Vulnerability Advisories

This page offers a comprehensive view of vulnerabilities identified by Nozomi Networks in critical OT, ICS, and IoT environments, showcasing the deep expertise and dedication of our world-class Security Research team.

Each advisory represents our ongoing effort to enhance the protection of industrial systems, identifying emerging threats before they can be exploited. Immediate protection is available through our Threat Intelligence (TI) subscription, supporting a proactive, forward-thinking defense strategy. For more on our responsible approach, refer to the Responsible Disclosure Policy.

Vulnerability Advisories

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Date Published
CVE ID
Vendor
Product
Type
Risk
Details
August 9, 2023
CVE-2023-21411
AXIS
License Plate Verifier
Improper Neutralization of Special Elements (‘Command Injection’)
High
August 9, 2023
CVE-2023-21410
AXIS
License Plate Verifier
Improper Neutralization of Special Elements (‘Command Injection’)
High
August 9, 2023
CVE-2023-21408
AXIS
License Plate Verifier
unsafe credentials handling
High
August 9, 2023
CVE-2023-21409
AXIS
License Plate Verifier
unsafe credentials handling
High
August 9, 2023
CVE-2023-21407
AXIS
License Plate Verifier
broken access control
High
August 18, 2023
CVE-2023-37860
Phoenix Contact
WP 6xxx series
Missing Authorization
High
August 18, 2023
CVE-2023-37864
Phoenix Contact
WP 6xxx series
Download of Code Without Integrity Check
High
August 18, 2023
CVE-2023-37863
Phoenix Contact
WP 6xxx series
Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
August 18, 2023
CVE-2023-37861
Phoenix Contact
WP 6xxx series
Neutralization of Special Elements used in an OS Command ('OS Command Injection')
High
August 18, 2023
CVE-2023-37859
Phoenix Contact
WP 6xxx series
Improper Privilege Management
High
August 18, 2023
CVE-2023-37857
Phoenix Contact
WP 6xxx series
Use of Hard-coded Credentials
Low
August 18, 2023
CVE-2023-37858
Phoenix Contact
WP 6xxx series
Use of Hard-coded Credentials
Low
August 18, 2023
CVE-2023-3570
Phoenix Contact
WP 6xxx series
Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Critical
August 18, 2023
CVE-2023-37856
Phoenix Contact
WP 6xxx series
Externally Controlled Reference to a Resource in Another Sphere
Medium
August 18, 2023
CVE-2023-37855
Phoenix Contact
WP 6xxx series
Externally Controlled Reference to a Resource in Another Sphere
Medium
August 18, 2023
CVE-2023-3573
Phoenix Contact
WP 6xxx series
Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Critical
August 18, 2023
CVE-2023-3572
Phoenix Contact
WP 6xxx series
Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Critical
August 18, 2023
CVE-2023-3571
Phoenix Contact
WP 6xxx series
Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Critical
September 1, 2023
CVE-2023-34392
Schweitzer Engineering Laboratories (SEL)
SEL-5037 SEL Grid Configurator
Missing Authentication for Critical Function
High
September 1, 2023
CVE-2023-31174
Schweitzer Engineering Laboratories (SEL)
SEL-5037 SEL Grid Configurator
Cross-Site Request Forgery (CSRF)
High
September 1, 2023
CVE-2023-31175
Schweitzer Engineering Laboratories (SEL)
SEL-5037 SEL Grid Configurator
Execution with Unnecessary Privileges
High
September 1, 2023
CVE-2023-31172
Schweitzer Engineering Laboratories (SEL)
SEL-5030 acSELerator QuickSet
Incomplete Filtering of Special Elements
Medium
September 1, 2023
CVE-2023-31173
Schweitzer Engineering Laboratories (SEL)
SEL-5037 SEL Grid Configurator
Use of Hard-coded Credentials
High
September 1, 2023
CVE-2023-31171
Schweitzer Engineering Laboratories (SEL)
SEL-5030 acSELerator QuickSet
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Medium
September 1, 2023
CVE-2023-31170
Schweitzer Engineering Laboratories (SEL)
SEL-5030 acSELerator QuickSet
Inclusion of Functionality from Untrusted Control Sphere
Medium
September 1, 2023
CVE-2023-31169
