Skip to content

Products › Network and edge

Network and edge

Industrial and building systems

PLCs, industrial control (SCADA), building automation and physical access control.

For example: Siemens, Rockwell, Schneider Electric, Unitronics.

Category RSS feed

Affected brands

In alphabetical order, with their number of vulnerabilities in this category.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

See also

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.

  1. Rank 1

    Lantronix EDS5000CVE-2025-67038

    Lantronix EDS5000 Code Injection Vulnerability

    CVSS severity 9.8critical

    Added Jun 23, 2026

  2. Rank 2

    Rockwell Automation Logix (PLCs, Studio 5000)CVE-2021-22681

    Rockwell Multiple Products Insufficient Protected Credentials Vulnerability

    CVE from 2021, added in 2026

    CVSS severity 9.8critical

    Added Mar 5, 2026

  3. Rank 3

    OpenPLC ScadaBRCVE-2021-26828

    OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability

    CVE from 2021, added in 2025

    CVSS severity 8.8high

    Added Dec 3, 2025

  4. Rank 4

    KNX Association Protocole KNXCVE-2023-4346

    KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability

    CVE from 2023, added in 2026

    CVSS severity 7.5high

    Added Jul 15, 2026

  5. Rank 5

    OpenPLC ScadaBRCVE-2021-26829

    OpenPLC ScadaBR Cross-site Scripting Vulnerability

    CVE from 2021, added in 2025

    CVSS severity 5.4medium

    Added Nov 28, 2025

  6. Rank 6

    Nice (Linear) Linear eMerge E3-SeriesCVE-2019-7256

    Nice Linear eMerge E3-Series OS Command Injection Vulnerability

    CVE from 2019, added in 2024

    CVSS severity 9.8critical

    Added Mar 25, 2024

  7. Rank 7

    Sunhillo SureLineCVE-2021-36380

    Sunhillo SureLine OS Command Injection Vulnerablity

    CVE from 2021, added in 2024

    CVSS severity 9.8critical

    Added Mar 5, 2024

  8. Rank 8

    Unitronics Vision PLC and HMICVE-2023-6448

    Unitronics Vision PLC and HMI Insecure Default Password Vulnerability

    CVSS severity 9.8critical

    Added Dec 11, 2023

  9. Rank 9

    CONTEC (SolarView) SolarView CompactCVE-2022-29303

    SolarView Compact Command Injection Vulnerability

    CVSS severity 9.8critical

    Added Jul 13, 2023

  10. Rank 10

    InduSoft Web StudioCVE-2014-0780

    InduSoft Web Studio NTWebServer Directory Traversal Vulnerability

    CVE from 2014, added in 2022

    CVSS severity 9.8critical

    Added Apr 15, 2022

Show 5 more vulnerabilities
  1. Rank 11

    Crestron AirMedia (AM-100, AM-101)CVE-2019-3929

    Crestron Multiple Products Command Injection Vulnerability

    CVE from 2019, added in 2022

    CVSS severity 9.8critical

    Added Apr 15, 2022

  2. Rank 12

    Audinate Dante DiscoveryCVE-2022-23748

    Dante Discovery Process Control Vulnerability

    CVE from 2022, added in 2025

    CVSS severity 7.8high

    Added Feb 6, 2025

  3. Rank 13

    ZKTeco BioTimeCVE-2023-38950

    ZKTeco BioTime Path Traversal Vulnerability

    CVE from 2023, added in 2025

    CVSS severity 7.5high

    Added May 19, 2025

  4. Rank 14

    Trihedral VTScada (formerly VTS)CVE-2016-4523

    Trihedral VTScada (formerly VTS) Denial-of-Service Vulnerability

    CVE from 2016, added in 2022

    CVSS severity 7.5high

    Added Apr 15, 2022

  5. Rank 15

    Siemens SIMATIC CPCVE-2016-8562

    Siemens SIMATIC CP 1543-1 Improper Privilege Management Vulnerability

    CVE from 2016, added in 2022

    CVSS severity 7.5high

    Added Mar 3, 2022

End of life: remove

These products are no longer supported: no patch is coming. Remove them or isolate them from the network.

  1. Delta Electronics DOPSoft 2CVE-2021-38406

    Delta Electronics DOPSoft 2 Improper Input Validation Vulnerability

    End of life

    CVSS severity 7.8high

    Added Aug 25, 2022

  2. Schneider Electric U.motion BuilderCVE-2018-7841

    Schneider Electric U.motion Builder SQL Injection Vulnerability

    End of lifeCVE from 2018, added in 2022

    CVSS severity 9.8critical

    Added Apr 15, 2022

Follow and verify

Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.