Vulnerability Advisories

This page offers a comprehensive view of vulnerabilities identified by Nozomi Networks in critical OT, ICS, and IoT environments, showcasing the deep expertise and dedication of our world-class Security Research team.

Each advisory represents our ongoing effort to enhance the protection of industrial systems, identifying emerging threats before they can be exploited. Immediate protection is available through our Threat Intelligence (TI) subscription, supporting a proactive, forward-thinking defense strategy. For more on our responsible approach, refer to the Responsible Disclosure Policy.

Vulnerability Advisories

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Date Published
CVE ID
Vendor
Product
Type
Risk
Details
August 5, 2025
CVE-2025-41659
CODESYS
Codesys Control
Incorrect Permission Assignment for Critical Resource
High
July 8, 2025
CVE-2025-41665
Phoenix Contact
PLCNext family
Incorrect Default Permissions
Medium
July 8, 2025
CVE-2025-41668
Phoenix Contact
PLCNext family
Improper Link Resolution Before File Access
High
July 8, 2025
CVE-2025-41667
Phoenix Contact
PLCNext family
Improper Link Resolution Before File Access
High
July 8, 2025
CVE-2025-41666
Phoenix Contact
PLCNext family
Improper Link Resolution Before File Access
High
June 9, 2025
CVE-2025-36513
I-Pro
Network Camera WV-X, WV-S and WV-U series
Cross-Site Request Forgery (CSRF)
Medium
May 27, 2025
CVE-2025-3944
Tridium
Niagara Framework and Niagara Enterprise Security
Incorrect Permission Assignment for Critical Resource
High
May 27, 2025
CVE-2025-3945
Tridium
Niagara Framework and Niagara Enterprise Security
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
Medium
May 27, 2025
CVE-2025-3943
Tridium
Niagara Framework and Niagara Enterprise Security
Use of GET Request Method With Sensitive Query Strings
Medium
May 27, 2025
CVE-2025-3942
Tridium
Niagara Framework and Niagara Enterprise Security
Improper Output Neutralization for Logs
Medium
May 27, 2025
CVE-2025-3936
Tridium
Niagara Framework and Niagara Enterprise Security
Incorrect Permission Assignment for Critical Resource
Medium
May 27, 2025
CVE-2025-3939
Tridium
Niagara Framework and Niagara Enterprise Security
Observable Response Discrepancy
Medium
May 27, 2025
CVE-2025-3938
Tridium
Niagara Framework and Niagara Enterprise Security
Missing Cryptographic Step
Medium
May 27, 2025
CVE-2025-3937
Tridium
Niagara Framework and Niagara Enterprise Security
Use of Password Hash With Insufficient Computational Effort
High
May 27, 2025
CVE-2025-3941
Tridium
Niagara Framework and Niagara Enterprise Security
Improper Handling of Windows ::DATA Alternate Data Stream
Medium
May 27, 2025
CVE-2025-3940
Tridium
Niagara Framework and Niagara Enterprise Security
Improper Use of Validation Framework
Medium
May 21, 2025
CVE-2025-40583
Siemens
SCALANCE LPE9403
Cleartext Transmission of Sensitive Information
Medium
May 21, 2025
CVE-2025-40573
Siemens
SCALANCE LPE9403
Path Traversal
Medium
May 21, 2025
CVE-2025-40579
Siemens
SCALANCE LPE9403
Stack-based Buffer Overflow
Medium
May 21, 2025
CVE-2025-40580
