MidnightBSD

Advisories for azeotech

CVE-2011-2956 HIGH

AzeoTech DAQFactory before 5.85 (Build 1842) does not perform authentication for certain signals, which allows remote attackers to cause a denial of service (system reboot or shutdown) via a signal.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-287,

Products Affected

Vendor Product Version
azeotech daqfactory 3.11
azeotech daqfactory 5.39
azeotech daqfactory 5.75
azeotech daqfactory 5.76
azeotech daqfactory 5.10
azeotech daqfactory 5.74
azeotech daqfactory 5.70
azeotech daqfactory 5.35
azeotech daqfactory 5.73
azeotech daqfactory *
azeotech daqfactory 5.82
azeotech daqfactory 5.02
azeotech daqfactory 3.55
azeotech daqfactory 5.72
azeotech daqfactory 3.05
azeotech daqfactory 5.30
azeotech daqfactory 5.37
azeotech daqfactory 3.10
azeotech daqfactory 5.11
azeotech daqfactory 4.10
azeotech daqfactory 5.40
azeotech daqfactory 5.12
azeotech daqfactory 5.77
azeotech daqfactory 3.0
azeotech daqfactory 5.33
azeotech daqfactory 5.36
azeotech daqfactory 3.03
azeotech daqfactory 3.52
azeotech daqfactory 5.03
azeotech daqfactory 5.71
azeotech daqfactory 5.15
azeotech daqfactory 3.5
azeotech daqfactory 5.80
azeotech daqfactory 3.53
azeotech daqfactory 5.04
azeotech daqfactory 5.32
azeotech daqfactory 5.83
azeotech daqfactory 5.05
azeotech daqfactory 5.01
azeotech daqfactory 5.0
azeotech daqfactory 5.31
azeotech daqfactory 5.34
azeotech daqfactory 4.00
azeotech daqfactory 5.78
azeotech daqfactory 5.38
azeotech daqfactory 5.79
azeotech daqfactory 3.09
azeotech daqfactory 4.11
azeotech daqfactory 3.51
CVE-2011-3492 HIGH

Stack-based buffer overflow in Azeotech DAQFactory 5.85 build 1853 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a crafted NETB packet to UDP port 20034.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
azeotech daqfactory 3.11
azeotech daqfactory 5.39
azeotech daqfactory 5.75
azeotech daqfactory 5.76
azeotech daqfactory 5.10
azeotech daqfactory 5.74
azeotech daqfactory 5.70
azeotech daqfactory 5.35
azeotech daqfactory 5.73
azeotech daqfactory *
azeotech daqfactory 5.82
azeotech daqfactory 5.02
azeotech daqfactory 3.55
azeotech daqfactory 5.72
azeotech daqfactory 3.05
azeotech daqfactory 5.30
azeotech daqfactory 5.37
azeotech daqfactory 3.10
azeotech daqfactory 5.11
azeotech daqfactory 4.10
azeotech daqfactory 5.40
azeotech daqfactory 5.12
azeotech daqfactory 5.77
azeotech daqfactory 3.0
azeotech daqfactory 5.33
azeotech daqfactory 5.36
azeotech daqfactory 3.03
azeotech daqfactory 3.52
azeotech daqfactory 5.03
azeotech daqfactory 5.71
azeotech daqfactory 5.15
azeotech daqfactory 3.5
azeotech daqfactory 5.80
azeotech daqfactory 3.53
azeotech daqfactory 5.04
azeotech daqfactory 5.32
azeotech daqfactory 5.83
azeotech daqfactory 5.05
azeotech daqfactory 5.84
azeotech daqfactory 5.01
azeotech daqfactory 5.0
azeotech daqfactory 5.31
azeotech daqfactory 5.34
azeotech daqfactory 4.00
azeotech daqfactory 5.78
azeotech daqfactory 5.38
azeotech daqfactory 5.79
azeotech daqfactory 3.09
azeotech daqfactory 4.11
azeotech daqfactory 3.51
CVE-2017-12699 LOW

An Incorrect Default Permissions issue was discovered in AzeoTech DAQFactory versions prior to 17.1. Local, non-administrative users may be able to replace or modify original application files with malicious ones.

