Show filters
43 Total Results
Displaying 21-30 of 43
Sort by:
Attacker Value
Unknown

CVE-2020-25176

Disclosure Date: March 18, 2022 (last updated October 07, 2023)
Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in the file system. Since the parameter pointing to the file name is not checked for reserved characters, it is possible for a remote, unauthenticated attacker to traverse an application’s directory, which could lead to remote code execution.
Attacker Value
Unknown

CVE-2021-22770

Disclosure Date: July 21, 2021 (last updated February 23, 2025)
A CWE-200: Information Exposure vulnerability exists in Easergy T300 with firmware V2.7.1 and older that exposes sensitive information to an actor not explicitly authorized to have access to that information.
Attacker Value
Unknown

CVE-2021-22771

Disclosure Date: July 21, 2021 (last updated February 23, 2025)
A CWE-1236: Improper Neutralization of Formula Elements in a CSV File vulnerability exists in Easergy T300 with firmware V2.7.1 and older that would allow arbitrary command execution.
Attacker Value
Unknown

CVE-2021-22769

Disclosure Date: June 11, 2021 (last updated February 22, 2025)
A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Easergy T300 with firmware V2.7.1 and older that could expose files or directory content when access from an attacker is not restricted or incorrectly restricted.
Attacker Value
Unknown

CVE-2020-28216

Disclosure Date: December 11, 2020 (last updated February 22, 2025)
A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to read network traffic over HTTP protocol.
Attacker Value
Unknown

CVE-2020-28217

Disclosure Date: December 11, 2020 (last updated February 22, 2025)
A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to read network traffic over HTTP protocol.
Attacker Value
Unknown

CVE-2020-28218

Disclosure Date: December 11, 2020 (last updated February 22, 2025)
A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to trick a user into initiating an unintended action.
Attacker Value
Unknown

CVE-2020-28215

Disclosure Date: December 11, 2020 (last updated February 22, 2025)
A CWE-862: Missing Authorization vulnerability exists in Easergy T300 (firmware 2.7 and older), that could cause a wide range of problems, including information exposures, denial of service, and arbitrary code execution when access control checks are not applied consistently.
Attacker Value
Unknown

CVE-2020-7561

Disclosure Date: November 19, 2020 (last updated February 22, 2025)
A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T300 (with firmware 2.7 and older) that could cause a wide range of problems, including information exposure, denial of service, and command execution when access to a resource from an attacker is not restricted or incorrectly restricted.
Attacker Value
Unknown

CVE-2020-7507

Disclosure Date: June 16, 2020 (last updated February 21, 2025)
A CWE-400: Uncontrolled Resource Consumption vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to login multiple times resulting in a denial of service.