Sauter Controls manufactures building automation and HVAC control systems, with a focused vulnerability footprint centered on its EY-AS525F001 gateway and ModuNet300 controller firmware products. The recurring disclosures reflect the integration and network-communication demands of embedded building controls, where firmware update cycles and field-device longevity can extend remediation timelines. Current severity, exploitation status, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sauter Controls over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-40190CRITICAL SAUTER Controls moduWeb firmware version 2.7.1 is vulnerable to reflective cross-site scripting (XSS). The web application does not adequately sanitize request strings of malicious | Oct 31, 2022 | 9.6 | 29 | NO | NO |
CVE-2023-0052HIGH SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior allows the execution of commands without credentials. As Telnet a | Jan 20, 2023 | 8.8 | 28 | NO | NO |
CVE-2018-17912HIGH An XXE vulnerability exists in CASE Suite Versions 3.10 and prior when processing parameter entities, which may allow remote file disclosure. | Nov 2, 2018 | 7.5 | 25 | NO | NO |
CVE-2023-0053HIGH SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and
prior and BACnetstac version 4.2.1 and prior have only FTP and Telnet
available for device management. Any s | Mar 2, 2023 | 7.5 | 23 | NO | NO |
CVE-2016-10224HIGH An issue was discovered in Sauter NovaWeb web HMI. The application uses a protection mechanism that relies on the existence or values of a cookie, but it does not properly ensure t | Feb 13, 2017 | 7.2 | 23 | NO | NO |
CVE-2023-28652MEDIUM An authenticated malicious user could successfully upload a malicious image could lead to a denial-of-service condition. | Mar 27, 2023 | 6.5 | 22 | NO | NO |
CVE-2023-27927MEDIUM An authenticated malicious user could acquire the simple mail transfer protocol (SMTP) Password in cleartext format, despite it being protected and hidden behind asterisks. The att | Mar 27, 2023 | 6.5 | 21 | NO | NO |
CVE-2023-22300MEDIUM An unauthenticated remote attacker could force all authenticated users, such as administrative users, to perform unauthorized actions by viewing the logs. This action would also gr | Mar 27, 2023 | 6.1 | 20 | NO | NO |
CVE-2023-28655MEDIUM A malicious user could leverage this vulnerability to escalate privileges or perform unauthorized actions in the context of the targeted privileged users. | Mar 27, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-28650MEDIUM An unauthenticated remote attacker could provide a malicious link and trick an unsuspecting user into clicking on it. If clicked, the attacker could execute the malicious JavaScrip | Mar 27, 2023 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sauter Controls.
Media articles that mention a CVE ID that affects a product developed by Sauter Controls — matched by CVE ID, not by vendor name.