DanfossCVEs & Vulnerabilities

10 CVEs affecting Danfoss products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

ak-em100 7ak-em100 firmware 7ak-sm 800a 3ak-sm 800a firmware 3
CVE-2023-25915HIGH

Due to improper input validation, an authenticated remote attacker could execute arbitrary commands on the target system.

22 Aug 2023
8.8
CVSS
CVE-2023-25914HIGH

Due to improper restriction, authenticated attackers could retrieve and read system files of the underlying server through the XML interface. The information that can be read can lead to a full system compromise.

22 Aug 2023
8.8
CVSS
CVE-2023-25913HIGH

Because of an authentication flaw an attacker would be capable of generating a web report that discloses sensitive information such as internal IP addresses, usernames, store names and other sensitive information.

22 Aug 2023
7.5
CVSS
CVE-2023-25912MEDIUM

The webreport generation feature in the Danfoss AK-EM100 allows an unauthorized actor to generate a web report that discloses sensitive information such as the internal IP address, usernames and internal device values.

11 Jun 2023
5.3
CVSS
CVE-2023-25911HIGH

The Danfoss AK-EM100 web applications allow for an authenticated user to perform OS command injection through the web application parameters.

11 Jun 2023
8.8
CVSS
CVE-2023-22586HIGH

The Danfoss AK-EM100 web applications allow for Local File Inclusion in the file parameter.

11 Jun 2023
7.5
CVSS
CVE-2023-22585MEDIUM

The Danfoss AK-EM100 web applications allow for Reflected Cross-Site Scripting in the title parameter.

11 Jun 2023
6.1
CVSS
CVE-2023-22584HIGH

The Danfoss AK-EM100 stores login credentials in cleartext.

11 Jun 2023
7.5
CVSS
CVE-2023-22583CRITICAL

The Danfoss AK-EM100 web forms allow for SQL injection in the login forms.

11 Jun 2023
9.8
CVSS
CVE-2023-22582MEDIUM

The Danfoss AK-EM100 web applications allow for Reflected Cross-Site Scripting.

11 Jun 2023
6.1
CVSS
← PrevPage 1 / 1Next →
Danfoss CVEs & Vulnerabilities — 10 Tracked