sauter-controls CVE Vulnerabilities & Metrics

Focus on sauter-controls vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About sauter-controls Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with sauter-controls. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total sauter-controls CVEs: 11
Earliest CVE date: 06 Feb 2016, 05:59 UTC
Latest CVE date: 27 Mar 2023, 20:15 UTC

Latest CVE reference: CVE-2023-28655

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical sauter-controls CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 1.36

Max CVSS: 6.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 9
4.0-6.9 2
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS sauter-controls CVEs

These are the five CVEs with the highest CVSS scores for sauter-controls, sorted by severity first and recency.

All CVEs for sauter-controls

CVE-2023-28655 sauter-controls vulnerability CVSS: 0 27 Mar 2023, 20:15 UTC

A malicious user could leverage this vulnerability to escalate privileges or perform unauthorized actions in the context of the targeted privileged users.

CVE-2023-28652 sauter-controls vulnerability CVSS: 0 27 Mar 2023, 20:15 UTC

An authenticated malicious user could successfully upload a malicious image could lead to a denial-of-service condition.

CVE-2023-28650 sauter-controls vulnerability CVSS: 0 27 Mar 2023, 20:15 UTC

An unauthenticated remote attacker could provide a malicious link and trick an unsuspecting user into clicking on it. If clicked, the attacker could execute the malicious JavaScript (JS) payload in the target’s security context.

CVE-2023-27927 sauter-controls vulnerability CVSS: 0 27 Mar 2023, 20:15 UTC

An authenticated malicious user could acquire the simple mail transfer protocol (SMTP) Password in cleartext format, despite it being protected and hidden behind asterisks. The attacker could then perform further attacks using the SMTP credentials.

CVE-2023-22300 sauter-controls vulnerability CVSS: 0 27 Mar 2023, 20:15 UTC

An unauthenticated remote attacker could force all authenticated users, such as administrative users, to perform unauthorized actions by viewing the logs. This action would also grant the attacker privilege escalation.

CVE-2023-0053 sauter-controls vulnerability CVSS: 0 02 Mar 2023, 01:15 UTC

SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior have only FTP and Telnet available for device management. Any sensitive information communicated through these protocols, such as credentials, is sent in cleartext. An attacker could obtain sensitive information such as user credentials to gain access to the system.

CVE-2023-0052 sauter-controls vulnerability CVSS: 0 20 Jan 2023, 22:15 UTC

SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior allows the execution of commands without credentials. As Telnet and file transfer protocol (FTP) are the only protocols available for device management, an unauthorized user could access the system and modify the device configuration, which could result in the unauthorized user executing unrestricted malicious commands.

CVE-2022-40190 sauter-controls vulnerability CVSS: 0 31 Oct 2022, 21:15 UTC

SAUTER Controls moduWeb firmware version 2.7.1 is vulnerable to reflective cross-site scripting (XSS). The web application does not adequately sanitize request strings of malicious JavaScript. An attacker utilizing XSS could then execute malicious code in users’ browsers and steal sensitive information, including user credentials.

CVE-2018-17912 sauter-controls vulnerability CVSS: 5.0 02 Nov 2018, 14:29 UTC

An XXE vulnerability exists in CASE Suite Versions 3.10 and prior when processing parameter entities, which may allow remote file disclosure.

CVE-2016-10224 sauter-controls vulnerability CVSS: 6.5 13 Feb 2017, 21:59 UTC

An issue was discovered in Sauter NovaWeb web HMI. The application uses a protection mechanism that relies on the existence or values of a cookie, but it does not properly ensure that the cookie is valid for the associated user.

CVE-2015-7916 sauter-controls vulnerability CVSS: 3.5 06 Feb 2016, 05:59 UTC

Cross-site scripting (XSS) vulnerability in Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 allows remote authenticated users to inject arbitrary web script or HTML via a crafted query.