Show filters
233 Total Results
Displaying 151-160 of 233
Sort by:
Attacker Value
Unknown
CVE-2020-10267
Disclosure Date: April 06, 2020 (last updated February 21, 2025)
Universal Robots control box CB 3.1 across firmware versions (tested on 1.12.1, 1.12, 1.11 and 1.10) does not encrypt or protect in any way the intellectual property artifacts installed from the UR+ platform of hardware and software components (URCaps). These files (*.urcaps) are stored under '/root/.urcaps' as plain zip files containing all the logic to add functionality to the UR3, UR5 and UR10 robots. This flaw allows attackers with access to the robot or the robot network (while in combination with other flaws) to retrieve and easily exfiltrate all installed intellectual property.
0
Attacker Value
Unknown
CVE-2020-10265
Disclosure Date: April 06, 2020 (last updated February 21, 2025)
Universal Robots Robot Controllers Version CB2 SW Version 1.4 upwards, CB3 SW Version 3.0 and upwards, e-series SW Version 5.0 and upwards expose a service called DashBoard server at port 29999 that allows for control over core robot functions like starting/stopping programs, shutdown, reset safety and more. The DashBoard server is not protected by any kind of authentication or authorization.
0
Attacker Value
Unknown
CVE-2020-10264
Disclosure Date: April 01, 2020 (last updated February 21, 2025)
CB3 SW Version 3.3 and upwards, e-series SW Version 5.0 and upwards allow authenticated access to the RTDE (Real-Time Data Exchange) interface on port 30004 which allows setting registers, the speed slider fraction as well as digital and analog Outputs. Additionally unautheticated reading of robot data is also possible
0
Attacker Value
Unknown
CVE-2011-0220
Disclosure Date: February 05, 2020 (last updated February 21, 2025)
Apple Bonjour before 2011 allows a crash via a crafted multicast DNS packet.
0
Attacker Value
Unknown
CF CLI writes the client id and secret to config file
Disclosure Date: August 05, 2019 (last updated November 27, 2024)
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.
0
Attacker Value
Unknown
CVE-2019-13505
Disclosure Date: July 11, 2019 (last updated November 27, 2024)
The Appointment Hour Booking plugin 1.1.44 for WordPress allows XSS via the E-mail field, as demonstrated by email_1.
0
Attacker Value
Unknown
CVE-2018-18802
Disclosure Date: June 18, 2019 (last updated November 27, 2024)
The Tubigan "Welcome to our Resort" 1.0 software allows CSRF via admin/mod_users/controller.php?action=edit.
0
Attacker Value
Unknown
CVE-2018-18800
Disclosure Date: May 14, 2019 (last updated November 27, 2024)
The Tubigan "Welcome to our Resort" 1.0 software allows SQL Injection via index.php?p=accomodation&q=[SQL], index.php?p=rooms&q=[SQL], or admin/login.php.
0
Attacker Value
Unknown
CVE-2018-18979
Disclosure Date: May 06, 2019 (last updated November 27, 2024)
An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically coded initialization vector. Extraction of the initialization vector is necessary for deciphering communications between this application and the backend server. This, in combination with retrieving any user's encrypted data from the Ascensia cloud through another vulnerability, allows an attacker to obtain and modify any patient's medical information.
0
Attacker Value
Unknown
CVE-2018-18977
Disclosure Date: May 06, 2019 (last updated November 27, 2024)
An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. An attacker may reverse engineer the codebase to extract sensitive data that contributes to the disclosure of medical information of patients utilizing the Ascensia platform. This occurs because of weak obfuscation.
0