Vulnerability Advisories

This page offers a comprehensive view of vulnerabilities identified by Nozomi Networks in critical OT, ICS, and IoT environments, showcasing the deep expertise and dedication of our world-class Security Research team.

Each advisory represents our ongoing effort to enhance the protection of industrial systems, identifying emerging threats before they can be exploited. Immediate protection is available through our Threat Intelligence (TI) subscription, supporting a proactive, forward-thinking defense strategy. For more on our responsible approach, refer to the Responsible Disclosure Policy.

Vulnerability Advisories

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Date Published
CVE ID
Vendor
Product
Type
Risk
Details
November 27, 2024
CVE-2024-50364
Advantech
EKI Access Points
Command Injection
High
November 27, 2024
CVE-2024-50367
Advantech
EKI Access Points
Command Injection
High
November 27, 2024
CVE-2024-50368
Advantech
EKI Access Points
Command Injection
High
November 27, 2024
CVE-2024-50365
Advantech
EKI Access Points
Command Injection
High
November 27, 2024
CVE-2024-50366
Advantech
EKI Access Points
Command Injection
High
November 27, 2024
CVE-2024-50362
Advantech
EKI Access Points
Command Injection
High
November 27, 2024
CVE-2024-50359
Advantech
EKI Access Points
Command Injection
High
November 27, 2024
CVE-2024-50361
Advantech
EKI Access Points
Command Injection
High
November 27, 2024
CVE-2024-50358
Advantech
EKI Access Points
Use of Hard-coded Cryptographic Key
High
November 27, 2024
CVE-2024-50360
Advantech
EKI Access Points
Command Injection
High
November 27, 2024
CVE-2024-50363
Advantech
EKI Access Points
Command Injection
High
November 18, 2024
CVE-2024-42383
Cesanta
Mongoose Web Server
CWE-823 Use of Out-of-range Pointer Offset
Medium
November 18, 2024
CVE-2024-42384
Cesanta
Mongoose Web Server
CWE-190 Integer Overflow or Wraparound
High
November 18, 2024
CVE-2024-42385
Cesanta
Mongoose Web Server
CWE-140 Improper Neutralization of Delimiters
Medium
November 18, 2024
CVE-2024-42386
Cesanta
Mongoose Web Server
CWE-823 Use of Out-of-range Pointer Offset
High
November 18, 2024
CVE-2024-42387
Cesanta
Mongoose Web Server
CWE-823 Use of Out-of-range Pointer Offset
Medium
November 18, 2024
CVE-2024-42388
Cesanta
Mongoose Web Server
CWE-823 Use of Out-of-range Pointer Offset
Medium
November 18, 2024
CVE-2024-42389
Cesanta
Mongoose Web Server
CWE-823 Use of Out-of-range Pointer Offset
Medium
November 18, 2024
CVE-2024-42390
Cesanta
Mongoose Web Server
CWE-823 Use of Out-of-range Pointer Offset
Medium
November 18, 2024
CVE-2024-42391
Cesanta
Mongoose Web Server
CWE-823 Use of Out-of-range Pointer Offset
Medium
November 18, 2024
CVE-2024-42392
Cesanta
Mongoose Web Server
CWE-140 Improper Neutralization of Delimiters
Medium
October 24, 2024
CVE-2024-3184
EmbedThis
GoAhead
Multiple NULL Pointer Dereference
Medium
October 24, 2024
CVE-2024-3186
EmbedThis
GoAhead
NULL Pointer Dereference
Medium
October 24, 2024
CVE-2024-3187
EmbedThis
GoAhead
Expired Pointer Dereference
Medium
October 24, 2024
CVE-2018-14797
Emerson
DeltaV DCS Workstations
Unauthorized Code Execution
High
October 24, 2024
CVE-2021-36205
Johnson Controls
Metasys ADS/ADX/OAS Servers
Incomplete Cleanup
High
September 18, 2024
CVE-2024-42483
Espressif
ESP-NOW
CWE-349 Acceptance of Extraneous Untrusted Data With Trusted Data
Medium
September 18, 2024
CVE-2024-42484
Espressif
ESP-NOW
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-41173
Beckhoff
TwinCAT/BSD
CWE-288 Authentication Bypass Using an Alternate Path or Channel
High
September 12, 2024
CVE-2024-41174
Beckhoff
TwinCAT/BSD
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
High
September 12, 2024
CVE-2024-41175
Beckhoff
TwinCAT/BSD
CWE-770 Allocation of Resources Without Limits or Throttling
Medium
September 12, 2024
CVE-2024-41176
Beckhoff
TwinCAT/BSD
