Vulnerability index

Browse CVEs

20 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Icdm Rx\/tcp Socketserver Firmware HIGH 7.1
CVE-2024-5849

An unauthenticated remote attacker may use a reflected XSS vulnerability to obtain information from a user or reboot the affected device once.

Fix: 1.0.7 / 1.08+
Fix from $1,950 2024-08-13
Icdm Rx\/tcp Socketserver Firmware HIGH 7.1
CVE-2024-38502

An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once.

Fix: 1.0.7 / 1.08+
Fix from $1,950 2024-08-13
Icdm Rx\/tcp Socketserver Firmware MEDIUM 6.1
CVE-2024-38501

An unauthenticated remote attacker may use a HTML injection vulnerability with limited length to inject malicious HTML code and gain low-privileged a…

Fix: 1.0.7 / 1.08+
Fix from $1,600 2024-08-13
Oit700 F113 B12 Cb Firmware CRITICAL 9.8
CVE-2024-6422

An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data.

Fix: after 2.11.0
Fix from $2,300 2024-07-10
Oit700 F113 B12 Cb Firmware HIGH 7.5
CVE-2024-6421

An unauthenticated remote attacker can read out sensitive device information through a incorrectly configured FTP service.

Fix: after 2.11.0
Fix from $1,950 2024-07-10
Wha Gw F2d2 0 As Z2 Eth Firmware CRITICAL 9.8
CVE-2021-34565

In PEPPERL+FUCHS WirelessHART-Gateway 3.0.7 to 3.0.9 the SSH and telnet services are active with hard-coded credentials.

Fix: after 3.0.9
Fix from $2,300 2021-08-31
Wha Gw F2d2 0 As Z2 Eth Firmware HIGH 8.8
CVE-2021-34561

In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 serious issue exists, if the application is not externally accessible or uses IP-based access restrict…

Fix: after 3.0.8
Fix from $1,950 2021-08-31
Wha Gw F2d2 0 As Z2 Eth Firmware HIGH 7.5
CVE-2021-33555

In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.7 the filename parameter is vulnerable to unauthenticated path traversal attacks, enabling read access t…

Fix: after 3.0.7
Fix from $1,950 2021-08-31
Wha Gw F2d2 0 As Z2 Eth Firmware MEDIUM 6.1
CVE-2021-34562

In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 it is possible to inject arbitrary JavaScript into the application's response.

Mitigation only
Fix from $1,600 2021-08-31
Wha Gw F2d2 0 As Z2 Eth Firmware MEDIUM 5.5
CVE-2021-34560

In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored credentials can be captured by …

Fix: after 3.0.9
Fix from $1,600 2021-08-31
Wha Gw F2d2 0 As Z2 Eth Firmware MEDIUM 5.5
CVE-2021-34564

Any cookie-stealing vulnerabilities within the application or browser would enable an attacker to steal the user's credentials to the PEPPERL+FUCHS W…

No fix yet
Fix from $1,600 2021-08-31
Wha Gw F2d2 0 As Z2 Eth Firmware MEDIUM 5.3
CVE-2021-34559

In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 a vulnerability may allow remote attackers to rewrite links and URLs in cached pages to arbitrary stri…

Fix: after 3.0.8
Fix from $1,600 2021-08-31
Io Link Master 4 Eip Firmware HIGH 8.8
CVE-2020-12513EPSS 31%

Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection.

Fix: after 1.5.48
Fix from $1,950 2021-01-22
Io Link Master 4 Eip Firmware MEDIUM 5.4
CVE-2020-12512

Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated reflected POST Cross-Site Scripting

Fix: after 1.5.48
Fix from $1,600 2021-01-22
Io Link Master 4 Eip Firmware HIGH 8.8
CVE-2020-12511

Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a Cross-Site Request Forgery (CSRF) in the web interface.

Fix: after 1.5.48
Fix from $1,950 2021-01-22
Es7510 Xt Firmware CRITICAL 9.8
CVE-2020-12500

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES…

No fix yet
Fix from $2,300 2020-10-15
Es7510 Xt Firmware CRITICAL 9.8
CVE-2020-12501

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES…

No fix yet
Fix from $2,300 2020-10-15
Es7510 Xt Firmware CRITICAL 9.8
CVE-2020-12504

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES…

Fix: 2.1.1+
Fix from $2,300 2020-10-15
Es7510 Xt Firmware HIGH 8.8
CVE-2020-12502

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES…

No fix yet
Fix from $1,950 2020-10-15
Es7510 Xt Firmware HIGH 7.2
CVE-2020-12503EPSS 23%

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES…

No fix yet
Fix from $1,950 2020-10-15