Machinesense's vulnerability footprint is concentrated in its FeverWarn product line, a network-monitoring and alerting system where exposure centers on authentication and access-control weaknesses affecting both the application and firmware components. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes, reflecting the direct control and information-disclosure risks inherent to a monitoring platform. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Machinesense over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-46706CRITICAL
Multiple MachineSense devices have credentials unable to be changed by the user or administrator.
| Feb 1, 2024 | 9.8 | 27 | NO | NO |
CVE-2023-49617CRITICAL
The MachineSense application programmable interface (API) is improperly protected and can be accessed without authentication. A remote attacker could retrieve and modify sensi | Feb 1, 2024 | 9.1 | 25 | NO | NO |
CVE-2023-47867HIGH
MachineSense FeverWarn devices are configured as Wi-Fi hosts in a way that attackers within range could connect to the device's web services and compromise the device.
| Feb 1, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-49610HIGH
MachineSense FeverWarn Raspberry Pi-based devices lack input sanitization, which could allow an attacker on an adjacent network to send a message running commands or cou | Feb 1, 2024 | 8.1 | 22 | NO | NO |
CVE-2023-49115HIGH
MachineSense devices use unauthenticated MQTT messaging to monitor devices and remote viewing of sensor data by users.
| Feb 1, 2024 | 7.5 | 22 | NO | NO |
CVE-2023-6221MEDIUM
The cloud provider MachineSense uses for integration and deployment for multiple MachineSense devices, such as the programmable logic controller (PLC), PumpSense, PowerAnalyzer, F | Feb 1, 2024 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Machinesense.
Media articles that mention a CVE ID that affects a product developed by Machinesense — matched by CVE ID, not by vendor name.