cbcvebase.

Azeotech Daqfactory vulnerabilities

16 known vulnerabilities affecting azeotech/daqfactory.

Total CVEs
16
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH8MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2011-3492P2CRITICALCVSS 10.0PoC≤ 5.85v3.0+48 more2011-09-16
CVE-2011-3492 [CRITICAL] CWE-119 CVE-2011-3492: Stack-based buffer overflow in Azeotech DAQFactory 5.85 build 1853 and earlier allows remote attacke Stack-based buffer overflow in Azeotech DAQFactory 5.85 build 1853 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a crafted NETB packet to UDP port 20034.
nvd
CVE-2011-2956P3HIGHCVSS 7.8PoC≤ 5.84v3.0+47 more2011-07-28
CVE-2011-2956 [HIGH] CWE-287 CVE-2011-2956: AzeoTech DAQFactory before 5.85 (Build 1842) does not perform authentication for certain signals, wh AzeoTech DAQFactory before 5.85 (Build 1842) does not perform authentication for certain signals, which allows remote attackers to cause a denial of service (system reboot or shutdown) via a signal.
nvd
CVE-2025-66590P3CRITICALCVSS 9.8fixed in 21.1≤ Release 20.7 (Build 2555)2025-12-11
CVE-2025-66590 [CRITICAL] CWE-787 CVE-2025-66590: In AzeoTech DAQFactory release 20.7 (Build 2555), an out-of-bounds write vulnerability can be exploi In AzeoTech DAQFactory release 20.7 (Build 2555), an out-of-bounds write vulnerability can be exploited by an attacker to cause the program to write data past the end of an allocated memory buffer. This can lead to arbitrary code execution or a system crash.
nvd
CVE-2025-66588P3CRITICALCVSS 9.8fixed in 21.1≤ Release 20.7 (Build 2555)2025-12-11
CVE-2025-66588 [CRITICAL] CWE-824 CVE-2025-66588: In AzeoTech DAQFactory release 20.7 (Build 2555), an access of uninitialized pointer vulnerability c In AzeoTech DAQFactory release 20.7 (Build 2555), an access of uninitialized pointer vulnerability can be exploited by an attacker which can lead to arbitrary code execution.
nvd
CVE-2025-66589P3CRITICALCVSS 9.1fixed in 21.1≤ Release 20.7 (Build 2555)2025-12-11
CVE-2025-66589 [CRITICAL] CWE-125 CVE-2025-66589: In AzeoTech DAQFactory release 20.7 (Build 2555), an Out-of-bounds Read vulnerability can be exploit In AzeoTech DAQFactory release 20.7 (Build 2555), an Out-of-bounds Read vulnerability can be exploited by an attacker to cause the program to read data past the end of an allocated buffer. This could allow an attacker to disclose information or cause a system crash.
nvd
CVE-2026-12390P3HIGHCVSS 8.4≤ 21.12026-06-18
CVE-2026-12390 [HIGH] CWE-843 CVE-2026-12390: In AzeoTech DAQFactory versions 21.1 and prior, a Type Confusion vulnerability can be exploited by a In AzeoTech DAQFactory versions 21.1 and prior, a Type Confusion vulnerability can be exploited by an attacker using specially crafted .ctl files which can result in code execution.
nvd
CVE-2026-12921P3HIGHCVSS 8.4≤ 21.12026-06-25
CVE-2026-12921 [HIGH] CWE-416 CVE-2026-12921: In AzeoTech DAQFactory versions 21.1 and prior, a Use After Free vulnerability can be exploited by a In AzeoTech DAQFactory versions 21.1 and prior, a Use After Free vulnerability can be exploited by an attacker using specially crafted .ctl files which can result in code execution.
nvd
CVE-2009-4480P3CRITICALCVSS 9.3v5.772009-12-30
CVE-2009-4480 [CRITICAL] CWE-119 CVE-2009-4480: Buffer overflow in the web service in AzeoTech DAQFactory 5.77 might allow remote attackers to execu Buffer overflow in the web service in AzeoTech DAQFactory 5.77 might allow remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a certain module in VulnDisco Pack Professional 7.16 through 8.11. NOTE: as of 20091229, this disclosure has no actionable information. However, because the VulnDisco Pack author is a relia
