Skip to content
English

Products › Network and edge

Network and edge

Industrial and building systems

PLCs, industrial control (SCADA), building automation and physical access control.

For example: Siemens, Rockwell, Schneider Electric, Unitronics.

Category RSS feed

Affected brands

In alphabetical order, with their number of vulnerabilities in this category.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

See also

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.

  1. Rank 1Lantronix EDS5000

    CVE-2025-67038

    Lantronix EDS5000 Code Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 23, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  2. Rank 2Rockwell Automation Logix (PLCs, Studio 5000)

    CVE-2021-22681

    CVE from 2021, added in 2026

    Rockwell Multiple Products Insufficient Protected Credentials Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 5, 2026
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  3. Rank 3OpenPLC ScadaBR

    CVE-2021-26828

    CVE from 2021, added in 2025

    OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 3, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  4. Rank 4KNX Association Protocole KNX

    CVE-2023-4346

    CVE from 2023, added in 2026

    KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 15, 2026
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  5. Rank 5OpenPLC ScadaBR

    CVE-2021-26829

    CVE from 2021, added in 2025

    OpenPLC ScadaBR Cross-site Scripting Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Nov 28, 2025
    CISA deadline
    21 days
    CVSS severity
    5.4 (medium)
  6. Rank 6Nice (Linear) Linear eMerge E3-Series

    CVE-2019-7256

    CVE from 2019, added in 2024

    Nice Linear eMerge E3-Series OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  7. Rank 7Sunhillo SureLine

    CVE-2021-36380

    CVE from 2021, added in 2024

    Sunhillo SureLine OS Command Injection Vulnerablity

    Added more than a year ago: ranked by severity.

    Added
    Mar 5, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  8. Rank 8Unitronics Vision PLC and HMI

    CVE-2023-6448

    Unitronics Vision PLC and HMI Insecure Default Password Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 11, 2023
    CISA deadline
    7 days
    CVSS severity
    9.8 (critical)
  9. Rank 9CONTEC (SolarView) SolarView Compact

    CVE-2022-29303

    SolarView Compact Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 13, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  10. Rank 10InduSoft Web Studio

    CVE-2014-0780

    CVE from 2014, added in 2022

    InduSoft Web Studio NTWebServer Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 15, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
Show 5 more vulnerabilities
  1. Rank 11Crestron AirMedia (AM-100, AM-101)

    CVE-2019-3929

    CVE from 2019, added in 2022

    Crestron Multiple Products Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 15, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  2. Rank 12Audinate Dante Discovery

    CVE-2022-23748

    CVE from 2022, added in 2025

    Dante Discovery Process Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 6, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  3. Rank 13ZKTeco BioTime

    CVE-2023-38950

    CVE from 2023, added in 2025

    ZKTeco BioTime Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 19, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  4. Rank 14Trihedral VTScada (formerly VTS)

    CVE-2016-4523

    CVE from 2016, added in 2022

    Trihedral VTScada (formerly VTS) Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  5. Rank 15Siemens SIMATIC CP

    CVE-2016-8562

    CVE from 2016, added in 2022

    Siemens SIMATIC CP 1543-1 Improper Privilege Management Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)

End of life: remove

These products are no longer supported: no patch is coming. Remove them or isolate them from the network.

  1. Delta Electronics DOPSoft 2

    CVE-2021-38406

    End of life

    Delta Electronics DOPSoft 2 Improper Input Validation Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Aug 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  2. Schneider Electric U.motion Builder

    CVE-2018-7841

    End of lifeCVE from 2018, added in 2022

    Schneider Electric U.motion Builder SQL Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 15, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)

Follow and verify

Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.