ARC Informatique is a small vendor focused on industrial automation and plant-management software, with its vulnerability exposure centered on products such as Frontvue, PCVue, and Plantvue. Observed disclosures involve memory-safety and bounds-checking weaknesses characteristic of legacy industrial control and supervisory systems. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by ARC Informatique over time
Of all the CVEs published by ARC Informatique as a CNA, 100.0% affect products that ARC Informatique develops as a vendor.
Of all the CVEs published that affect products developed by ARC Informatique, 58.3% are self-published by ARC Informatique as a CNA.
Signals from CVEs in this vendor scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-4044MEDIUM An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to modify files via calls to unknown method | Apr 3, 2012 | 5.8 | 53 | NO | YES |
CVE-2011-4043HIGH Integer overflow in an unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute arbitrary co | Apr 3, 2012 | 9.3 | 44 | NO | YES |
CVE-2011-4042HIGH An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute arbitrary code by using a crafte | Apr 3, 2012 | 9.3 | 42 | NO | YES |
CVE-2020-26867CRITICAL ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code on the we | Oct 12, 2020 | 9.8 | 35 | NO | NO |
CVE-2026-14868MEDIUM The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of PcVue projects, all versions prior to 17.0.0, is not strong en | Jul 7, 2026 | 5.5 | 29 | NO | NO |
CVE-2026-1693HIGH The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in v | Feb 26, 2026 | 7.5 | 28 | NO | NO |
CVE-2011-4045MEDIUM Buffer overflow in an unspecified ActiveX control in aipgctl.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to cause a denial of ser | Apr 3, 2012 | 4.3 | 28 | NO | YES |
CVE-2026-14867MEDIUM Credentials of built-in users are insecurely stored in the User directory of PcVue projects, all versions prior to 17.0.0. A local attacker could retrieve users’ credentials.
Act | Jul 7, 2026 | 5.5 | 27 | NO | NO |
CVE-2020-26869HIGH ARC Informatique PcVue prior to version 12.0.17 is vulnerable to information exposure, allowing unauthorized users to access session data of legitimate users. This issue also affec | Oct 12, 2020 | 7.5 | 27 | NO | NO |
CVE-2020-26868HIGH ARC Informatique PcVue prior to version 12.0.17 is vulnerable to a denial-of-service attack due to the ability of an unauthorized user to modify information used to validate messag | Oct 12, 2020 | 7.5 | 27 | NO | NO |
Signals from CVEs in this vendor scope (24 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by ARC Informatique.
Media articles that mention a CVE ID that affects a product developed by ARC Informatique — matched by CVE ID, not by vendor name.