Fatek maintains a focused portfolio of industrial automation and control software products, including design and programming tools such as FVDesigner, WinProLadder, and its PM/Automation Designer suite, which serve embedded and operational-technology environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through memory-safety weakness classes including out-of-bounds writes and reads, stack-based buffer overflows, and improper bounds restrictions that are characteristic of compiled control software. The exposure footprint is narrower than many enterprise vendors but carries elevated risk in critical infrastructure and manufacturing settings where these tools are deployed to program industrial devices. Defenders should prioritize patching instances of these design tools, particularly in air-gapped or legacy automation environments where upgrades may be delayed; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fatek over time
Signals from CVEs in this vendor scope (44 CVEs).
44 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-8377HIGH An issue was discovered in Fatek Automation PLC WinProladder Version 3.11 Build 14701. A stack-based buffer overflow vulnerability exists when the software application connects to | Feb 13, 2017 | 8.0 | 33 | NO | YES |
CVE-2017-6023CRITICAL An issue was discovered in Fatek Automation PLC Ethernet Module. The affected Ether_cfg software configuration tool runs on the following Fatek PLCs: CBEH versions prior to V3.6 Bu | Mar 16, 2017 | 9.8 | 32 | NO | NO |
CVE-2021-38432CRITICAL FATEK Automation Communication Server Versions 1.13 and prior lacks proper validation of user-supplied data, which could result in a stack-based buffer overflow condition and allow | Oct 15, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-32992CRITICAL FATEK Automation WinProladder Versions 3.30 and prior do not properly restrict operations within the bounds of a memory buffer, which may allow an attacker to execute arbitrary cod | Jun 29, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-32990CRITICAL FATEK Automation WinProladder Versions 3.30 and prior are vulnerable to an out-of-bounds read, which may allow an attacker to execute arbitrary code. | Jun 29, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-32988CRITICAL FATEK Automation WinProladder Versions 3.30 and prior are vulnerable to an out-of-bounds write, which may allow an attacker to execute arbitrary code. | Jun 29, 2021 | 9.8 | 29 | NO | NO |
CVE-2016-5796HIGH An issue was discovered in Fatek Automation PM Designer V3 Version 2.1.2.2, and Automation FV Designer Version 1.2.8.0. Sending additional valid packets could allow the attacker to | Feb 13, 2017 | 8.8 | 28 | NO | NO |
CVE-2021-43556HIGH FATEK WinProladder Versions 3.30_24518 and prior are vulnerable to a stack-based buffer overflow while processing project files, which may allow an attacker to execute arbitrary co | Dec 28, 2021 | 7.8 | 26 | NO | NO |
CVE-2021-43554HIGH FATEK WinProladder Versions 3.30_24518 and prior are vulnerable to an out-of-bounds write while processing project files, which may allow an attacker to execute arbitrary code. | Dec 28, 2021 | 7.8 | 26 | NO | NO |
CVE-2022-25170HIGH The affected product is vulnerable to a stack-based buffer overflow while processing project files, which may allow an attacker to execute arbitrary code | Feb 25, 2022 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (44 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fatek.
Media articles that mention a CVE ID that affects a product developed by Fatek — matched by CVE ID, not by vendor name.