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Medium
September 12, 2024
CVE-2024-31174
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-23915
Open Networking Foundation (ONF)
libfluid
CWE-690 Unchecked Return Value to NULL Pointer Dereference
Medium
September 12, 2024
CVE-2024-31181
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31178
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31197
Open Networking Foundation (ONF)
libfluid
CWE-170 Improper Null Termination
Medium
September 12, 2024
CVE-2024-31179
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31196
Open Networking Foundation (ONF)
libfluid
CWE-690 Unchecked Return Value to NULL Pointer Dereference
Medium
September 12, 2024
CVE-2024-31180
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31175
Open Networking Foundation (ONF)
libfluid
CWE-690 Unchecked Return Value to NULL Pointer Dereference
Medium
September 12, 2024
CVE-2024-31168
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31187
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31191
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31164
Open Networking Foundation (ONF)
libfluid
CWE-690 Unchecked Return Value to NULL Pointer Dereference
Medium
September 12, 2024
CVE-2024-31172
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31173
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31165
Open Networking Foundation (ONF)
libfluid
CWE-690 Unchecked Return Value to NULL Pointer Dereference
Medium
September 12, 2024
CVE-2024-31190
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31169
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31186
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31193
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31185
Open Networking Foundation (ONF)
libfluid
CWE-690 Unchecked Return Value to NULL Pointer Dereference
Medium
September 12, 2024
CVE-2024-31170
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31189
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31166
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31188
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31167
Open Networking Foundation (ONF)
libfluid
CWE-690 Unchecked Return Value to NULL Pointer Dereference
Medium
September 12, 2024
CVE-2024-31171
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 10, 2024
CVE-2024-31184
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 10, 2024
CVE-2024-31192
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 10, 2024
CVE-2024-31176
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 10, 2024
CVE-2024-31195
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 10, 2024
CVE-2024-31183
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-23916
Open Networking Foundation (ONF)
libfluid
CWE-690 Unchecked Return Value to NULL Pointer Dereference
Medium
September 12, 2024
CVE-2024-31182
Open Networking Foundation (ONF)
libfluid
CWE-690 Unchecked Return Value to NULL Pointer Dereference
Medium
September 12, 2024
CVE-2024-31194
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31198
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31177
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
August 7, 2024
CVE-2024-32862
Johnson Controls
exacqVision Web Service
Permissive Cross-domain Policy with Untrusted Domains
Medium
August 7, 2024
CVE-2024-32863
Johnson Controls
exacqVision Web Service
Cross-Site Request Forgery (CSRF)
Medium
August 7, 2024
CVE-2024-32864
Johnson Controls
exacqVision Web Service
Cleartext Transmission of Sensitive Information
Medium
August 7, 2024
CVE-2024-32865
Johnson Controls
exacqVision Server
Improper Certificate Validation
Medium
August 7, 2024
CVE-2024-32931
Johnson Controls
exacqVision Web Service
Use of GET Request Method With Sensitive Query Strings (Operator)
Medium
August 7, 2024
CVE-2024-32931
Johnson Controls
exacqVision Web Service
Use of GET Request Method With Sensitive Query Strings (Administrator)
