Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

ikus060 — Vulnerabilities & Security Advisories 44

Browse all 44 CVE security advisories affecting ikus060. AI-powered Chinese analysis, POCs, and references for each vulnerability.

ikus060 operates primarily as a provider of industrial automation and control system software, facilitating process monitoring and data acquisition for manufacturing environments. Security audits reveal a historical prevalence of remote code execution and cross-site scripting vulnerabilities within its web-based interfaces, often stemming from inadequate input validation and improper session management. These flaws frequently allow unauthenticated attackers to escalate privileges or execute arbitrary commands on affected servers. Notable incidents include multiple disclosed exploits that enabled lateral movement within industrial networks, highlighting the critical risk posed to operational technology infrastructure. The vendor has since released patches addressing these specific weaknesses, though the recurring nature of these vulnerability classes suggests persistent challenges in secure coding practices. Continuous monitoring and strict network segmentation remain essential for mitigating the residual risks associated with the current 44 recorded CVEs, ensuring the integrity of dependent industrial processes against potential exploitation.

CVE IDTitleCVSSSeverityPublished
CVE-2023-5289 Allocation of Resources Without Limits or Throttling in ikus060/rdiffweb — ikus060/rdiffwebCWE-770 7.5 -2023-09-29
CVE-2023-4138 Allocation of Resources Without Limits or Throttling in ikus060/rdiffweb — ikus060/rdiffwebCWE-770 7.5 -2023-08-03
CVE-2022-4724 Improper Access Control in ikus060/rdiffweb — ikus060/rdiffwebCWE-284 7.5 -2022-12-23
CVE-2022-4723 Allocation of Resources Without Limits or Throttling in ikus060/rdiffweb — ikus060/rdiffwebCWE-770 9.1 -2022-12-23
CVE-2022-4722 Authentication Bypass by Primary Weakness in ikus060/rdiffweb — ikus060/rdiffwebCWE-305 9.8 -2022-12-23
CVE-2022-4721 Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in ikus060/rdiffweb — ikus060/rdiffwebCWE-75 7.6 -2022-12-23
CVE-2022-4720 Open Redirect in ikus060/rdiffweb — ikus060/rdiffwebCWE-601 6.1 -2022-12-23
CVE-2022-4719 Business Logic Errors in ikus060/rdiffweb — ikus060/rdiffwebCWE-840 5.3 -2022-12-23
CVE-2022-4646 Cross-Site Request Forgery (CSRF) in ikus060/rdiffweb — ikus060/rdiffwebCWE-352 7.1 -2022-12-22
CVE-2022-4644 Open Redirect in ikus060/rdiffweb — ikus060/rdiffwebCWE-601 6.1 -2022-12-22
CVE-2022-4314 Improper Privilege Management in ikus060/rdiffweb — ikus060/rdiffwebCWE-269 9.8 -2022-12-06
CVE-2022-4018 Missing Authentication for Critical Function in ikus060/rdiffweb — ikus060/rdiffwebCWE-306 9.4 -2022-11-16
CVE-2022-3362 Insufficient Session Expiration in ikus060/rdiffweb — ikus060/rdiffwebCWE-613 9.8 -2022-11-14
CVE-2022-3363 Business Logic Errors in ikus060/rdiffweb — ikus060/rdiffwebCWE-840 5.3 -2022-10-26
CVE-2022-3327 Missing Authentication for Critical Function in ikus060/rdiffweb — ikus060/rdiffwebCWE-306 9.4 -2022-10-19
CVE-2022-3439 Allocation of Resources Without Limits or Throttling in ikus060/rdiffweb — ikus060/rdiffwebCWE-770 9.1 -2022-10-14
CVE-2022-3457 Origin Validation Error in ikus060/rdiffweb — ikus060/rdiffwebCWE-346 8.8 -2022-10-13
CVE-2022-3456 Allocation of Resources Without Limits or Throttling in ikus060/rdiffweb — ikus060/rdiffwebCWE-770 9.1 -2022-10-13
CVE-2022-3438 Open Redirect in ikus060/rdiffweb — ikus060/rdiffwebCWE-601 6.1 -2022-10-10
CVE-2022-3273 Allocation of Resources Without Limits or Throttling in ikus060/rdiffweb — ikus060/rdiffwebCWE-770 9.1 -2022-10-06
CVE-2022-3389 Path Traversal in ikus060/rdiffweb — ikus060/rdiffwebCWE-22 7.5 -2022-10-06
CVE-2022-3376 Weak Password Requirements in ikus060/rdiffweb — ikus060/rdiffwebCWE-521 9.8 -2022-10-06
CVE-2022-3371 No limit in length of "Token name" parameter results in DOS attack /memory corruption in ikus060/rdiffweb prior to 2.5.0a3 in ikus060/rdiffweb — ikus060/rdiffwebCWE-770 9.1 -2022-09-30
CVE-2022-3364 No limit in length of "Fullname" parameter results in DOS attack /memory corruption in ikus060/rdiffweb prior to 2.5.0a3 in ikus060/rdiffweb — ikus060/rdiffwebCWE-770 9.1 -2022-09-29
CVE-2022-3326 Weak Password Requirements in ikus060/rdiffweb — ikus060/rdiffwebCWE-521 9.8 -2022-09-28
CVE-2022-3292 Use of Cache Containing Sensitive Information in ikus060/rdiffweb — ikus060/rdiffwebCWE-524 6.5 -2022-09-28
CVE-2022-3298 Allocation of Resources Without Limits or Throttling in ikus060/rdiffweb — ikus060/rdiffwebCWE-770 9.1 -2022-09-26
CVE-2022-3290 Improper Handling of Length Parameter Inconsistency in ikus060/rdiffweb — ikus060/rdiffwebCWE-130 7.5 -2022-09-26
CVE-2022-3272 Improper Handling of Length Parameter Inconsistency in ikus060/rdiffweb — ikus060/rdiffwebCWE-130 7.5 -2022-09-26
CVE-2022-3295 Allocation of Resources Without Limits or Throttling in ikus060/rdiffweb — ikus060/rdiffwebCWE-770 9.1 -2022-09-26

This page lists every published CVE security advisory associated with ikus060. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.