Microsys maintains a narrow product portfolio centered on industrial automation and monitoring software such as Promotic and Cyberpatrol, serving specialized control and surveillance use cases. The recurring vulnerability patterns reflect the software's data-handling and file-access responsibilities, with buffer-boundary issues, path-traversal conditions, and miscellaneous input-validation flaws appearing across the product line; vulnerabilities in this vendor frequently acquire public exploit code. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Microsys over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-4518MEDIUM Directory traversal vulnerability in the PmWebDir object in the web server in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to read arbitrary files via unspecified vectors | May 23, 2013 | 5.0 | 38 | NO | YES |
CVE-2014-9205HIGH Stack-based buffer overflow in the PmBase64Decode function in an unspecified demonstration application in MICROSYS PROMOTIC stable before 8.2.19 and PROMOTIC development before 8.3 | Mar 29, 2015 | 7.5 | 25 | NO | NO |
CVE-2011-4520MEDIUM Heap-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a denial of service via a crafted web page. | May 23, 2013 | 4.3 | 23 | NO | YES |
CVE-2011-4519MEDIUM Stack-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a denial of service via a crafted web page. | May 23, 2013 | 4.3 | 23 | NO | YES |
CVE-2011-4874HIGH Use-after-free vulnerability in MICROSYS PROMOTIC before 8.1.7 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (data corruption and app | Apr 13, 2012 | 7.9 | 23 | NO | NO |
CVE-2000-1173MEDIUM Microsys CyberPatrol uses weak encryption (trivial encoding) for credit card numbers and uses no encryption for the remainder of the information during registration, which could al | Jan 9, 2001 | 5.0 | 22 | NO | YES |
CVE-2016-0869MEDIUM Heap-based buffer overflow in MICROSYS PROMOTIC before 8.3.11 allows remote authenticated users to cause a denial of service via a malformed HTML document. | Jan 26, 2016 | 5.0 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Microsys.
Media articles that mention a CVE ID that affects a product developed by Microsys — matched by CVE ID, not by vendor name.