Network and edge
Industrial and building systems
PLCs, industrial control (SCADA), building automation and physical access control.
For example: Siemens, Rockwell, Schneider Electric, Unitronics.
-
5 vulnerabilities added in the last 12 months
-
17 exploited vulnerabilities in the catalog, in total
-
0 added in the last 30 days
Affected brands
In alphabetical order, with their number of vulnerabilities in this category.
- Audinate 1 vulnerability
- CONTEC (SolarView) 1 vulnerability
- Crestron 1 vulnerability
- Delta Electronics 1 vulnerability
- InduSoft 1 vulnerability
- KNX Association 1 vulnerability · 1 in the last 12 months
- Lantronix 1 vulnerability · 1 in the last 12 months
- Nice (Linear) 1 vulnerability
- OpenPLC 2 vulnerabilities · 2 in the last 12 months
- Rockwell Automation 1 vulnerability · 1 in the last 12 months
- Schneider Electric 1 vulnerability
- Siemens 1 vulnerability
- Sunhillo 1 vulnerability
- Trihedral 1 vulnerability
- Unitronics 1 vulnerability
- ZKTeco 1 vulnerability
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
See also
- Home and small-office routers, cameras and IoT 90 vulnerabilities
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.
Rank 1Lantronix EDS5000
CVE-2025-67038Lantronix EDS5000 Code Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jun 23, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 2Rockwell Automation Logix (PLCs, Studio 5000)
CVE-2021-22681CVE from 2021, added in 2026
Rockwell Multiple Products Insufficient Protected Credentials Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Mar 5, 2026
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 3OpenPLC ScadaBR
CVE-2021-26828CVE from 2021, added in 2025
OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Dec 3, 2025
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 4KNX Association Protocole KNX
CVE-2023-4346CVE from 2023, added in 2026
KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jul 15, 2026
- CISA deadline
- 14 days
- CVSS severity
- 7.5 (high)
Rank 5OpenPLC ScadaBR
CVE-2021-26829CVE from 2021, added in 2025
OpenPLC ScadaBR Cross-site Scripting Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Nov 28, 2025
- CISA deadline
- 21 days
- CVSS severity
- 5.4 (medium)
Rank 6Nice (Linear) Linear eMerge E3-Series
CVE-2019-7256CVE from 2019, added in 2024
Nice Linear eMerge E3-Series OS Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 7Sunhillo SureLine
CVE-2021-36380CVE from 2021, added in 2024
Sunhillo SureLine OS Command Injection Vulnerablity
Added more than a year ago: ranked by severity.
- Added
- Mar 5, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 8Unitronics Vision PLC and HMI
CVE-2023-6448Unitronics Vision PLC and HMI Insecure Default Password Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Dec 11, 2023
- CISA deadline
- 7 days
- CVSS severity
- 9.8 (critical)
Rank 9CONTEC (SolarView) SolarView Compact
CVE-2022-29303SolarView Compact Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 13, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 10InduSoft Web Studio
CVE-2014-0780CVE from 2014, added in 2022
InduSoft Web Studio NTWebServer Directory Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 15, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Show 5 more vulnerabilities
Rank 11Crestron AirMedia (AM-100, AM-101)
CVE-2019-3929CVE from 2019, added in 2022
Crestron Multiple Products Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 15, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 12Audinate Dante Discovery
CVE-2022-23748CVE from 2022, added in 2025
Dante Discovery Process Control Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 6, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.8 (high)
Rank 13ZKTeco BioTime
CVE-2023-38950CVE from 2023, added in 2025
ZKTeco BioTime Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 19, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 14Trihedral VTScada (formerly VTS)
CVE-2016-4523CVE from 2016, added in 2022
Trihedral VTScada (formerly VTS) Denial-of-Service Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 15, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 15Siemens SIMATIC CP
CVE-2016-8562CVE from 2016, added in 2022
Siemens SIMATIC CP 1543-1 Improper Privilege Management Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
End of life: remove
These products are no longer supported: no patch is coming. Remove them or isolate them from the network.
Delta Electronics DOPSoft 2
CVE-2021-38406End of life
Delta Electronics DOPSoft 2 Improper Input Validation Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Aug 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.8 (high)
Schneider Electric U.motion Builder
CVE-2018-7841End of lifeCVE from 2018, added in 2022
Schneider Electric U.motion Builder SQL Injection Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Apr 15, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Follow and verify
Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.