Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sauter Controls

First CVE: Feb 6, 2016Active for: 10 yearsTotal CVEs: 22

Sauter Controls manufactures building automation and HVAC control systems, with a focused vulnerability footprint centered on its EY-AS525F001 gateway and ModuNet300 controller firmware products. The recurring disclosures reflect the integration and network-communication demands of embedded building controls, where firmware update cycles and field-device longevity can extend remediation timelines. Current severity, exploitation status, and exposure details are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Sauter Controls over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 6, 2016
10 years ago
Most Recent CVE
Mar 27, 2023
1,216 days ago

Products(17 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-40190CRITICAL
SAUTER Controls moduWeb firmware version 2.7.1 is vulnerable to reflective cross-site scripting (XSS). The web application does not adequately sanitize request strings of malicious
Oct 31, 20229.629NONO
CVE-2023-0052HIGH
SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior allows the execution of commands without credentials. As Telnet a
Jan 20, 20238.828NONO
CVE-2018-17912HIGH
An XXE vulnerability exists in CASE Suite Versions 3.10 and prior when processing parameter entities, which may allow remote file disclosure.
Nov 2, 20187.525NONO
CVE-2023-0053HIGH
SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior have only FTP and Telnet available for device management. Any s
Mar 2, 20237.523NONO
CVE-2016-10224HIGH
An issue was discovered in Sauter NovaWeb web HMI. The application uses a protection mechanism that relies on the existence or values of a cookie, but it does not properly ensure t
Feb 13, 20177.223NONO
CVE-2023-28652MEDIUM
An authenticated malicious user could successfully upload a malicious image could lead to a denial-of-service condition.
Mar 27, 20236.522NONO
CVE-2023-27927MEDIUM
An authenticated malicious user could acquire the simple mail transfer protocol (SMTP) Password in cleartext format, despite it being protected and hidden behind asterisks. The att
Mar 27, 20236.521NONO
CVE-2023-22300MEDIUM
An unauthenticated remote attacker could force all authenticated users, such as administrative users, to perform unauthorized actions by viewing the logs. This action would also gr
Mar 27, 20236.120NONO
CVE-2023-28655MEDIUM
A malicious user could leverage this vulnerability to escalate privileges or perform unauthorized actions in the context of the targeted privileged users.
Mar 27, 20235.419NONO
CVE-2023-28650MEDIUM
An unauthenticated remote attacker could provide a malicious link and trick an unsuspecting user into clicking on it. If clicked, the attacker could execute the malicious JavaScrip
Mar 27, 20236.117NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
55%
36%
9%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (54.5%)
Unknown0 (0.0%)
Required5 (45.5%)
Privileges Required
Low5 (45.5%)
High1 (9.1%)
None5 (45.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sauter Controls.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sauter Controls — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sauter Controls's Products

View all 1 CNAs →

Top CWEs