Skip to content
Noroxi

OpenC3 records

15 published records for vendor openc3.

All records

15 records
  • A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary

    CriticalCVSS 9.8No exploitEPSS 1%

    openc3 · cosmosJun 13, 2025

  • OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.

    CriticalCVSS 9.8No exploitEPSS 1%

    openc3 · cosmosJun 13, 2025

  • Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack.

    CriticalCVSS 9.8No exploitEPSS 1%

    openc3 · cosmosJun 13, 2025

  • OpenC3 COSMOS: SQL Injection in QuestDB Time-Series Data Base

    CriticalCVSS 9.6No exploitEPSS 0%

    openc3 · cosmosMay 4, 2026

  • An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.

    CriticalCVSS 9.1No exploitEPSS 1%

    openc3 · cosmosJun 13, 2025

  • OpenC3 COSMOS: Administrative Actions via the Script Runner Tool

    HighCVSS 8.1No exploitEPSS 0%

    openc3 · cosmosMay 4, 2026

  • OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence

    HighCVSS 8.1No exploitEPSS 0%

    openc3 · cosmosMay 4, 2026

  • An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.

    HighCVSS 7.5No exploitEPSS 1%

    openc3 · cosmosJun 13, 2025

  • A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all conta

    HighCVSS 7.5No exploitEPSS 1%

    openc3 · cosmosJun 13, 2025

  • A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via inje

    MediumCVSS 6.1No exploitEPSS 0%

    openc3 · cosmosJun 13, 2025

  • OpenC3 COSMOS allows a path traversal via screen controller (`GHSL-2024-127`)

    MediumCVSS 5.3No exploitEPSS 1%

    openc3 · cosmosOct 2, 2024

  • OpenC3 COSMOS vulnerable to cross-site scripting in Login functionality (`GHSL-2024-128`)

    MediumCVSS 5.1No exploitEPSS 0%

    openc3 · cosmosOct 2, 2024

  • OpenC3 COSMOS uses clear text storage of password/token (`GHSL-2024-129`)

    MediumCVSS 4.8No exploitEPSS 0%

    openc3 · cosmosOct 2, 2024

  • OpenC3 COSMOS: Self-XSS in the Command Sender

    MediumCVSS 4.6No exploitEPSS 0%

    openc3 · cosmosMay 4, 2026

  • OpenC3 COSMOS: Arbitrary write to plugins directory via path-traversed config filenames

    MediumCVSS 4.3No exploitEPSS 0%

    openc3 · cosmosMay 4, 2026