Danfoss develops industrial automation and climate-control products, with a concentrated vulnerability footprint around its energy management and building automation appliances such as the AK-EM100 and AK-SM 800A controllers. The vendor's disclosures recur through application-layer weakness classes including sensitive-information exposure, cross-site scripting, cleartext credential storage, improper authentication, and input-validation flaws that reflect the web-interface and remote-management attack surface of deployed building systems. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Danfoss over time
Of all the CVEs published by Danfoss as a CNA, 0.0% affect products that Danfoss develops as a vendor.
Of all the CVEs published that affect products developed by Danfoss, 0.0% are self-published by Danfoss as a CNA.
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-22583CRITICAL The Danfoss AK-EM100 web forms allow for SQL injection in the login forms. | Jun 11, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-25911HIGH The Danfoss AK-EM100 web applications allow for an authenticated user to perform OS command injection through the web application parameters. | Jun 11, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-25915HIGH Due to improper input validation, an authenticated remote attacker could execute arbitrary commands on the target system. | Aug 21, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-25914HIGH Due to improper restriction, authenticated attackers could retrieve and read system files of the underlying server through the XML interface. The information that can be read can l | Aug 21, 2023 | 8.8 | 23 | NO | NO |
CVE-2023-22585MEDIUM The Danfoss AK-EM100 web applications allow for Reflected Cross-Site Scripting in the title parameter. | Jun 11, 2023 | 6.1 | 21 | NO | NO |
CVE-2023-22584HIGH The Danfoss AK-EM100 stores login credentials in cleartext. | Jun 11, 2023 | 7.5 | 21 | NO | NO |
CVE-2023-25913HIGH Because of an authentication flaw an attacker would be capable of generating a web report that discloses sensitive information such as internal IP addresses, usernames, store names | Aug 21, 2023 | 7.5 | 20 | NO | NO |
CVE-2023-22586HIGH The Danfoss AK-EM100 web applications allow for Local File Inclusion in the file parameter. | Jun 11, 2023 | 7.5 | 20 | NO | NO |
CVE-2023-22582MEDIUM The Danfoss AK-EM100 web applications allow for Reflected Cross-Site Scripting. | Jun 11, 2023 | 6.1 | 19 | NO | NO |
CVE-2023-25912MEDIUM The webreport generation feature in the Danfoss AK-EM100 allows an unauthorized actor to generate a web report that discloses sensitive information such as the internal IP address, | Jun 11, 2023 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Danfoss.
Media articles that mention a CVE ID that affects a product developed by Danfoss — matched by CVE ID, not by vendor name.