Subnet's vulnerability footprint centers on power-grid and industrial control products, specifically PowerSystem Center and Substation Server, which operate in critical infrastructure environments. The observed weakness classes—including improper input validation, authentication bypass via capture-replay, cross-site scripting, memory-buffer issues, and unquoted search-path flaws—reflect the authentication and web-interface complexity characteristic of grid management and monitoring platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Subnet over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-26024HIGH SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in Substation Server. | May 28, 2024 | 8.4 | 24 | NO | NO |
CVE-2024-28042HIGH SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in PowerSYSTEM Center. | May 15, 2024 | 8.4 | 24 | NO | NO |
CVE-2023-29158CRITICAL
SUBNET PowerSYSTEM Center versions 2020 U10 and prior are vulnerable to replay attacks which may result in a denial-of-service condition or a loss of data integrity.
| Jun 19, 2023 | 9.1 | 24 | NO | NO |
CVE-2023-6631HIGH PowerSYSTEM Center versions 2020 Update 16 and prior contain a vulnerability that may allow an authorized local user to insert arbitrary code into the unquoted service path and esc | Jan 8, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-32659MEDIUM
SUBNET PowerSYSTEM Center versions 2020 U10 and prior contain a cross-site scripting vulnerability that may allow an attacker to inject malicious code into report header graphic f | Jun 19, 2023 | 6.1 | 20 | NO | NO |
CVE-2014-2357HIGH The GPT library in the Telegyr 8979 Master Protocol application in SUBNET SubSTATION Server 2 before SSNET 2.12 HF18808 allows remote attackers to cause a denial of service (persis | Aug 11, 2014 | 7.1 | 19 | NO | NO |
CVE-2013-2788MEDIUM The DNP3 Slave service in SUBNET Solutions SubSTATION Server 2.7.0033 and 2.8.0106 allows remote attackers to cause a denial of service (unhandled exception and process crash) via | Sep 17, 2013 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Subnet.
Media articles that mention a CVE ID that affects a product developed by Subnet — matched by CVE ID, not by vendor name.