Vulnerability Advisories

This page offers a comprehensive view of vulnerabilities identified by Nozomi Networks in critical OT, ICS, and IoT environments, showcasing the deep expertise and dedication of our world-class Security Research team.

Each advisory represents our ongoing effort to enhance the protection of industrial systems, identifying emerging threats before they can be exploited. Immediate protection is available through our Threat Intelligence (TI) subscription, supporting a proactive, forward-thinking defense strategy. For more on our responsible approach, refer to the Responsible Disclosure Policy.

Vulnerability Advisories

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Date Published
CVE ID
Vendor
Product
Type
Risk
Details
January 17, 2024
CVE-2023-48248
Bosch Rexroth
Nexo cordless nutrunners
Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
Medium
January 17, 2024
CVE-2023-48247
Bosch Rexroth
Nexo cordless nutrunners
Missing Authorization
Medium
January 17, 2024
CVE-2023-48244
Bosch Rexroth
Nexo cordless nutrunners
Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
Medium
January 17, 2024
CVE-2023-48243
Bosch Rexroth
Nexo cordless nutrunners
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)
High
March 12, 2024
CVE-2023-45600
AiLux
imx6 bundle
Insufficient Session Expiration
Medium
January 17, 2024
CVE-2023-48242
Bosch Rexroth
Nexo cordless nutrunners
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)
Medium
March 12, 2024
CVE-2023-45599
AiLux
imx6 bundle
iec61850 Reliance on File Name or Extension of Externally-Supplied File
Medium
March 12, 2024
CVE-2023-45598
AiLux
imx6 bundle
measure Direct Request ('Forced Browsing')
Medium
March 12, 2024
CVE-2023-45596
AiLux
imx6 bundle
file_configuration Direct Request ('Forced Browsing')
Medium
March 12, 2024
CVE-2023-45591
AiLux
imx6 bundle
Ax_rtu logger_generic Heap-Based Buffer Overflow
High
March 12, 2024
CVE-2023-5456
AiLux
imx6 bundle
Use of Hard-coded MariaDB Password
High
March 12, 2024
CVE-2023-45597
AiLux
imx6 bundle
file_configuration Improper Neutralization of Formula Elements in a CSV File
Medium
March 12, 2024
CVE-2023-45595
AiLux
imx6 bundle
file_configuration Unrestricted Upload of File with Dangerous Type
Medium
March 12, 2024
CVE-2023-45593
AiLux
imx6 bundle
Chromium Alternative URLs Incomplete List of Disallowed Inputs
Medium
March 12, 2024
CVE-2023-45594
AiLux
imx6 bundle
Chromium Files or Directories Accessible to External Parties
Medium
March 12, 2024
CVE-2023-5457
AiLux
imx6 bundle
“Debug” Enabled in Django Framework Configuration
High
March 12, 2024
CVE-2023-45592
AiLux
imx6 bundle
Chromium Execution with Unnecessary Privileges
Medium
CVE ID
CVE-2025-41660
Vendor
CODESYS
Product
Codesys Control
Date Published
March 24, 2026
Type
Incorrect Resource Transfer Between Spheres
Risk Score
High
CVE ID
CVE-2026-22323
Vendor
Phoenix Contact
Product
FL SWITCH TSN 2312-2GC-2SFP
Date Published
March 19, 2026
Type
Cross-Site Request Forgery (CSRF)
Risk Score
High
CVE ID
CVE-2026-22322
Vendor
Phoenix Contact
Product
FL SWITCH TSN 2312-2GC-2SFP
Date Published
March 19, 2026
Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Risk Score
High
CVE ID
CVE-2026-22318
Vendor
Phoenix Contact
Product
FL SWITCH TSN 2312-2GC-2SFP
Date Published
March 19, 2026
Type
Stack-based Buffer Overflow
Risk Score
Medium
CVE ID
CVE-2026-22320
Vendor
Phoenix Contact
Product
FL SWITCH TSN 2312-2GC-2SFP
Date Published
March 19, 2026
Type
Stack-based Buffer Overflow
Risk Score
Medium
CVE ID
CVE-2026-22317
Vendor
Phoenix Contact
Product
FL SWITCH TSN 2312-2GC-2SFP
Date Published
March 19, 2026
Type
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Risk Score
High

Take the next step.

Discover how easy it is to identify and respond to cyber threats by automating your OT and IoT asset discovery, inventory, and management.