Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

ikus060 — Vulnerabilities & Security Advisories 44

Browse all 44 CVE security advisories affecting ikus060. AI-powered Chinese analysis, POCs, and references for each vulnerability.

ikus060 operates primarily as a provider of industrial automation and control system software, facilitating process monitoring and data acquisition for manufacturing environments. Security audits reveal a historical prevalence of remote code execution and cross-site scripting vulnerabilities within its web-based interfaces, often stemming from inadequate input validation and improper session management. These flaws frequently allow unauthenticated attackers to escalate privileges or execute arbitrary commands on affected servers. Notable incidents include multiple disclosed exploits that enabled lateral movement within industrial networks, highlighting the critical risk posed to operational technology infrastructure. The vendor has since released patches addressing these specific weaknesses, though the recurring nature of these vulnerability classes suggests persistent challenges in secure coding practices. Continuous monitoring and strict network segmentation remain essential for mitigating the residual risks associated with the current 44 recorded CVEs, ensuring the integrity of dependent industrial processes against potential exploitation.

CVE IDTitleCVSSSeverityPublished
CVE-2022-3301 Improper Cleanup on Thrown Exception in ikus060/rdiffweb — ikus060/rdiffwebCWE-460 4.3 -2022-09-26
CVE-2022-3269 Session Fixation in ikus060/rdiffweb — ikus060/rdiffwebCWE-384 8.8 -2022-09-23
CVE-2022-3274 Cross-Site Request Forgery (CSRF) on user's settings in GitHub repository ikus060/rdiffweb prior to 2.4.6. in ikus060/rdiffweb — ikus060/rdiffwebCWE-352 7.1 -2022-09-22
CVE-2022-3267 Cross-Site Request Forgery (CSRF) in ikus060/rdiffweb — ikus060/rdiffwebCWE-352 7.1 -2022-09-22
CVE-2022-3268 Weak Password Requirements in ikus060/minarca — ikus060/minarcaCWE-521 9.8 -2022-09-22
CVE-2022-3233 Cross-Site Request Forgery (CSRF) in ikus060/rdiffweb — ikus060/rdiffwebCWE-352 7.1 -2022-09-21
CVE-2022-3250 Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in ikus060/rdiffweb — ikus060/rdiffwebCWE-614 5.3 -2022-09-21
CVE-2022-3251 Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in ikus060/minarca — ikus060/minarcaCWE-614 5.3 -2022-09-21
CVE-2022-3232 Cross-Site Request Forgery (CSRF) in ikus060/rdiffweb — ikus060/rdiffwebCWE-352 7.1 -2022-09-17
CVE-2022-3221 Cross-Site Request Forgery (CSRF) in ikus060/rdiffweb — ikus060/rdiffwebCWE-352 7.1 -2022-09-15
CVE-2022-3179 Weak Password Requirements in ikus060/rdiffweb — ikus060/rdiffwebCWE-521 9.8 -2022-09-13
CVE-2022-3174 Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in ikus060/rdiffweb — ikus060/rdiffwebCWE-614 5.3 -2022-09-13
CVE-2022-3175 Missing Custom Error Page in ikus060/rdiffweb — ikus060/rdiffwebCWE-756 8.2 -2022-09-13
CVE-2022-3167 Improper Restriction of Rendered UI Layers or Frames in ikus060/rdiffweb — ikus060/rdiffwebCWE-1021 7.1 -2022-09-08

This page lists every published CVE security advisory associated with ikus060. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.