Schweitzer Engineering Laboratories (SEL)
SEL-5030 acSELerator QuickSet
Improper Handling of Unicode Encoding
Medium
October 3, 2023
CVE-2023-36857
Baker Hughes
Bently Nevada 3500 Rack (USB and Serial Versions)
CWE-294: Authentication Bypass by Capture-replay
High
October 3, 2023
CVE-2023-34441
Baker Hughes
Bently Nevada 3500 Rack (USB and Serial Versions)
CWE-319: Cleartext Transmission of Sensitive Information
High
September 1, 2023
CVE-2023-31168
Schweitzer Engineering Laboratories (SEL)
SEL-5030 acSELerator QuickSet
Inclusion of Functionality from Untrusted Control Sphere
Medium
October 30, 2023
CVE-2023-43801
Arduino
Create Agent Service
Service Path Traversal
High
October 3, 2023
CVE-2023-34437
Baker Hughes
Bently Nevada 3500 Rack (USB and Serial Versions)
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
High
December 1, 2023
CVE-2023-34389
Schweitzer Engineering Laboratories (SEL)
SEL-451
Allocation of Resources Without Limits or Throttling
Medium
October 30, 2023
CVE-2023-43803
Arduino
Create Agent Service
Service Path Traversal
High
October 30, 2023
CVE-2023-43800
Arduino
Create Agent Service
Insufficient Verification of Data Authenticity
High
October 30, 2023
CVE-2023-43802
Arduino
Create Agent Service
Service Path Traversal
High
December 1, 2023
CVE-2023-31177
Schweitzer Engineering Laboratories (SEL)
SEL-451
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Medium
December 1, 2023
CVE-2023-34390
Schweitzer Engineering Laboratories (SEL)
SEL-451
Improper Input Validation
Medium
December 1, 2023
CVE-2023-31176
Schweitzer Engineering Laboratories (SEL)
SEL-451
Insufficient Entropy
High
December 1, 2023
CVE-2023-34388
Schweitzer Engineering Laboratories (SEL)
SEL-451
Improper Authentication
Medium
January 8, 2024
CVE-2023-41255
Advantech
TPC-110W
Improper Authorization
High
January 8, 2024
CVE-2023-46102
Advantech
TPC-110W
Use of Hard-coded Credentials
High
January 8, 2024
CVE-2023-45851
Advantech
TPC-110W
Missing Authentication for Critical Function
High
January 8, 2024
CVE-2023-45220
Advantech
TPC-110W
Missing Authentication for Critical Function
High
January 8, 2024
CVE-2023-45844
Advantech
TPC-110W
Improper Access Control
High
January 8, 2024
CVE-2023-45321
Advantech
TPC-110W
Cleartext Transmission of Information
High
January 8, 2024
CVE-2023-43488
Advantech
TPC-110W
Missing Authentication for Critical Function
High
January 8, 2024
CVE-2023-41960
Advantech
TPC-110W
Improper Export of Application Component
High
January 8, 2024
CVE-2023-41372
Advantech
TPC-110W
Use of Hard-coded Credentials
High
January 17, 2024
CVE-2023-48266
Bosch Rexroth
Nexo cordless nutrunners
Stack-based Buffer Overflow
High
January 17, 2024
CVE-2023-48265
Bosch Rexroth
Nexo cordless nutrunners
Stack-based Buffer Overflow
High
January 17, 2024
CVE-2023-48261
Bosch Rexroth
Nexo cordless nutrunners
Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)
Medium
January 17, 2024
CVE-2023-48264
Bosch Rexroth
Nexo cordless nutrunners
Stack-based Buffer Overflow
High
January 17, 2024
CVE-2023-48259
Bosch Rexroth
Nexo cordless nutrunners
Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)
Medium
January 17, 2024
CVE-2023-48262
Bosch Rexroth
Nexo cordless nutrunners
Stack-based Buffer Overflow
High
January 17, 2024
CVE-2023-48260
Bosch Rexroth
Nexo cordless nutrunners
Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)
Medium
January 17, 2024
CVE-2023-48263
Bosch Rexroth
Nexo cordless nutrunners
Heap-based Buffer Overflow
High
January 17, 2024
CVE-2023-48254
Bosch Rexroth
Nexo cordless nutrunners
Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
Medium
January 17, 2024
CVE-2023-48258
Bosch Rexroth
Nexo cordless nutrunners
Cross-Site Request Forgery (CSRF)
Medium
January 17, 2024
CVE-2023-48257
Bosch Rexroth
Nexo cordless nutrunners
Use of Weak Credentials
High
January 17, 2024
CVE-2023-48252
Bosch Rexroth
Nexo cordless nutrunners
Improper Authorization
High
