Show filters
62 Total Results
Displaying 31-40 of 62
Sort by:
Attacker Value
Unknown

CVE-2022-38743

Disclosure Date: October 17, 2022 (last updated October 08, 2023)
Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an improper access control vulnerability. The FactoryTalk VantagePoint SQL Server account could allow a malicious user with read-only privileges to execute SQL statements in the back-end database. If successfully exploited, this could allow the attacker to execute arbitrary code and gain access to restricted data.
Attacker Value
Unknown

CVE-2020-28419

Disclosure Date: November 09, 2021 (last updated October 07, 2023)
During installation with certain driver software or application packages an arbitrary code execution could occur.
Attacker Value
Unknown

CVE-2020-7590

Disclosure Date: October 13, 2020 (last updated February 22, 2025)
A vulnerability has been identified in DCA Vantage Analyzer (All versions < V4.5 are affected by CVE-2020-7590. In addition, serial numbers < 40000 running software V4.4.0 are also affected by CVE-2020-15797). Affected devices use a hard-coded password to protect the onboard database. This could allow an attacker to read and or modify the onboard database. Successful exploitation requires direct physical access to the device.
Attacker Value
Unknown

CVE-2020-15797

Disclosure Date: October 13, 2020 (last updated February 22, 2025)
A vulnerability has been identified in DCA Vantage Analyzer (All versions < V4.5 are affected by CVE-2020-7590. In addition, serial numbers < 40000 running software V4.4.0 are also affected by CVE-2020-15797). Improper Access Control could allow an unauthenticated attacker to escape from the restricted environment (“kiosk mode”) and access the underlying operating system. Successful exploitation requires direct physical access to the system.
Attacker Value
Unknown

CVE-2020-8316

Disclosure Date: May 14, 2020 (last updated February 21, 2025)
A vulnerability was reported in Lenovo Vantage prior to version 10.2003.10.0 that could allow an authenticated user to read files on the system with elevated privileges.
Attacker Value
Unknown

CVE-2020-8327

Disclosure Date: April 14, 2020 (last updated February 21, 2025)
A privilege escalation vulnerability was reported in LenovoBatteryGaugePackage for Lenovo System Interface Foundation bundled in Lenovo Vantage prior to version 10.2003.10.0 that could allow an authenticated user to execute code with elevated privileges.
Attacker Value
Unknown

CVE-2019-18917

Disclosure Date: March 16, 2020 (last updated February 21, 2025)
A potential security vulnerability has been identified for certain HP Printers and All-in-Ones that would allow bypassing account lockout.
Attacker Value
Unknown

CVE-2020-7959

Disclosure Date: February 17, 2020 (last updated February 21, 2025)
LabVantage LIMS 8.3 does not properly maintain the confidentiality of database names. For example, the web application exposes the database name. An attacker might be able to enumerate database names by providing his own database name in a request, because the response will return an 'Unrecognized Database exception message if the database does not exist.
Attacker Value
Unknown

CVE-2020-9025

Disclosure Date: February 17, 2020 (last updated February 21, 2025)
Iteris Vantage Velocity Field Unit 2.4.2 devices have multiple stored XSS issues in all parameters of the Start Data Viewer feature of the /cgi-bin/loaddata.py script.
Attacker Value
Unknown

CVE-2020-9023

Disclosure Date: February 17, 2020 (last updated February 21, 2025)
Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have two users that are not documented and are configured with weak passwords (User bluetooth, password bluetooth; User eclipse, password eclipse). Also, bluetooth is the root password.