Ingeteam develops a narrow portfolio of power-conversion and grid-management devices, primarily its Ingepac inverter and controller firmware lines, which sit at the intersection of renewable energy infrastructure and industrial control networks. The observed vulnerability profile centers on input-validation and authorization-handling weaknesses typical of embedded systems with network interfaces, alongside sensitive-information exposure risks. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ingeteam over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-3768HIGH Incorrect data input validation vulnerability, which could allow an attacker with access to the network to implement fuzzing techniques that would allow him to gain knowledge about | Oct 2, 2023 | 7.5 | 25 | NO | NO |
CVE-2023-3769HIGH Incorrect data input validation vulnerability, which could allow an attacker with access to the network to implement fuzzing techniques that would allow him to gain knowledge about | Oct 2, 2023 | 7.5 | 23 | NO | NO |
CVE-2017-20007MEDIUM Ingeteam INGEPAC DA AU AUC_1.13.0.28 (and before) web application allows access to a certain path that contains sensitive information that could be used by an attacker to execute m | Oct 25, 2021 | 5.3 | 20 | NO | NO |
CVE-2023-3770MEDIUM
Incorrect validation vulnerability of the data entered, allowing an attacker with access to the network on which the affected device is located to use the discovery port protocol | Oct 2, 2023 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ingeteam.
Media articles that mention a CVE ID that affects a product developed by Ingeteam — matched by CVE ID, not by vendor name.