Products: 12
    Vulnerabilities: 11
    Known Exploited: 0
    1
    Critical Level Threats
    8
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2023-3643

    Boss Mini document file inclusion

    Last Modified: Nov 21, 2024
    Published: Jul 12, 2023

    CVE-2020-18329

    An issue was discovered in Rehau devices that use a pCOWeb card BIOS v6.27, BOOT v5.00, web version v2.2, allows attackers to gain full unauthenticated access to the configuration and service interface.

    Last Modified: Apr 02, 2025
    Published: Jan 25, 2023

    CVE-2022-34827

    Carel Boss Mini 1.5.0 has Improper Access Control.

    Last Modified: Apr 29, 2025
    Published: Nov 18, 2022

    CVE-2022-37122

    Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 suffers from an unauthenticated arbitrary file disclosure vulnerability. Input passed through the 'file' GET parameter through the 'logdownload.cgi' Bash script is not properly verified before being used to download log files. This can be exploited to disclose the contents of arbitrary and sensitive files via directory traversal attacks.

    Last Modified: Nov 21, 2024
    Published: Aug 31, 2022

    CVE-2019-13553

    Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems is configured using hard-coded credentials. These credentials could allow attackers to influence the primary operations of the affected systems, namely turning the cooling unit on and off and setting the temperature set point.

    Last Modified: Nov 21, 2024
    Published: Oct 25, 2019
    Items Per Page
    Carel Vulnerabilities & Security CVEs | CVE-DB