Spidercontrol develops SCADA and industrial web server products that sit in supervisory-control and monitoring systems, a high-value attack surface where vulnerabilities often carry serious operational consequences. The vendor's durable exposure reflects the web-facing and privileged nature of these systems, concentrating in path-traversal, authentication bypass, cross-site scripting, privilege escalation, and memory-safety issues that recur across its microbrowser and web server product line and skew toward critical-severity outcomes. Defenders managing SCADA and critical infrastructure should inventory affected instances and prioritize patches for these products; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Spidercontrol over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-13995CRITICAL An Improper Authentication issue was discovered in iniNet Solutions iniNet Webserver, all versions prior to V2.02.0100. The webserver does not properly authenticate users, which ma | Oct 5, 2017 | 10.0 | 30 | NO | NO |
CVE-2017-12707CRITICAL A Stack-based Buffer Overflow issue was discovered in SpiderControl SCADA MicroBrowser Versions 1.6.30.144 and prior. Opening a maliciously crafted html file may cause a stack over | Aug 25, 2017 | 9.8 | 28 | NO | NO |
CVE-2017-14010HIGH In SpiderControl MicroBrowser Windows XP, Vista 7, 8 and 10, Versions 1.6.30.144 and prior, an uncontrolled search path element vulnerability has been identified which could be exp | Apr 26, 2018 | 7.8 | 24 | NO | NO |
CVE-2017-12728HIGH An Improper Privilege Management issue was discovered in SpiderControl SCADA Web Server Version 2.02.0007 and prior. Authenticated, non-administrative local users are able to alter | Oct 5, 2017 | 7.8 | 23 | NO | NO |
CVE-2018-18991MEDIUM Reflected cross-site scripting (non-persistent) in SCADA WebServer (Versions prior to 2.03.0001) could allow an attacker to send a crafted URL that contains JavaScript, which can b | Dec 4, 2018 | 6.1 | 22 | NO | NO |
CVE-2023-3329MEDIUM SpiderControl SCADA Webserver versions 2.08 and prior are vulnerable to path traversal. An attacker with administrative privileges could overwrite files on the webserver using the | Aug 2, 2023 | 6.5 | 21 | NO | NO |
CVE-2017-12694HIGH A Directory Traversal issue was discovered in SpiderControl SCADA Web Server. An attacker may be able to use a simple GET request to perform a directory traversal into system files | Aug 25, 2017 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Spidercontrol.
Media articles that mention a CVE ID that affects a product developed by Spidercontrol — matched by CVE ID, not by vendor name.