Busch Jaeger manufactures building automation and control systems, with vulnerability disclosures centered on its 6186/11 gateway device and associated firmware, as well as its mybusch_jaeger cloud-connected management platform. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Busch Jaeger over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-22272CRITICAL The vulnerability origins in the commissioning process where an attacker of the ControlTouch can enter a serial number in a specific way to transfer the device virtually into her/h | Sep 27, 2021 | 9.4 | 28 | NO | NO |
CVE-2019-19104CRITICAL The web server in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway allows access to different endpoints of the application without authenticating by accessin | Apr 22, 2020 | 9.8 | 28 | NO | NO |
CVE-2019-19106CRITICAL Improper implementation of Access Control in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway allows an unauthorized user to access data marked as restricted | Apr 22, 2020 | 9.1 | 27 | NO | NO |
CVE-2019-19107MEDIUM The Configuration pages in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway for user profiles and services transfer the password in plaintext (although hidde | Apr 22, 2020 | 5.5 | 18 | NO | NO |
CVE-2019-19105MEDIUM The backup function in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway saves the current settings and configuration of the application, including credential | Apr 22, 2020 | 5.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Busch Jaeger.
Media articles that mention a CVE ID that affects a product developed by Busch Jaeger — matched by CVE ID, not by vendor name.