Vulnerability index

Browse CVEs

689 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Modicon M340 Bmxp341000 Firmware MEDIUM 5.3
CVE-2020-7549

A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum…

Fix: 3.4 / 3.30+
Fix from $1,600 2020-12-11
Easergy T300 Firmware CRITICAL 9.8
CVE-2020-28215

A CWE-862: Missing Authorization vulnerability exists in Easergy T300 (firmware 2.7 and older), that could cause a wide range of problems, including …

Fix: after 2.7
Fix from $2,300 2020-12-11
Ecostruxure Geo Scada Expert 2019 HIGH 7.8
CVE-2020-28219

A CWE-522: Insufficiently Protected Credentials vulnerability exists in EcoStruxure Geo SCADA Expert 2019 (Original release and Monthly Updates to Se…

Fix: after 83.7578.1
Fix from $1,950 2020-12-11
Easergy T300 Firmware HIGH 7.5
CVE-2020-28216

A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to read n…

Fix: after 2.7
Fix from $1,950 2020-12-11
Easergy T300 Firmware HIGH 7.5
CVE-2020-28217

A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to read n…

Fix: after 2.7
Fix from $1,950 2020-12-11
Modicon M258 Firmware MEDIUM 6.8
CVE-2020-28220

A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Modicon M258 Firmware (All versions prior …

Fix: 5.0.4.11+
Fix from $1,600 2020-12-11
Easergy T300 Firmware MEDIUM 6.5
CVE-2020-28218

A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an a…

Fix: after 2.7
Fix from $1,600 2020-12-11
Modicon M221 Firmware MEDIUM 5.5
CVE-2020-28214

A CWE-760: Use of a One-Way Hash with a Predictable Salt vulnerability exists in Modicon M221 (all references, all versions), that could allow an att…

Mitigation only
Fix from $1,600 2020-12-11
Modicon M340 Bmxp3420302 Firmware CRITICAL 9.8
CVE-2020-7533

CWE-287: Improper Authentication vulnerability exists which could cause the execution of commands on the webserver without authentication when sendin…

Fix: 2.10 / 3.3+
Fix from $2,300 2020-12-01
Acti9 Smartlink Si D Firmware CRITICAL 9.8
CVE-2020-7548

A CWE-330 - Use of Insufficiently Random Values vulnerability exists in Smartlink, PowerTag, and Wiser Series Gateways (see security notification for…

Fix: 1.2.1 / 1.5.0+
Fix from $2,300 2020-12-01
Ecostruxure Energy Expert HIGH 8.8
CVE-2020-7547

A CWE-284: Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notifica…

Mitigation only
Fix from $1,950 2020-12-01
Ecostruxure Energy Expert HIGH 7.2
CVE-2020-7545

A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notificat…

Mitigation only
Fix from $1,950 2020-12-01
Ecostruxure Energy Expert MEDIUM 5.4
CVE-2020-7546

A CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SC…

Mitigation only
Fix from $1,600 2020-12-01
Webreports HIGH 8.8
CVE-2020-7569

A CWE-434 Unrestricted Upload of File with Dangerous Type vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could ca…

Fix: after 3.1
Fix from $1,950 2020-11-19
Webreports HIGH 8.8
CVE-2020-7572

A CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that co…

Fix: after 3.1
Fix from $1,950 2020-11-19
Modicon M221 Firmware HIGH 7.3
CVE-2020-7566

A CWE-334: Small Space of Random Values vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to break th…

Mitigation only
Fix from $1,950 2020-11-19
Webreports MEDIUM 6.5
CVE-2020-7573

A CWE-284 Improper Access Control vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause a remote attacker be…

Fix: after 3.1
Fix from $1,600 2020-11-19
Modicon M221 Firmware MEDIUM 5.7
CVE-2020-7567

A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to …

Mitigation only
Fix from $1,600 2020-11-19
Webreports MEDIUM 5.4
CVE-2020-7570

A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Stored) vulnerability exists in EcoStruxure Building Opera…

Fix: after 3.1
Fix from $1,600 2020-11-19
Webreports MEDIUM 5.4
CVE-2020-7571

A CWE-79 Multiple Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Reflected) vulnerability exists in EcoStruxure Bu…

Fix: after 3.1
Fix from $1,600 2020-11-19
Easergy T300 Firmware CRITICAL 9.8
CVE-2020-7561

A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T300 (with firmware 2.7 and older) that could cause a wide ra…

Fix: after 2.7
Fix from $2,300 2020-11-19
Operator Terminal Expert Runtime HIGH 7.8
CVE-2020-7544

A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD) that could cause privilege e…

Fix: 3.1+
Fix from $1,950 2020-11-19
Interactive Graphical Scada System HIGH 7.8
CVE-2020-7550

A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20…

Fix: after 14.0.0.20247
Fix from $1,950 2020-11-19
Interactive Graphical Scada System HIGH 7.8
CVE-2020-7551

A CWE-787: Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247, that could cause Remote Code Execution when ma…

Fix: after 14.0.0.20247
Fix from $1,950 2020-11-19
Interactive Graphical Scada System HIGH 7.8
CVE-2020-7552

A CWE-787: Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247, that could cause Remote Code Execution when ma…

Fix: after 14.0.0.20247
Fix from $1,950 2020-11-19
Interactive Graphical Scada System HIGH 7.8
CVE-2020-7553

A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when mali…

Fix: after 14.0.0.20247
Fix from $1,950 2020-11-19
Interactive Graphical Scada System HIGH 7.8
CVE-2020-7554

A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20…

Fix: after 14.0.0.20247
Fix from $1,950 2020-11-19
Interactive Graphical Scada System HIGH 7.8
CVE-2020-7555

A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when mali…

Fix: after 14.0.0.20247
Fix from $1,950 2020-11-19
Interactive Graphical Scada System HIGH 7.8
CVE-2020-7556

A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when mali…

Fix: after 14.0.0.20247
Fix from $1,950 2020-11-19
Interactive Graphical Scada System HIGH 7.8
CVE-2020-7557

A CWE-125 Out-of-bounds Read vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malic…

Fix: after 14.0.0.20247
Fix from $1,950 2020-11-19