nvd
CVE-2025-66585P3HIGHCVSS 7.8fixed in 21.1≤ Release 20.7 (Build 2555)2025-12-11
CVE-2025-66585 [HIGH] CWE-416 CVE-2025-66585: In AzeoTech DAQFactory release 20.7 (Build 2555), a use after free vulnerability can be exploited to In AzeoTech DAQFactory release 20.7 (Build 2555), a use after free vulnerability can be exploited to cause memory corruption while parsing specially crafted .ctl files. This could allow an attacker to execute code in the context of the current process.
nvd
CVE-2025-66586P3HIGHCVSS 7.8fixed in 21.1≤ Release 20.7 (Build 2555)2025-12-11
CVE-2025-66586 [HIGH] CWE-843 CVE-2025-66586: In AzeoTech DAQFactory release 20.7 (Build 2555), an access of resource using incompatible type vuln In AzeoTech DAQFactory release 20.7 (Build 2555), an access of resource using incompatible type vulnerability can be exploited to cause memory corruption while parsing specially crafted .ctl files. This could allow an attacker to execute code in the context of the current process.
nvd
CVE-2021-42698P3HIGHCVSS 7.8≤ 18.1v18.1+1 more2021-11-05
CVE-2021-42698 [HIGH] CWE-502 CVE-2021-42698: Project files are stored memory objects in the form of binary serialized data that can later be read Project files are stored memory objects in the form of binary serialized data that can later be read and deserialized again to instantiate the original objects in memory. Malicious manipulation of these files may allow an attacker to corrupt memory.
nvd
CVE-2021-42543P3HIGHCVSS 7.8≤ 18.1v18.1+1 more2021-11-05
CVE-2021-42543 [HIGH] CWE-242 CVE-2021-42543: The affected application uses specific functions that could be abused through a crafted project file The affected application uses specific functions that could be abused through a crafted project file, which could lead to code execution, system reboot, and system shutdown.
nvd
CVE-2021-42701P4MEDIUMCVSS 6.3≤ 18.1v18.1+1 more2021-11-05
CVE-2021-42701 [MEDIUM] CWE-471 CVE-2021-42701: An attacker could prepare a specially crafted project file that, if opened, would attempt to connect An attacker could prepare a specially crafted project file that, if opened, would attempt to connect to the cloud and trigger a man in the middle (MiTM) attack. This could allow an attacker to obtain credentials and take over the user’s cloud account.
nvd
CVE-2021-42699P4MEDIUMCVSS 5.9≤ 18.1v18.1+1 more2021-11-05
CVE-2021-42699 [MEDIUM] CWE-319 CVE-2021-42699: The affected product is vulnerable to cookie information being transmitted as cleartext over HTTP. A The affected product is vulnerable to cookie information being transmitted as cleartext over HTTP. An attacker can capture network traffic, obtain the user’s cookie and take over the account.
nvd
CVE-2017-12699P4HIGHCVSS 7.1≤ 16.32017-09-09
CVE-2017-12699 [HIGH] CWE-276 CVE-2017-12699: An Incorrect Default Permissions issue was discovered in AzeoTech DAQFactory versions prior to 17.1. An Incorrect Default Permissions issue was discovered in AzeoTech DAQFactory versions prior to 17.1. Local, non-administrative users may be able to replace or modify original application files with malicious ones.
nvd
CVE-2017-5147P4MEDIUMCVSS 5.3≤ 16.32017-09-09
CVE-2017-5147 [MEDIUM] CWE-427 CVE-2017-5147: An Uncontrolled Search Path Element issue was discovered in AzeoTech DAQFactory versions prior to 17 An Uncontrolled Search Path Element issue was discovered in AzeoTech DAQFactory versions prior to 17.1. An uncontrolled search path element vulnerability has been identified, which may execute malicious DLL files that have been placed within the search path.
nvd
Azeotech Daqfactory vulnerabilities | cvebase