Vulnerabilities in ifm
7 resultsVexday analysis
A ifm apresenta um portfólio modesto de 7 vulnerabilidades catalogadas, com 4 delas classificadas como críticas, mas nenhuma sob exploração ativa conhecida. A fraqueza dominante é injeção de comando (CWE-78), típica de produtos de automação industrial, e a ausência de divulgações recentes sugere um risco estabilizado, embora as vulnerabilidades críticas existentes permaneçam relevantes para ambientes de produção.
CVE-2022-3485CRITICALWeak Password Recovery in ifm moneo applianceEPSS 0.9%CVE-2024-28748HIGHifm: Reading function in Smart PLC allows command injections EPSS 0.8%CVE-2024-28749HIGHifm: Writing file function in Smart PLC allows command injections EPSS 0.8%CVE-2024-28750HIGHifm: Deleting function in Smart PLC allows command injectionsEPSS 0.8%CVE-2024-28747CRITICALifm: Use of Hard-coded CredentialsEPSS 0.7%CVE-2024-28751CRITICALifm: Hardcoded telnet credentials in Smart PLCEPSS 0.6%CVE-2024-5404CRITICALifm: moneo prone to weak password recovery mechanism EPSS 0.5%