Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Fatek

First CVE: Feb 13, 2017Active for: 9 yearsTotal CVEs: 44
51.3
VTI Score
TOP TARGET

Fatek maintains a focused portfolio of industrial automation and control software products, including design and programming tools such as FVDesigner, WinProLadder, and its PM/Automation Designer suite, which serve embedded and operational-technology environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through memory-safety weakness classes including out-of-bounds writes and reads, stack-based buffer overflows, and improper bounds restrictions that are characteristic of compiled control software. The exposure footprint is narrower than many enterprise vendors but carries elevated risk in critical infrastructure and manufacturing settings where these tools are deployed to program industrial devices. Defenders should prioritize patching instances of these design tools, particularly in air-gapped or legacy automation environments where upgrades may be delayed; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
44
Total CVEs
More Total CVEs than 98% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Fatek over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 13, 2017
9 years ago
Most Recent CVE
May 3, 2024
812 days ago

Products(14 total)

Top CVEs

Signals from CVEs in this vendor scope (44 CVEs).

44 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2016-8377HIGH
An issue was discovered in Fatek Automation PLC WinProladder Version 3.11 Build 14701. A stack-based buffer overflow vulnerability exists when the software application connects to
Feb 13, 20178.033NOYES
CVE-2017-6023CRITICAL
An issue was discovered in Fatek Automation PLC Ethernet Module. The affected Ether_cfg software configuration tool runs on the following Fatek PLCs: CBEH versions prior to V3.6 Bu
Mar 16, 20179.832NONO
CVE-2021-38432CRITICAL
FATEK Automation Communication Server Versions 1.13 and prior lacks proper validation of user-supplied data, which could result in a stack-based buffer overflow condition and allow
Oct 15, 20219.829NONO
CVE-2021-32992CRITICAL
FATEK Automation WinProladder Versions 3.30 and prior do not properly restrict operations within the bounds of a memory buffer, which may allow an attacker to execute arbitrary cod
Jun 29, 20219.829NONO
CVE-2021-32990CRITICAL
FATEK Automation WinProladder Versions 3.30 and prior are vulnerable to an out-of-bounds read, which may allow an attacker to execute arbitrary code.
Jun 29, 20219.829NONO
CVE-2021-32988CRITICAL
FATEK Automation WinProladder Versions 3.30 and prior are vulnerable to an out-of-bounds write, which may allow an attacker to execute arbitrary code.
Jun 29, 20219.829NONO
CVE-2016-5796HIGH
An issue was discovered in Fatek Automation PM Designer V3 Version 2.1.2.2, and Automation FV Designer Version 1.2.8.0. Sending additional valid packets could allow the attacker to
Feb 13, 20178.828NONO
CVE-2021-43556HIGH
FATEK WinProladder Versions 3.30_24518 and prior are vulnerable to a stack-based buffer overflow while processing project files, which may allow an attacker to execute arbitrary co
Dec 28, 20217.826NONO
CVE-2021-43554HIGH
FATEK WinProladder Versions 3.30_24518 and prior are vulnerable to an out-of-bounds write while processing project files, which may allow an attacker to execute arbitrary code.
Dec 28, 20217.826NONO
CVE-2022-25170HIGH
The affected product is vulnerable to a stack-based buffer overflow while processing project files, which may allow an attacker to execute arbitrary code
Feb 25, 20227.825NONO
View all 44 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products44 CVEs
86%
11%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowHighCritical
Attack Vector
Local35 (79.5%)
Network9 (20.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low44 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (15.9%)
Unknown0 (0.0%)
Required37 (84.1%)
Privileges Required
Low1 (2.3%)
High0 (0.0%)
None43 (97.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (44 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.3% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Fatek.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Fatek — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Fatek's Products

View all 2 CNAs →

Top CWEs