Siemens
SCALANCE LPE9403
Stack-based Buffer Overflow
Medium
May 21, 2025
CVE-2025-40578
Siemens
SCALANCE LPE9403
Out-of-bounds Read
Medium
May 21, 2025
CVE-2025-40577
Siemens
SCALANCE LPE9403
Out-of-bounds Read
Medium
May 21, 2025
CVE-2025-40576
Siemens
SCALANCE LPE9403
NULL Pointer Dereference
Medium
May 21, 2025
CVE-2025-40582
Siemens
SCALANCE LPE9403
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
May 21, 2025
CVE-2025-40581
Siemens
SCALANCE LPE9403
Incorrect Permission Assignment for Critical Resource
High
May 21, 2025
CVE-2025-40574
Siemens
SCALANCE LPE9403
Incorrect Permission Assignment for Critical Resource
High
May 21, 2025
CVE-2025-40572
Siemens
SCALANCE LPE9403
Incorrect Permission Assignment for Critical Resource
Medium
May 21, 2025
CVE-2025-40575
Siemens
SCALANCE LPE9403
Use of Uninitialized Variable
Medium
May 7, 2025
CVE-2025-1399
libplctag
libplctag
Out-of-bounds Read
Low
May 7, 2025
CVE-2025-1400
libplctag
libplctag
Out-of-bounds Read
Low
May 5, 2025
CVE-2025-32405
RT-Labs
P-Net
Out-of-bounds Write
High
May 5, 2025
CVE-2025-32404
RT-Labs
P-Net
Out-of-bounds Write
Medium
May 5, 2025
CVE-2025-32403
RT-Labs
P-Net
Out-of-bounds Write
Medium
May 5, 2025
CVE-2025-32399
RT-Labs
P-Net
Unchecked Input for Loop Condition
Medium
May 5, 2025
CVE-2025-32402
RT-Labs
P-Net
Out-of-bounds Write
High
May 5, 2025
CVE-2025-32401
RT-Labs
P-Net
Heap-based Buffer Overflow
Medium
May 5, 2025
CVE-2025-32398
RT-Labs
P-Net
NULL Pointer Dereference
High
May 5, 2025
CVE-2025-32400
RT-Labs
P-Net
Heap-based Buffer Overflow
High
May 5, 2025
CVE-2025-32396
RT-Labs
P-Net
Heap-based Buffer Overflow
High
May 5, 2025
CVE-2025-32397
RT-Labs
P-Net
Heap-based Buffer Overflow
High
May 5, 2025
CVE-2025-32730
I-Pro
I-Pro Configuration Tool
Use of Hard-coded Credentials
Medium
April 29, 2025
CVE-2025-24339
Bosch Rexroth
ctrlX CORE
Improper Neutralization of HTTP Headers for Scripting Syntax
Medium
April 29, 2025
CVE-2025-24338
Bosch Rexroth
ctrlX CORE
Improper Encoding or Escaping of Output
High
April 29, 2025
CVE-2025-24340
Bosch Rexroth
ctrlX CORE
Use of Password Hash With Insufficient Computational Effort
Medium
April 29, 2025
CVE-2025-24345
Bosch Rexroth
ctrlX CORE
Improper Validation of Syntactic Correctness of Input
Medium
April 29, 2025
CVE-2025-24341
Bosch Rexroth
ctrlX CORE
Allocation of Resources Without Limits or Throttling
Medium
April 29, 2025
CVE-2025-24342
Bosch Rexroth
ctrlX CORE
Observable Response Discrepancy
Medium
April 29, 2025
CVE-2025-24343
Bosch Rexroth
ctrlX CORE
Relative Path Traversal
Medium
April 29, 2025
CVE-2025-24346
Bosch Rexroth
ctrlX CORE
Improper Validation of Syntactic Correctness of Input
High
April 29, 2025
CVE-2025-24344
Bosch Rexroth
ctrlX CORE
Improper Neutralization of Script in an Error Message Web Page
Medium
April 29, 2025
CVE-2025-24350
Bosch Rexroth
ctrlX CORE
Relative Path Traversal
High
April 29, 2025
CVE-2025-27532
Bosch Rexroth
ctrlX CORE
Cleartext Storage of Sensitive Information
Medium
April 29, 2025
CVE-2025-24351
Bosch Rexroth
ctrlX CORE
Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’)
High
April 29, 2025
