Show filters
941 Total Results
Displaying 281-290 of 941
Sort by:
Attacker Value
Unknown

CVE-2021-22824

Disclosure Date: February 11, 2022 (last updated February 23, 2025)
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in denial of service, due to missing length check on user-supplied data from a constructed message received on the network. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21320 and prior)
Attacker Value
Unknown

CVE-2021-22823

Disclosure Date: February 11, 2022 (last updated February 23, 2025)
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user running IGSS due to lack of validation of network messages. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21320 and prior)
Attacker Value
Unknown

CVE-2021-22806

Disclosure Date: February 11, 2022 (last updated February 23, 2025)
A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could cause data exfiltration and unauthorized access when accessing a malicious website. Affected Product: spaceLYnk (V2.6.1 and prior), Wiser for KNX (V2.6.1 and prior), fellerLYnk (V2.6.1 and prior)
Attacker Value
Unknown

CVE-2021-22805

Disclosure Date: February 11, 2022 (last updated February 23, 2025)
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user running IGSS due to lack of validation of network messages. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior)
Attacker Value
Unknown

CVE-2021-22804

Disclosure Date: February 11, 2022 (last updated February 23, 2025)
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause disclosure of arbitrary files being read in the context of the user running IGSS, due to missing validation of user supplied data in network messages. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior)
Attacker Value
Unknown

CVE-2021-22803

Disclosure Date: February 11, 2022 (last updated February 23, 2025)
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could lead to remote code execution through a number of paths, when an attacker, writes arbitrary files to folders in context of the DC module, by sending constructed messages on the network. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior)
Attacker Value
Unknown

CVE-2021-22802

Disclosure Date: February 11, 2022 (last updated February 23, 2025)
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution due to missing length check on user supplied data, when a constructed message is received on the network. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior)
Attacker Value
Unknown

CVE-2021-22801

Disclosure Date: February 11, 2022 (last updated February 23, 2025)
A CWE-269: Improper Privilege Management vulnerability exists that could cause an arbitrary command execution when the software is configured with specially crafted event actions. Affected Product: ConneXium Network Manager Software (All Versions)
Attacker Value
Unknown

CVE-2021-22800

Disclosure Date: February 11, 2022 (last updated February 23, 2025)
A CWE-20: Improper Input Validation vulnerability exists that could cause a Denial of Service when a crafted packet is sent to the controller over network port 1105/TCP. Affected Product: Modicon M218 Logic Controller (V5.1.0.6 and prior)
Attacker Value
Unknown

CVE-2021-22798

Disclosure Date: February 11, 2022 (last updated February 23, 2025)
A CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause Sensitive data such as login credentials being exposed when a Network is sniffed. Affected Product: Conext� ComBox (All Versions)