Vulnerability index

Browse CVEs

689 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2020-7549 A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum… Modicon M340 Bmxp341000 Firmware 3.4 / 3.30+ Fix from $1,6002020-12-11 CRITICAL 9.8 CVE-2020-28215 A CWE-862: Missing Authorization vulnerability exists in Easergy T300 (firmware 2.7 and older), that could cause a wide range of problems, including … Easergy T300 Firmware after 2.7 Fix from $2,3002020-12-11 HIGH 7.8 CVE-2020-28219 A CWE-522: Insufficiently Protected Credentials vulnerability exists in EcoStruxure Geo SCADA Expert 2019 (Original release and Monthly Updates to Se… Ecostruxure Geo Scada Expert 2019 after 83.7578.1 Fix from $1,9502020-12-11 HIGH 7.5 CVE-2020-28216 A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to read n… Easergy T300 Firmware after 2.7 Fix from $1,9502020-12-11 HIGH 7.5 CVE-2020-28217 A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to read n… Easergy T300 Firmware after 2.7 Fix from $1,9502020-12-11 MEDIUM 6.8 CVE-2020-28220 A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Modicon M258 Firmware (All versions prior … Modicon M258 Firmware 5.0.4.11+ Fix from $1,6002020-12-11 MEDIUM 6.5 CVE-2020-28218 A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an a… Easergy T300 Firmware after 2.7 Fix from $1,6002020-12-11 MEDIUM 5.5 CVE-2020-28214 A CWE-760: Use of a One-Way Hash with a Predictable Salt vulnerability exists in Modicon M221 (all references, all versions), that could allow an att… Modicon M221 Firmware Mitigation only Fix from $1,6002020-12-11 CRITICAL 9.8 CVE-2020-7533 CWE-287: Improper Authentication vulnerability exists which could cause the execution of commands on the webserver without authentication when sendin… Modicon M340 Bmxp3420302 Firmware 2.10 / 3.3+ Fix from $2,3002020-12-01 CRITICAL 9.8 CVE-2020-7548 A CWE-330 - Use of Insufficiently Random Values vulnerability exists in Smartlink, PowerTag, and Wiser Series Gateways (see security notification for… Acti9 Smartlink Si D Firmware 1.2.1 / 1.5.0+ Fix from $2,3002020-12-01 HIGH 8.8 CVE-2020-7547 A CWE-284: Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notifica… Ecostruxure Energy Expert Mitigation only Fix from $1,9502020-12-01 HIGH 7.2 CVE-2020-7545 A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notificat… Ecostruxure Energy Expert Mitigation only Fix from $1,9502020-12-01 MEDIUM 5.4 CVE-2020-7546 A CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SC… Ecostruxure Energy Expert Mitigation only Fix from $1,6002020-12-01 HIGH 8.8 CVE-2020-7569 A CWE-434 Unrestricted Upload of File with Dangerous Type vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could ca… Webreports after 3.1 Fix from $1,9502020-11-19 HIGH 8.8 CVE-2020-7572 A CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that co… Webreports after 3.1 Fix from $1,9502020-11-19 HIGH 7.3 CVE-2020-7566 A CWE-334: Small Space of Random Values vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to break th… Modicon M221 Firmware Mitigation only Fix from $1,9502020-11-19 MEDIUM 6.5 CVE-2020-7573 A CWE-284 Improper Access Control vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause a remote attacker be… Webreports after 3.1 Fix from $1,6002020-11-19 MEDIUM 5.7 CVE-2020-7567 A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to … Modicon M221 Firmware Mitigation only Fix from $1,6002020-11-19 MEDIUM 5.4 CVE-2020-7570 A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Stored) vulnerability exists in EcoStruxure Building Opera… Webreports after 3.1 Fix from $1,6002020-11-19 MEDIUM 5.4 CVE-2020-7571 A CWE-79 Multiple Improper Neutralization of Input During Web Page Generation (Cross-site Scripting Reflected) vulnerability exists in EcoStruxure Bu… Webreports after 3.1 Fix from $1,6002020-11-19 CRITICAL 9.8 CVE-2020-7561 A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T300 (with firmware 2.7 and older) that could cause a wide ra… Easergy T300 Firmware after 2.7 Fix from $2,3002020-11-19 HIGH 7.8 CVE-2020-7544 A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD) that could cause privilege e… Operator Terminal Expert Runtime 3.1+ Fix from $1,9502020-11-19 HIGH 7.8 CVE-2020-7550 A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20… Interactive Graphical Scada System after 14.0.0.20247 Fix from $1,9502020-11-19 HIGH 7.8 CVE-2020-7551 A CWE-787: Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247, that could cause Remote Code Execution when ma… Interactive Graphical Scada System after 14.0.0.20247 Fix from $1,9502020-11-19 HIGH 7.8 CVE-2020-7552 A CWE-787: Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247, that could cause Remote Code Execution when ma… Interactive Graphical Scada System after 14.0.0.20247 Fix from $1,9502020-11-19 HIGH 7.8 CVE-2020-7553 A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when mali… Interactive Graphical Scada System after 14.0.0.20247 Fix from $1,9502020-11-19 HIGH 7.8 CVE-2020-7554 A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20… Interactive Graphical Scada System after 14.0.0.20247 Fix from $1,9502020-11-19 HIGH 7.8 CVE-2020-7555 A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when mali… Interactive Graphical Scada System after 14.0.0.20247 Fix from $1,9502020-11-19 HIGH 7.8 CVE-2020-7556 A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when mali… Interactive Graphical Scada System after 14.0.0.20247 Fix from $1,9502020-11-19 HIGH 7.8 CVE-2020-7557 A CWE-125 Out-of-bounds Read vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malic… Interactive Graphical Scada System after 14.0.0.20247 Fix from $1,9502020-11-19