Vulnerability Advisories

This page offers a comprehensive view of vulnerabilities identified by Nozomi Networks in critical OT, ICS, and IoT environments, showcasing the deep expertise and dedication of our world-class Security Research team.

Each advisory represents our ongoing effort to enhance the protection of industrial systems, identifying emerging threats before they can be exploited. Immediate protection is available through our Threat Intelligence (TI) subscription, supporting a proactive, forward-thinking defense strategy. For more on our responsible approach, refer to the Responsible Disclosure Policy.

Vulnerability Advisories

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Date Published
CVE ID
Vendor
Product
Type
Risk
Details
February 12, 2025
CVE-2025-26345
Q-Free
MaxTime
Missing Authentication for Critical Function
Critical
February 12, 2025
CVE-2025-26349
Q-Free
MaxTime
Relative Path Traversal
High
February 12, 2025
CVE-2025-26347
Q-Free
MaxTime
Missing Authentication for Critical Function
Critical
February 12, 2025
CVE-2025-26348
Q-Free
MaxTime
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Medium
February 12, 2025
CVE-2025-26346
Q-Free
MaxTime
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Medium
February 12, 2025
CVE-2025-26344
Q-Free
MaxTime
Missing Authentication for Critical Function
Critical
February 12, 2025
CVE-2025-1100
Q-Free
MaxTime
Use of Hard-coded Password
Critical
February 12, 2025
CVE-2025-1101
Q-Free
MaxTime
Observable Response Discrepancy
Medium
February 12, 2025
CVE-2025-26343
Q-Free
MaxTime
Weak Authentication
High
February 12, 2025
CVE-2025-26342
Q-Free
MaxTime
Missing Authentication for Critical Function
Critical
February 12, 2025
CVE-2025-26339
Q-Free
MaxTime
Missing Authentication for Critical Function
Critical
February 12, 2025
CVE-2025-1102
Q-Free
MaxTime
Origin Validation Error
Medium
February 12, 2025
CVE-2025-26341
Q-Free
MaxTime
Missing Authentication for Critical Function
Critical
February 12, 2025
CVE-2025-26340
Q-Free
MaxTime
Use of Hard-coded Cryptographic Key
High
January 27, 2025
CVE-2025-0695
Cesanta
Frozen
Allocation of Resources Without Limits or Throttling
Medium
January 27, 2025
CVE-2025-0696
Cesanta
Frozen
NULL Pointer Dereference
Medium
December 10, 2024
CVE-2024-43384
Phoenix Contact
mGuard Families
Improper Removal of Sensitive Information Before Storage or Transfer
High
December 10, 2024
CVE-2024-43393
Phoenix Contact
mGuard Families
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Medium
December 10, 2024
CVE-2024-43392
Phoenix Contact
mGuard Families
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Medium
December 10, 2024
CVE-2024-43391
Phoenix Contact
mGuard Families
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Medium
December 10, 2024
CVE-2024-43390
Phoenix Contact
mGuard Families
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Medium
December 10, 2024
CVE-2024-43389
Phoenix Contact
mGuard Families
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Medium
December 10, 2024
CVE-2024-43387
Phoenix Contact
mGuard Families
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
December 10, 2024
CVE-2024-7698
Phoenix Contact
mGuard Families
Improper Removal of Sensitive Information Before Storage or Transfer
Medium
December 10, 2024
CVE-2024-43385
Phoenix Contact
mGuard Families
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
December 10, 2024
CVE-2024-43388
Phoenix Contact
mGuard Families
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
High
December 10, 2024
CVE-2024-43386
Phoenix Contact
mGuard Families
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
December 10, 2024
CVE-2024-7699
Phoenix Contact
mGuard Families
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
December 3, 2024
CVE-2024-41967
Wago
Multiple Products
Improper Access Control
Medium
December 3, 2024
CVE-2024-41970
Wago
Multiple Products
Improper Access Control
Medium
December 3, 2024
CVE-2024-41973
Wago
Multiple Products
Path Traversal
Medium
December 3, 2024
CVE-2024-41974
Wago
Multiple Products
Improper Access Control
Medium
December 3, 2024
CVE-2024-41972
Wago
Multiple Products
Path Traversal
Medium
December 3, 2024
CVE-2024-41971
Wago
Multiple Products
