Show filters
46 Total Results
Displaying 11-20 of 46
Sort by:
Attacker Value
Unknown
CVE-2023-32673
Disclosure Date: June 12, 2023 (last updated October 08, 2023)
Certain versions of HP PC Hardware Diagnostics Windows, HP Image Assistant, and HP Thunderbolt Dock G2 Firmware are potentially vulnerable to elevation of privilege.
0
Attacker Value
Unknown
CVE-2023-27497
Disclosure Date: April 11, 2023 (last updated October 08, 2023)
Due to missing authentication and input sanitization of code the EventLogServiceCollector of SAP Diagnostics Agent - version 720, allows an attacker to execute malicious scripts on all connected Diagnostics Agents running on Windows. On successful exploitation, the attacker can completely compromise confidentiality, integrity and availability of the system.
0
Attacker Value
Unknown
CVE-2023-27267
Disclosure Date: April 11, 2023 (last updated October 08, 2023)
Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version 720, allows an attacker with deep knowledge of the system to execute scripts on all connected Diagnostics Agents. On successful exploitation, the attacker can completely compromise confidentiality, integrity and availability of the system.
0
Attacker Value
Unknown
CVE-2022-29149
Disclosure Date: June 15, 2022 (last updated November 29, 2024)
Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability
0
Attacker Value
Unknown
CVE-2022-24396
Disclosure Date: March 10, 2022 (last updated November 08, 2023)
The Simple Diagnostics Agent - versions 1.0 up to version 1.57, does not perform any authentication checks for functionalities that can be accessed via localhost on http port 3005. Due to lack of authentication checks, an attacker could access administrative or other privileged functionalities and read, modify, or delete sensitive information and configurations.
0
Attacker Value
Unknown
CVE-2022-22547
Disclosure Date: March 10, 2022 (last updated November 29, 2024)
Simple Diagnostics Agent - versions 1.0 (up to version 1.57.), allows an attacker to access information which would otherwise be restricted via a random port 9000-65535. This allows information gathering which could be used exploit future open-source security exploits.
0
Attacker Value
Unknown
CVE-2021-38649
Disclosure Date: September 15, 2021 (last updated November 28, 2024)
Open Management Infrastructure Elevation of Privilege Vulnerability
0
Attacker Value
Unknown
CVE-2021-38645
Disclosure Date: September 15, 2021 (last updated November 28, 2024)
Open Management Infrastructure Elevation of Privilege Vulnerability
0
Attacker Value
Unknown
CVE-2020-12526
Disclosure Date: April 27, 2021 (last updated February 22, 2025)
TwinCAT OPC UA Server in versions up to 2.3.0.12 and IPC Diagnostics UA Server in versions up to 3.1.0.1 from Beckhoff Automation GmbH & Co. KG are vulnerable to denial of service attacks. The attacker needs to send several specifically crafted requests to the running OPC UA server. After some of these requests the OPC UA server is no longer responsive to any client. This is without effect to the real-time functionality of IPCs.
0
Attacker Value
Unknown
CVE-2020-5807
Disclosure Date: December 29, 2020 (last updated February 22, 2025)
An unauthenticated remote attacker can send data to RsvcHost.exe listening on TCP port 5241 to add entries in the FactoryTalk Diagnostics event log. The attacker can specify long fields in the log entry, which can cause an unhandled exception in wcscpy_s() if a local user opens FactoryTalk Diagnostics Viewer (FTDiagViewer.exe) to view the log entry. Observed in FactoryTalk Diagnostics 6.11. All versions of FactoryTalk Diagnostics are affected.
0