Automatedlogic develops a focused product line centered on building automation and facility management systems, including the i-vu, WebCTRL, and SiteScan Web platforms that manage HVAC, security, and energy control in commercial and institutional environments. The vendor's vulnerability disclosures concentrate around web-facing components and recur through weakness classes including path traversal, cross-site scripting, XML external entity injection, open redirects, and unquoted search paths—all characteristic of input-handling and URI-processing flaws in web-accessible management interfaces. Defenders managing these systems should prioritize patching to restrict direct internet exposure of these administrative platforms; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Automatedlogic over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-31682MEDIUM The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for reflected XSS attacks due to the operatorlocale GET parameter | Oct 22, 2021 | 6.1 | 43 | NO | YES |
CVE-2017-9650HIGH An Unrestricted Upload of File with Dangerous Type issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan We | Aug 25, 2017 | 7.8 | 36 | NO | YES |
CVE-2017-9640MEDIUM A Path Traversal issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web prior to 6.5; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu | Aug 25, 2017 | 6.3 | 35 | NO | YES |
CVE-2017-9644HIGH An Unquoted Search Path or Element issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; | Aug 25, 2017 | 7.0 | 33 | NO | YES |
CVE-2016-5795HIGH An XXE issue was discovered in Automated Logic Corporation (ALC) Liebert SiteScan Web Version 6.5 and prior, ALC WebCTRL Version 6.5 and prior, and Carrier i-Vu Version 6.5 and pri | Aug 31, 2017 | 7.3 | 24 | NO | NO |
CVE-2022-1019MEDIUM Automated Logic's WebCtrl Server Version 6.1 'Help' index pages are vulnerable to open redirection. The vulnerability allows an attacker to send a maliciously crafted URL which cou | Apr 19, 2022 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Automatedlogic.
Media articles that mention a CVE ID that affects a product developed by Automatedlogic — matched by CVE ID, not by vendor name.