Path Traversal
Medium
December 3, 2024
CVE-2024-41968
Wago
Multiple Products
Improper Access Control
Medium
December 3, 2024
CVE-2024-41969
Wago
Multiple Products
Improper Access Control
High
November 27, 2024
CVE-2024-50377
Advantech
EKI Access Points
Hardcoded encryption key
Medium
November 27, 2024
CVE-2024-50371
Advantech
EKI Access Points
Remote Command Execution (RCE)
Critical
November 27, 2024
CVE-2024-50376
Advantech
EKI Access Points
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
High
November 27, 2024
CVE-2024-50372
Advantech
EKI Access Points
Remote Command Execution (RCE)
Critical
November 27, 2024
CVE-2024-50375
Advantech
EKI Access Points
Missing Authentication for Critical Function
Critical
November 27, 2024
CVE-2024-50373
Advantech
EKI Access Points
Remote Command Execution (RCE)
Critical
November 27, 2024
CVE-2024-50374
Advantech
EKI Access Points
Remote Command Execution (RCE)
Critical
November 27, 2024
CVE-2024-50370
Advantech
EKI Access Points
Remote Command Execution (RCE)
Critical
November 27, 2024
CVE-2024-50369
Advantech
EKI Access Points
Command Injection
High
November 27, 2024
CVE-2024-50364
Advantech
EKI Access Points
Command Injection
High
November 27, 2024
CVE-2024-50367
Advantech
EKI Access Points
Command Injection
High
November 27, 2024
CVE-2024-50368
Advantech
EKI Access Points
Command Injection
High
November 27, 2024
CVE-2024-50365
Advantech
EKI Access Points
Command Injection
High
November 27, 2024
CVE-2024-50366
Advantech
EKI Access Points
Command Injection
High
November 27, 2024
CVE-2024-50362
Advantech
EKI Access Points
Command Injection
High
November 27, 2024
CVE-2024-50359
Advantech
EKI Access Points
Command Injection
High
November 27, 2024
CVE-2024-50361
Advantech
EKI Access Points
Command Injection
High
November 27, 2024
CVE-2024-50358
Advantech
EKI Access Points
Use of Hard-coded Cryptographic Key
High
November 27, 2024
CVE-2024-50360
Advantech
EKI Access Points
Command Injection
High
November 27, 2024
CVE-2024-50363
Advantech
EKI Access Points
Command Injection
High
November 18, 2024
CVE-2024-42383
Cesanta
Mongoose Web Server
CWE-823 Use of Out-of-range Pointer Offset
Medium
November 18, 2024
CVE-2024-42384
Cesanta
Mongoose Web Server
CWE-190 Integer Overflow or Wraparound
High
November 18, 2024
CVE-2024-42385
Cesanta
Mongoose Web Server
CWE-140 Improper Neutralization of Delimiters
Medium
November 18, 2024
CVE-2024-42386
Cesanta
Mongoose Web Server
CWE-823 Use of Out-of-range Pointer Offset
High
November 18, 2024
CVE-2024-42387
Cesanta
Mongoose Web Server
CWE-823 Use of Out-of-range Pointer Offset
Medium
November 18, 2024
CVE-2024-42388
Cesanta
Mongoose Web Server
CWE-823 Use of Out-of-range Pointer Offset
Medium
November 18, 2024
CVE-2024-42389
Cesanta
Mongoose Web Server
CWE-823 Use of Out-of-range Pointer Offset
Medium
November 18, 2024
CVE-2024-42390
Cesanta
Mongoose Web Server
CWE-823 Use of Out-of-range Pointer Offset
Medium
November 18, 2024
CVE-2024-42391
Cesanta
Mongoose Web Server
CWE-823 Use of Out-of-range Pointer Offset
Medium
November 18, 2024
CVE-2024-42392
Cesanta
Mongoose Web Server
CWE-140 Improper Neutralization of Delimiters
Medium
October 24, 2024
CVE-2024-3184
EmbedThis
GoAhead
Multiple NULL Pointer Dereference
Medium
October 24, 2024
CVE-2024-3186
EmbedThis
GoAhead
NULL Pointer Dereference
Medium
October 24, 2024
CVE-2024-3187
EmbedThis
GoAhead
Expired Pointer Dereference
Medium
October 24, 2024
CVE-2018-14797
Emerson
DeltaV DCS Workstations
Unauthorized Code Execution
High
October 24, 2024
CVE-2021-36205
Johnson Controls
Metasys ADS/ADX/OAS Servers
Incomplete Cleanup
High
September 18, 2024
CVE-2024-42483
Espressif
ESP-NOW
CWE-349 Acceptance of Extraneous Untrusted Data With Trusted Data
Medium
September 18, 2024
CVE-2024-42484
Espressif
ESP-NOW
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-41173
Beckhoff
TwinCAT/BSD
CWE-288 Authentication Bypass Using an Alternate Path or Channel
High
September 12, 2024
CVE-2024-41174
Beckhoff
TwinCAT/BSD
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
High
September 12, 2024
CVE-2024-41175
Beckhoff
TwinCAT/BSD
CWE-770 Allocation of Resources Without Limits or Throttling
Medium
September 12, 2024
CVE-2024-41176
