Xylem develops a focused portfolio of water-utility monitoring and management systems, including products such as MultiSmart firmware, AanderAA GeoView, and AquaView, which support critical water infrastructure and industrial process automation. Vulnerabilities affecting these products skew toward critical severity and cluster around credential-handling and data-access weaknesses—hard-coded credentials, cleartext transmission of sensitive information, path traversal, SQL injection, and insufficiently protected credential storage—reflecting the legacy embedded and database-driven nature of operational-technology software. Defenders should treat Xylem advisories as high-priority for water-utility and industrial environments; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xylem over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-25176CRITICAL Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in the file system. Since the param | Mar 18, 2022 | 9.8 | 33 | NO | NO |
CVE-2021-41063CRITICAL SQL injection vulnerability was discovered in Aanderaa GeoView Webservice prior to version 2.1.3 that could allow an unauthenticated attackers to execute arbitrary commands. | Dec 8, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-42833HIGH A Use of Hardcoded Credentials vulnerability exists in AquaView versions 1.60, 7.x, and 8.x that could allow an authenticated local attacker to manipulate users and system settings | Feb 7, 2022 | 8.8 | 27 | NO | NO |
CVE-2020-25182MEDIUM Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x searches for and loads DLLs as dynamic libraries. Uncontrolled loading of dynamic libraries could allow a local, unauthenti | Mar 18, 2022 | 6.7 | 23 | NO | NO |
CVE-2020-25180MEDIUM Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged commands. The password value passed | Mar 18, 2022 | 6.5 | 23 | NO | NO |
CVE-2020-25178HIGH ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communication protocol provides various file system operations, as w | Mar 18, 2022 | 8.8 | 22 | NO | NO |
CVE-2020-25184MEDIUM Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable file. ISaGRAF Runtime reads the | Mar 18, 2022 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xylem.
Media articles that mention a CVE ID that affects a product developed by Xylem — matched by CVE ID, not by vendor name.