Vulnerability index

Browse CVEs

689 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2022-34762 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause unauthorized firmware … Opc Ua Module For M580 Firmware after 1.10 Fix from $1,9502022-07-13 HIGH 7.5 CVE-2022-34763 A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists that could cause loading of unauthorized firmware images due to improp… Opc Ua Module For M580 Firmware after 1.10 Fix from $1,9502022-07-13 HIGH 7.5 CVE-2022-34764 A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service when parsi… Opc Ua Module For M580 Firmware after 1.10 Fix from $1,9502022-07-13 MEDIUM 6.8 CVE-2022-34754 A CWE-269: Improper Privilege Management vulnerability exists that could allow elevated functionality when guessing credentials. Affected Products: A… Acti9 Powertag Link C \(a9xelc10 A\) Firmware after 2.12.0 Fix from $1,6002022-07-13 MEDIUM 5.3 CVE-2022-34757 A CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists where weak cipher suites can be used for the SSH connection between … Easergy P5 Firmware after 01.401.102 Fix from $1,6002022-07-13 MEDIUM 5.3 CVE-2022-34765 A CWE-73: External Control of File Name or Path vulnerability exists that could cause loading of unauthorized firmware images when user-controlled da… Opc Ua Module For M580 Firmware after 1.10 Fix from $1,6002022-07-13 HIGH 7.8 CVE-2022-32530 A CWE-668 Exposure of Resource to Wrong Sphere vulnerability exists that could cause users to be misled, hiding alarms, showing the wrong server conn… Geo Scada Mobile 2020+ Fix from $1,9502022-06-24 CRITICAL 9.8 CVE-2022-30234 A CWE-798: Use of Hard-coded Credentials vulnerability exists that could allow arbitrary code to be executed when root level access is obtained. Affe… Wiser Smart Eer21000 Firmware after 4.5 Fix from $2,3002022-06-02 CRITICAL 9.8 CVE-2022-30235 A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow unauthorized access when an attacker uses … Wiser Smart Eer21000 Firmware after 4.5 Fix from $2,3002022-06-02 HIGH 8.8 CVE-2022-30232 A CWE-20: Improper Input Validation vulnerability exists that could cause potential remote code execution when an attacker is able to intercept and m… Powerlogic Ion Setup Firmware 3.2.22096.01+ Fix from $1,9502022-06-02 HIGH 8.8 CVE-2022-30238 A CWE-287: Improper Authentication vulnerability exists that could allow an attacker to take over the admin account when an attacker hijacks a sessio… Wiser Smart Eer21000 Firmware after 4.5 Fix from $1,9502022-06-02 HIGH 8.2 CVE-2022-30236 A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could allow unauthorized access when an attacker uses cross-domain a… Wiser Smart Eer21000 Firmware after 4.5 Fix from $1,9502022-06-02 HIGH 7.5 CVE-2022-30237 A CWE-311: Missing Encryption of Sensitive Data vulnerability exists that could allow authentication credentials to be recovered when an attacker bre… Wiser Smart Eer21000 Firmware after 4.5 Fix from $1,9502022-06-02 MEDIUM 6.5 CVE-2022-30233 A CWE-20: Improper Input Validation vulnerability exists that could allow the product to be maliciously manipulated when the user is tricked into per… Wiser Smart Eer21000 Firmware after 4.5 Fix from $1,6002022-06-02 CRITICAL 9.8 CVE-2021-22794 A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution. … Struxureware Data Center Expert after 7.8.1 Fix from $2,3002022-04-13 CRITICAL 9.8 CVE-2021-22795 A CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code… Struxureware Data Center Expert after 7.8.1 Fix from $2,3002022-04-13 HIGH 7.8 CVE-2019-6834 A CWE-502: Deserialization of Untrusted Data vulnerability exists which could allow an attacker to execute arbitrary code on the targeted system with… Software Update after 2.3.0 Fix from $1,9502022-04-13 HIGH 7.8 CVE-2021-22797EPSS 26% A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be … Ecostruxure Control Expert 15.1 / 2021+ Fix from $1,9502022-04-13 MEDIUM 5.5 CVE-2022-0221 A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could result in information disclosure when opening a mali… Scadapack Workbench after 6.6.8a Fix from $1,6002022-04-13 CRITICAL 9.8 CVE-2020-25176EPSS 6% Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in t… Epas Gtw Firmware 1.1.0+ Fix from $2,3002022-03-18 HIGH 8.8 CVE-2020-25178 ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communication protocol provides vario… Epas Gtw Firmware 1.1.0+ Fix from $1,9502022-03-18 MEDIUM 6.7 CVE-2020-25182 Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x searches for and loads DLLs as dynamic libraries. Uncontrolled loading of dynamic libraries … Epas Gtw Firmware 1.1.0+ Fix from $1,6002022-03-18 MEDIUM 6.5 CVE-2020-25180 Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged comm… Epas Gtw Firmware 1.1.0+ Fix from $1,6002022-03-18 MEDIUM 5.5 CVE-2020-25184 Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable f… Epas Gtw Firmware 1.1.0+ Fix from $1,6002022-03-18 HIGH 7.6 CVE-2021-22783 A CWE-200: Information Exposure vulnerability exists which could allow a session hijack when the door panel is communicating with the door. Affected … Ritto Wiser Door Mitigation only Fix from $1,9502022-03-09 MEDIUM 5.9 CVE-2022-24322 A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a disruption of communicatio… Ecostruxure Control Expert 15.0+ Fix from $1,6002022-03-09 MEDIUM 5.9 CVE-2022-24323 A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause a disruption of communication between the Modic… Ecostruxure Control Expert 15.0+ Fix from $1,6002022-03-09 CRITICAL 9.8 CVE-2022-22805EPSS 12% A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause remote code execution when an… Smt Series 1015 Ups Firmware after 04.5 Fix from $2,3002022-03-09 CRITICAL 9.8 CVE-2022-22806EPSS 12% A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause an unauthenticated connection to the UPS when a malformed co… Smt Series 1015 Ups Firmware after 04.5 Fix from $2,3002022-03-09 CRITICAL 9.1 CVE-2022-0715EPSS 6% A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leak… Smt Series 1015 Ups Firmware after 04.5 Fix from $2,3002022-03-09