading content from another site upon unsuccessful user authentication on an unknown application (unknown client_id). This vulnerability only affects the error page of the OAuth server. 87c8e6ad-f0f5-4ca8-89e2-89f26d6ed932 5.3 0.21% 2026-02-26 2026-07-09
CVE-2026-1694 HTTP headers are added by the default configuration of IIS and ASP.net, and are not removed at the deployment phase of the webservices used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It unnecessarily exposes sensitive information about the server configuration. 87c8e6ad-f0f5-4ca8-89e2-89f26d6ed932 2.3 0.17% 2026-02-26 2026-07-09
CVE-2026-1693 The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in version 12.0.0 through 16.3.3 included despite being deprecated. It might allow a remote attacker to steal user credentials. 87c8e6ad-f0f5-4ca8-89e2-89f26d6ed932 5.3 0.31% 2026-02-26 2026-07-09
CVE-2026-1692 A missing origin validation in WebSockets vulnerability affects the GraphicalData web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote attacker to lure a successfully authenticated user to a malicious website. This vulnerability only affects the following two endpoints: GraphicalData/js/signalR/connect and GraphicalData/js/signalR/reconnect. 87c8e6ad-f0f5-4ca8-89e2-89f26d6ed932 5.3 0.11% 2026-02-26 2026-07-09
CVE-2025-9999 Some payload elements of the messages sent between two stations in a networking architecture are not properly checked on the receiving station allowing an attacker to execute unauthorized commands in the application. 87c8e6ad-f0f5-4ca8-89e2-89f26d6ed932 7.6 0.15% 2025-09-05 2026-06-17
CVE-2025-9998 The sequence of packets received by a Networking server are not correctly checked. An attacker could exploit this vulnerability to send specially crafted messages to force the application to stop. 87c8e6ad-f0f5-4ca8-89e2-89f26d6ed932 6.0 0.25% 2025-09-05 2026-06-17
CVE-2022-4312 A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3. This could allow an unauthorized user with access the email and short messaging service (SMS) accounts configuration files to discover the associated simple mail transfer protocol (SMTP) account credentials and the SIM card PIN code. Successful exploitation of this vulnerability could allow an unauthorized user access to the underlying email account and SIM card. [email protected] 5.5 0.05% 2022-12-12 2026-07-09
CVE-2022-4311 An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This could allow a user with access to the log files to discover connection strings of data sources configured for the DbConnect, which could include credentials. Successful exploitation of this vulnerability could allow other users unauthorized access to the underlying data sources. [email protected] 4.7 0.33% 2022-12-12 2026-07-09
CVE-2022-2569 The affected device stores sensitive information in cleartext, which may allow an authenticated user to access session data stored in the OAuth database belonging to legitimate users [email protected] 5.5 0.05% 2022-08-24 2026-07-09
CVE-2020-26869 ARC Informatique PcVue prior to version 12.0.17 is vulnerable to information exposure, allowing unauthorized users to access session data of legitimate users. This issue also affects third-party systems based on the Web Services Toolkit. [email protected] 7.5 1.65% 2020-10-12 2026-07-09
CVE-2020-26868 ARC Informatique PcVue prior to version 12.0.17 is vulnerable to a denial-of-service attack due to the ability of an unauthorized user to modify information used to validate messages sent by legitimate web clients. This issue also affects third-party systems based on the Web Services Toolkit. [email protected] 7.5 2.11% 2020-10-12 2026-07-09
CVE-2020-26867 ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code on the web and mobile back-end server. [email protected] 9.8 3.72% 2020-10-12 2026-07-09
CVE-2011-4045 Buffer overflow in an unspecified ActiveX control in aipgctl.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to cause a denial of service via a crafted HTML document. [email protected] 4.3 3.70% 2012-04-02 2026-07-09
CVE-2011-4044 An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to modify files via calls to unknown methods. [email protected] 5.8 26.73% 2012-04-02 2026-07-09
CVE-2011-4043 Integer overflow in an unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute arbitrary code via a large value for an integer parameter, leading to a buffer overflow. [email protected] 9.3 7.44% 2012-04-02 2026-07-09
«« 第一頁 « 上一頁 第 1 / 2 頁 下一頁 »
cvelogic Threat Intelligence