Progea develops industrial automation and human-machine-interface (HMI) software, primarily through its Movicon and Movicon.PowerHMI product lines, which serve manufacturing and process-control environments. The vendor's vulnerability footprint, while narrow in scope, frequently acquires public exploit code and recurs across memory-safety, information-disclosure, authentication, and path-handling weakness classes that are typical of legacy automation software. Defenders deploying these HMI platforms should prioritize inventory and access controls; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Progea over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-3491HIGH Heap-based buffer overflow in Progea Movicon / PowerHMI 11.2.1085 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a | Sep 16, 2011 | 10.0 | 48 | NO | YES |
CVE-2011-3499HIGH Progea Movicon / PowerHMI 11.2.1085 and earlier allows remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via an EIDP p | Sep 16, 2011 | 10.0 | 47 | NO | YES |
CVE-2011-3498HIGH Heap-based buffer overflow in Progea Movicon / PowerHMI 11.2.1085 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a | Sep 16, 2011 | 10.0 | 43 | NO | YES |
CVE-2011-2963HIGH TCPUploadServer.exe in Progea Movicon 11.2 before Build 1084 does not require authentication for critical functions, which allows remote attackers to obtain sensitive information, | Jul 29, 2011 | 10.0 | 42 | NO | YES |
CVE-2012-1804HIGH The OPC server in Progea Movicon before 11.3 allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) via a crafted HTTP request. | May 14, 2012 | 7.8 | 24 | NO | NO |
CVE-2017-14017HIGH An Uncontrolled Search Path Element issue was discovered in Progea Movicon Version 11.5.1181 and prior. An uncontrolled search path element vulnerability has been identified, which | Oct 19, 2017 | 7.8 | 23 | NO | NO |
CVE-2017-14019MEDIUM An Unquoted Search Path or Element issue was discovered in Progea Movicon Version 11.5.1181 and prior. An unquoted search path or element vulnerability has been identified, which m | Oct 19, 2017 | 6.7 | 21 | NO | NO |
CVE-2014-0778MEDIUM TCPUploader module listens on Port 10651/TCP for incoming connections.
Exploitation of this vulnerability could allow a remote unauthenticated
user access to release OS version i | Apr 19, 2014 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Progea.
Media articles that mention a CVE ID that affects a product developed by Progea — matched by CVE ID, not by vendor name.