目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

Carlo Gavazzi 厂商漏洞列表 / CVE 中文分析 12

Carlo Gavazzi 厂商相关 12 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。

Carlo Gavazzi 是工业自动化控制设备制造商,专注于传感器、控制器和能源管理解决方案。其产品常见漏洞包括远程代码执行、权限绕过和缓冲区溢出,主要源于未经验证的输入处理和默认凭证问题。历史上多次因固件更新不及时导致漏洞被利用,2021年曾曝出多个设备存在硬编码后门风险,引发工业控制系统安全社区广泛关注。

CVE IDタイトルCVSS深刻度公開日
CVE-2017-20184 Carlo Gavazzi Powersoft prone to Path Traversal — PowersoftCWE-22 7.5 High2023-05-04
CVE-2022-28816 Reflected XSS in Carlo Gavazzi UWP 3.0 — UWP 3.0 Monitoring Gateway and ControllerCWE-79 6.1 Medium2022-09-28
CVE-2022-28815 SQL-Injection in Carlo Gavazzi UWP 3.0 Sentilo Proxy — UWP 3.0 Monitoring Gateway and ControllerCWE-89 2.7 Low2022-09-28
CVE-2022-28814 Path traversal in Carlo Gavazzi UWP 3.0 could lead to full device access — UWP 3.0 Monitoring Gateway and ControllerCWE-23 9.8 Critical2022-09-28
CVE-2022-28812 Use of Hard-coded Credentials in UWP3.0 allows SuperUser authentication bypass in Car Park Server. — UWP 3.0 Monitoring Gateway and ControllerCWE-798 9.8 Critical2022-09-28
CVE-2022-28811 Possible command injection in Car Park Server in Carlo Gavazzi UWP3.0 — UWP 3.0 Monitoring Gateway and ControllerCWE-78 9.8 Critical2022-09-28
CVE-2022-22526 Missing authentication for API in Carlo Gavazzi UWP 3.0 Car Park Server — UWP 3.0 Monitoring Gateway and ControllerCWE-306 9.8 Critical2022-09-28
CVE-2022-22524 SQL-injection in Carlo Gavazzi UWP 3.0 allows for full database access — UWP 3.0 Monitoring Gateway and ControllerCWE-89 9.4 Critical2022-09-28
CVE-2022-22525 Command injection in restore function of Carlo Gavazzi UWP3.0 allows for command injection — UWP 3.0 Monitoring Gateway and ControllerCWE-20 7.2 High2022-09-28
CVE-2022-22523 Carlo Gavazzi UWP 3.0 WebApp allows for authentication bypass — UWP 3.0 Monitoring Gateway and ControllerCWE-287 7.5 High2022-09-28
CVE-2022-22522 Hard-coded credentials in Carlo Gavazzi UWP3.0 allows for authentication bypass and full control of the device — UWP 3.0 Monitoring Gateway and ControllerCWE-798 9.8 Critical2022-09-28
CVE-2022-28813 SQL-injection in Car Park Server 3.0 allows for full database access. — UWP 3.0 Monitoring Gateway and ControllerCWE-89 7.5 High2022-09-28

本页汇总了 Carlo Gavazzi 厂商截至目前公开的全部 12 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。