Gira manufactures building automation and control products centered on KNX IP networking devices such as routers and gateways that serve as integration points for intelligent building systems. The observed vulnerabilities cluster around web-interface and command-processing mechanisms, with recurring exposure to path traversal, cross-site scripting, and OS command injection weaknesses characteristic of networked embedded device interfaces. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gira over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-10794CRITICAL Gira TKS-IP-Gateway 4.0.7.7 is vulnerable to unauthenticated path traversal that allows an attacker to download the application database. This can be combined with CVE-2020-10795 f | May 7, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-10795HIGH Gira TKS-IP-Gateway 4.0.7.7 is vulnerable to authenticated remote code execution via the backup functionality of the web frontend. This can be combined with CVE-2020-10794 for remo | May 7, 2020 | 7.2 | 26 | NO | NO |
CVE-2023-33277HIGH The web interface of Gira Giersiepen Gira KNX/IP-Router 3.1.3683.0 and 3.3.8.0 allows a remote attacker to read sensitive files via directory-traversal sequences in the URL. | Jun 29, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-2739MEDIUM A vulnerability classified as problematic was found in Gira HomeServer up to 4.12.0.220829 beta. This vulnerability affects unknown code of the file /hslist. The manipulation of th | May 16, 2023 | 6.1 | 21 | NO | NO |
CVE-2023-33276MEDIUM The web interface of Gira Giersiepen Gira KNX/IP-Router 3.1.3683.0 and 3.3.8.0 responds with a "404 - Not Found" status code if a path is accessed that does not exist. However, the | Jun 30, 2023 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gira.
Media articles that mention a CVE ID that affects a product developed by Gira — matched by CVE ID, not by vendor name.