LS Electric's vulnerability footprint centers on industrial control and automation products, including programmable logic controllers and firmware components such as the XBC and XEC controller families, which serve critical infrastructure and manufacturing environments. The exposure spans a modest volume of disclosures but reaches a prominent segment of the control-systems landscape where deployment longevity and operational constraints make patching cycles slow; defenders should inventory affected devices and assess their network isolation posture. Current severity, exploitation activity, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ls Electric over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-22807CRITICAL LS ELECTRIC XBC-DN32U with operating system version 01.80 does not properly control access to the PLC over its internal XGT protocol. An attacker could control and tamper with the | Feb 15, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-22804CRITICAL LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to create users on the PLC. This could allow an attacker to create and use an account with eleva | Feb 15, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-22803HIGH LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to perform critical functions to the PLC. This could allow an attacker to change the PLC's mode | Feb 15, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-0103HIGH If an attacker were to access memory locations of LS ELECTRIC XBC-DN32U with operating system version 01.80 that are outside of the communication buffer, the device stops operating | Feb 15, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-22806HIGH LS ELECTRIC XBC-DN32U with operating system version 01.80 transmits sensitive information in cleartext when communicating over its XGT protocol. This could allow an attacker to gai | Feb 15, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-0102CRITICAL LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication for its deletion command. This could allow an attacker to delete arbitrary files.
| Feb 15, 2023 | 9.1 | 22 | NO | NO |
CVE-2022-2758MEDIUM Passwords are not adequately encrypted during the communication process between all versions of LS Industrial Systems (LSIS) Co. Ltd LS Electric XG5000 software prior to V4.0 and L | Aug 31, 2022 | 5.9 | 22 | NO | NO |
CVE-2023-22805MEDIUM LS ELECTRIC XBC-DN32U with operating system version 01.80 has improper access control to its read prohibition feature. This could allow a remote attacker to remotely set the featur | Feb 15, 2023 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ls Electric.
Media articles that mention a CVE ID that affects a product developed by Ls Electric — matched by CVE ID, not by vendor name.