Propumpservice manufactures the Osprey Pump Controller and its firmware, embedded systems serving industrial pumping and fluid-management applications. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur across command-injection, cross-site request forgery, improper authentication, and file-disclosure weakness classes that are typical of web-accessible industrial control interfaces. Defenders should prioritize patching these devices, particularly in internet-reachable or supply-chain-critical deployments; current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Propumpservice over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-27394CRITICAL Osprey Pump Controller version 1.01 is vulnerable an unauthenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands throug | Mar 28, 2023 | 9.8 | 40 | NO | NO |
CVE-2023-27886CRITICAL Osprey Pump Controller version 1.01 is vulnerable to an unauthenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands thr | Mar 28, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-28654CRITICAL Osprey Pump Controller version 1.01 has a hidden administrative account that has the hardcoded password that allows full access to the web management interface configuration. The u | Mar 28, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-28718HIGH Osprey Pump Controller version 1.01 allows users to perform certain actions via HTTP requests without performing any checks to verify the requests. This may allow an attacker to pe | Mar 28, 2023 | 8.0 | 24 | NO | NO |
CVE-2023-28712CRITICAL Osprey Pump Controller version 1.01 contains an unauthenticated command injection vulnerability that could allow system access with www-data permissions. | Mar 28, 2023 | 9.8 | 24 | NO | NO |
CVE-2023-28398CRITICAL Osprey Pump Controller version 1.01 could allow an unauthenticated user to create an account and bypass authentication, thereby gaining unauthorized access to the system. A threat | Mar 28, 2023 | 9.8 | 24 | NO | NO |
CVE-2023-28375HIGH Osprey Pump Controller version 1.01 is vulnerable to an unauthenticated file disclosure. Using a GET parameter, attackers can disclose arbitrary files on the affected device and di | Mar 28, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-28395HIGH Osprey Pump Controller version 1.01 is vulnerable to a weak session token generation algorithm that can be predicted and can aid in authentication and authorization bypass. This ma | Mar 28, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-28648MEDIUM Osprey Pump Controller version 1.01 inputs passed to a GET parameter are not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML/J | Mar 28, 2023 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Propumpservice.
Media articles that mention a CVE ID that affects a product developed by Propumpservice — matched by CVE ID, not by vendor name.