CVE-2025-24349
Bosch Rexroth
ctrlX CORE
Permissive List of Allowed Inputs
High
April 29, 2025
CVE-2025-24347
Bosch Rexroth
ctrlX CORE
Improper Validation of Syntactic Correctness of Input
Medium
April 29, 2025
CVE-2025-24348
Bosch Rexroth
ctrlX CORE
Improper Validation of Syntactic Correctness of Input
Medium
March 25, 2025
CVE-2025-24517
Inaba
IB-MCT001
Use of client-side authentication
High
March 25, 2025
CVE-2025-26689
Inaba
IB-MCT001
Forced browsing
Critical
March 25, 2025
CVE-2025-24852
Inaba
IB-MCT001
Storing passwords in a recoverable format
Medium
March 25, 2025
CVE-2025-25211
Inaba
IB-MCT001
Weak password requirements
Critical
March 7, 2025
CVE-2025-27256
GE Vernova
Enervista UR Setup
Missing Authentication for Critical Function
High
March 7, 2025
CVE-2025-27254
GE Vernova
Enervista UR Setup
Improper Authentication
High
March 7, 2025
CVE-2025-27257
GE Vernova
UR IED family
Insufficient Verification of Data Authenticity
Medium
March 18, 2025
CVE-2024-41975
CODESYS
CODESYS Gateway
Initialization of a Resource with an Insecure Default
Medium
March 7, 2025
CVE-2025-27255
GE Vernova
Enervista UR Setup
Use of Hard-coded Password
High
March 7, 2025
CVE-2025-27253
GE Vernova
UR IED family
Improper Input Validation
High
February 27, 2025
CVE-2024-10918
libmodbus
libmodbus
Stack-based Buffer Overflow
Medium
March 6, 2025
CVE-2024-12650
Wago
libwagosnmp
Unchecked Return Value
Medium
February 13, 2025
CVE-2024-12011
Zettler
130.8005
Buffer Over-read
High
February 13, 2025
CVE-2024-12012
Zettler
130.8005
Use of GET Request Method With Sensitive Query Strings
Medium
February 13, 2025
CVE-2024-12013
Zettler
130.8005
Use of Default Credentials
High
February 12, 2025
CVE-2025-26376
Q-Free
MaxTime
Missing Authorization
Medium
February 12, 2025
CVE-2025-26374
Q-Free
MaxTime
Missing Authorization
Medium
February 12, 2025
CVE-2025-26378
Q-Free
MaxTime
Missing Authorization
High
February 12, 2025
CVE-2025-26377
Q-Free
MaxTime
Missing Authorization
High
February 12, 2025
CVE-2025-26375
Q-Free
MaxTime
Missing Authorization
High
February 12, 2025
CVE-2025-26372
Q-Free
MaxTime
Missing Authorization
High
February 12, 2025
CVE-2025-26373
Q-Free
MaxTime
Missing Authorization
Medium
February 12, 2025
CVE-2025-26371
Q-Free
MaxTime
Missing Authorization
High
February 12, 2025
CVE-2025-26370
Q-Free
MaxTime
Missing Authorization
High
February 12, 2025
CVE-2025-26367
Q-Free
MaxTime
Missing Authorization
Medium
February 12, 2025
CVE-2025-26369
Q-Free
MaxTime
Missing Authorization
High
February 12, 2025
CVE-2025-26368
Q-Free
MaxTime
Missing Authorization
High
February 12, 2025
CVE-2025-26362
Q-Free
MaxTime
Missing Authentication for Critical Function
High
February 12, 2025
CVE-2025-26361
Q-Free
MaxTime
Missing Authentication for Critical Function
Critical
February 12, 2025
CVE-2025-26366
Q-Free
MaxTime
Missing Authentication for Critical Function
High
February 12, 2025
CVE-2025-26365
Q-Free
MaxTime
Missing Authentication for Critical Function
High
February 12, 2025
CVE-2025-26364
Q-Free
MaxTime
Missing Authentication for Critical Function
High
February 12, 2025
