carel CVE Vulnerabilities & Metrics

Focus on carel vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About carel Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with carel. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total carel CVEs: 10
Earliest CVE date: 30 Jan 2016, 15:59 UTC
Latest CVE date: 12 Jul 2023, 18:15 UTC

Latest CVE reference: CVE-2023-3643

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical carel CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.28

Max CVSS: 10.0

Critical CVEs (≥9): 1

CVSS Range vs. Count

Range Count
0.0-3.9 4
4.0-6.9 3
7.0-8.9 2
9.0-10.0 1

CVSS Distribution Chart

Top 5 Highest CVSS carel CVEs

These are the five CVEs with the highest CVSS scores for carel, sorted by severity first and recency.

All CVEs for carel

CVE-2023-3643 carel vulnerability CVSS: 7.5 12 Jul 2023, 18:15 UTC

A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/document. The manipulation of the argument path leads to file inclusion. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-233889 was assigned to this vulnerability.

CVE-2020-18329 carel vulnerability CVSS: 0 26 Jan 2023, 21:15 UTC

An issue was discovered in Rehau devices that use a pCOWeb card BIOS v6.27, BOOT v5.00, web version v2.2, allows attackers to gain full unauthenticated access to the configuration and service interface.

CVE-2022-34827 carel vulnerability CVSS: 0 18 Nov 2022, 23:15 UTC

Carel Boss Mini 1.5.0 has Improper Access Control.

CVE-2022-37122 carel vulnerability CVSS: 0 31 Aug 2022, 16:15 UTC

Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 suffers from an unauthenticated arbitrary file disclosure vulnerability. Input passed through the 'file' GET parameter through the 'logdownload.cgi' Bash script is not properly verified before being used to download log files. This can be exploited to disclose the contents of arbitrary and sensitive files via directory traversal attacks.

CVE-2019-13553 carel vulnerability CVSS: 10.0 25 Oct 2019, 18:15 UTC

Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems is configured using hard-coded credentials. These credentials could allow attackers to influence the primary operations of the affected systems, namely turning the cooling unit on and off and setting the temperature set point.

CVE-2019-13549 carel vulnerability CVSS: 5.0 25 Oct 2019, 18:15 UTC

Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems does not provide a sufficient level of protection against unauthorized configuration changes. Primary operations, namely turning the cooling unit on and off and setting the temperature set point, can be modified without authentication.

CVE-2019-11370 carel vulnerability CVSS: 3.5 03 Jun 2019, 20:29 UTC

Stored XSS was discovered in Carel pCOWeb prior to B1.2.4, as demonstrated by the config/pw_snmp.html "System contact" field.

CVE-2019-11369 carel vulnerability CVSS: 4.0 03 Jun 2019, 20:29 UTC

An issue was discovered in Carel pCOWeb prior to B1.2.4. In /config/pw_changeusers.html the device stores cleartext passwords, which may allow sensitive information to be read by someone with access to the device.

CVE-2019-9484 carel vulnerability CVSS: 5.0 01 Mar 2019, 07:29 UTC

The Glen Dimplex Deutschland GmbH implementation of the Carel pCOWeb configuration tool allows remote attackers to obtain access via an HTTP session on port 10000, as demonstrated by reading the modem password (which is 1234), or reconfiguring "party mode" or "vacation mode."

CVE-2016-0867 carel vulnerability CVSS: 7.8 30 Jan 2016, 15:59 UTC

CAREL PlantVisorEnhanced allows remote attackers to bypass intended access restrictions via a direct file request.