Known vulnerabilities in Osprey Pump Controller

Software CPE: cpe:2.3:h:propump_and_controls:osprey_pump_controller:*:*:*:*:*:*:*:*
Total vulnerabilities: 9
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Osprey Pump Controller Osprey Pump Controller is affected by 9 known vulnerabilities: 6 high, 1 medium, 2 low Critical High Medium Low

Vulnerabilities (9)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU74170 - Command injection
CVE-2023-28712
CWE-77 High
No
No
- 29.03.2023 SB2023032930
#VU74169 - Cross-Site Request Forgery (CSRF)
CVE-2023-28718
CWE-352 Low
No
No
- 29.03.2023 SB2023032930
#VU74168 - Authentication Bypass Using an Alternate Path or Channel
CVE-2023-28398
CWE-288 High
No
No
- 29.03.2023 SB2023032930
#VU74167 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-28648
CWE-79 Low
No
No
- 29.03.2023 SB2023032930
#VU74166 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-27394
CWE-78 High
No
No
- 29.03.2023 SB2023032930
#VU74165 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-27886
CWE-78 High
No
No
- 29.03.2023 SB2023032930
#VU74164 - Use of Hard-coded Password
CVE-2023-28654
CWE-259 High
No
No
- 29.03.2023 SB2023032930
#VU74163 - Exposure of sensitive information to an unauthorized actor
CVE-2023-28375
CWE-200 Medium
No
No
- 29.03.2023 SB2023032930
#VU74162 - Insufficient Entropy
CVE-2023-28395
CWE-331 High
No
No
- 29.03.2023 SB2023032930