Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sepcos Control And Protection Relay Firmware CRITICAL 9.8
CVE-2022-2104

The www-data (Apache web server) account is configured to run sudo with no password for many commands (including /bin/sh and /bin/bash).

Fix: 1.23.21 / 1.24.8+
Fix from $2,300 2022-06-24
Sepcos Control And Protection Relay Firmware CRITICAL 9.1
CVE-2022-2103

An attacker with weak credentials could access the TCP port via an open FTP port, allowing an attacker to read sensitive files and write to remotely …

Fix: 1.23.21 / 1.24.8+
Fix from $2,300 2022-06-24
Sepcos Control And Protection Relay Firmware CRITICAL 9.1
CVE-2022-2105

Client-side JavaScript controls may be bypassed to change user credentials and permissions without authentication, including a “root” user level mean…

Fix: 1.23.21 / 1.24.8+
Fix from $2,300 2022-06-24
Sepcos Control And Protection Relay Firmware HIGH 7.5
CVE-2022-2102

Controls limiting uploads to certain file extensions may be bypassed. This could allow an attacker to intercept the initial file upload page response…

Fix: 1.23.21 / 1.24.8+
Fix from $1,950 2022-06-24
Sepcos Control And Protection Relay Firmware CRITICAL 9.8
CVE-2022-1668

Weak default root user credentials allow remote attackers to easily obtain OS superuser privileges over the open TCP port for SSH.

Fix: 1.23.21 / 1.24.8+
Fix from $2,300 2022-06-24
Sepcos Control And Protection Relay Firmware HIGH 7.5
CVE-2022-1667

Client-side JavaScript controls may be bypassed by directly running a JS function to reboot the PLC (e.g., from the browser console) or by loading th…

Fix: 1.23.21 / 1.24.8+
Fix from $1,950 2022-06-24
Sepcos Control And Protection Relay Firmware MEDIUM 6.5
CVE-2022-1666

The default password for the web application’s root user (the vendor’s private account) was weak and the MD5 hash was used to crack the password usin…

Fix: 1.23.21 / 1.24.8+
Fix from $1,600 2022-06-24