Dexma's vulnerability footprint centers on its DexGate energy-management and building-automation product, with a durable signal in web application and credential-handling weaknesses including cleartext transmission of sensitive data, cross-site scripting, cross-site request forgery, and improper authentication. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dexma over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-42435HIGH
The affected product is vulnerable to a cross-site request forgery vulnerability, which may allow an attacker to perform actions with the permissions of a victim user.
| Oct 19, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-41089HIGH
The affected product is vulnerable to an improper authentication vulnerability, which may allow an attacker to impersonate a legitimate user as long as the device keeps th | Oct 19, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-41088MEDIUM
The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which may allow an attacker with access to the network, where clie | Oct 19, 2023 | 6.5 | 19 | NO | NO |
CVE-2023-40153MEDIUM
The affected product is vulnerable to a cross-site scripting vulnerability, which could allow an attacker to access the web application to introduce arbitrary Java Script by injec | Oct 19, 2023 | 6.1 | 19 | NO | NO |
CVE-2023-42666MEDIUM
The affected product is vulnerable to an exposure of sensitive information to an unauthorized actor vulnerability, which may allow an attacker to create malicious requ | Oct 19, 2023 | 5.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dexma.
Media articles that mention a CVE ID that affects a product developed by Dexma — matched by CVE ID, not by vendor name.