Show filters
247 Total Results
Displaying 31-40 of 247
Sort by:
Attacker Value
Unknown
CVE-2023-41372
Disclosure Date: October 25, 2023 (last updated November 07, 2023)
The vulnerability allows an unprivileged (untrusted) third- party application to arbitrary modify the server settings of the Android Client application, inducing it to connect to an attacker - controlled malicious server.This is possible by forging a valid broadcast intent encrypted with a hardcoded RSA key pair
0
Attacker Value
Unknown
CVE-2023-41255
Disclosure Date: October 25, 2023 (last updated November 07, 2023)
The vulnerability allows an unprivileged user with access to the subnet of the TPC-110W device to gain a root shell on the device itself abusing the lack of authentication
of the ‘su’ binary file installed on the device that can be accessed through the ADB (Android Debug Bridge) protocol exposed on the network.
0
Attacker Value
Unknown
CVE-2022-4046
Disclosure Date: August 03, 2023 (last updated October 08, 2023)
In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user privileges to gain full access of the device.
0
Attacker Value
Unknown
CVE-2023-37559
Disclosure Date: August 03, 2023 (last updated October 08, 2023)
After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37558
0
Attacker Value
Unknown
CVE-2023-37558
Disclosure Date: August 03, 2023 (last updated October 08, 2023)
After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37559
0
Attacker Value
Unknown
CVE-2023-37557
Disclosure Date: August 03, 2023 (last updated October 08, 2023)
After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted remote communication requests can cause the CmpAppBP component to overwrite a heap-based buffer, which can lead to a denial-of-service condition.
0
Attacker Value
Unknown
CVE-2023-37556
Disclosure Date: August 03, 2023 (last updated October 08, 2023)
In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-37553, CVE-2023-37554 and CVE-2023-37555.
0
Attacker Value
Unknown
CVE-2023-37555
Disclosure Date: August 03, 2023 (last updated October 08, 2023)
In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-37553, CVE-2023-37554 and CVE-2023-37556.
0
Attacker Value
Unknown
CVE-2023-37554
Disclosure Date: August 03, 2023 (last updated October 08, 2023)
In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-37553, CVE-2023-37555 and CVE-2023-37556.
0
Attacker Value
Unknown
CVE-2023-37553
Disclosure Date: August 03, 2023 (last updated October 08, 2023)
In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-37554, CVE-2023-37555 and CVE-2023-37556.
0