Medium
July 5, 2024
CVE-2024-31199
Plug&Track
Sensor Net Connect V2
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
High
July 5, 2024
CVE-2024-3083
Plug&Track
Sensor Net Connect V2
Cross-Site Request Forgery (CSRF)
High
July 5, 2024
CVE-2024-3082
Plug&Track
Sensor Net Connect V2
Plaintext Storage of a Password
Medium
July 5, 2024
CVE-2024-31200
Plug&Track
Sensor Net Connect V2
Insertion of Sensitive Information Into Sent Data
Medium
July 5, 2024
CVE-2024-31202
Plug&Track
Thermoscan IP
Incorrect Permission Assignment for Critical Resource
High
July 5, 2024
CVE-2024-31201
Plug&Track
Thermoscan IP
Unquoted Search Path or Element
Medium
July 5, 2024
CVE-2024-31203
Plug&Track
Thermoscan IP
Stack-based Buffer Overflow
Low
May 14, 2024
CVE-2024-1630
GE HealthCare
Common Service Desktop
Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
High
May 14, 2024
CVE-2024-1628
GE HealthCare
Common Service Desktop
Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
High
May 14, 2024
CVE-2024-27110
GE HealthCare
EchoPAC Software Only (SWO), EchoPAC TurnKey and ImageVault
Execution with Unnecessary Privileges
High
May 14, 2024
CVE-2024-27109
GE HealthCare
EchoPAC Software Only (SWO), EchoPAC TurnKey and ImageVault
Insufficiently Protected Credentials
High
May 14, 2024
CVE-2024-27108
GE HealthCare
EchoPAC Software Only (SWO), EchoPAC TurnKey and ImageVault
Incorrect Permission Assignment for Critical Resource
Medium
May 14, 2024
CVE-2024-27107
GE HealthCare
EchoPAC Software Only (SWO), EchoPAC TurnKey and ImageVault
Use of Hard-coded Credentials
Critical
May 14, 2024
CVE-2024-27106
GE HealthCare
EchoPAC Software Only (SWO), EchoPAC TurnKey and ImageVault
Missing Encryption of Sensitive Data
Medium
May 14, 2024
CVE-2024-1629
GE HealthCare
Common Service Desktop
Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
Medium
May 14, 2024
CVE-2024-1486
GE HealthCare
Ultrasound Imaging Families
Incorrect Permission Assignment for Critical Resource
High
May 14, 2024
CVE-2020-6977
GE HealthCare
Ultrasound Imaging Families
Execution with Unnecessary Privileges
Medium
May 14, 2024
CVE-2020-6977
GE HealthCare
Ultrasound Imaging Families
Protection Mechanism Failure
High
May 1, 2024
CVE-2023-6949
DJI
Mini Pro 3
DJI Mini Pro 3 Missing Authentication for Critical Function
Medium
May 1, 2024
CVE-2023-51456
DJI
Mavic 3
DJI Mavic 3 Series Improper Input Validation
Medium
May 1, 2024
CVE-2023-51455
DJI
Mavic 3
DJI Mavic 3 Series Improper Validation of Array
Medium
May 1, 2024
CVE-2023-51454
DJI
Mavic 3
DJI Mavic 3 Series Out-of-bounds Write
Medium
May 1, 2024
CVE-2023-51453
DJI
Mavic 3
DJI Mavic 3 Series Out-of-bounds Write
Low
May 1, 2024
CVE-2023-51452
DJI
Mavic 3
DJI Mavic 3 Series Out-of-bounds Write
Low
May 1, 2024
CVE-2023-6948
DJI
Mavic 3
DJI Mavic 3 Series Buffer Copy without Checking Size of Input
Low
CVE ID
CVE-2026-2273
Vendor
Schneider Electric
Product
EcoStruxure™ Automation Expert
Date Published
March 10, 2026
Type
Improper Control of Generation of Code ('Code Injection')
Risk Score
High
CVE ID
CVE-2026-22614
Vendor
Eaton
Product
EasySoft
Date Published
March 11, 2026
Type
Insufficiently Protected Credentials
Risk Score
Medium
CVE ID
CVE-2026-3588
Vendor
Ikea
Product
Dirigera
Date Published
March 9, 2026
Type
Server Side Request Forgery
Risk Score
High
CVE ID
CVE-2026-26098
Vendor
Owl
Product
opds
Date Published
February 23, 2026
Type
Uncontrolled Search Path Element
Risk Score
High
CVE ID
CVE-2026-26101
Vendor
Owl
Product
opds
Date Published
February 23, 2026
Type
Incorrect Permission Assignment for Critical Resource
Risk Score
High
CVE ID
CVE-2026-26099
Vendor
Owl
Product
opds
Date Published
February 23, 2026
Type
Uncontrolled Search Path Element
Risk Score
High

Take the next step.

Discover how easy it is to identify and respond to cyber threats by automating your OT and IoT asset discovery, inventory, and management.