Show filters
649 Total Results
Displaying 11-20 of 649
Sort by:
Attacker Value
Unknown
CVE-2025-20014
Disclosure Date: January 29, 2025 (last updated January 30, 2025)
mySCADA myPRO does not properly neutralize POST requests sent to a specific port with version information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system.
0
Attacker Value
Unknown
CVE-2024-8603
Disclosure Date: January 15, 2025 (last updated January 16, 2025)
A “Use of a Broken or Risky Cryptographic Algorithm” vulnerability in the SSL/TLS component used in B&R Automation Runtime versions before 6.1 and B&R mapp View versions before 6.1 may be abused by unauthenticated network-based attackers to masquerade as services on impacted devices.
0
Attacker Value
Unknown
CVE-2024-11999
Disclosure Date: December 17, 2024 (last updated December 18, 2024)
CWE-1104: Use of Unmaintained Third-Party Components vulnerability exists that could cause complete
control of the device when an authenticated user installs malicious code into HMI product.
0
Attacker Value
Unknown
CVE-2024-52051
Disclosure Date: December 10, 2024 (last updated December 21, 2024)
A vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC S7-PLCSIM V18 (All versions), SIMATIC STEP 7 Safety V17 (All versions), SIMATIC STEP 7 Safety V18 (All versions), SIMATIC STEP 7 Safety V19 (All versions), SIMATIC STEP 7 V17 (All versions), SIMATIC STEP 7 V18 (All versions), SIMATIC STEP 7 V19 (All versions), SIMATIC WinCC Unified PC Runtime V18 (All versions), SIMATIC WinCC Unified PC Runtime V19 (All versions), SIMATIC WinCC Unified V17 (All versions), SIMATIC WinCC Unified V18 (All versions), SIMATIC WinCC Unified V19 (All versions), SIMATIC WinCC V17 (All versions), SIMATIC WinCC V18 (All versions), SIMATIC WinCC V19 (All versions), SIMOCODE ES V17 (All versions), SIMOCODE ES V18 (All versions), SIMOCODE ES V19 (All versions), SIMOTION SCOUT TIA V5.4 SP3 (All versions), SIMOTION SCOUT TIA V5.5 SP1 (All versions), SIMOTION SCOUT TIA V5.6 SP1 (All versions), SINAMICS Startdrive V17 (All versions), SINAMICS Startdrive V18 (All versions), SINAMICS St…
0
Attacker Value
Unknown
CVE-2024-52034
Disclosure Date: November 22, 2024 (last updated January 05, 2025)
An OS Command Injection vulnerability exists within myPRO Manager. A parameter within a command can be exploited by an unauthenticated remote attacker to inject arbitrary operating system commands.
0
Attacker Value
Unknown
CVE-2024-50054
Disclosure Date: November 22, 2024 (last updated January 05, 2025)
The back-end does not sufficiently verify the user-controlled filename parameter which makes it possible for an attacker to perform a path traversal attack and retrieve arbitrary files from the file system.
0
Attacker Value
Unknown
CVE-2024-47407
Disclosure Date: November 22, 2024 (last updated January 05, 2025)
A parameter within a command does not properly validate input within myPRO Manager which could be exploited by an unauthenticated remote attacker to inject arbitrary operating system commands.
0
Attacker Value
Unknown
CVE-2024-47138
Disclosure Date: November 22, 2024 (last updated January 05, 2025)
The administrative interface listens by default on all interfaces on a TCP port and does not require authentication when being accessed.
0
Attacker Value
Unknown
CVE-2024-45369
Disclosure Date: November 22, 2024 (last updated January 05, 2025)
The web application uses a weak authentication mechanism to verify that a request is coming from an authenticated and authorized resource.
0
Attacker Value
Unknown
CVE-2023-4639
Disclosure Date: November 17, 2024 (last updated February 08, 2025)
A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or modification. The main threat from this flaw impacts data confidentiality and integrity.
0