Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Danfoss

First CVE: Jun 11, 2023Active for: 3 yearsTotal CVEs: 10
38.9
VTI Score
Medium

Danfoss develops industrial automation and climate-control products, with a concentrated vulnerability footprint around its energy management and building automation appliances such as the AK-EM100 and AK-SM 800A controllers. The vendor's disclosures recur through application-layer weakness classes including sensitive-information exposure, cross-site scripting, cleartext credential storage, improper authentication, and input-validation flaws that reflect the web-interface and remote-management attack surface of deployed building systems. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
2.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Danfoss over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 11, 2023
3 years ago
Most Recent CVE
Aug 21, 2023
1,068 days ago

Self-Reporting Analysis

Of all the CVEs published by Danfoss as a CNA, 0.0% affect products that Danfoss develops as a vendor.

100.0%
Self-reported: 0 (0.0%)
Third-party: 3 (100.0%)

Of all the CVEs published that affect products developed by Danfoss, 0.0% are self-published by Danfoss as a CNA.

100.0%
Self-published: 0 (0.0%)
Other CNAs: 10 (100.0%)

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-22583CRITICAL
The Danfoss AK-EM100 web forms allow for SQL injection in the login forms.
Jun 11, 20239.827NONO
CVE-2023-25911HIGH
The Danfoss AK-EM100 web applications allow for an authenticated user to perform OS command injection through the web application parameters.
Jun 11, 20238.825NONO
CVE-2023-25915HIGH
Due to improper input validation, an authenticated remote attacker could execute arbitrary commands on the target system.
Aug 21, 20238.824NONO
CVE-2023-25914HIGH
Due to improper restriction, authenticated attackers could retrieve and read system files of the underlying server through the XML interface. The information that can be read can l
Aug 21, 20238.823NONO
CVE-2023-22585MEDIUM
The Danfoss AK-EM100 web applications allow for Reflected Cross-Site Scripting in the title parameter.
Jun 11, 20236.121NONO
CVE-2023-22584HIGH
The Danfoss AK-EM100 stores login credentials in cleartext.
Jun 11, 20237.521NONO
CVE-2023-25913HIGH
Because of an authentication flaw an attacker would be capable of generating a web report that discloses sensitive information such as internal IP addresses, usernames, store names
Aug 21, 20237.520NONO
CVE-2023-22586HIGH
The Danfoss AK-EM100 web applications allow for Local File Inclusion in the file parameter.
Jun 11, 20237.520NONO
CVE-2023-22582MEDIUM
The Danfoss AK-EM100 web applications allow for Reflected Cross-Site Scripting.
Jun 11, 20236.119NONO
CVE-2023-25912MEDIUM
The webreport generation feature in the Danfoss AK-EM100 allows an unauthorized actor to generate a web report that discloses sensitive information such as the internal IP address,
Jun 11, 20235.316NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
30%
60%
10%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (80.0%)
Unknown0 (0.0%)
Required2 (20.0%)
Privileges Required
Low3 (30.0%)
High0 (0.0%)
None7 (70.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Danfoss.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Danfoss — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Danfoss's Products

View all 1 CNAs →

Top CWEs