Infinite Automation Systems maintains Mango Automation, a web-based industrial control and data-acquisition platform deployed across operational-technology environments, whose vulnerability profile reflects the inherent risks of internet-facing automation software. The recurring weakness classes—including information disclosure, cross-site scripting, cross-site request forgery, OS command injection, and SQL injection—are characteristic of web application input handling and access control, spanning both client-side and server-side attack surfaces. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Infinite Automation Systems over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-7901MEDIUM Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenticated users to execute arbitrary OS commands via unspecified vectors. | Oct 28, 2015 | 6.5 | 33 | NO | YES |
CVE-2015-7904MEDIUM Unrestricted file upload vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated users to execute arbitrary JSP cod | Oct 28, 2015 | 6.5 | 32 | NO | YES |
CVE-2015-7903MEDIUM SQL injection vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated users to execute arbitrary SQL commands via u | Oct 28, 2015 | 6.5 | 32 | NO | YES |
CVE-2015-6493MEDIUM Cross-site request forgery (CSRF) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenticated users to hijack the auth | Oct 28, 2015 | 6.8 | 26 | NO | YES |
CVE-2015-7902MEDIUM Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 provides different error messages for failed login attempts in unspecified circumstances, which allows r | Oct 28, 2015 | 5.0 | 23 | NO | YES |
CVE-2015-7900MEDIUM Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote attackers to obtain sensitive debugging information by entering a crafted URL to trigger a | Oct 28, 2015 | 4.3 | 22 | NO | YES |
Cross-site scripting (XSS) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated users to inject arbitrary web sc | Oct 28, 2015 | 3.5 | 19 | NO | YES |
CVE-2015-1179MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in data_point_details.shtm in Mango Automation 2.4.0 and earlier allow remote attackers to inject arbitrary web script or HTML v | Jan 26, 2015 | 4.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Infinite Automation Systems.
Media articles that mention a CVE ID that affects a product developed by Infinite Automation Systems — matched by CVE ID, not by vendor name.