ifm records
7 published records for vendor ifm.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-640 Weak Password Recovery Mechanism for Forgotten Password2
- CWE-798 Use of Hard-coded Credentials2
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2022-3485No exploit | Weak Password Recovery in ifm moneo applianceifm · moneo qha210 firmware · CWE-640 | Critical9.8 | — | 1.0% | Dec 12, 2022 |
39Monitor | CVE-2024-28747No exploit | ifm: Use of Hard-coded Credentialsifm · smart plc ac14xx firmware · CWE-798 | Critical9.8 | — | 0.7% | Jul 9, 2024 |
39Monitor | CVE-2024-5404No exploit | ifm: moneo prone to weak password recovery mechanismifm · moneo appliance qva200 · CWE-640 | Critical9.8 | — | 0.6% | Jun 3, 2024 |
36Monitor | CVE-2024-28751No exploit | ifm: Hardcoded telnet credentials in Smart PLCifm · smart plc ac14xx firmware · CWE-798 | Critical9.1 | — | 0.6% | Jul 9, 2024 |
28Monitor | CVE-2024-28749No exploit | ifm: Writing file function in Smart PLC allows command injectionsifm · smart plc ac14xx firmware · CWE-78 | High7.2 | — | 0.8% | Jul 9, 2024 |
28Monitor | CVE-2024-28748No exploit | ifm: Reading function in Smart PLC allows command injectionsifm · smart plc ac14xx firmware · CWE-78 | High7.2 | — | 0.8% | Jul 9, 2024 |
28Monitor | CVE-2024-28750No exploit | ifm: Deleting function in Smart PLC allows command injectionsifm · smart plc ac14xx firmware · CWE-78 | High7.2 | — | 0.8% | Jul 9, 2024 |
- CVE-2022-348539Monitor
Weak Password Recovery in ifm moneo appliance
CriticalCVSS 9.8No exploitEPSS 1%ifm · moneo qha210 firmwareDec 12, 2022
- CVE-2024-2874739Monitor
ifm: Use of Hard-coded Credentials
CriticalCVSS 9.8No exploitEPSS 1%ifm · smart plc ac14xx firmwareJul 9, 2024
- CVE-2024-540439Monitor
ifm: moneo prone to weak password recovery mechanism
CriticalCVSS 9.8No exploitEPSS 1%ifm · moneo appliance qva200Jun 3, 2024
- CVE-2024-2875136Monitor
ifm: Hardcoded telnet credentials in Smart PLC
CriticalCVSS 9.1No exploitEPSS 1%ifm · smart plc ac14xx firmwareJul 9, 2024
- CVE-2024-2874928Monitor
ifm: Writing file function in Smart PLC allows command injections
HighCVSS 7.2No exploitEPSS 1%ifm · smart plc ac14xx firmwareJul 9, 2024
- CVE-2024-2874828Monitor
ifm: Reading function in Smart PLC allows command injections
HighCVSS 7.2No exploitEPSS 1%ifm · smart plc ac14xx firmwareJul 9, 2024
- CVE-2024-2875028Monitor
ifm: Deleting function in Smart PLC allows command injections
HighCVSS 7.2No exploitEPSS 1%ifm · smart plc ac14xx firmwareJul 9, 2024