January 17, 2024
CVE-2023-48256
Bosch Rexroth
Nexo cordless nutrunners
Improper Neutralization of CRLF Sequences in HTTP Headers (‘HTTP Response Splitting’)
Medium
January 17, 2024
CVE-2023-48255
Bosch Rexroth
Nexo cordless nutrunners
Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
Medium
January 17, 2024
CVE-2023-48253
Bosch Rexroth
Nexo cordless nutrunners
Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)
High
January 17, 2024
CVE-2023-48245
Bosch Rexroth
Nexo cordless nutrunners
Missing Authorization
Medium
January 17, 2024
CVE-2023-48246
Bosch Rexroth
Nexo cordless nutrunners
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)
Medium
January 17, 2024
CVE-2023-48251
Bosch Rexroth
Nexo cordless nutrunners
Use of Hard-coded Credentials
High
January 17, 2024
CVE-2023-48250
Bosch Rexroth
Nexo cordless nutrunners
Use of Hard-coded Credentials
High
January 17, 2024
CVE-2023-48249
Bosch Rexroth
Nexo cordless nutrunners
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)
Medium
January 17, 2024
CVE-2023-48248
Bosch Rexroth
Nexo cordless nutrunners
Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
Medium
January 17, 2024
CVE-2023-48247
Bosch Rexroth
Nexo cordless nutrunners
Missing Authorization
Medium
January 17, 2024
CVE-2023-48244
Bosch Rexroth
Nexo cordless nutrunners
Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
Medium
January 17, 2024
CVE-2023-48243
Bosch Rexroth
Nexo cordless nutrunners
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)
High
March 12, 2024
CVE-2023-45600
AiLux
imx6 bundle
Insufficient Session Expiration
Medium
January 17, 2024
CVE-2023-48242
Bosch Rexroth
Nexo cordless nutrunners
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)
Medium
March 12, 2024
CVE-2023-45599
AiLux
imx6 bundle
iec61850 Reliance on File Name or Extension of Externally-Supplied File
Medium
March 12, 2024
CVE-2023-45598
AiLux
imx6 bundle
measure Direct Request ('Forced Browsing')
Medium
March 12, 2024
CVE-2023-45596
AiLux
imx6 bundle
file_configuration Direct Request ('Forced Browsing')
Medium
March 12, 2024
CVE-2023-45591
AiLux
imx6 bundle
Ax_rtu logger_generic Heap-Based Buffer Overflow
High
March 12, 2024
CVE-2023-5456
AiLux
imx6 bundle
Use of Hard-coded MariaDB Password
High
March 12, 2024
CVE-2023-45597
AiLux
imx6 bundle
file_configuration Improper Neutralization of Formula Elements in a CSV File
Medium
March 12, 2024
CVE-2023-45595
AiLux
imx6 bundle
file_configuration Unrestricted Upload of File with Dangerous Type
Medium
March 12, 2024
CVE-2023-45593
AiLux
imx6 bundle
Chromium Alternative URLs Incomplete List of Disallowed Inputs
Medium
March 12, 2024
CVE-2023-45594
AiLux
imx6 bundle
Chromium Files or Directories Accessible to External Parties
Medium
March 12, 2024
CVE-2023-5457
AiLux
imx6 bundle
“Debug” Enabled in Django Framework Configuration
High
March 12, 2024
CVE-2023-45592
AiLux
imx6 bundle
Chromium Execution with Unnecessary Privileges
Medium
CVE ID
CVE-2025-11243
Vendor
Shelly
Product
Pro 4PM
Date Published
November 18, 2025
Type
Allocation of Resources Without Limits or Throttling
Risk Score
High
CVE ID
CVE-2025-12056
Vendor
Shelly
Product
Pro 3EM
Date Published
November 18, 2025
Type
Out-of-bounds Read
Risk Score
High
CVE ID
CVE-2025-11678
Vendor
warmcat
Product
libwebsockets
Date Published
October 10, 2025
Type
Stack-based Buffer Overflow
Risk Score
High
CVE ID
CVE-2025-11680
Vendor
warmcat
Product
libwebsockets
Date Published
October 10, 2025
Type
Out-of-bounds Write
Risk Score
Medium
CVE ID
CVE-2025-11677
Vendor
warmcat
Product
libwebsockets
Date Published
October 10, 2025
Type
Use after free
Risk Score
Medium
CVE ID
CVE-2025-11679
Vendor
warmcat
Product
libwebsockets
Date Published
October 10, 2025
Type
Out-of-bounds Read
Risk Score
Medium

Take the next step.

Discover how easy it is to identify and respond to cyber threats by automating your OT and IoT asset discovery, inventory, and management.