xylem records
7 published records for vendor xylem.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-23 Relative Path Traversal1
- CWE-256 Plaintext Storage of a Password1
- CWE-319 Cleartext Transmission of Sensitive Information1
- CWE-321 Use of Hard-coded Cryptographic Key1
- CWE-427 Uncontrolled Search Path Element1
- CWE-798 Use of Hard-coded Credentials1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2020-25176No exploit | Rockwell Automation ISaGRAF5 Runtime Relative Path Traversalschneider-electric · easergy t300 firmware · CWE-23 | Critical9.8 | — | 6.4% | Mar 18, 2022 |
40Plan | CVE-2021-41063No exploit | SQL injection vulnerability was discovered in Aanderaa GeoView Webservice prior to version 2.1.3 that could allow an unauthenticated attackexylem · aanderaa geoview · CWE-89 | Critical9.8 | — | 2.0% | Dec 8, 2021 |
36Monitor | CVE-2020-25178No exploit | Rockwell Automation ISaGRAF5 Runtime Cleartext Transmission of Sensitive Informationschneider-electric · easergy t300 firmware · CWE-319 | High8.8 | — | 1.7% | Mar 18, 2022 |
35Monitor | CVE-2021-42833No exploit | Use of hardcoded credentials impacting AquaView versions 1.60, 7.x, 8.xxylem · aquaview · CWE-798 | High8.8 | — | 0.2% | Feb 7, 2022 |
26Monitor | CVE-2020-25180No exploit | Rockwell Automation ISaGRAF5 Runtime Use of Hard-coded Cryptographic Keyschneider-electric · easergy t300 firmware · CWE-321 | Medium6.5 | — | 1.2% | Mar 18, 2022 |
26Monitor | CVE-2020-25182No exploit | Rockwell Automation ISaGRAF5 Runtime Uncontrolled Search Path Elementschneider-electric · easergy t300 firmware · CWE-427 | Medium6.7 | — | 0.4% | Mar 18, 2022 |
22Monitor | CVE-2020-25184No exploit | Rockwell Automation ISaGRAF5 Runtime Unprotected Storage of Credentialsschneider-electric · easergy t300 firmware · CWE-256 | Medium5.5 | — | 0.4% | Mar 18, 2022 |
- CVE-2020-2517641Plan
Rockwell Automation ISaGRAF5 Runtime Relative Path Traversal
CriticalCVSS 9.8No exploitEPSS 6%schneider-electric · easergy t300 firmwareMar 18, 2022
- CVE-2021-4106340Plan
SQL injection vulnerability was discovered in Aanderaa GeoView Webservice prior to version 2.1.3 that could allow an unauthenticated attacke
CriticalCVSS 9.8No exploitEPSS 2%xylem · aanderaa geoviewDec 8, 2021
- CVE-2020-2517836Monitor
Rockwell Automation ISaGRAF5 Runtime Cleartext Transmission of Sensitive Information
HighCVSS 8.8No exploitEPSS 2%schneider-electric · easergy t300 firmwareMar 18, 2022
- CVE-2021-4283335Monitor
Use of hardcoded credentials impacting AquaView versions 1.60, 7.x, 8.x
HighCVSS 8.8No exploitEPSS 0%xylem · aquaviewFeb 7, 2022
- CVE-2020-2518026Monitor
Rockwell Automation ISaGRAF5 Runtime Use of Hard-coded Cryptographic Key
MediumCVSS 6.5No exploitEPSS 1%schneider-electric · easergy t300 firmwareMar 18, 2022
- CVE-2020-2518226Monitor
Rockwell Automation ISaGRAF5 Runtime Uncontrolled Search Path Element
MediumCVSS 6.7No exploitEPSS 0%schneider-electric · easergy t300 firmwareMar 18, 2022
- CVE-2020-2518422Monitor
Rockwell Automation ISaGRAF5 Runtime Unprotected Storage of Credentials
MediumCVSS 5.5No exploitEPSS 0%schneider-electric · easergy t300 firmwareMar 18, 2022