Show filters
27 Total Results
Displaying 11-20 of 27
Sort by:
Attacker Value
Unknown

CVE-2021-34563

Disclosure Date: August 16, 2021 (last updated November 28, 2024)
In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 and 3.0.9 the HttpOnly attribute is not set on a cookie. This allows the cookie's value to be read or set by client-side JavaScript.
Attacker Value
Unknown

CVE-2021-34565

Disclosure Date: August 16, 2021 (last updated November 28, 2024)
In PEPPERL+FUCHS WirelessHART-Gateway 3.0.7 to 3.0.9 the SSH and telnet services are active with hard-coded credentials.
Attacker Value
Unknown

CVE-2021-33555

Disclosure Date: August 16, 2021 (last updated November 28, 2024)
In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.7 the filename parameter is vulnerable to unauthenticated path traversal attacks, enabling read access to arbitrary files on the server.
Attacker Value
Unknown

CVE-2021-34561

Disclosure Date: August 16, 2021 (last updated November 28, 2024)
In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 serious issue exists, if the application is not externally accessible or uses IP-based access restrictions. Attackers can use DNS Rebinding to bypass any IP or firewall based access restrictions that may be in place, by proxying through their target's browser.
Attacker Value
Unknown

CVE-2021-20987

Disclosure Date: February 15, 2021 (last updated February 22, 2025)
A denial of service and memory corruption vulnerability was found in Hilscher EtherNet/IP Core V2 prior to V2.13.0.21that may lead to code injection through network or make devices crash without recovery.
Attacker Value
Unknown

CVE-2021-20986

Disclosure Date: February 15, 2021 (last updated February 22, 2025)
A Denial of Service vulnerability was found in Hilscher PROFINET IO Device V3 in versions prior to V3.14.0.7. This may lead to unexpected loss of cyclic communication or interruption of acyclic communication.
Attacker Value
Unknown

CVE-2021-20988

Disclosure Date: February 15, 2021 (last updated February 22, 2025)
In Hilscher rcX RTOS versions prios to V2.1.14.1 the actual UDP packet length is not verified against the length indicated by the packet. This may lead to a denial of service of the affected device.
Attacker Value
Unknown

CVE-2020-12525

Disclosure Date: January 14, 2021 (last updated February 22, 2025)
M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.
Attacker Value
Unknown

CVE-2020-12513

Disclosure Date: January 04, 2021 (last updated February 22, 2025)
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection.
Attacker Value
Unknown

CVE-2020-12512

Disclosure Date: January 04, 2021 (last updated February 22, 2025)
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated reflected POST Cross-Site Scripting