Show filters
346 Total Results
Displaying 1-10 of 346
Sort by:
Attacker Value
Unknown

CVE-2024-8401

Disclosure Date: January 28, 2025 (last updated January 29, 2025)
CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when an authenticated attacker modifies folder names within the context of the product.
0
Attacker Value
Unknown

CVE-2024-12703

Disclosure Date: January 17, 2025 (last updated January 17, 2025)
CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote code execution on workstation when a non-admin authenticated user opens a malicious project file.
0
Attacker Value
Unknown

CVE-2024-10313

Disclosure Date: October 24, 2024 (last updated October 25, 2024)
iniNet Solutions SpiderControl SCADA PC HMI Editor has a path traversal vulnerability. When the software loads a malicious ‘ems' project template file constructed by an attacker, it can write files to arbitrary directories. This can lead to overwriting system files, causing system paralysis, or writing to startup items, resulting in remote control.
0
Attacker Value
Unknown

CVE-2024-9414

Disclosure Date: October 17, 2024 (last updated October 18, 2024)
In LAquis SCADA version 4.7.1.511, a cross-site scripting vulnerability could allow an attacker to inject arbitrary code into a web page. This could allow an attacker to steal cookies, redirect users, or perform unauthorized actions.
0
Attacker Value
Unknown

CVE-2024-47221

Disclosure Date: September 22, 2024 (last updated September 29, 2024)
CheckUser in ScadaServerEngine/MainLogic.cs in Rapid SCADA through 5.8.4 allows an empty password.
Attacker Value
Unknown

CVE-2024-8232

Disclosure Date: September 10, 2024 (last updated September 11, 2024)
SpiderControl SCADA Web Server has a vulnerability that could allow an attacker to upload specially crafted malicious files without authentication.
0
Attacker Value
Unknown

CVE-2024-7941

Disclosure Date: August 27, 2024 (last updated October 31, 2024)
An HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified URL. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.
Attacker Value
Unknown

CVE-2024-7940

Disclosure Date: August 27, 2024 (last updated August 29, 2024)
The product exposes a service that is intended for local only to all network interfaces without any authentication.
Attacker Value
Unknown

CVE-2024-4872

Disclosure Date: August 27, 2024 (last updated October 31, 2024)
A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated attacker to inject code towards persistent data. Note that to successfully exploit this vulnerability an attacker must have a valid credential.
Attacker Value
Unknown

CVE-2024-3982

Disclosure Date: August 27, 2024 (last updated August 29, 2024)
An attacker with local access to machine where MicroSCADA X SYS600 is installed, could enable the session logging supporting the product and try to exploit a session hijacking of an already established session. By default, the session logging level is not enabled and only users with administrator rights can enable it.