CVSS 2.0

Severity: LOW

Problem Type: CWE-276,CWE-276,

Products Affected

Vendor Product Version
azeotech daqfactory *
CVE-2017-5147 MEDIUM

An Uncontrolled Search Path Element issue was discovered in AzeoTech DAQFactory versions prior to 17.1. An uncontrolled search path element vulnerability has been identified, which may execute malicious DLL files that have been placed within the search path.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-427,CWE-427,

Products Affected

Vendor Product Version
azeotech daqfactory *
CVE-2021-42543 HIGH

The affected application uses specific functions that could be abused through a crafted project file, which could lead to code execution, system reboot, and system shutdown.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 1.8 5.9
ics-cert@hq.dhs.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 1.8 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-242,

Products Affected

Vendor Product Version
azeotech daqfactory *
azeotech daqfactory 18.1
CVE-2021-42698 MEDIUM

Project files are stored memory objects in the form of binary serialized data that can later be read and deserialized again to instantiate the original objects in memory. Malicious manipulation of these files may allow an attacker to corrupt memory.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
ics-cert@hq.dhs.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 1.8 5.9
nvd@nist.gov 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 1.8 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-502,

Products Affected

Vendor Product Version
azeotech daqfactory *
azeotech daqfactory 18.1
CVE-2021-42699 MEDIUM

The affected product is vulnerable to cookie information being transmitted as cleartext over HTTP. An attacker can capture network traffic, obtain the user’s cookie and take over the account.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 5.9 MEDIUM CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N 2.2 3.6
ics-cert@hq.dhs.gov 5.7 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N 2.1 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-319,

Products Affected

Vendor Product Version
azeotech daqfactory *
azeotech daqfactory 18.1
CVE-2021-42701 LOW

An attacker could prepare a specially crafted project file that, if opened, would attempt to connect to the cloud and trigger a man in the middle (MiTM) attack. This could allow an attacker to obtain credentials and take over the user’s cloud account.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.3 MEDIUM CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N 1.0 5.2
ics-cert@hq.dhs.gov 5.0 MEDIUM CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N 1.3 3.6

CVSS 2.0

Severity: LOW

Problem Type: CWE-471,

Products Affected

Vendor Product Version
azeotech daqfactory *
azeotech daqfactory 18.1
CVE-2025-66585

In AzeoTech DAQFactory release 20.7 (Build 2555), a Use After Free vulnerability can be exploited to cause memory corruption while parsing specially crafted .ctl files. This could allow an attacker to execute code in the context of the current process.

Products Affected

Vendor Product Version
azeotech daqfactory *
CVE-2025-66586

In AzeoTech DAQFactory release 20.7 (Build 2555), an Access of Resource Using Incompatible Type vulnerability can be exploited to cause memory corruption while parsing specially crafted .ctl files. This could allow an attacker to execute code in the context of the current process.

Products Affected

Vendor Product Version
azeotech daqfactory *
CVE-2025-66588

In AzeoTech DAQFactory release 20.7 (Build 2555), an Access of Uninitialized Pointer vulnerability can be exploited by an attacker which can lead to arbitrary code execution.

Products Affected

Vendor Product Version
azeotech daqfactory *
CVE-2025-66589

In AzeoTech DAQFactory release 20.7 (Build 2555), an Out-of-bounds Read vulnerability can be exploited by an attacker to cause the program to read data past the end of an allocated buffer. This could allow an attacker to disclose information or cause a system crash.

Products Affected

Vendor Product Version
azeotech daqfactory *
CVE-2025-66590

In AzeoTech DAQFactory release 20.7 (Build 2555), an Out-of-bounds Write vulnerability can be exploited by an attacker to cause the program to write data past the end of an allocated memory buffer. This can lead to arbitrary code execution or a system crash.

Products Affected

Vendor Product Version
azeotech daqfactory *