Skip to main content

Vendor archive

trianglemicroworks CVEs

Beta · best-effort

25 CVEs tagged to vendor trianglemicroworks3 Critical, 13 High, 8 Medium, 1 Low, 0 Unrated.

CVE-2024-34057

Published Sep 18, 2024

Triangle Microworks TMW IEC 61850 Client source code libraries before 12.2.0 lack a buffer size check when processing received messages. The resulting buffer overflow can cause a…

CVSS 7.5 · High

CVE-2022-0369

Published May 7, 2024

Triangle MicroWorks SCADA Data Gateway Restore Workspace Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary c…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39468

Published May 3, 2024

Triangle MicroWorks SCADA Data Gateway DbasSectorFileToExecuteOnReset Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39467

Published May 3, 2024

Triangle MicroWorks SCADA Data Gateway certificate Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected i…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39466

Published May 3, 2024

Triangle MicroWorks SCADA Data Gateway get_config Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive inf…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39465

Published May 3, 2024

Triangle MicroWorks SCADA Data Gateway Use of Hard-coded Cryptograhic Key Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive in…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39464

Published May 3, 2024

Triangle MicroWorks SCADA Data Gateway GTWWebMonitorService Unquoted Search Path Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute code on…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39463

Published May 3, 2024

Triangle MicroWorks SCADA Data Gateway Trusted Certification Unrestricted Upload of File Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39462

Published May 3, 2024

Triangle MicroWorks SCADA Data Gateway Workspace Unrestricted Upload Vulnerability. This vulnerability allows remote attackers to upload arbitrary files on affected installations…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39461

Published May 3, 2024

Triangle MicroWorks SCADA Data Gateway Event Log Improper Output Neutralization For Logs Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to write ar…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39460

Published May 3, 2024

Triangle MicroWorks SCADA Data Gateway Event Log Directory Traversal Arbitrary File Creation Vulnerability. This vulnerability allows remote attackers to create arbitrary files on…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39459

Published May 3, 2024

Triangle MicroWorks SCADA Data Gateway Directory Traversal Arbitrary File Creation Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39458

Published May 3, 2024

Triangle MicroWorks SCADA Data Gateway Use of Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentica…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39457

Published May 3, 2024

Triangle MicroWorks SCADA Data Gateway Missing Authentication Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Trian…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-2187

Published Jun 7, 2023

On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send broadcast events to any user via the WebMonitor.An unauthenticated user can us…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2186

Published Jun 7, 2023

On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send a specially crafted broadcast message including format string characters to th…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10613

Published Apr 15, 2020

Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers to disclose sensitive information due to the lack of proper val…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10611

Published Apr 15, 2020

Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers to execute arbitrary code due to the lack of proper validation…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-2342

Published May 30, 2014

Triangle MicroWorks SCADA Data Gateway before 3.00.0635 allows remote attackers to cause a denial of service (excessive data processing) via a crafted DNP3 packet.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 25 CVEsPage 1 of 1