Atvise develops industrial control and web-based supervisory software, particularly its webMI2ADS and Atvise products, which sit in critical operational technology environments and present a narrow but high-value attack surface. The vendor's vulnerability disclosures cluster around application-layer weaknesses—cleartext transmission of sensitive information, code injection, input validation failures, and path traversal—that are characteristic of web-facing control interfaces, and public exploit code has frequently become available for these flaws. Defenders should prioritize patching this vendor's releases in operational technology deployments and restrict network access to these systems; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Atvise over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-4881MEDIUM The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 does not properly check return values from functions, which allows remote attackers to cause a denial of service | Apr 13, 2012 | 5.0 | 29 | NO | YES |
CVE-2011-4880MEDIUM Directory traversal vulnerability in the web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 allows remote attackers to read arbitrary files via a crafted HTTP request. | Apr 13, 2012 | 5.0 | 28 | NO | YES |
CVE-2011-4882MEDIUM The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 allows remote attackers to cause a denial of service (application exit) via an unspecified command in an HTTP req | Apr 13, 2012 | 5.0 | 27 | NO | YES |
CVE-2011-4883MEDIUM The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 does not properly validate values in HTTP requests, which allows remote attackers to cause a denial of service (r | Apr 13, 2012 | 5.0 | 26 | NO | YES |
CVE-2022-21184MEDIUM An information disclosure vulnerability exists in the License registration functionality of Bachmann Visutec GmbH Atvise 3.5.4, 3.6 and 3.7. A plaintext HTTP request can lead to a | Jun 17, 2022 | 5.9 | 21 | NO | NO |
CVE-2011-4873MEDIUM Unspecified vulnerability in the server in Certec EDV atvise before 2.1 allows remote attackers to cause a denial of service (daemon crash) via crafted requests to TCP port 4840. | Jan 19, 2012 | 5.0 | 18 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Atvise.
Media articles that mention a CVE ID that affects a product developed by Atvise — matched by CVE ID, not by vendor name.