Viessmann manufactures building services and heating systems, with its vulnerability profile centered on the Vitogate gateway product line that provides remote monitoring and control for HVAC installations. The observed weakness classes—direct request/forced browsing, command injection, and hard-coded password use—reflect typical exposure patterns in IoT gateway and industrial control interfaces where authentication and input handling are critical to securing physical building systems. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Viessmann over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-5222CRITICAL A vulnerability classified as critical was found in Viessmann Vitogate 300 up to 2.1.3.0. This vulnerability affects the function isValidUser of the file /cgi-bin/vitogate.cgi of t | Sep 27, 2023 | 9.8 | 85 | NO | YES |
CVE-2023-45852CRITICAL In Vitogate 300 2.1.3.0, /cgi-bin/vitogate.cgi allows an unauthenticated attacker to bypass authentication and execute arbitrary commands via shell metacharacters in the ipaddr par | Oct 14, 2023 | 9.8 | 48 | NO | YES |
CVE-2023-5702MEDIUM A vulnerability was found in Viessmann Vitogate 300 up to 2.1.3.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /cgi-bin/. The man | Oct 23, 2023 | 6.5 | 36 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Viessmann.
Media articles that mention a CVE ID that affects a product developed by Viessmann — matched by CVE ID, not by vendor name.