Vulnerability Advisories

This page offers a comprehensive view of vulnerabilities identified by Nozomi Networks in critical OT, ICS, and IoT environments, showcasing the deep expertise and dedication of our world-class Security Research team.

Each advisory represents our ongoing effort to enhance the protection of industrial systems, identifying emerging threats before they can be exploited. Immediate protection is available through our Threat Intelligence (TI) subscription, supporting a proactive, forward-thinking defense strategy. For more on our responsible approach, refer to the Responsible Disclosure Policy.

Vulnerability Advisories

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Date Published
CVE ID
Vendor
Product
Type
Risk
Details
March 12, 2024
CVE-2023-45591
AiLux
imx6 bundle
Ax_rtu logger_generic Heap-Based Buffer Overflow
High
March 12, 2024
CVE-2023-5456
AiLux
imx6 bundle
Use of Hard-coded MariaDB Password
High
March 12, 2024
CVE-2023-45597
AiLux
imx6 bundle
file_configuration Improper Neutralization of Formula Elements in a CSV File
Medium
March 12, 2024
CVE-2023-45595
AiLux
imx6 bundle
file_configuration Unrestricted Upload of File with Dangerous Type
Medium
March 12, 2024
CVE-2023-45593
AiLux
imx6 bundle
Chromium Alternative URLs Incomplete List of Disallowed Inputs
Medium
March 12, 2024
CVE-2023-45594
AiLux
imx6 bundle
Chromium Files or Directories Accessible to External Parties
Medium
March 12, 2024
CVE-2023-5457
AiLux
imx6 bundle
“Debug” Enabled in Django Framework Configuration
High
March 12, 2024
CVE-2023-45592
AiLux
imx6 bundle
Chromium Execution with Unnecessary Privileges
Medium
CVE ID
CVE-2026-2273
Vendor
Schneider Electric
Product
EcoStruxure™ Automation Expert
Date Published
March 10, 2026
Type
Improper Control of Generation of Code ('Code Injection')
Risk Score
High
CVE ID
CVE-2026-22614
Vendor
Eaton
Product
EasySoft
Date Published
March 11, 2026
Type
Insufficiently Protected Credentials
Risk Score
Medium
CVE ID
CVE-2026-3588
Vendor
Ikea
Product
Dirigera
Date Published
March 9, 2026
Type
Server Side Request Forgery
Risk Score
High
CVE ID
CVE-2026-26098
Vendor
Owl
Product
opds
Date Published
February 23, 2026
Type
Uncontrolled Search Path Element
Risk Score
High
CVE ID
CVE-2026-26101
Vendor
Owl
Product
opds
Date Published
February 23, 2026
Type
Incorrect Permission Assignment for Critical Resource
Risk Score
High
CVE ID
CVE-2026-26099
Vendor
Owl
Product
opds
Date Published
February 23, 2026
Type
Uncontrolled Search Path Element
Risk Score
High

Take the next step.

Discover how easy it is to identify and respond to cyber threats by automating your OT and IoT asset discovery, inventory, and management.