Vulnerability index

Browse CVEs

689 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Easergy T300 Firmware CRITICAL 9.8
CVE-2020-7508

A CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which cou…

Fix: after 1.5.2
Fix from $2,300 2020-06-16
Easergy T300 Firmware CRITICAL 9.8
CVE-2020-7512

A CWE-1103: Use of Platform-Dependent Third Party Components with vulnerabilities vulnerability exists in Easergy T300 (Firmware version 1.5.2 and ol…

Fix: after 1.5.2
Fix from $2,300 2020-06-16
Easergy T300 Firmware HIGH 8.8
CVE-2020-7503

A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to…

Fix: after 1.5.2
Fix from $1,950 2020-06-16
Modicon M218 Firmware HIGH 7.5
CVE-2020-7502

A CWE-787: Out-of-bounds Write vulnerability exists in Modicon M218 Logic Controller (Firmware version 4.3 and prior), which may cause a Denial of Se…

Fix: after 4.3
Fix from $1,950 2020-06-16
Easergy T300 Firmware HIGH 7.5
CVE-2020-7506

A CWE-200: Information Exposure vulnerability exists in Easergy T300, Firmware V1.5.2 and prior, which could allow an attacker to pack or unpack the …

Fix: after 1.5.2
Fix from $1,950 2020-06-16
Easergy T300 Firmware HIGH 7.5
CVE-2020-7507

A CWE-400: Uncontrolled Resource Consumption vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to…

Fix: after 1.5.2
Fix from $1,950 2020-06-16
Easergy T300 Firmware HIGH 7.5
CVE-2020-7510

A CWE-200: Information Exposure vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow attacker to obtain private …

Fix: after 1.5.2
Fix from $1,950 2020-06-16
Easergy T300 Firmware HIGH 7.5
CVE-2020-7511

A CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow…

Fix: after 1.5.2
Fix from $1,950 2020-06-16
Easergy T300 Firmware HIGH 7.5
CVE-2020-7513

A CWE-312: Cleartext Storage of Sensitive Information vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an at…

Fix: after 1.5.2
Fix from $1,950 2020-06-16
Easergy T300 Firmware HIGH 7.2
CVE-2020-7505

A CWE-494 Download of Code Without Integrity Check vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attac…

Fix: after 1.5.2
Fix from $1,950 2020-06-16
Easergy T300 Firmware HIGH 7.2
CVE-2020-7509

A CWE-269: Improper privilege management (write) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacke…

Fix: after 1.5.2
Fix from $1,950 2020-06-16
Easergy T300 Firmware MEDIUM 5.3
CVE-2020-7504

A CWE-20: Improper Input Validation vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to disable …

Fix: after 1.5.2
Fix from $1,600 2020-06-16
Ecostruxure Operator Terminal Expert CRITICAL 9.8
CVE-2020-7497

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert…

Fix: after 3.0
Fix from $2,300 2020-06-16
Os Loader CRITICAL 9.8
CVE-2020-7498

A CWE-798: Use of Hard-coded Credentials vulnerability exists in the Unity Loader and OS Loader Software (all versions). The fixed credentials are us…

Mitigation only
Fix from $2,300 2020-06-16
Mtn6501 0001 Firmware CRITICAL 9.8
CVE-2020-7500

A CWE-89:Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in U.motion Servers and Touch Pane…

Fix: 1.4.2+
Fix from $2,300 2020-06-16
Vijeo Designer HIGH 8.8
CVE-2020-7501

A CWE-798: Use of Hard-coded Credentials vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 16 and prior) and Vijeo Designer (V6.2 SP9 and pri…

Fix: after 6.2
Fix from $1,950 2020-06-16
Ecostruxure Operator Terminal Expert HIGH 7.8
CVE-2020-7493

A CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in EcoStruxure Operator Terminal …

Fix: after 3.0
Fix from $1,950 2020-06-16
Ecostruxure Operator Terminal Expert HIGH 7.8
CVE-2020-7494

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert…

Fix: after 3.0
Fix from $1,950 2020-06-16
Gp Pro Ex Firmware MEDIUM 6.5
CVE-2020-7492

A CWE-521: Weak Password Requirements vulnerability exists in the GP-Pro EX V1.00 to V4.09.100 which could cause the discovery of the password when t…

Fix: after 4.09.120
Fix from $1,600 2020-06-16
Mtn6501 0001 Firmware MEDIUM 6.5
CVE-2020-7499

A CWE-863: Incorrect Authorization vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notification) …

Fix: 1.4.2+
Fix from $1,600 2020-06-16
Ecostruxure Operator Terminal Expert MEDIUM 5.5
CVE-2020-7495

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability during zip file extraction exists in EcoStruxu…

Fix: after 3.0
Fix from $1,600 2020-06-16
Ecostruxure Machine Expert CRITICAL 9.8
CVE-2020-7487

A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists which could allow the attacker to execute malicious code on the Modico…

Mitigation only
Fix from $2,300 2020-04-22
Ecostruxure Machine Expert CRITICAL 9.8
CVE-2020-7489

A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability exists on EcoStruxure Mach…

Patch available
Fix from $2,300 2020-04-22
Vijeo Designer HIGH 7.8
CVE-2020-7490

A CWE-426: Untrusted Search Path vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 15 and prior) and Vijeo Designer (V6.9 SP9 and prior), whi…

Fix: after 6.2
Fix from $1,950 2020-04-22
Bmx P34x Firmware HIGH 7.5
CVE-2019-6859

A CWE-798: Use of Hardcoded Credentials vulnerability exists in Modicon Controllers (All versions of the following CPUs and Communication Module prod…

Mitigation only
Fix from $1,950 2020-04-22
Ecostruxure Machine Expert HIGH 7.5
CVE-2020-7488

A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists which could leak sensitive information transmitted between the softwa…

Mitigation only
Fix from $1,950 2020-04-22
Tristation 1131 CRITICAL 9.8
CVE-2020-7485

**VERSION NOT SUPPORTED WHEN ASSIGNED** A legacy support account in the TriStation software version v4.9.0 and earlier could cause improper access to…

Fix: after 4.9.0
Fix from $2,300 2020-04-16
Tristation 1131 HIGH 7.5
CVE-2020-7483

**VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause certain data to be visible on the network when the 'password' feature is enabled.…

Fix: after 4.12.0
Fix from $1,950 2020-04-16
Tristation 1131 HIGH 7.5
CVE-2020-7484

**VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability with the former 'password' feature could allow a denial of service attack if the user is not …

Fix: 4.13.0+
Fix from $1,950 2020-04-16
Tricon Tcm 4351 Firmware HIGH 7.5
CVE-2020-7486

**VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause TCM modules to reset when under high network load in TCM v10.4.x and in system v1…

Mitigation only
Fix from $1,950 2020-04-16