Mnc develops a narrowly scoped product line centered on real-time industrial control and embedded systems software, including variants of its INPLC runtime and SDK platforms. The observed vulnerability surface reflects the authentication and memory-safety constraints of these systems, with recurring patterns in improper authentication, privilege management, buffer boundary enforcement, and untrusted search-path handling. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mnc over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-0670CRITICAL INplc-RT 3.08 and earlier allows remote attackers to bypass authentication to execute an arbitrary command through the protocol-compliant traffic. This is a different vulnerability | Jan 9, 2019 | 9.8 | 31 | NO | NO |
CVE-2018-0669CRITICAL INplc-RT 3.08 and earlier allows remote attackers to bypass authentication to execute an arbitrary command through the protocol-compliant traffic. This is a different vulnerability | Jan 9, 2019 | 9.8 | 29 | NO | NO |
CVE-2018-0668CRITICAL Buffer overflow in INplc-RT 3.08 and earlier allows remote attackers to cause denial-of-service (DoS) condition that may result in executing arbtrary code via unspecified vectors. | Jan 9, 2019 | 9.8 | 28 | NO | NO |
CVE-2018-0667HIGH Untrusted search path vulnerability in Installer of INplc SDK Express 3.08 and earlier and Installer of INplc SDK Pro+ 3.08 and earlier allows an attacker to gain privileges via a | Jan 9, 2019 | 7.8 | 24 | NO | NO |
CVE-2018-0671MEDIUM Privilege escalation vulnerability in INplc-RT 3.08 and earlier allows an attacker with administrator rights to execute arbitrary code on the Windows system via unspecified vectors | Jan 9, 2019 | 6.7 | 21 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mnc.
Media articles that mention a CVE ID that affects a product developed by Mnc — matched by CVE ID, not by vendor name.