Danfoss records
10 published records for vendor danfoss.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-20 Improper Input Validation1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-312 Cleartext Storage of Sensitive Information1
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-22583No exploit | SQL Injection in Danfoss AK-EM100danfoss · ak-em100 firmware · CWE-89 | Critical9.8 | — | 0.8% | Jun 11, 2023 |
36Monitor | CVE-2023-25911No exploit | Authenticated OS Command Injection in Danfoss AK-EM100danfoss · ak-em100 firmware · CWE-77 | High8.8 | — | 2.3% | Jun 11, 2023 |
35Monitor | CVE-2023-25915No exploit | Authenticated Remote Command Execution in Danfoss AK-SM800Adanfoss · ak-sm 800a firmware · CWE-20 | High8.8 | — | 1.0% | Aug 21, 2023 |
35Monitor | CVE-2023-25914No exploit | Authneticated Path Traversal in Danfoss AK-SM800Adanfoss · ak-sm 800a firmware · CWE-22 | High8.8 | — | 0.8% | Aug 21, 2023 |
30Monitor | CVE-2023-22586No exploit | Local File Inclusion in Danfoss AK-EM100danfoss · ak-em100 firmware · CWE-200 | High7.5 | — | 0.7% | Jun 11, 2023 |
30Monitor | CVE-2023-25913No exploit | Authentication Bypass in Danfoss AK-SM800Adanfoss · ak-sm 800a firmware · CWE-200 | High7.5 | — | 0.6% | Aug 21, 2023 |
30Monitor | CVE-2023-22584No exploit | Cleartext credentials in Danfoss AK-EM100danfoss · ak-em100 firmware · CWE-312 | High7.5 | — | 0.5% | Jun 11, 2023 |
24Monitor | CVE-2023-22582No exploit | Reflected Cross-Site Scripting in Danfoss AK-EM100danfoss · ak-em100 firmware · CWE-79 | Medium6.1 | — | 0.6% | Jun 11, 2023 |
24Monitor | CVE-2023-22585No exploit | Reflected Cross-Site Scripting in Danfoss AK-EM100danfoss · ak-em100 firmware · CWE-79 | Medium6.1 | — | 0.6% | Jun 11, 2023 |
21Monitor | CVE-2023-25912No exploit | Webreport disclosure to unauthorized actor in Danfoss AK-EM100danfoss · ak-em100 firmware · CWE-200 | Medium5.3 | — | 0.6% | Jun 11, 2023 |
- CVE-2023-2258339Monitor
SQL Injection in Danfoss AK-EM100
CriticalCVSS 9.8No exploitEPSS 1%danfoss · ak-em100 firmwareJun 11, 2023
- CVE-2023-2591136Monitor
Authenticated OS Command Injection in Danfoss AK-EM100
HighCVSS 8.8No exploitEPSS 2%danfoss · ak-em100 firmwareJun 11, 2023
- CVE-2023-2591535Monitor
Authenticated Remote Command Execution in Danfoss AK-SM800A
HighCVSS 8.8No exploitEPSS 1%danfoss · ak-sm 800a firmwareAug 21, 2023
- CVE-2023-2591435Monitor
Authneticated Path Traversal in Danfoss AK-SM800A
HighCVSS 8.8No exploitEPSS 1%danfoss · ak-sm 800a firmwareAug 21, 2023
- CVE-2023-2258630Monitor
Local File Inclusion in Danfoss AK-EM100
HighCVSS 7.5No exploitEPSS 1%danfoss · ak-em100 firmwareJun 11, 2023
- CVE-2023-2591330Monitor
Authentication Bypass in Danfoss AK-SM800A
HighCVSS 7.5No exploitEPSS 1%danfoss · ak-sm 800a firmwareAug 21, 2023
- CVE-2023-2258430Monitor
Cleartext credentials in Danfoss AK-EM100
HighCVSS 7.5No exploitEPSS 0%danfoss · ak-em100 firmwareJun 11, 2023
- CVE-2023-2258224Monitor
Reflected Cross-Site Scripting in Danfoss AK-EM100
MediumCVSS 6.1No exploitEPSS 1%danfoss · ak-em100 firmwareJun 11, 2023
- CVE-2023-2258524Monitor
Reflected Cross-Site Scripting in Danfoss AK-EM100
MediumCVSS 6.1No exploitEPSS 1%danfoss · ak-em100 firmwareJun 11, 2023
- CVE-2023-2591221Monitor
Webreport disclosure to unauthorized actor in Danfoss AK-EM100
MediumCVSS 5.3No exploitEPSS 1%danfoss · ak-em100 firmwareJun 11, 2023