Products: 18
    Vulnerabilities: 12
    Known Exploited: 0
    4
    Critical Level Threats
    4
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2024-47945

    Predictable Session ID

    Last Modified: Nov 03, 2025
    Published: Oct 15, 2024

    CVE-2022-40633

    Rittal CMC III Improper Access Control

    Last Modified: Jan 17, 2025
    Published: Mar 02, 2023

    CVE-2021-40223

    Rittal CMC PU III Web management (version V3.11.00_2) fails to sanitize user input on several parameters of the configuration (User Configuration dialog, Task Configuration dialog and set logging filter dialog). This allows an attacker to backdoor the device with HTML and browser-interpreted content (such as JavaScript or other client-side scripts). The XSS payload will be triggered when the user accesses some specific sections of the application.

    Last Modified: Nov 21, 2024
    Published: Sep 09, 2021

    CVE-2021-40222

    Rittal CMC PU III Web management Version affected: V3.11.00_2. Version fixed: V3.17.10 is affected by a remote code execution vulnerablity. It is possible to introduce shell code to create a reverse shell in the PU-Hostname field of the TCP/IP Configuration dialog. Web application fails to sanitize user input on Network TCP/IP configuration page. This allows the attacker to inject commands as root on the device which will be executed once the data is received.

    Last Modified: Nov 21, 2024
    Published: Sep 09, 2021

    CVE-2019-19393

    The Web application on Rittal CMC PU III 7030.000 V3.00 V3.11.00_2 to V3.15.70_4 devices fails to sanitize user input on the system configurations page. This allows an attacker to backdoor the device with HTML and browser-interpreted content (such as JavaScript or other client-side scripts) as the content is always displayed after and before login. Persistent XSS allows an attacker to modify displayed content or to change the victim's information. Successful exploitation requires access to the web management interface, either with valid credentials or a hijacked session.

    Last Modified: Nov 21, 2024
    Published: Oct 01, 2020
    Items Per Page