Show filters
796 Total Results
Displaying 11-20 of 796
Sort by:
Attacker Value
Unknown

CVE-2024-10083

Disclosure Date: February 13, 2025 (last updated February 13, 2025)
CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of engineering workstation when specific driver interface is invoked locally by an authenticated user with crafted input.
0
Attacker Value
Unknown

CVE-2024-8401

Disclosure Date: January 28, 2025 (last updated January 29, 2025)
CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when an authenticated attacker modifies folder names within the context of the product.
0
Attacker Value
Unknown

CVE-2024-12703

Disclosure Date: January 17, 2025 (last updated January 17, 2025)
CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote code execution on workstation when a non-admin authenticated user opens a malicious project file.
0
Attacker Value
Unknown

CVE-2024-12142

Disclosure Date: January 17, 2025 (last updated January 17, 2025)
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information disclosure of restricted web page, modification of web page and denial of service when specific web pages are modified and restricted functions are invoked.
0
Attacker Value
Unknown

CVE-2024-10498

Disclosure Date: January 17, 2025 (last updated January 17, 2025)
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could allow an unauthorized attacker to modify configuration values outside of the normal range when the attacker sends specific Modbus write packets to the device which could result in invalid data or loss of web interface functionality.
0
Attacker Value
Unknown

CVE-2024-10497

Disclosure Date: January 17, 2025 (last updated January 17, 2025)
CWE-639: Authorization Bypass Through User-Controlled Key vulnerability exists that could allow an authorized attacker to modify values outside those defined by their privileges (Elevation of Privileges) when the attacker sends modified HTTPS requests to the device.
0
Attacker Value
Unknown

CVE-2024-12476

Disclosure Date: January 17, 2025 (last updated January 17, 2025)
CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure, impacts workstation integrity and potential remote code execution on the compromised computer, when specific crafted XML file is imported in the Web Designer configuration tool.
0
Attacker Value
Unknown

CVE-2024-12399

Disclosure Date: January 17, 2025 (last updated January 17, 2025)
CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause partial loss of confidentiality, loss of integrity and availability of the HMI when attacker performs man in the middle attack by intercepting the communication.
0
Attacker Value
Unknown

CVE-2024-11425

Disclosure Date: January 17, 2025 (last updated January 17, 2025)
CWE-131: Incorrect Calculation of Buffer Size vulnerability exists that could cause Denial-of-Service of the product when an unauthenticated user is sending a crafted HTTPS packet to the webserver.
0
Attacker Value
Unknown

CVE-2024-11139

Disclosure Date: January 17, 2025 (last updated January 17, 2025)
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could allow local attackers to exploit these issues to potentially execute arbitrary code when opening a malicious project file.
0