CVE-2025-26363
Q-Free
MaxTime
Missing Authentication for Critical Function
High
February 12, 2025
CVE-2025-26360
Q-Free
MaxTime
Missing Authentication for Critical Function
Medium
February 12, 2025
CVE-2025-26358
Q-Free
MaxTime
Improper Input Validation
Medium
February 12, 2025
CVE-2025-26357
Q-Free
MaxTime
Path Traversal
Medium
February 12, 2025
CVE-2025-26359
Q-Free
MaxTime
Missing Authentication for Critical Function
Critical
February 12, 2025
CVE-2025-26356
Q-Free
MaxTime
Path Traversal
High
February 12, 2025
CVE-2025-26355
Q-Free
MaxTime
Path Traversal
Medium
February 12, 2025
CVE-2025-26354
Q-Free
MaxTime
Path Traversal
High
February 12, 2025
CVE-2025-26352
Q-Free
MaxTime
Path Traversal
Medium
February 12, 2025
CVE-2025-26351
Q-Free
MaxTime
Path Traversal
Medium
February 12, 2025
CVE-2025-26353
Q-Free
MaxTime
Path Traversal
Medium
February 12, 2025
CVE-2025-26350
Q-Free
MaxTime
Unrestricted Upload of File with Dangerous Type
Medium
CVE ID
CVE-2026-56136
Vendor
Tuxera
Product
ntfs-3g
Date Published
July 15, 2026
Type
Out-of-bounds Read
Risk Score
Medium
CVE ID
CVE-2026-56135
Vendor
Tuxera
Product
ntfs-3g
Date Published
July 15, 2026
Type
Heap-based Buffer Overflow
Risk Score
High
CVE ID
CVE-2026-46572
Vendor
Tuxera
Product
ntfs-3g
Date Published
July 15, 2026
Type
Heap-based Buffer Overflow
Risk Score
High
CVE ID
CVE-2026-46571
Vendor
Tuxera
Product
ntfs-3g
Date Published
July 15, 2026
Type
Out-of-bounds Read
Risk Score
Medium
CVE ID
CVE-2026-46570
Vendor
Tuxera
Product
ntfs-3g
Date Published
July 15, 2026
Type
Heap-based Buffer Overflow
Risk Score
High
CVE ID
CVE-2026-46569
Vendor
Tuxera
Product
ntfs-3g
Date Published
July 15, 2026
Type
Heap-based Buffer Overflow
Risk Score
High
CVE ID
CVE-2026-42618
Vendor
Tuxera
Product
ntfs-3g
Date Published
July 15, 2026
Type
Off-by-one Error
Risk Score
High
CVE ID
CVE-2026-42617
Vendor
Tuxera
Product
ntfs-3g
Date Published
July 15, 2026
Type
Heap-based Buffer Overflow
Risk Score
High
CVE ID
CVE-2026-42616
Vendor
Tuxera
Product
ntfs-3g
Date Published
July 15, 2026
Type
Heap-based Buffer Overflow
Risk Score
High
CVE ID
CVE-2026-61378
Vendor
Automationdirect
Product
ADCUP Usb Driver
Date Published
July 20, 2026
Type
Divide By Zero
Risk Score
Medium
CVE ID
CVE-2026-60073
Vendor
Automationdirect
Product
ADCUP Usb Driver
Date Published
July 20, 2026
Type
Out-of-bounds Read
Risk Score
Medium
CVE ID
CVE-2026-57896
Vendor
Automationdirect
Product
ADCUP Usb Driver
Date Published
July 20, 2026
Type
Out-of-bounds Read
Risk Score
Medium
CVE ID
CVE-2026-60140
Vendor
Automationdirect
Product
ADCUP Usb Driver
Date Published
July 20, 2026
Type
Out-of-bounds Read
Risk Score
Medium
CVE ID
CVE-2026-61389
Vendor
Automationdirect
Product
ADCUP Usb Driver
Date Published
July 20, 2026
Type
Out-of-bounds Write
Risk Score
High
CVE ID
CVE-2026-60063
Vendor
Automationdirect
Product
ADCUP Usb Driver
Date Published
July 20, 2026
Type
Out-of-bounds Write
Risk Score
High

Take the next step.

Discover how easy it is to identify and respond to cyber threats by automating your OT and IoT asset discovery, inventory, and management.