Beckhoff
TwinCAT/BSD
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Medium
September 12, 2024
CVE-2024-31174
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-23915
Open Networking Foundation (ONF)
libfluid
CWE-690 Unchecked Return Value to NULL Pointer Dereference
Medium
September 12, 2024
CVE-2024-31181
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31178
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31197
Open Networking Foundation (ONF)
libfluid
CWE-170 Improper Null Termination
Medium
September 12, 2024
CVE-2024-31179
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31196
Open Networking Foundation (ONF)
libfluid
CWE-690 Unchecked Return Value to NULL Pointer Dereference
Medium
September 12, 2024
CVE-2024-31180
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31175
Open Networking Foundation (ONF)
libfluid
CWE-690 Unchecked Return Value to NULL Pointer Dereference
Medium
September 12, 2024
CVE-2024-31168
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31187
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31191
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31164
Open Networking Foundation (ONF)
libfluid
CWE-690 Unchecked Return Value to NULL Pointer Dereference
Medium
September 12, 2024
CVE-2024-31172
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31173
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31165
Open Networking Foundation (ONF)
libfluid
CWE-690 Unchecked Return Value to NULL Pointer Dereference
Medium
September 12, 2024
CVE-2024-31190
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31169
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31186
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31193
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31185
Open Networking Foundation (ONF)
libfluid
CWE-690 Unchecked Return Value to NULL Pointer Dereference
Medium
September 12, 2024
CVE-2024-31170
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
September 12, 2024
CVE-2024-31189
Open Networking Foundation (ONF)
libfluid
CWE-125 Out-of-bounds Read
Medium
CVE ID
CVE-2026-56136
Vendor
Tuxera
Product
ntfs-3g
Date Published
July 15, 2026
Type
Out-of-bounds Read
Risk Score
Medium
CVE ID
CVE-2026-56135
Vendor
Tuxera
Product
ntfs-3g
Date Published
July 15, 2026
Type
Heap-based Buffer Overflow
Risk Score
High
CVE ID
CVE-2026-46572
Vendor
Tuxera
Product
ntfs-3g
Date Published
July 15, 2026
Type
Heap-based Buffer Overflow
Risk Score
High
CVE ID
CVE-2026-46571
Vendor
Tuxera
Product
ntfs-3g
Date Published
July 15, 2026
Type
Out-of-bounds Read
Risk Score
Medium
CVE ID
CVE-2026-46570
Vendor
Tuxera
Product
ntfs-3g
Date Published
July 15, 2026
Type
Heap-based Buffer Overflow
Risk Score
High
CVE ID
CVE-2026-46569
Vendor
Tuxera
Product
ntfs-3g
Date Published
July 15, 2026
Type
Heap-based Buffer Overflow
Risk Score
High
CVE ID
CVE-2026-42618
Vendor
Tuxera
Product
ntfs-3g
Date Published
July 15, 2026
Type
Off-by-one Error
Risk Score
High
CVE ID
CVE-2026-42617
Vendor
Tuxera
Product
ntfs-3g
Date Published
July 15, 2026
Type
Heap-based Buffer Overflow
Risk Score
High
CVE ID
CVE-2026-42616
Vendor
Tuxera
Product
ntfs-3g
Date Published
July 15, 2026
Type
Heap-based Buffer Overflow
Risk Score
High
CVE ID
CVE-2026-61378
Vendor
Automationdirect
Product
ADCUP Usb Driver
Date Published
July 20, 2026
Type
Divide By Zero
Risk Score
Medium
CVE ID
CVE-2026-60073
Vendor
Automationdirect
Product
ADCUP Usb Driver
Date Published
July 20, 2026
Type
Out-of-bounds Read
Risk Score
Medium
CVE ID
CVE-2026-57896
Vendor
Automationdirect
Product
ADCUP Usb Driver
Date Published
July 20, 2026
Type
Out-of-bounds Read
Risk Score
Medium
CVE ID
CVE-2026-60140
Vendor
Automationdirect
Product
ADCUP Usb Driver
Date Published
July 20, 2026
Type
Out-of-bounds Read
Risk Score
Medium
CVE ID
CVE-2026-61389
Vendor
Automationdirect
Product
ADCUP Usb Driver
Date Published
July 20, 2026
Type
Out-of-bounds Write
Risk Score
High
CVE ID
CVE-2026-60063
Vendor
Automationdirect
Product
ADCUP Usb Driver
Date Published
July 20, 2026
Type
Out-of-bounds Write
Risk Score
High

Take the next step.

Discover how easy it is to identify and respond to cyber threats by automating your OT and IoT asset discovery, inventory, and management.