Busbaer's vulnerability footprint centers on the Eisbaer SCADA system, a narrowly scoped but critical industrial control platform. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through a pattern of dangerous method exposure, sensitive information disclosure, improper authorization and access control, path traversal, and permission misconfigurations—all of which are characteristic of legacy or insufficiently hardened supervisory control environments. Defenders operating SCADA and industrial systems using this platform should treat patches and access restriction as high priority; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Busbaer over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-42493CRITICAL EisBaer Scada - CWE-256: Plaintext Storage of a Password | Oct 25, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-42492CRITICAL EisBaer Scada - CWE-321: Use of Hard-coded Cryptographic Key | Oct 25, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-42491CRITICAL EisBaer Scada - CWE-285: Improper Authorization | Oct 25, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-42494CRITICAL EisBaer Scada - CWE-749: Exposed Dangerous Method or Function | Oct 25, 2023 | 9.8 | 25 | NO | NO |
CVE-2023-42489CRITICAL EisBaer Scada - CWE-732: Incorrect Permission Assignment for Critical Resource | Oct 25, 2023 | 9.8 | 25 | NO | NO |
CVE-2023-42488HIGH EisBaer Scada - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Oct 25, 2023 | 7.5 | 20 | NO | NO |
CVE-2023-42490HIGH
EisBaer Scada - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
| Oct 25, 2023 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Busbaer.
Media articles that mention a CVE ID that affects a product developed by Busbaer — matched by CVE ID, not by vendor name.