Vulnerabilities in Danfoss
14 resultsVexday analysis
A Danfoss apresenta 13 vulnerabilidades catalogadas, das quais 5 são críticas, mas nenhuma está sob ataque ativo no momento e nenhuma foi publicada nos últimos 90 dias, indicando risco estabilizado. A fraqueza dominante é exposição de informações (CWE-200), sugerindo foco em controles de acesso e vazamento de dados em seus produtos. O panorama atual não sinaliza ameaça imediata, embora o volume de críticas demande atenção contínua na gestão de patches.
CVE-2023-25911CRITICALAuthenticated OS Command Injection in Danfoss AK-EM100EPSS 2.3%CVE-2023-25915CRITICALAuthenticated Remote Command Execution in Danfoss AK-SM800AEPSS 1.0%CVE-2025-41451HIGHPost-Authentication OS Command Injection RCE in Danfoss AK-SM8xxA SeriesEPSS 0.9%CVE-2023-25914HIGHAuthneticated Path Traversal in Danfoss AK-SM800AEPSS 0.8%CVE-2023-22583CRITICALSQL Injection in Danfoss AK-EM100EPSS 0.8%CVE-2023-22586HIGHLocal File Inclusion in Danfoss AK-EM100EPSS 0.7%CVE-2023-25913HIGHAuthentication Bypass in Danfoss AK-SM800AEPSS 0.6%CVE-2023-25912MEDIUMWebreport disclosure to unauthorized actor in Danfoss AK-EM100EPSS 0.6%CVE-2023-22582CRITICALReflected Cross-Site Scripting in Danfoss AK-EM100EPSS 0.6%CVE-2023-22585CRITICALReflected Cross-Site Scripting in Danfoss AK-EM100EPSS 0.6%CVE-2023-22584HIGHCleartext credentials in Danfoss AK-EM100EPSS 0.5%CVE-2026-15203CRITICALDebug interfaces are accessible by default in Danfoss iC7 Automation SP, iC7 Marine and iC7 7Hybrid softwareEPSS 0.4%CVE-2025-41450HIGHAuthentication bypass with privileged access in Danfoss AK-SM 8xxA Series prior to version 4.2EPSS 0.3%CVE-2025-41452MEDIUMPost auth nginx configuration injection in Danfoss AK-SM8xxA SeriesEPSS 0.3%