Viessmann Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Viessmann products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

2

In CISA KEV

0

Beyond CISA KEV

2

Sensor Observed

0

Virtual Patch Available

0

Viessmann KEVs Added by Year

Loading...

2 Viessmann KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2023-5222

Viessmann Vitogate 300 Web Management Interface vitogate.cgi isValidUser hard-coded password

High Not in CISA 05 Oct 2025
CVE-2023-45852

In Vitogate 300 2.1.3.0, /cgi-bin/vitogate.cgi allows an unauthenticated attacker to bypass authentication and execute arbitrary commands via shell...

High Not in CISA 29 Jul 2025

Common Vulnerability Classes (CWE)

  • CWE-259 — Use of Hard-coded Password 1
  • CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology