An attacker may be able to cause a denial-of-service condition by sending many packets repeatedly.
An attacker may be able to cause a denial-of-service condition by sending many SSH packets repeatedly.
Plain text credentials and session ID can be captured with a network sniffer.
A potential attacker with access to the Westermo Lynx device may be able to execute malicious code that could affect the correct functioning of the d…
An attacker with access to the web application with vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payl…
A potential attacker with access to the Westermo Lynx device would be able to execute malicious code that could affect the correct functioning of the…
An attacker with access to the network where the affected devices are located could maliciously actions to obtain, via a sniffer, sensitive informati…
An attacker with access to the Westermo Lynx web application that has the vulnerable software could introduce arbitrary JavaScript by injecting a cro…
An attacker with access to the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "usernam…
An attacker with access to the web application that has the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site script…
The cross-site request forgery token in the request may be predictable or easily guessable allowing attackers to craft a malicious request, which cou…
Westermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remote attacker to retrieve the so…
The /uploadfile? functionality in Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allows remote users to upload malicious file types and execute…
Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers allow CSRF.
XSS exists in the /cmdexec/cmdexe?cmd= function in Westermo DR-250 Pre-5162 and DR-260 Pre-5162 routers.
A Cross-Site Request Forgery (CSRF) issue was discovered in Westermo MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions …
A Use of Hard-Coded Cryptographic Key issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older t…
A Use of Hard-Coded Credentials issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.…
Westermo WeOS before 4.19.0 uses the same SSL private key across different customers' installations, which makes it easier for man-in-the-middle atta…