Vulnerability index

Browse CVEs

89 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2023-5515 The responses for web queries with certain parameters disclose internal path of resources. This information can be used to learn internal structure o… Esoms after 6.3.13 Fix from $1,6002023-11-01 HIGH 8.8 CVE-2023-4816 A vulnerability exists in the Equipment Tag Out authentication, when configured with Single Sign-On (SSO) with password validation in T214. This vuln… Asset Suite after 9.6.3.11.1 Fix from $1,9502023-09-11 HIGH 7.5 CVE-2022-4608 A vulnerability exists in HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be explo… Rtu500 Firmware Mitigation only Fix from $1,9502023-07-26 HIGH 7.5 CVE-2022-2502 A vulnerability exists in the HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vulnerability can only be e… Rtu500 Firmware Mitigation only Fix from $1,9502023-07-26 HIGH 7.2 CVE-2022-3685 A vulnerability exists in the SDM600 software. The software operates at a privilege level that is higher than the minimum level required. An attacker… Sdm600 1.3+ Fix from $1,9502023-03-28 CRITICAL 9.1 CVE-2022-3686 A vulnerability exists in a SDM600 endpoint. An attacker could exploit this vulnerability by running multiple parallel requests, the SDM600 web servi… Sdm600 1.2.23000.291+ Fix from $2,3002023-03-28 HIGH 7.5 CVE-2022-3683 A vulnerability exists in the SDM600 API web services authorization validation implementation. An attacker who successfully exploits the vulnerabili… Sdm600 1.2.23000.291+ Fix from $1,9502023-03-28 HIGH 7.5 CVE-2022-3684 A vulnerability exists in a SDM600 endpoint. An attacker could exploit this vulnerability by running multiple parallel requests, the SDM600 web servi… Sdm600 1.2.23000.291+ Fix from $1,9502023-03-28 HIGH 8.8 CVE-2022-3682 A vulnerability exists in the SDM600 file permission validation. An attacker could exploit the vulnerability by gaining access to the system and upl… Sdm600 1.3.0.1339+ Fix from $1,9502023-03-28 HIGH 7.5 CVE-2022-3353 A vulnerability exists in the IEC 61850 communication stack that affects multiple Hitachi Energy products.  An attacker could exploit the vulnerabil… Sys600 Firmware 8.3.3+ Fix from $1,9502023-02-21 HIGH 7.1 CVE-2022-2155 A vulnerability exists in the affected versions of Lumada APM’s User Asset Group feature due to a flaw in access control mechanism implementation on … Lumada Asset Performance Management 6.4.0.1+ Fix from $1,9502023-01-12 CRITICAL 9.8 CVE-2022-3927 The affected products store both public and private key that are used to sign and protect Custom Parameter Set (CPS) file from modification. An attac… Foxman Un Mitigation only Fix from $2,3002023-01-05 CRITICAL 9.8 CVE-2022-3929 Communication between the client and the server application of the affected products is partially done using CORBA (Common Object Request Broker Arch… Foxman Un Mitigation only Fix from $2,3002023-01-05 MEDIUM 5.5 CVE-2022-3928 Hardcoded credential is found in affected products' message queue. An attacker that manages to exploit this vulnerability will be able to access data… Foxman Un Mitigation only Fix from $1,6002023-01-05 CRITICAL 9.8 CVE-2021-40342 In the DES implementation, the affected product versions use a default key for encryption. Successful exploitation allows an attacker to obtain sensi… Foxman Un Mitigation only Fix from $2,3002023-01-05 MEDIUM 5.5 CVE-2021-40341 DES cipher, which has inadequate encryption strength, is used Hitachi Energy FOXMAN-UN to encrypt user credentials used to access the Network Element… Foxman Un Mitigation only Fix from $1,6002023-01-05 MEDIUM 5.5 CVE-2022-2513 A vulnerability exists in the Intelligent Electronic Device (IED) Connectivity Package (ConnPack) credential storage function in Hitachi Energy’s PCM… 650connectivitypackage after 2.11 Fix from $1,6002022-11-22 HIGH 7.8 CVE-2022-3388 An input validation vulnerability exists in the Monitor Pro interface of MicroSCADA Pro and MicroSCADA X SYS600. An authenticated user can launch an … Microscada Pro Sys600 Mitigation only Fix from $1,9502022-11-21 HIGH 7.5 CVE-2022-29492 Improper Input Validation vulnerability in the handling of a malformed IEC 104 TCP packet in the Hitachi Energy MicroSCADA X SYS600, MicroSCADA Pro S… Microscada X Sys600 10.4+ Fix from $1,9502022-09-14 HIGH 7.5 CVE-2022-29922 Improper Input Validation vulnerability in the handling of a specially crafted IEC 61850 packet with a valid data item but with incorrect data type i… Microscada X Sys600 10.4+ Fix from $1,9502022-09-14 HIGH 7.5 CVE-2022-2277 Improper Input Validation vulnerability exists in the Hitachi Energy MicroSCADA X SYS600's ICCP stack during the ICCP communication establishment cau… Microscada X Sys600 after 10.3.1 Fix from $1,9502022-09-14 HIGH 8.8 CVE-2022-29490 Improper Authorization vulnerability exists in the Workplace X WebUI of the Hitachi Energy MicroSCADA X SYS600 allows an authenticated user to execut… Microscada X Sys600 after 10.3.1 Fix from $1,9502022-09-12 HIGH 8.8 CVE-2021-40335 A vulnerability exists in the HTTP web interface where the web interface does not sufficiently verify if a well-formed, valid, consistent request was… Modular Switchgear Monitoring Firmware after 2.2.0 Fix from $1,9502022-07-25 HIGH 8.8 CVE-2021-40336 A vulnerability exists in the http web interface where the web interface does not validate data in an HTTP header. This causes a possible HTTP respon… Modular Switchgear Monitoring Firmware after 2.2.0 Fix from $1,9502022-07-25 MEDIUM 6.7 CVE-2021-35530 A vulnerability in the application authentication and authorization mechanism in Hitachi Energy's TXpert Hub CoreTec 4, that depends on a token valid… Txpert Hub Coretec 4 Firmware Mitigation only Fix from $1,6002022-06-07 MEDIUM 6.7 CVE-2021-35531 Improper Input Validation vulnerability in a particular configuration setting field of Hitachi Energy TXpert Hub CoreTec 4 product, allows an attacke… Txpert Hub Coretec 4 Firmware Mitigation only Fix from $1,6002022-06-07 MEDIUM 6.7 CVE-2021-35532 A vulnerability exists in the file upload validation part of Hitachi Energy TXpert Hub CoreTec 4 product. The vulnerability allows an attacker or mal… Txpert Hub Coretec 4 Firmware Mitigation only Fix from $1,6002022-06-07 MEDIUM 6.1 CVE-2021-27414 An attacker could trick a user of Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to and including 9.0.25 into visit… Ellipse Enterprise Asset Management 9.0.23+ Fix from $1,6002022-03-11 MEDIUM 5.4 CVE-2021-27416 An attacker could exploit this vulnerability in Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to and including 9.0… Ellipse Enterprise Asset Management 9.0.26+ Fix from $1,6002022-03-11 HIGH 7.5 CVE-2021-40334 Missing Handler vulnerability in the proprietary management protocol (port TCP 5558) of Hitachi Energy FOX61x, XCM20 allows an attacker that exploits… Fox615 Firmware Mitigation only Fix from $1,9502021-12-02