Show filters
232 Total Results
Displaying 111-120 of 232
Sort by:
Attacker Value
Unknown

CVE-2021-27434

Disclosure Date: May 20, 2021 (last updated February 22, 2025)
Products with Unified Automation .NET based OPC UA Client/Server SDK Bundle: Versions V3.0.7 and prior (.NET 4.5, 4.0, and 3.5 Framework versions only) are vulnerable to an uncontrolled recursion, which may allow an attacker to trigger a stack overflow.
Attacker Value
Unknown

CVE-2021-29242

Disclosure Date: May 03, 2021 (last updated February 22, 2025)
CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.
Attacker Value
Unknown

CVE-2020-12526

Disclosure Date: April 27, 2021 (last updated February 22, 2025)
TwinCAT OPC UA Server in versions up to 2.3.0.12 and IPC Diagnostics UA Server in versions up to 3.1.0.1 from Beckhoff Automation GmbH & Co. KG are vulnerable to denial of service attacks. The attacker needs to send several specifically crafted requests to the running OPC UA server. After some of these requests the OPC UA server is no longer responsive to any client. This is without effect to the real-time functionality of IPCs.
Attacker Value
Unknown

CVE-2021-27389

Disclosure Date: April 22, 2021 (last updated February 22, 2025)
A vulnerability has been identified in Opcenter Quality (All versions < V12.2), QMS Automotive (All versions < V12.30). A private sign key is shipped with the product without adequate protection.
Attacker Value
Unknown

CVE-2021-29661

Disclosure Date: April 02, 2021 (last updated February 22, 2025)
Softing AG OPC Toolbox through 4.10.1.13035 allows /en/diag_values.html Stored XSS via the ITEMLISTVALUES##ITEMID parameter, resulting in JavaScript payload injection into the trace file. This payload will then be triggered every time an authenticated user browses the page containing it.
Attacker Value
Unknown

CVE-2021-29660

Disclosure Date: April 02, 2021 (last updated February 22, 2025)
A Cross-Site Request Forgery (CSRF) vulnerability in en/cfg_setpwd.html in Softing AG OPC Toolbox through 4.10.1.13035 allows attackers to reset the administrative password by inducing the Administrator user to browse a URL controlled by an attacker.
Attacker Value
Unknown

CVE-2021-26916

Disclosure Date: February 08, 2021 (last updated February 22, 2025)
In nopCommerce 4.30, a Reflected XSS issue in the Discount Coupon component allows remote attackers to inject arbitrary web script or HTML through the Filters/CheckDiscountCouponAttribute.cs discountcode parameter.
Attacker Value
Unknown

CVE-2020-27295

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
The affected product has uncontrolled resource consumption issues, which may allow an attacker to cause a denial-of-service condition on the OPC UA Tunneller (versions prior to 6.3.0.8233).
Attacker Value
Unknown

CVE-2020-27297

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
The affected product is vulnerable to a heap-based buffer overflow, which may allow an attacker to manipulate memory with controlled values and remotely execute code on the OPC UA Tunneller (versions prior to 6.3.0.8233).
Attacker Value
Unknown

CVE-2020-27274

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
Some parsing functions in the affected product do not check the return value of malloc and the thread handling the message is forced to close, which may lead to a denial-of-service condition on the OPC UA Tunneller (versions prior to 6.3.0.8233).